sábado, 14 de mayo de 2011

vulnerable a Cross Site Tracing en Web

Saludos Mundo Libre.

Me he puesto a jugar un rato y encontre esto.

El servidor web en "http://www.megacable.com.mx/" es vulnerable a Cross Site Tracing. Esta vulnerabilidad fue encontrada en la solicitud con el ID 361.

Aqui les dejo el scaneo:

[Sat 14 May 2011 10:36:31 PM CDT] Auto-enabling plugin: grep.collectCookies
[Sat 14 May 2011 10:36:31 PM CDT] Auto-enabling plugin: grep.httpAuthDetect
[Sat 14 May 2011 10:36:31 PM CDT] Auto-enabling plugin: grep.error500
[Sat 14 May 2011 10:36:31 PM CDT] Auto-enabling plugin: discovery.serverHeader
[Sat 14 May 2011 10:36:31 PM CDT] Auto-enabling plugin: discovery.allowedMethods
[Sat 14 May 2011 10:36:32 PM CDT] Auto-enabling plugin: discovery.frontpage_version
[Sat 14 May 2011 10:36:32 PM CDT] Auto-enabling plugin: grep.passwordProfiling
[Sat 14 May 2011 10:36:32 PM CDT] Auto-enabling plugin: grep.getMails
[Sat 14 May 2011 10:36:32 PM CDT] Auto-enabling plugin: grep.lang
[Sat 14 May 2011 10:36:38 PM CDT] The "lang" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:36:43 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:36:59 PM CDT] The server header for the remote web server is: "Apache/1.3.33 (Unix) PHP/5.0.4-dev mod_ssl/2.8.22 OpenSSL/0.9.7d". This information was found in the request with id 28.
[Sat 14 May 2011 10:37:00 PM CDT] The URL: "http://www.megacable.com.mx/" has the following DAV methods enabled:
[Sat 14 May 2011 10:37:00 PM CDT] - CONNECT, COPY, DELETE, GET, HEAD, LOCK, MKCOL, MOVE, OPTIONS, PATCH, POST, PROPFIND, PROPPATCH, PUT, TRACE, UNLOCK
[Sat 14 May 2011 10:37:00 PM CDT] Starting formAuthBrute plugin execution.
[Sat 14 May 2011 10:37:00 PM CDT] Starting basicAuthBrute plugin execution.
[Sat 14 May 2011 10:37:00 PM CDT] Found 2 URLs and 2 different points of injection.
[Sat 14 May 2011 10:37:00 PM CDT] The list of URLs is:
[Sat 14 May 2011 10:37:00 PM CDT] - http://www.megacable.com.mx
[Sat 14 May 2011 10:37:00 PM CDT] - http://www.megacable.com.mx/resultados.html
[Sat 14 May 2011 10:37:00 PM CDT] The list of fuzzable requests is:
[Sat 14 May 2011 10:37:00 PM CDT] - http://www.megacable.com.mx | Method: GET
[Sat 14 May 2011 10:37:00 PM CDT] - http://www.megacable.com.mx/resultados.html | Method: GET | Parameters: (q="", cx="0168582234...", ie="UTF-8", cof="FORID:10")
[Sat 14 May 2011 10:37:01 PM CDT] The page language is: es</b>
[Sat 14 May 2011 10:37:16 PM CDT] The server header for the remote web server is: "Apache/1.3.33 (Unix) PHP/5.0.4-dev mod_ssl/2.8.22 OpenSSL/0.9.7d". This information was found in the request with id 28.
[Sat 14 May 2011 10:37:16 PM CDT] The URL "http://www.megacable.com.mx/" has the following allowed methods, which include DAV methods: CONNECT, COPY, DELETE, GET, HEAD, LOCK, MKCOL, MOVE, OPTIONS, PATCH, POST, PROPFIND, PROPPATCH, PUT, TRACE, UNLOCK. This information was found in the request with id 30.
[Sat 14 May 2011 10:38:05 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:05 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:06 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:11 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:11 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:12 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:12 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:12 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:12 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:12 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:12 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:12 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:12 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:12 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:12 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:13 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:13 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:13 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:13 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:13 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:13 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:13 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:13 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:33 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:33 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:39 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:39 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:39 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:40 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:41 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:38:49 PM CDT] The web server at "http://www.megacable.com.mx/" is vulnerable to Cross Site Tracing. This vulnerability was found in the request with id 361.
[Sat 14 May 2011 10:39:27 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:28 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:29 PM CDT] The "passwordProfiling" plugin took more than 5 seconds to run. For a plugin that should only perform pattern matching, this is too much, please review its source code.
[Sat 14 May 2011 10:39:43 PM CDT] Password profiling TOP 100:
[Sat 14 May 2011 10:39:43 PM CDT] - [1] Megacable with 1296 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [2] Megared with 1296 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [3] Ayuda with 1296 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [4] Portal with 972 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [5] fono with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [6] Corporativo with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [7] servicio with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [8] Bolsa with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [9] Megakids with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [10] Pago with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [11] Internet with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [12] Inversionistas with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [13] telef with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [14] tiene with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [15] Megacanal with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [16] Servicios with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [17] Webmail with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [18] ofrece with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [19] Televisi with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [20] Correo with 648 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [21] Premier with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [22] como with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [23] googleSearchFrameWidth with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [24] Portabilidad with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [25] membres with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [26] forzosos with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [27] Canales with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [28] esto with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [29] Rednegocios with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [30] conexi with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [31] VideoRola with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [32] Paquetes with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [33] Digital with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [34] Contacto with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [35] Trabajo with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [36] googleSearchFormName with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [37] Residencial with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [38] Centro with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [39] cuenta with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [40] Videorola with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [41] barato with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [42] Todos with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [43] sobre with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [44] Demand with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [45] googleSearchPath with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [46] Facebook with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [47] nica with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [48] trabajo with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [49] Velocidades with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [50] empleados with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [51] Cable with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [52] seguridad with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [53] lambrico with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [54] Wifi with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [55] Youtube with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [56] Planes with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [57] Adicionales with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [58] Metro with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [59] plazos with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [60] cualquier with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [61] rdenas with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [62] necesitas with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [63] mite with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [64] Megaf with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [65] muchas with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [66] googleSearchDomain with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [67] Fresno with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [68] solid with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [69] Twitter with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [70] Share with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [71] googleSearchIframeName with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [72] Funciona with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [73] neas with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [74] derechos with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [75] zaro with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [76] Negocios with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [77] ventajas with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [78] Comunidad with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [79] Digitalizaci with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] - [80] pida with 324 repetitions.
[Sat 14 May 2011 10:39:43 PM CDT] Finished scanning process.

Raw:

HTTP/1.1 200 OK
date: Sun, 15 May 2011 03:38:49 GMT
transfer-encoding: chunked
content-type: message/http
server: Apache/1.3.33 (Unix) PHP/5.0.4-dev mod_ssl/2.8.22 OpenSSL/0.9.7d


TRACE / HTTP/1.1

Accept: */*

Accept-encoding: identity

Host: www.megacable.com.mx

The web server at "http://www.megacable.com.mx/" is vulnerable to Cross Site Tracing. This vulnerability was found in the request with id 361.

Hay selas dejo para que juegen un rato.

Saludos Mundo Libre.

No hay comentarios:

Publicar un comentario