Ratproxy audit report

Generated on: 2008/07/10 11:28
Input file: /download/ratproxy/libero/ratproxy.log

NOTE: Not all of the issues reported necessarily correspond to actual security flaws. Findings should be validated by manual testing and analysis where appropriate. When in doubt, contact the author.


Report risk and risk modifier designations:
LOW to HIGH Issue urgency classification (composite of impact and identification accuracy)
INFO Non-discriminatory entry for further analysis
ECHO / echo Query parameters echoed back / not echoed in HTTP response, respectively
PRED / pred Request URL or query data likely is / is not predictable to third parties, respectively
AUTH / auth Request requires / does not require cookie authentication, respectively


POST query with no XSRF protection [toggle]
    Parameter-accepting POST requests that lack security tokens. Some POST requests change application state, and may be vulnerable to cross-site request forgery attacks.

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=fb410a8fa378c066535f1e05aa473150%2Eflv
    Response (330): s=1&msg1=&url_base=http://video.libero.it/static&media_id=173950&url_swf=/swf/&url_flv=/video16/f/b/4/fb410a8fa378c066535f1e05aa473150.flv&url_thumb=/video16/f/b/4/fb410a8fa378c066535f1e05aa473150_0.jpg&flen=277&fx=320&fy=256&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=e75cbc00bce10147d074d38fc14f16e6%2Eflv
    Response (330): s=1&msg1=&url_base=http://video.libero.it/static&media_id=175437&url_swf=/swf/&url_flv=/video15/e/7/5/e75cbc00bce10147d074d38fc14f16e6.flv&url_thumb=/video15/e/7/5/e75cbc00bce10147d074d38fc14f16e6_0.jpg&flen=158&fx=320&fy=256&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=61b3a97e0f17d5d78e73be49de594487
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=18085&url_swf=/swf/&url_flv=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487.flv&url_thumb=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487_0.jpg&flen=378&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=879e2b8814f0285cd851ef702d1f074e
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=4366db2f9990f509e735d7496f3a4f78%2Eflv
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=77960&url_swf=/swf/&url_flv=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78.flv&url_thumb=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78_0.jpg&flen=260&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=b80979a5a5f1533c4d4a8f6b2bfc3a3a
    MIME type: text/html, detected: application/x-javascript, charset: -

MIME type mismatch on renderable file [toggle]
    Text documents that seem to have a poorly chosen Content-Type value. Even slight mismatches may trigger content sniffing in Internet Explorer, and potentially lead to cross-site scripting if any part of the file is user-controlled.

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=fb410a8fa378c066535f1e05aa473150%2Eflv
    Response (330): s=1&msg1=&url_base=http://video.libero.it/static&media_id=173950&url_swf=/swf/&url_flv=/video16/f/b/4/fb410a8fa378c066535f1e05aa473150.flv&url_thumb=/video16/f/b/4/fb410a8fa378c066535f1e05aa473150_0.jpg&flen=277&fx=320&fy=256&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=e75cbc00bce10147d074d38fc14f16e6%2Eflv
    Response (330): s=1&msg1=&url_base=http://video.libero.it/static&media_id=175437&url_swf=/swf/&url_flv=/video15/e/7/5/e75cbc00bce10147d074d38fc14f16e6.flv&url_thumb=/video15/e/7/5/e75cbc00bce10147d074d38fc14f16e6_0.jpg&flen=158&fx=320&fy=256&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=61b3a97e0f17d5d78e73be49de594487
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=18085&url_swf=/swf/&url_flv=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487.flv&url_thumb=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487_0.jpg&flen=378&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=879e2b8814f0285cd851ef702d1f074e
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=4366db2f9990f509e735d7496f3a4f78%2Eflv
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=77960&url_swf=/swf/&url_flv=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78.flv&url_thumb=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78_0.jpg&flen=260&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=b80979a5a5f1533c4d4a8f6b2bfc3a3a
    MIME type: text/html, detected: application/x-javascript, charset: -

External code inclusion [toggle] Dynamic Javascript for direct inclusion [toggle]
    Server-generated, authenticated Javascript apparently structured for <SCRIPT SRC=...> or eval(...) consumption. If the code reveals any sensitive user data and lacks XSRF defenses, privacy breaches may occur.

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=fb410a8fa378c066535f1e05aa473150%2Eflv
    Response (330): s=1&msg1=&url_base=http://video.libero.it/static&media_id=173950&url_swf=/swf/&url_flv=/video16/f/b/4/fb410a8fa378c066535f1e05aa473150.flv&url_thumb=/video16/f/b/4/fb410a8fa378c066535f1e05aa473150_0.jpg&flen=277&fx=320&fy=256&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=e75cbc00bce10147d074d38fc14f16e6%2Eflv
    Response (330): s=1&msg1=&url_base=http://video.libero.it/static&media_id=175437&url_swf=/swf/&url_flv=/video15/e/7/5/e75cbc00bce10147d074d38fc14f16e6.flv&url_thumb=/video15/e/7/5/e75cbc00bce10147d074d38fc14f16e6_0.jpg&flen=158&fx=320&fy=256&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=61b3a97e0f17d5d78e73be49de594487
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=18085&url_swf=/swf/&url_flv=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487.flv&url_thumb=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487_0.jpg&flen=378&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=879e2b8814f0285cd851ef702d1f074e
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=4366db2f9990f509e735d7496f3a4f78%2Eflv
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=77960&url_swf=/swf/&url_flv=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78.flv&url_thumb=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78_0.jpg&flen=260&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=b80979a5a5f1533c4d4a8f6b2bfc3a3a
    MIME type: text/html, detected: application/x-javascript, charset: -

Bad caching headers [toggle]
    Pages that set cookies or require authentication, but have HTTP headers that may, in some scenarios, lead to proxy-level document caching. Depending on runtime settings, this may also include subtle HTTP/1.1 and HTTP/1.0 intent mismatches (such as Cache-Control: private with no Expires header).

  • HIGHecho PRED auth GET http://www.libero.it:80/ ⇒ 200 [view trace]
    Response (129624): <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">\n<HTML>\n<HEAD>\n<META http-equiv="content-type" content="text/html; charset=iso-8859-1">\n<META name="description" content="Libero.it: Community, Search, Mail, News, Video, Adsl & Internet">\n<META name="keywords" content="Libero, Community, Search, Mail, News, Video, Adsl & Internet">\n<TITLE>Libero</TITLE>\n<LINK rel="shortcut icon" type="images/x-icon" href="http://img3.iol.it/i/favicon.ico">\n\n<!-- armonia -->\n<style>\nbody{background-image:url(http://img1.iol.it/i/200803/bg_nero.gif);background-repeat:repeat-x;text-align:center;}\ninput{font-size:11px;font-family:Tahoma, Arial,sans-serif;}\n\nform{display:inline;}\na,a:hover{text-decoration:underline;}\na:hover{color:#000066;}...
    Cookies set: Libero=78.46.80.205.1215682043004499
    Offending value: cacheable SetCookie
    MIME type: text/html, detected: text/html, charset: iso-8859-1

Bad or no charset declared for renderable file [toggle]
    Text documents with missing, mistyped, or obscure character sets (see config.h). For some values, UTF-7 and other types of character set sniffing in Internet Explorer may occur if any part of the file is user-controlled.

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=fb410a8fa378c066535f1e05aa473150%2Eflv
    Response (330): s=1&msg1=&url_base=http://video.libero.it/static&media_id=173950&url_swf=/swf/&url_flv=/video16/f/b/4/fb410a8fa378c066535f1e05aa473150.flv&url_thumb=/video16/f/b/4/fb410a8fa378c066535f1e05aa473150_0.jpg&flen=277&fx=320&fy=256&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=e75cbc00bce10147d074d38fc14f16e6%2Eflv
    Response (330): s=1&msg1=&url_base=http://video.libero.it/static&media_id=175437&url_swf=/swf/&url_flv=/video15/e/7/5/e75cbc00bce10147d074d38fc14f16e6.flv&url_thumb=/video15/e/7/5/e75cbc00bce10147d074d38fc14f16e6_0.jpg&flen=158&fx=320&fy=256&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=61b3a97e0f17d5d78e73be49de594487
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=18085&url_swf=/swf/&url_flv=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487.flv&url_thumb=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487_0.jpg&flen=378&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=879e2b8814f0285cd851ef702d1f074e
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=4366db2f9990f509e735d7496f3a4f78%2Eflv
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=77960&url_swf=/swf/&url_flv=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78.flv&url_thumb=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78_0.jpg&flen=260&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=b80979a5a5f1533c4d4a8f6b2bfc3a3a
    MIME type: text/html, detected: application/x-javascript, charset: -

  • HIGHECHO PRED auth GET http://blog.libero.it:80/maxsoblog/view.php?nocache=1215682105 ⇒ 200 [view trace]
    Response (114597): \n\n<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">\n<html>\n<head>\n<title>Maxso's Blog - Libero Community - Blog</title>\n\n<META NAME="Keywords" CONTENT="community, chat, blog, forum, cupido, dating, pagine personali">\n\n<link rel='stylesheet' type=text/css href='/blog/css/moblog.css'>\n<link rel='stylesheet' type=text/css href='/blog/css/skin/67/blue.css'>\n<script type='text/javascript' src='/blog/js/fx_blog.js'></script>\n\n<script language="javascript">\n<!--\nnav_name = navigator.userAgent.toLowerCase();\nis_opera = (nav_name.indexOf("opera") != -1);\nis_mac = (nav_name.indexOf("mac") != -1);\nif (is_opera || is_mac){\n\tdocument.write('<style> .defender { overflow: hidden; } </style>');\n}\n-->\n</sc...
    Cookies set: PHPSESSIDMOB=51a97ff659e142796c021e8c3e5826c0; DGL_UPD_LOGIN=0; BG_RT=f_41_C_41__3d_kRIK_2d_0N_2d_rc_7c_Tn5Vzl_3d_g1nrc_7c_Tn5V0_41_up_3d_mpPvbEz8Y_7c_mbE5k_3d_O
    MIME type: text/html, detected: text/html, charset: -

  • LOWecho PRED auth GET http://blog.libero.it:80/blog/js/fx_blog.js ⇒ 200 [view trace]
    Response (7120): // fx_01.js (c)2K2 Digiland - Italia OnLine\n\n// Browser ID\n\nvar DG_BROW_N="UNK";\nvar DG_BROW_V=0;\nvar DG_PLAT="UNK";\nvar DG_JAVA=false;\n\nvar agt=navigator.userAgent.toLowerCase();\nvar appVer = navigator.appVersion.toLowerCase();\nvar is_minor = parseFloat(appVer);\nvar is_major = parseInt(is_minor);\n\nvar iePos = appVer.indexOf('msie');\nif (iePos !=-1) {\n\tis_minor = parseFloat(appVer.substring(iePos+5,appVer.indexOf(';',iePos)))\n\tis_major = parseInt(is_minor);\n}\nvar nav6Pos = agt.indexOf('netscape6');\nif (nav6Pos !=-1) {\n\tis_minor = parseFloat(agt.substring(nav6Pos+10))\n\tis_major = parseInt(is_minor)\n}\n\nDG_BROW_V=is_major;\n\nif (document.layers) DG_BROW_N="nav";\nif (document.all)\n\tDG_BROW_N="ie";\nelse\n\tif (document.getElementById) DG_BROW_N="nav";\n\nif (agt.indexOf("opera")!=-1) DG_BROW_N="opera";\n\nif (agt.indexOf("win")!=-1) DG_PLAT="win";\nif (agt.index...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digiland.libero.it:80/fsrscripts/triggerParams.js ⇒ 200 [view trace]
    Response (5871): /****Customer: Bitbang Libero.it\r\n/************ don't modify below this line *********\r\n ************* Version: Std 5.3 v.21 ***********\r\n ****** Copyright 2001-2008 ForeseeResults, Inc****/\r\n\r\n/**MAIN PARAMETERS**/\r\nif(!window.foresee) window.foresee = new Object();\r\nforesee.triggerParms= new Array();\r\nforesee.triggerParms["displayMode"] = 3;\t\t \t\t //0=disable survey, 1=Invitation when PUB present, 2=No Invitation, 3=Invitation Only\r\nforesee.triggerParms["mid"] = "1QVsNQE84xlUw9shYVAV9g=="; // model instance id (Default is XYZ Company survey) - Comment if using 'sid'\r\nforesee.triggerParms["cid"] = "Yg0U0ckBU8dZkRZxYY59lw=="; // customer id\r\nforesee.triggerParms["lf"] = 0;\t\t \t \t \t\t\t// * loyalty factor 5\r\nforesee.triggerParms["sp"] = 10.0;\t \t\t \t\t\t// * sampling percentage 50\r\nforesee.triggerParms["rw"] = 129600; \t \t\t \t\t\t// duration of persistent surve...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digistatic.libero.it:80//js/search-header.js ⇒ 200 [view trace]
    Response (5134): if ( typeof(Libero) == "undefined" ) {\n\tLibero = {\n\t\tVersion: '1.0.0'\n };\n}\n\n// test prototype library\nif ( typeof(Prototype) == "undefined" ) {\n\tvar Class = {\n\t\tcreate: function() {\n\t\t\treturn function() {\n\t\t\t\tthis.initialize.apply(this, arguments);\n\t\t\t}\n\t\t}\n\t};\n\tObject.extend = function(destination, source) {\n\t\tfor (var property in source) {\n\t\t\tdestination[property] = source[property];\n \t\t}\n\t\treturn destination;\n\t};\n}\n\n// Create search class\nLibero.Search = Class.create();\nLibero.Search.prototype = {\n\n\t// constructor\n\tinitialize: function() {\n\t\tvar params = Object.extend({\n\t\t\tform_el: 'search',\n\t\t\tengine_el : 'search_engine',\n\t\t\tquery_el: 'search_query',\n\t\t\tclass_query_empty: 'sn-search-form-empty',\n\t\t\tclass_query: 'sn-search-form',\n\t\t\tinitial_query : '',\n\t\t\tengine_drivers: {\n\t\t\t\tvideo: {\n\t\t\t\t\taction: 'http://v...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://barra-spazio.libero.it:80//x/js/barra_n01.js ⇒ 200 [view trace]
    Response (4922): var bsl1_init;\nvar bsl1_init2;\nvar bsl1_sup=0;\nvar bsl1_ie=((document.all)&&(!window.opera));\n\nif (document.getElementById) bsl1_sup=1;\n\nfunction n_width() {\n\tif (self.innerHeight) return(self.innerWidth);\n\telse if (document.documentElement && document.documentElement.clientHeight) return(document.documentElement.clientWidth);\n\telse if (document.body) return(document.body.clientWidth);\n\treturn 0;\n}\n\nfunction bsl1_wd() {\n\tvar d = n_width();\n\tif (d!=bsl1_oldd) {\n\t\ta = document.getElementById('vb2main');\n\t\ta.style.width = d+"px";\n\t\tbsl1_oldd = d;\n\t}\n\tsetTimeout("bsl1_wd()", 250);\n}\n\nfunction bsl1_remote(ur) { \n \tvar element = document.createElement('script');\n\telement.setAttribute('type','text/javascript'); \n\telement.setAttribute('src',ur); \n\tdocument.body.appendChild(element);\n}\n\nfunction bsl1_ok(gu) {\n\tvar o = document.getElementById('bsl1-lbuff');\n\tif (o) o.innerHTML = gu;\n}\n...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digiland.libero.it:80/fsrscripts/stdLauncher.js ⇒ 200 [view trace]
    Response (28957): /****Customer: **SAMPLE CODE FOR TESTING ** NOT FOR PRODUCTION ****\r\n/************ don't modify below this line *********\r\n ************* Version: Std 5.3 v.21 ***********\r\n ****** Copyright 2001-2008 ForeseeResults, Inc****/\r\n \r\nforesee.popupURL = "//www.foreseeresults.com/survey/display";\t//do not change this url\r\nforesee.FSRImgURL= "//www.foreseeresults.com/survey/FSRImg"; \t//do not change this url\r\nforesee.CSURL= "//www.foreseeresults.com/survey/processCPP"; \t//do not change this url\r\nforesee.OTCImgURL = "//controller.foreseeresults.com/fsrSurvey/OTCImg";\r\nforesee.ckAlreadyShown = foresee.triggerParms["ascookie"]; /* name of the persistent/session cookie*/\r\nforesee.ckLoyaltyCount = foresee.triggerParms["lfcookie"]; /* name of the loyalty count cookie*/\r\nforesee.fullURL=null;\r\nforesee.myPopUp=null;\r\nforesee.detect = navigator.userAgent.toLowerCase();\r\nforesee.version= navigator.appVersion.toLowerCase();\r\nfor...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digistatic.libero.it:80//js/tbx.js ⇒ 200 [view trace]
    Response (1847): // SWITCHING TAB\n// pre = id_prefix\n// n = tab\n// i = mode (0,1)\n// area = area box\n// coo = cookie mode (0,1)\n\nvar tbx_stat = new Array();\n\nfunction tbx_switch(pre, n, i, area, coo) {\n\tif (document.getElementById) {\n\t\n\t\tif (coo == 1) {\n\t\t\tif (i==1) {\n\t\t\t\tvar cccc=tbx_gc("tbx"+area);\n\t\t\t\tif (cccc!='') n = cccc;\n\t\t\t} else {\n\t\t\t\tvar kk = "tbx" + area + "=" + n + "; path=/; domain=.libero.it";\n\t\t\t\tdocument.cookie=kk;\n\t\t\t}\n\t\t}\n\t\t\n\t\tvar d = document.getElementById(pre+n);\n\t\tvar dc = document.getElementById(pre+'c'+n);\n\n\t\tif (tbx_stat[pre]>0) {\n\t\t\tvar doo, dco;\n\t\t\tdoo = document.getElementById(pre+tbx_stat[pre]);\n\t\t\tdco = document.getElementById(pre+'c'+tbx_stat[pre]);\n\t\t\tdco.style.display="none";\n\t\t\tdoo.className = "";\n\t\t}\n\t\t\n\t\tdc.style.display = "block";\n\t\td.className = "act";\n\t\ttbx_stat[pre]=n;\n\n\t\t...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digiland.libero.it:80/ssi/menu_chat.html ⇒ 200 [view trace]
    Response (18090): <html>\n<link rel="stylesheet" type="text/css" href="/css/menu_chat.css" />\n<script language="JavaScript">\n<!--\nvar old = false;\nvar nome_stanza ='';\nfunction changestyle_stanza(o){\n\t\n\to.style.backgroundColor = '#000000';\n\to.style.color = '#FFFFFF';\n\tif (old) {\n\t\told.style.backgroundColor='';\n\t\told.style.color='#333333';\n\t}\t\n\told = o; \n}\t\n\nfunction apri_nodo(){\n\ttrees[nodo_root].toggle(nodo_ingresso);\n\told= document.getElementById('i_txt' + nodo_root + '_' + nodo_stanza);\n\told.style.backgroundColor = '#000000';\n\told.style.color = '#FFFFFF';\n}\t\nfunction tree (a_items, a_template) {\n\n\tthis.a_tpl = a_template;\n\tthis.a_config = a_items;\n\tthis.o_root = this;\n\tthis.a_index = [];\n\tthis.o_selected = null;\n\tthis.n_depth = -1;\n\t\n\tvar o_icone = new Image(),\n\t\to_iconl = new Image();\n...
    MIME type: text/html, detected: text/html, charset: -

  • LOWecho PRED auth GET http://digistatic.libero.it:80//js/header.js ⇒ 200 [view trace]
    Response (1401): var com_userAgent=navigator.userAgent.toLowerCase();\n//linux\nif(com_userAgent.indexOf("linux")!=-1){ \n\tdocument.write('<style>');\n\tdocument.write('.com_v7-riga-top_off, .com_v7-riga-top_on{font-size:11px}');\n\tdocument.write('.com_v7-riga-sotto-top,.com_v7-riga-sotto-top_on{font-size:10px}');\n\tdocument.write('</style>');\n}\nif(com_userAgent.indexOf("safari")!=-1){ \n\tdocument.write('<style>');\n\tdocument.write('#com_v7-query{font-size:11px;}');\n\tdocument.write('</style>');\n}\n\n\n\t//adv\n\tfunction adv_flashDisp(flashobj)\n\t{if (typeof(flashobj)!='undefined'&&flashobj!=''){document.write(flashobj);}}\n\n\tfunction com07e_controlla(area_click){\n\t\tq=encodeURIComponent(document.search.query.value);\n\t\tif (q == '') {\n\t\t\tckSrv('http://arianna.libero.it','HF1',area_click,'s1',null);\n\t\t\treturn false;...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digistatic.libero.it:80//js/nu08.js ⇒ 200 [view trace]
    Response (11339): function dgl_vars(){\n\n\tvar av = navigator.appVersion; // retrocomp\n\tvar ua = navigator.userAgent; // retrocomp\n\n\tthis.dom = document.getElementById?1:0;\n\tthis.op = (ua.indexOf("pera")>-1)?1:0;\n\tthis.ie = (ua.indexOf("MSIE")>-1 && this.dom && !this.op)?1:0;\n\tthis.ie4 = (document.all && !this.dom)?1:0;\n\tthis.ns4 = (document.layers && !this.dom)?1:0;\n\tthis.gecko = (this.dom && ua.indexOf("Gecko")>-1)?1:0;\n\tthis.comp = (this.dom || this.ie4)?1:0;\n\tthis.win = (ua.indexOf('Windows')>-1)?1:0;\n\tthis.mx=-1;\n\tthis.my=-1;\n\tthis.tip=-1;\n\tthis.mac= (av.indexOf("Mac")>-1)?1:0;\n\treturn this\n}\n\nvar dgl=new dgl_vars();\n\nvar n_lay = Array();\n\nvar n_path = 'http://digiland.libero.it/x/pics/nu/';\nvar n_laytmr=false;\nvar n_lay_act=false;\nvar n_pagew = 0;\nvar n_scrh = 0;\nvar n_info_pic = n_path + 'info_s.gif';\nvar n_warn_pic = n_path + 'alert_s.gif';\nvar n_stip_tm = Array...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://spazio.libero.it:80/x/js/base.js ⇒ 200 [view trace]
    Response (10194): function dgl_vars(){\n\n\tvar av = navigator.appVersion; // retrocomp\n\tvar ua = navigator.userAgent; // retrocomp\n\n\tthis.dom = document.getElementById?1:0;\n\tthis.op = (ua.indexOf("pera")>-1)?1:0;\n\tthis.ie = (ua.indexOf("MSIE")>-1 && this.dom && !this.op)?1:0;\n\tthis.ie4 = (document.all && !this.dom)?1:0;\n\tthis.ns4 = (document.layers && !this.dom)?1:0;\n\tthis.gecko = (this.dom && ua.indexOf("Gecko")>-1)?1:0;\n\tthis.comp = (this.dom || this.ie4)?1:0;\n\tthis.win = (ua.indexOf('Windows')>-1)?1:0;\n\tthis.mx=-1;\n\tthis.my=-1;\n\tthis.tip=-1;\n\tthis.mac= (av.indexOf("Mac")>-1)?1:0;\n\treturn this\n}\n\nvar dgl=new dgl_vars();\n\nvar n_lay = Array();\n\nvar n_laytmr=false;\nvar n_lay_act=false;\nvar n_pagew = 0;\nvar n_scrh = 0;\nvar n_info_pic = '/x/pics/nu/info_s.gif';\nvar n_warn_pic = '/x/pics/nu/alert_s.gif';\nvar n_stip_tm = Array();\nvar n_newmsg = false;\nvar n_bcstid = false;\nvar n_bcs...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

Risky Javascript code [toggle]
    Pages that seem to contain potentially dangerous or discouraged Javascript statements. These statements are particularly likely to open up security vulnerabilities on the page, and as such, the code should be carefully analyzed.

  • MEDIUMECHO PRED auth GET http://blog.libero.it:80/maxsoblog/view.php?nocache=1215682105 ⇒ 200 [view trace]
    Response (114597): \n\n<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">\n<html>\n<head>\n<title>Maxso's Blog - Libero Community - Blog</title>\n\n<META NAME="Keywords" CONTENT="community, chat, blog, forum, cupido, dating, pagine personali">\n\n<link rel='stylesheet' type=text/css href='/blog/css/moblog.css'>\n<link rel='stylesheet' type=text/css href='/blog/css/skin/67/blue.css'>\n<script type='text/javascript' src='/blog/js/fx_blog.js'></script>\n\n<script language="javascript">\n<!--\nnav_name = navigator.userAgent.toLowerCase();\nis_opera = (nav_name.indexOf("opera") != -1);\nis_mac = (nav_name.indexOf("mac") != -1);\nif (is_opera || is_mac){\n\tdocument.write('<style> .defender { overflow: hidden; } </style>');\n}\n-->\n</sc...
    Cookies set: PHPSESSIDMOB=51a97ff659e142796c021e8c3e5826c0; DGL_UPD_LOGIN=0; BG_RT=f_41_C_41__3d_kRIK_2d_0N_2d_rc_7c_Tn5Vzl_3d_g1nrc_7c_Tn5V0_41_up_3d_mpPvbEz8Y_7c_mbE5k_3d_O
    Offending value: document.referrer
    MIME type: text/html, detected: text/html, charset: -

  • MEDIUMecho PRED AUTH GET http://www.libero.it:80/ ⇒ 200 [view trace]
    Response (129615): <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">\n<HTML>\n<HEAD>\n<META http-equiv="content-type" content="text/html; charset=iso-8859-1">\n<META name="description" content="Libero.it: Community, Search, Mail, News, Video, Adsl & Internet">\n<META name="keywords" content="Libero, Community, Search, Mail, News, Video, Adsl & Internet">\n<TITLE>Libero</TITLE>\n<LINK rel="shortcut icon" type="images/x-icon" href="http://img3.iol.it/i/favicon.ico">\n\n<!-- latona -->\n<style>\nbody{background-image:url(http://img1.iol.it/i/200803/bg_nero.gif);background-repeat:repeat-x;text-align:center;}\ninput{font-size:11px;font-family:Tahoma, Arial,sans-serif;}\n\nform{display:inline;}\na,a:hover{text-decoration:underline;}\na:hover{color:#000066;}\n...
    Offending value: document.referrer
    MIME type: text/html, detected: text/html, charset: iso-8859-1

  • MEDIUMecho PRED auth GET http://digiland.libero.it:80/fsrscripts/stdLauncher.js ⇒ 200 [view trace]
    Response (28957): /****Customer: **SAMPLE CODE FOR TESTING ** NOT FOR PRODUCTION ****\r\n/************ don't modify below this line *********\r\n ************* Version: Std 5.3 v.21 ***********\r\n ****** Copyright 2001-2008 ForeseeResults, Inc****/\r\n \r\nforesee.popupURL = "//www.foreseeresults.com/survey/display";\t//do not change this url\r\nforesee.FSRImgURL= "//www.foreseeresults.com/survey/FSRImg"; \t//do not change this url\r\nforesee.CSURL= "//www.foreseeresults.com/survey/processCPP"; \t//do not change this url\r\nforesee.OTCImgURL = "//controller.foreseeresults.com/fsrSurvey/OTCImg";\r\nforesee.ckAlreadyShown = foresee.triggerParms["ascookie"]; /* name of the persistent/session cookie*/\r\nforesee.ckLoyaltyCount = foresee.triggerParms["lfcookie"]; /* name of the loyalty count cookie*/\r\nforesee.fullURL=null;\r\nforesee.myPopUp=null;\r\nforesee.detect = navigator.userAgent.toLowerCase();\r\nforesee.version= navigator.appVersion.toLowerCase();\r\nfor...
    Offending value: document.referrer
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • MEDIUMecho PRED auth GET http://spazio.libero.it:80/maxsof1/?top=1 ⇒ 200 [view trace]
    Response (22985): <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">\n<html>\n<head>\n<title>Libero - Community Profilo di maxsof1</title>\n<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">\n<META NAME="Description" CONTENT="Digiland è la community del portale Libero: Chat, Cupido, Messaggeria, Forum, Sondaggi, Tribu, Crea il tuo Sito e molto altro...">\n<META NAME="Keywords" CONTENT="community, chat, blog, forum, cupido, dating, pagine personali">\n<link rel="shortcut icon" href="/x/pics/hd_img/favicon.ico">\n\n\n<style type="text/css">\n@import url("http://barra-spazio.libero.it//x/css/barra_n01.css");\n</style>\n<script src="http://barra-spazio.libero.it//x/js/barra_n01.js" type="text/javascript" language="Javascript"></scri...
    Cookies set: SPAZIO_SESSID=fb949caf46de2245bb730db4b43f2fc1; DGL_UPD_LOGIN=0; DIGI_PVP=KcdC_3a__2f__2f_33ajAr_2e_8LptEX_2e_Ut_2f_4X2fRtK_2f_C11fxDr_2e_cK8_2d_KNdi6nScp0_2d_AvfFt0mSMIF1n
    Offending value: document.referrer
    MIME type: text/html, detected: text/html, charset: iso-8859-1

  • MEDIUMecho PRED auth GET http://www.libero.it:80/ ⇒ 200 [view trace]
    Response (129624): <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">\n<HTML>\n<HEAD>\n<META http-equiv="content-type" content="text/html; charset=iso-8859-1">\n<META name="description" content="Libero.it: Community, Search, Mail, News, Video, Adsl & Internet">\n<META name="keywords" content="Libero, Community, Search, Mail, News, Video, Adsl & Internet">\n<TITLE>Libero</TITLE>\n<LINK rel="shortcut icon" type="images/x-icon" href="http://img3.iol.it/i/favicon.ico">\n\n<!-- armonia -->\n<style>\nbody{background-image:url(http://img1.iol.it/i/200803/bg_nero.gif);background-repeat:repeat-x;text-align:center;}\ninput{font-size:11px;font-family:Tahoma, Arial,sans-serif;}\n\nform{display:inline;}\na,a:hover{text-decoration:underline;}\na:hover{color:#000066;}...
    Cookies set: Libero=78.46.80.205.1215682043004499
    Offending value: document.referrer
    MIME type: text/html, detected: text/html, charset: iso-8859-1

  • LOWECHO PRED auth GET http://blog.libero.it:80/maxsoblog/view.php?nocache=1215682105 ⇒ 200 [view trace]
    Response (114597): \n\n<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">\n<html>\n<head>\n<title>Maxso's Blog - Libero Community - Blog</title>\n\n<META NAME="Keywords" CONTENT="community, chat, blog, forum, cupido, dating, pagine personali">\n\n<link rel='stylesheet' type=text/css href='/blog/css/moblog.css'>\n<link rel='stylesheet' type=text/css href='/blog/css/skin/67/blue.css'>\n<script type='text/javascript' src='/blog/js/fx_blog.js'></script>\n\n<script language="javascript">\n<!--\nnav_name = navigator.userAgent.toLowerCase();\nis_opera = (nav_name.indexOf("opera") != -1);\nis_mac = (nav_name.indexOf("mac") != -1);\nif (is_opera || is_mac){\n\tdocument.write('<style> .defender { overflow: hidden; } </style>');\n}\n-->\n</sc...
    Cookies set: PHPSESSIDMOB=51a97ff659e142796c021e8c3e5826c0; DGL_UPD_LOGIN=0; BG_RT=f_41_C_41__3d_kRIK_2d_0N_2d_rc_7c_Tn5Vzl_3d_g1nrc_7c_Tn5V0_41_up_3d_mpPvbEz8Y_7c_mbE5k_3d_O
    Offending value: document.write
    MIME type: text/html, detected: text/html, charset: -

  • LOWecho PRED AUTH GET http://www.libero.it:80/ ⇒ 200 [view trace]
    Response (129615): <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">\n<HTML>\n<HEAD>\n<META http-equiv="content-type" content="text/html; charset=iso-8859-1">\n<META name="description" content="Libero.it: Community, Search, Mail, News, Video, Adsl & Internet">\n<META name="keywords" content="Libero, Community, Search, Mail, News, Video, Adsl & Internet">\n<TITLE>Libero</TITLE>\n<LINK rel="shortcut icon" type="images/x-icon" href="http://img3.iol.it/i/favicon.ico">\n\n<!-- latona -->\n<style>\nbody{background-image:url(http://img1.iol.it/i/200803/bg_nero.gif);background-repeat:repeat-x;text-align:center;}\ninput{font-size:11px;font-family:Tahoma, Arial,sans-serif;}\n\nform{display:inline;}\na,a:hover{text-decoration:underline;}\na:hover{color:#000066;}\n...
    Offending value: innerHTML, document.write
    MIME type: text/html, detected: text/html, charset: iso-8859-1

  • LOWecho PRED auth GET http://barra-spazio.libero.it:80//x/js/barra_n01.js ⇒ 200 [view trace]
    Response (4922): var bsl1_init;\nvar bsl1_init2;\nvar bsl1_sup=0;\nvar bsl1_ie=((document.all)&&(!window.opera));\n\nif (document.getElementById) bsl1_sup=1;\n\nfunction n_width() {\n\tif (self.innerHeight) return(self.innerWidth);\n\telse if (document.documentElement && document.documentElement.clientHeight) return(document.documentElement.clientWidth);\n\telse if (document.body) return(document.body.clientWidth);\n\treturn 0;\n}\n\nfunction bsl1_wd() {\n\tvar d = n_width();\n\tif (d!=bsl1_oldd) {\n\t\ta = document.getElementById('vb2main');\n\t\ta.style.width = d+"px";\n\t\tbsl1_oldd = d;\n\t}\n\tsetTimeout("bsl1_wd()", 250);\n}\n\nfunction bsl1_remote(ur) { \n \tvar element = document.createElement('script');\n\telement.setAttribute('type','text/javascript'); \n\telement.setAttribute('src',ur); \n\tdocument.body.appendChild(element);\n}\n\nfunction bsl1_ok(gu) {\n\tvar o = document.getElementById('bsl1-lbuff');\n\tif (o) o.innerHTML = gu;\n}\n...
    Offending value: innerHTML
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digistatic.libero.it:80//js/tbx.js ⇒ 200 [view trace]
    Response (1847): // SWITCHING TAB\n// pre = id_prefix\n// n = tab\n// i = mode (0,1)\n// area = area box\n// coo = cookie mode (0,1)\n\nvar tbx_stat = new Array();\n\nfunction tbx_switch(pre, n, i, area, coo) {\n\tif (document.getElementById) {\n\t\n\t\tif (coo == 1) {\n\t\t\tif (i==1) {\n\t\t\t\tvar cccc=tbx_gc("tbx"+area);\n\t\t\t\tif (cccc!='') n = cccc;\n\t\t\t} else {\n\t\t\t\tvar kk = "tbx" + area + "=" + n + "; path=/; domain=.libero.it";\n\t\t\t\tdocument.cookie=kk;\n\t\t\t}\n\t\t}\n\t\t\n\t\tvar d = document.getElementById(pre+n);\n\t\tvar dc = document.getElementById(pre+'c'+n);\n\n\t\tif (tbx_stat[pre]>0) {\n\t\t\tvar doo, dco;\n\t\t\tdoo = document.getElementById(pre+tbx_stat[pre]);\n\t\t\tdco = document.getElementById(pre+'c'+tbx_stat[pre]);\n\t\t\tdco.style.display="none";\n\t\t\tdoo.className = "";\n\t\t}\n\t\t\n\t\tdc.style.display = "block";\n\t\td.className = "act";\n\t\ttbx_stat[pre]=n;\n\n\t\t...
    Offending value: innerHTML
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digiland.libero.it:80/ssi/menu_chat.html ⇒ 200 [view trace]
    Response (18090): <html>\n<link rel="stylesheet" type="text/css" href="/css/menu_chat.css" />\n<script language="JavaScript">\n<!--\nvar old = false;\nvar nome_stanza ='';\nfunction changestyle_stanza(o){\n\t\n\to.style.backgroundColor = '#000000';\n\to.style.color = '#FFFFFF';\n\tif (old) {\n\t\told.style.backgroundColor='';\n\t\told.style.color='#333333';\n\t}\t\n\told = o; \n}\t\n\nfunction apri_nodo(){\n\ttrees[nodo_root].toggle(nodo_ingresso);\n\told= document.getElementById('i_txt' + nodo_root + '_' + nodo_stanza);\n\told.style.backgroundColor = '#000000';\n\told.style.color = '#FFFFFF';\n}\t\nfunction tree (a_items, a_template) {\n\n\tthis.a_tpl = a_template;\n\tthis.a_config = a_items;\n\tthis.o_root = this;\n\tthis.a_index = [];\n\tthis.o_selected = null;\n\tthis.n_depth = -1;\n\t\n\tvar o_icone = new Image(),\n\t\to_iconl = new Image();\n...
    Offending value: innerHTML
    MIME type: text/html, detected: text/html, charset: -

  • LOWecho PRED auth GET http://www.libero.it:80/ ⇒ 200 [view trace]
    Response (129624): <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">\n<HTML>\n<HEAD>\n<META http-equiv="content-type" content="text/html; charset=iso-8859-1">\n<META name="description" content="Libero.it: Community, Search, Mail, News, Video, Adsl & Internet">\n<META name="keywords" content="Libero, Community, Search, Mail, News, Video, Adsl & Internet">\n<TITLE>Libero</TITLE>\n<LINK rel="shortcut icon" type="images/x-icon" href="http://img3.iol.it/i/favicon.ico">\n\n<!-- armonia -->\n<style>\nbody{background-image:url(http://img1.iol.it/i/200803/bg_nero.gif);background-repeat:repeat-x;text-align:center;}\ninput{font-size:11px;font-family:Tahoma, Arial,sans-serif;}\n\nform{display:inline;}\na,a:hover{text-decoration:underline;}\na:hover{color:#000066;}...
    Cookies set: Libero=78.46.80.205.1215682043004499
    Offending value: innerHTML
    MIME type: text/html, detected: text/html, charset: iso-8859-1

  • LOWecho PRED auth GET http://digistatic.libero.it:80//js/nu08.js ⇒ 200 [view trace]
    Response (11339): function dgl_vars(){\n\n\tvar av = navigator.appVersion; // retrocomp\n\tvar ua = navigator.userAgent; // retrocomp\n\n\tthis.dom = document.getElementById?1:0;\n\tthis.op = (ua.indexOf("pera")>-1)?1:0;\n\tthis.ie = (ua.indexOf("MSIE")>-1 && this.dom && !this.op)?1:0;\n\tthis.ie4 = (document.all && !this.dom)?1:0;\n\tthis.ns4 = (document.layers && !this.dom)?1:0;\n\tthis.gecko = (this.dom && ua.indexOf("Gecko")>-1)?1:0;\n\tthis.comp = (this.dom || this.ie4)?1:0;\n\tthis.win = (ua.indexOf('Windows')>-1)?1:0;\n\tthis.mx=-1;\n\tthis.my=-1;\n\tthis.tip=-1;\n\tthis.mac= (av.indexOf("Mac")>-1)?1:0;\n\treturn this\n}\n\nvar dgl=new dgl_vars();\n\nvar n_lay = Array();\n\nvar n_path = 'http://digiland.libero.it/x/pics/nu/';\nvar n_laytmr=false;\nvar n_lay_act=false;\nvar n_pagew = 0;\nvar n_scrh = 0;\nvar n_info_pic = n_path + 'info_s.gif';\nvar n_warn_pic = n_path + 'alert_s.gif';\nvar n_stip_tm = Array...
    Offending value: innerHTML
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://spazio.libero.it:80/x/js/base.js ⇒ 200 [view trace]
    Response (10194): function dgl_vars(){\n\n\tvar av = navigator.appVersion; // retrocomp\n\tvar ua = navigator.userAgent; // retrocomp\n\n\tthis.dom = document.getElementById?1:0;\n\tthis.op = (ua.indexOf("pera")>-1)?1:0;\n\tthis.ie = (ua.indexOf("MSIE")>-1 && this.dom && !this.op)?1:0;\n\tthis.ie4 = (document.all && !this.dom)?1:0;\n\tthis.ns4 = (document.layers && !this.dom)?1:0;\n\tthis.gecko = (this.dom && ua.indexOf("Gecko")>-1)?1:0;\n\tthis.comp = (this.dom || this.ie4)?1:0;\n\tthis.win = (ua.indexOf('Windows')>-1)?1:0;\n\tthis.mx=-1;\n\tthis.my=-1;\n\tthis.tip=-1;\n\tthis.mac= (av.indexOf("Mac")>-1)?1:0;\n\treturn this\n}\n\nvar dgl=new dgl_vars();\n\nvar n_lay = Array();\n\nvar n_laytmr=false;\nvar n_lay_act=false;\nvar n_pagew = 0;\nvar n_scrh = 0;\nvar n_info_pic = '/x/pics/nu/info_s.gif';\nvar n_warn_pic = '/x/pics/nu/alert_s.gif';\nvar n_stip_tm = Array();\nvar n_newmsg = false;\nvar n_bcstid = false;\nvar n_bcs...
    Offending value: innerHTML
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://blog.libero.it:80/blog/js/fx_blog.js ⇒ 200 [view trace]
    Response (7120): // fx_01.js (c)2K2 Digiland - Italia OnLine\n\n// Browser ID\n\nvar DG_BROW_N="UNK";\nvar DG_BROW_V=0;\nvar DG_PLAT="UNK";\nvar DG_JAVA=false;\n\nvar agt=navigator.userAgent.toLowerCase();\nvar appVer = navigator.appVersion.toLowerCase();\nvar is_minor = parseFloat(appVer);\nvar is_major = parseInt(is_minor);\n\nvar iePos = appVer.indexOf('msie');\nif (iePos !=-1) {\n\tis_minor = parseFloat(appVer.substring(iePos+5,appVer.indexOf(';',iePos)))\n\tis_major = parseInt(is_minor);\n}\nvar nav6Pos = agt.indexOf('netscape6');\nif (nav6Pos !=-1) {\n\tis_minor = parseFloat(agt.substring(nav6Pos+10))\n\tis_major = parseInt(is_minor)\n}\n\nDG_BROW_V=is_major;\n\nif (document.layers) DG_BROW_N="nav";\nif (document.all)\n\tDG_BROW_N="ie";\nelse\n\tif (document.getElementById) DG_BROW_N="nav";\n\nif (agt.indexOf("opera")!=-1) DG_BROW_N="opera";\n\nif (agt.indexOf("win")!=-1) DG_PLAT="win";\nif (agt.index...
    Offending value: document.write
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://barra-spazio.libero.it:80//x/js/barra_n01.js ⇒ 200 [view trace]
    Response (4922): var bsl1_init;\nvar bsl1_init2;\nvar bsl1_sup=0;\nvar bsl1_ie=((document.all)&&(!window.opera));\n\nif (document.getElementById) bsl1_sup=1;\n\nfunction n_width() {\n\tif (self.innerHeight) return(self.innerWidth);\n\telse if (document.documentElement && document.documentElement.clientHeight) return(document.documentElement.clientWidth);\n\telse if (document.body) return(document.body.clientWidth);\n\treturn 0;\n}\n\nfunction bsl1_wd() {\n\tvar d = n_width();\n\tif (d!=bsl1_oldd) {\n\t\ta = document.getElementById('vb2main');\n\t\ta.style.width = d+"px";\n\t\tbsl1_oldd = d;\n\t}\n\tsetTimeout("bsl1_wd()", 250);\n}\n\nfunction bsl1_remote(ur) { \n \tvar element = document.createElement('script');\n\telement.setAttribute('type','text/javascript'); \n\telement.setAttribute('src',ur); \n\tdocument.body.appendChild(element);\n}\n\nfunction bsl1_ok(gu) {\n\tvar o = document.getElementById('bsl1-lbuff');\n\tif (o) o.innerHTML = gu;\n}\n...
    Offending value: document.write
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digiland.libero.it:80/ ⇒ 200 [view trace]
    Response (43155): \n<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">\n<html>\n<head>\n<title>Libero - Community Homepage</title>\n<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">\n<META NAME="Description" CONTENT="Digiland è la community del portale Libero: Chat, Cupido, Messaggeria, Forum, Sondaggi, Tribu, Crea il tuo Sito e molto altro...">\n<META NAME="Keywords" CONTENT="community, chat, blog, forum, cupido, dating, pagine personali">\n<link rel="shortcut icon" href="http://digistatic.libero.it//pics/favicon.ico">\n\n\n<LINK href="http://digistatic.libero.it//css/header.css" rel="stylesheet">\n<LINK href="http://digistatic.libero.it//css/community.css" rel="stylesheet">\n<LINK href="http://digistatic.libero.it//css/tbx.css" rel="...
    Cookies set: DIGISESSID=acb599e99e43feb6f7be43e3a6df979f; DGL_UPD_LOGIN=0
    Offending value: document.write
    MIME type: text/html, detected: text/html, charset: iso-8859-1

  • LOWecho PRED auth GET http://digiland.libero.it:80/fsrscripts/stdLauncher.js ⇒ 200 [view trace]
    Response (28957): /****Customer: **SAMPLE CODE FOR TESTING ** NOT FOR PRODUCTION ****\r\n/************ don't modify below this line *********\r\n ************* Version: Std 5.3 v.21 ***********\r\n ****** Copyright 2001-2008 ForeseeResults, Inc****/\r\n \r\nforesee.popupURL = "//www.foreseeresults.com/survey/display";\t//do not change this url\r\nforesee.FSRImgURL= "//www.foreseeresults.com/survey/FSRImg"; \t//do not change this url\r\nforesee.CSURL= "//www.foreseeresults.com/survey/processCPP"; \t//do not change this url\r\nforesee.OTCImgURL = "//controller.foreseeresults.com/fsrSurvey/OTCImg";\r\nforesee.ckAlreadyShown = foresee.triggerParms["ascookie"]; /* name of the persistent/session cookie*/\r\nforesee.ckLoyaltyCount = foresee.triggerParms["lfcookie"]; /* name of the loyalty count cookie*/\r\nforesee.fullURL=null;\r\nforesee.myPopUp=null;\r\nforesee.detect = navigator.userAgent.toLowerCase();\r\nforesee.version= navigator.appVersion.toLowerCase();\r\nfor...
    Offending value: document.write
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://spazio.libero.it:80/maxsof1/?top=1 ⇒ 200 [view trace]
    Response (22985): <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">\n<html>\n<head>\n<title>Libero - Community Profilo di maxsof1</title>\n<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">\n<META NAME="Description" CONTENT="Digiland è la community del portale Libero: Chat, Cupido, Messaggeria, Forum, Sondaggi, Tribu, Crea il tuo Sito e molto altro...">\n<META NAME="Keywords" CONTENT="community, chat, blog, forum, cupido, dating, pagine personali">\n<link rel="shortcut icon" href="/x/pics/hd_img/favicon.ico">\n\n\n<style type="text/css">\n@import url("http://barra-spazio.libero.it//x/css/barra_n01.css");\n</style>\n<script src="http://barra-spazio.libero.it//x/js/barra_n01.js" type="text/javascript" language="Javascript"></scri...
    Cookies set: SPAZIO_SESSID=fb949caf46de2245bb730db4b43f2fc1; DGL_UPD_LOGIN=0; DIGI_PVP=KcdC_3a__2f__2f_33ajAr_2e_8LptEX_2e_Ut_2f_4X2fRtK_2f_C11fxDr_2e_cK8_2d_KNdi6nScp0_2d_AvfFt0mSMIF1n
    Offending value: document.write
    MIME type: text/html, detected: text/html, charset: iso-8859-1

  • LOWecho PRED auth GET http://digiland.libero.it:80/ssi/menu_chat.html ⇒ 200 [view trace]
    Response (18090): <html>\n<link rel="stylesheet" type="text/css" href="/css/menu_chat.css" />\n<script language="JavaScript">\n<!--\nvar old = false;\nvar nome_stanza ='';\nfunction changestyle_stanza(o){\n\t\n\to.style.backgroundColor = '#000000';\n\to.style.color = '#FFFFFF';\n\tif (old) {\n\t\told.style.backgroundColor='';\n\t\told.style.color='#333333';\n\t}\t\n\told = o; \n}\t\n\nfunction apri_nodo(){\n\ttrees[nodo_root].toggle(nodo_ingresso);\n\told= document.getElementById('i_txt' + nodo_root + '_' + nodo_stanza);\n\told.style.backgroundColor = '#000000';\n\told.style.color = '#FFFFFF';\n}\t\nfunction tree (a_items, a_template) {\n\n\tthis.a_tpl = a_template;\n\tthis.a_config = a_items;\n\tthis.o_root = this;\n\tthis.a_index = [];\n\tthis.o_selected = null;\n\tthis.n_depth = -1;\n\t\n\tvar o_icone = new Image(),\n\t\to_iconl = new Image();\n...
    Offending value: document.write
    MIME type: text/html, detected: text/html, charset: -

  • LOWecho PRED auth GET http://digistatic.libero.it:80//js/header.js ⇒ 200 [view trace]
    Response (1401): var com_userAgent=navigator.userAgent.toLowerCase();\n//linux\nif(com_userAgent.indexOf("linux")!=-1){ \n\tdocument.write('<style>');\n\tdocument.write('.com_v7-riga-top_off, .com_v7-riga-top_on{font-size:11px}');\n\tdocument.write('.com_v7-riga-sotto-top,.com_v7-riga-sotto-top_on{font-size:10px}');\n\tdocument.write('</style>');\n}\nif(com_userAgent.indexOf("safari")!=-1){ \n\tdocument.write('<style>');\n\tdocument.write('#com_v7-query{font-size:11px;}');\n\tdocument.write('</style>');\n}\n\n\n\t//adv\n\tfunction adv_flashDisp(flashobj)\n\t{if (typeof(flashobj)!='undefined'&&flashobj!=''){document.write(flashobj);}}\n\n\tfunction com07e_controlla(area_click){\n\t\tq=encodeURIComponent(document.search.query.value);\n\t\tif (q == '') {\n\t\t\tckSrv('http://arianna.libero.it','HF1',area_click,'s1',null);\n\t\t\treturn false;...
    Offending value: document.write
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://www.libero.it:80/ ⇒ 200 [view trace]
    Response (129624): <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN" "http://www.w3.org/TR/html4/loose.dtd">\n<HTML>\n<HEAD>\n<META http-equiv="content-type" content="text/html; charset=iso-8859-1">\n<META name="description" content="Libero.it: Community, Search, Mail, News, Video, Adsl & Internet">\n<META name="keywords" content="Libero, Community, Search, Mail, News, Video, Adsl & Internet">\n<TITLE>Libero</TITLE>\n<LINK rel="shortcut icon" type="images/x-icon" href="http://img3.iol.it/i/favicon.ico">\n\n<!-- armonia -->\n<style>\nbody{background-image:url(http://img1.iol.it/i/200803/bg_nero.gif);background-repeat:repeat-x;text-align:center;}\ninput{font-size:11px;font-family:Tahoma, Arial,sans-serif;}\n\nform{display:inline;}\na,a:hover{text-decoration:underline;}\na:hover{color:#000066;}...
    Cookies set: Libero=78.46.80.205.1215682043004499
    Offending value: document.write
    MIME type: text/html, detected: text/html, charset: iso-8859-1

Inline PNG image [toggle] Cookie issuer with no XSRF protection [toggle]
    Pages that accept parameters and issue new HTTP cookies, but miss security tokens. Session fixation or other attacks might be possible if the cookie stores important, query-dependent user data.

  • MEDIUMECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=61b3a97e0f17d5d78e73be49de594487
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=18085&url_swf=/swf/&url_flv=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487.flv&url_thumb=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487_0.jpg&flen=378&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=879e2b8814f0285cd851ef702d1f074e
    MIME type: text/html, detected: application/x-javascript, charset: -

  • MEDIUMECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=4366db2f9990f509e735d7496f3a4f78%2Eflv
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=77960&url_swf=/swf/&url_flv=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78.flv&url_thumb=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78_0.jpg&flen=260&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=b80979a5a5f1533c4d4a8f6b2bfc3a3a
    MIME type: text/html, detected: application/x-javascript, charset: -

  • MEDIUMECHO PRED auth GET http://blog.libero.it:80/maxsoblog/view.php?nocache=1215682105 ⇒ 200 [view trace]
    Response (114597): \n\n<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">\n<html>\n<head>\n<title>Maxso's Blog - Libero Community - Blog</title>\n\n<META NAME="Keywords" CONTENT="community, chat, blog, forum, cupido, dating, pagine personali">\n\n<link rel='stylesheet' type=text/css href='/blog/css/moblog.css'>\n<link rel='stylesheet' type=text/css href='/blog/css/skin/67/blue.css'>\n<script type='text/javascript' src='/blog/js/fx_blog.js'></script>\n\n<script language="javascript">\n<!--\nnav_name = navigator.userAgent.toLowerCase();\nis_opera = (nav_name.indexOf("opera") != -1);\nis_mac = (nav_name.indexOf("mac") != -1);\nif (is_opera || is_mac){\n\tdocument.write('<style> .defender { overflow: hidden; } </style>');\n}\n-->\n</sc...
    Cookies set: PHPSESSIDMOB=51a97ff659e142796c021e8c3e5826c0; DGL_UPD_LOGIN=0; BG_RT=f_41_C_41__3d_kRIK_2d_0N_2d_rc_7c_Tn5Vzl_3d_g1nrc_7c_Tn5V0_41_up_3d_mpPvbEz8Y_7c_mbE5k_3d_O
    MIME type: text/html, detected: text/html, charset: -

  • MEDIUMecho PRED auth GET http://blog-logger.libero.it:80/cgi-bin/rating.cgi?code=f_41_C_41__3d_kRIK_2d_0N_2d_rc_7c_Tn5Vzl_3d_g1nrc_7c_Tn5V0_41_up_3d_mpPvbEz8Y_7c_mbE5k_3d_O&serv=_2f_PohFXNl87_2f_y2Hf_2e_0ZY_3f_ZorXfzH_3d_JkmfJ8krcP_26_ ⇒ 200 [view trace]
    Response (95): ‰PNG\r\n\x1a\n
    Cookies set: BG_SRT=/maxsoblog/view.php?nocache=1215682105& 1215682116
    MIME type: image/png, detected: image/png, charset: -

  • MEDIUMecho PRED auth GET http://spazio.libero.it:80/maxsof1/?top=1 ⇒ 200 [view trace]
    Response (22985): <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">\n<html>\n<head>\n<title>Libero - Community Profilo di maxsof1</title>\n<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=iso-8859-1">\n<META NAME="Description" CONTENT="Digiland è la community del portale Libero: Chat, Cupido, Messaggeria, Forum, Sondaggi, Tribu, Crea il tuo Sito e molto altro...">\n<META NAME="Keywords" CONTENT="community, chat, blog, forum, cupido, dating, pagine personali">\n<link rel="shortcut icon" href="/x/pics/hd_img/favicon.ico">\n\n\n<style type="text/css">\n@import url("http://barra-spazio.libero.it//x/css/barra_n01.css");\n</style>\n<script src="http://barra-spazio.libero.it//x/js/barra_n01.js" type="text/javascript" language="Javascript"></scri...
    Cookies set: SPAZIO_SESSID=fb949caf46de2245bb730db4b43f2fc1; DGL_UPD_LOGIN=0; DIGI_PVP=KcdC_3a__2f__2f_33ajAr_2e_8LptEX_2e_Ut_2f_4X2fRtK_2f_C11fxDr_2e_cK8_2d_KNdi6nScp0_2d_AvfFt0mSMIF1n
    MIME type: text/html, detected: text/html, charset: iso-8859-1

XSS candidates (script) [toggle]
    Pages where non-trivial query parameters appear to be echoed back inside a script. This does not imply a vulnerability, but these resources are prime candidates for further code injection testing.

  • LOWECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=fb410a8fa378c066535f1e05aa473150%2Eflv
    Response (330): s=1&msg1=&url_base=http://video.libero.it/static&media_id=173950&url_swf=/swf/&url_flv=/video16/f/b/4/fb410a8fa378c066535f1e05aa473150.flv&url_thumb=/video16/f/b/4/fb410a8fa378c066535f1e05aa473150_0.jpg&flen=277&fx=320&fy=256&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Offending value: id
    MIME type: text/html, detected: application/x-javascript, charset: -

  • LOWECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=e75cbc00bce10147d074d38fc14f16e6%2Eflv
    Response (330): s=1&msg1=&url_base=http://video.libero.it/static&media_id=175437&url_swf=/swf/&url_flv=/video15/e/7/5/e75cbc00bce10147d074d38fc14f16e6.flv&url_thumb=/video15/e/7/5/e75cbc00bce10147d074d38fc14f16e6_0.jpg&flen=158&fx=320&fy=256&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Offending value: id
    MIME type: text/html, detected: application/x-javascript, charset: -

  • LOWECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=61b3a97e0f17d5d78e73be49de594487
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=18085&url_swf=/swf/&url_flv=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487.flv&url_thumb=/video07/6/1/b/61b3a97e0f17d5d78e73be49de594487_0.jpg&flen=378&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=879e2b8814f0285cd851ef702d1f074e
    Offending value: id
    MIME type: text/html, detected: application/x-javascript, charset: -

  • LOWECHO PRED AUTH POST http://video.libero.it:80/app/play/get_url_flv.html?e ⇒ 200 [view trace]
    Payload: embed=yes&id=4366db2f9990f509e735d7496f3a4f78%2Eflv
    Response (329): s=1&msg1=&url_base=http://video.libero.it/static&media_id=77960&url_swf=/swf/&url_flv=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78.flv&url_thumb=/video05/4/3/6/4366db2f9990f509e735d7496f3a4f78_0.jpg&flen=260&fx=320&fy=240&v_s=&nielsen_probe=n&em_log=1&f_tr=1&f_to=4&f_server=1&fakeID=P01&staf_opt=440_500_150_120&custom_skin=0
    Cookies set: LIBEROVIDEO-SESSIONID=b80979a5a5f1533c4d4a8f6b2bfc3a3a
    Offending value: id
    MIME type: text/html, detected: application/x-javascript, charset: -

References to external active content [toggle] MIME type mismatch on binary file [toggle] MIME type set to text/plain [toggle] Markup in dynamic Javascript [toggle]
    Code that resembles JSON responses or other dynamic code snippets, and quotes non-escaped HTML. If this rendered markup is attacker-controlled, content sniffing in Internet Explorer may potentially kick in and trigger XSS flaws, regardless of MIME type used.

  • LOWecho PRED auth GET http://blog.libero.it:80/blog/js/fx_blog.js ⇒ 200 [view trace]
    Response (7120): // fx_01.js (c)2K2 Digiland - Italia OnLine\n\n// Browser ID\n\nvar DG_BROW_N="UNK";\nvar DG_BROW_V=0;\nvar DG_PLAT="UNK";\nvar DG_JAVA=false;\n\nvar agt=navigator.userAgent.toLowerCase();\nvar appVer = navigator.appVersion.toLowerCase();\nvar is_minor = parseFloat(appVer);\nvar is_major = parseInt(is_minor);\n\nvar iePos = appVer.indexOf('msie');\nif (iePos !=-1) {\n\tis_minor = parseFloat(appVer.substring(iePos+5,appVer.indexOf(';',iePos)))\n\tis_major = parseInt(is_minor);\n}\nvar nav6Pos = agt.indexOf('netscape6');\nif (nav6Pos !=-1) {\n\tis_minor = parseFloat(agt.substring(nav6Pos+10))\n\tis_major = parseInt(is_minor)\n}\n\nDG_BROW_V=is_major;\n\nif (document.layers) DG_BROW_N="nav";\nif (document.all)\n\tDG_BROW_N="ie";\nelse\n\tif (document.getElementById) DG_BROW_N="nav";\n\nif (agt.indexOf("opera")!=-1) DG_BROW_N="opera";\n\nif (agt.indexOf("win")!=-1) DG_PLAT="win";\nif (agt.index...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digiland.libero.it:80/fsrscripts/triggerParams.js ⇒ 200 [view trace]
    Response (5871): /****Customer: Bitbang Libero.it\r\n/************ don't modify below this line *********\r\n ************* Version: Std 5.3 v.21 ***********\r\n ****** Copyright 2001-2008 ForeseeResults, Inc****/\r\n\r\n/**MAIN PARAMETERS**/\r\nif(!window.foresee) window.foresee = new Object();\r\nforesee.triggerParms= new Array();\r\nforesee.triggerParms["displayMode"] = 3;\t\t \t\t //0=disable survey, 1=Invitation when PUB present, 2=No Invitation, 3=Invitation Only\r\nforesee.triggerParms["mid"] = "1QVsNQE84xlUw9shYVAV9g=="; // model instance id (Default is XYZ Company survey) - Comment if using 'sid'\r\nforesee.triggerParms["cid"] = "Yg0U0ckBU8dZkRZxYY59lw=="; // customer id\r\nforesee.triggerParms["lf"] = 0;\t\t \t \t \t\t\t// * loyalty factor 5\r\nforesee.triggerParms["sp"] = 10.0;\t \t\t \t\t\t// * sampling percentage 50\r\nforesee.triggerParms["rw"] = 129600; \t \t\t \t\t\t// duration of persistent surve...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digiland.libero.it:80/fsrscripts/stdLauncher.js ⇒ 200 [view trace]
    Response (28957): /****Customer: **SAMPLE CODE FOR TESTING ** NOT FOR PRODUCTION ****\r\n/************ don't modify below this line *********\r\n ************* Version: Std 5.3 v.21 ***********\r\n ****** Copyright 2001-2008 ForeseeResults, Inc****/\r\n \r\nforesee.popupURL = "//www.foreseeresults.com/survey/display";\t//do not change this url\r\nforesee.FSRImgURL= "//www.foreseeresults.com/survey/FSRImg"; \t//do not change this url\r\nforesee.CSURL= "//www.foreseeresults.com/survey/processCPP"; \t//do not change this url\r\nforesee.OTCImgURL = "//controller.foreseeresults.com/fsrSurvey/OTCImg";\r\nforesee.ckAlreadyShown = foresee.triggerParms["ascookie"]; /* name of the persistent/session cookie*/\r\nforesee.ckLoyaltyCount = foresee.triggerParms["lfcookie"]; /* name of the loyalty count cookie*/\r\nforesee.fullURL=null;\r\nforesee.myPopUp=null;\r\nforesee.detect = navigator.userAgent.toLowerCase();\r\nforesee.version= navigator.appVersion.toLowerCase();\r\nfor...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

  • LOWecho PRED auth GET http://digistatic.libero.it:80//js/tbx.js ⇒ 200 [view trace]
    Response (1847): // SWITCHING TAB\n// pre = id_prefix\n// n = tab\n// i = mode (0,1)\n// area = area box\n// coo = cookie mode (0,1)\n\nvar tbx_stat = new Array();\n\nfunction tbx_switch(pre, n, i, area, coo) {\n\tif (document.getElementById) {\n\t\n\t\tif (coo == 1) {\n\t\t\tif (i==1) {\n\t\t\t\tvar cccc=tbx_gc("tbx"+area);\n\t\t\t\tif (cccc!='') n = cccc;\n\t\t\t} else {\n\t\t\t\tvar kk = "tbx" + area + "=" + n + "; path=/; domain=.libero.it";\n\t\t\t\tdocument.cookie=kk;\n\t\t\t}\n\t\t}\n\t\t\n\t\tvar d = document.getElementById(pre+n);\n\t\tvar dc = document.getElementById(pre+'c'+n);\n\n\t\tif (tbx_stat[pre]>0) {\n\t\t\tvar doo, dco;\n\t\t\tdoo = document.getElementById(pre+tbx_stat[pre]);\n\t\t\tdco = document.getElementById(pre+'c'+tbx_stat[pre]);\n\t\t\tdco.style.display="none";\n\t\t\tdoo.className = "";\n\t\t}\n\t\t\n\t\tdc.style.display = "block";\n\t\td.className = "act";\n\t\ttbx_stat[pre]=n;\n\n\t\t...
    MIME type: application/x-javascript, detected: application/x-javascript, charset: -

File name in query parameters [toggle] XSS candidates [toggle]

Section hidden

All cookie setting URLs [toggle]

Section hidden

All Flash applications [toggle]

Section hidden

All POST requests [toggle]

Section hidden