You are on page 1of 64

Acunetix Website Audit 14 October, 2011

Detailed Scan Report

Generated by Acunetix WVS Reporter (v7.0 Build 20111005)

Scan of http://www.hcarmy.net/
Scan details
Scan information Starttime Finish time Scan time Profile Server information Responsive Server banner Server OS Server technologies Threat level

14.10.2011 22:01:53 14.10.2011 23:39:57 1 hours, 38 minutes Default

True Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Unix PHP,mod_ssl,OpenSSL,FrontPage

Alerts distribution Total alerts found High Medium Low Informational 119 0 0 39 80

Knowledge base
List of open TCP ports

Acunetix Website Audit

DNS server running DNS server running on TCP FTP server running Whois lookup

SSH server running

Webmin running

Acunetix Website Audit

Alerts summary
Directory Listing Affects /logo /modules /modules/mod_artwijmomenu /modules/mod_banners2 /modules/mod_cool_contact /modules/mod_jacatslwi /modules/mod_socialmedialinks/icons/default /modules/mod_socialmedialinks/icons/default/size3 /plugins/content/JoomLifebookmarks /plugins/system/rokbox /plugins/system/rokbox/jwplayer /plugins/system/rokbox/themes /plugins/system/rokbox/themes/clean /plugins/system/rokbox/themes/dark /plugins/system/rokbox/themes/light /plugins/system/rokbox/themes/mynxx /plugins/system/rokbox/themes/sample /templates/hcarmy/css /templates/hcarmy/images Possible sensitive directories Affects /administrator /administrator/backups /administrator/cache /administrator/templates/system /cache /cgi-bin /cgi-sys /logs /mailman /media/system /modules/mod_globalnews/scripts /plugins/system /plugins/tmp /plugins/xmlrpc /templates/system /tmp /xmlrpc /xmlrpc/cache Possible sensitive files Affects /plugins/system/debug.php TRACE method is enabled Affects Web Server Variations 1 Variations 1 Variations 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 Variations 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1

Acunetix Website Audit

Broken links Affects /a /www.facebook.com /www.frienndfeed.com/hcarmy /www.twitter.com Email address found Affects /administrator/templates/khepri/css/general.css /administrator/templates/khepri/css/login.css /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/jquery-wijmo.css /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/jquery-wijmo2.css Error page Web Server version disclosure Affects Web Server Files listed in robots.txt but not linked Affects /administrator /cache /components /images /includes /language /libraries /media /plugins /templates /tmp /xmlrpc Variations 1 1 1 1 1 1 1 1 1 1 1 1 Variations 1 Variations 1 1 1 1 Variations 1 1 1 1

Acunetix Website Audit

GHDB: Apache directory listing which show Apache version Affects /administrator/templates/khepri/images/h_cherry /administrator/templates/khepri/images/h_green /administrator/templates/khepri/images/h_teal /logo /modules /modules/mod_artwijmomenu /modules/mod_artwijmomenu/mod_artwijmomenu /modules/mod_artwijmomenu/mod_artwijmomenu/helpers /modules/mod_artwijmomenu/mod_artwijmomenu/stuff /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/external /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/external/globinfo /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/images /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/midnight /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/midnight/images /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ui-lightness /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ui-lightness/images /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/wijmo /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/wijmo/images /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/wijmo /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/wijmo/minified /modules/mod_artwijmomenu/mod_artwijmomenu/templates /modules/mod_banners2 /modules/mod_cool_contact /modules/mod_jacatslwi /modules/mod_jaslideshow2 /modules/mod_slick_rss /modules/mod_slick_rss/tmpl /modules/mod_socialmedialinks/icons/default /modules/mod_socialmedialinks/icons/default/size1 /modules/mod_socialmedialinks/icons/default/size2 /modules/mod_socialmedialinks/icons/default/size3 /modules/mod_socialmedialinks/icons/default/size4 /modules/mod_socialmedialinks/icons/default/size5 /modules/mod_the_tranquil /modules/mod_the_tranquil/banner /plugins/content/JoomLifebookmarks /plugins/system/rokbox /plugins/system/rokbox/jwplayer /plugins/system/rokbox/themes /plugins/system/rokbox/themes/clean /plugins/system/rokbox/themes/dark /plugins/system/rokbox/themes/light /plugins/system/rokbox/themes/mynxx /plugins/system/rokbox/themes/sample /templates/hcarmy/css /templates/hcarmy/images Variations 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1 1

Acunetix Website Audit

GHDB: Possible temporary file/directory Affects /modules/mod_jaslideshow2/tmpl /modules/mod_slick_rss/tmpl /modules/mod_slick_rss/tmpl/default.php /modules/tmpl /tmp Password type input with autocomplete enabled Affects /administrator /administrator/index.php /administrator/index.php (8777c66fca8866ed2d0de75899bcfc7c) Possible server path disclosure (Unix) Affects /administrator/index.php /index.php /robots.txt Variations 1 1 1 Variations 1 1 1 Variations 1 1 1 1 1

Acunetix Website Audit

Alert details
Directory Listing
Severity Low Type Information Reported by module Scripting (Directory_Listing.script) Description

Impact

Recommendation

Affected items /logo Details

Request GET /logo/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/logo/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:54 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 566 Keep-Alive: timeout=5, max=53 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules Details

Request GET /modules/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Acunetix Website Audit 8

Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:51 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 3432 Keep-Alive: timeout=5, max=69 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu Details

Request GET /modules/mod_artwijmomenu/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 630 Keep-Alive: timeout=5, max=93 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_banners2 Details

Request GET /modules/mod_banners2/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Acunetix Website Audit 9

Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 546 Keep-Alive: timeout=5, max=95 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_cool_contact Details

Request GET /modules/mod_cool_contact/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 570 Keep-Alive: timeout=5, max=93 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_jacatslwi Details

Request GET /modules/mod_jacatslwi/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_jacatslwi/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:51 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 646 Keep-Alive: timeout=5, max=99 Acunetix Website Audit

10

Connection: Keep-Alive /modules/mod_socialmedialinks/icons/default Details

Request GET /modules/mod_socialmedialinks/icons/default/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_socialmedialinks/icons/default/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:53 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 691 Keep-Alive: timeout=5, max=52 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_socialmedialinks/icons/default/size3 Details

Request GET /modules/mod_socialmedialinks/icons/default/size3/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_socialmedialinks/icons/default/size3/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:53 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 2059 Keep-Alive: timeout=5, max=60 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1

Acunetix Website Audit

11

/plugins/content/JoomLifebookmarks Details

Request GET /plugins/content/JoomLifebookmarks/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/content/JoomLifebookmarks/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:03 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 634 Keep-Alive: timeout=5, max=96 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox Details

Request GET /plugins/system/rokbox/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:50 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 729 Keep-Alive: timeout=5, max=89 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/jwplayer Details

Acunetix Website Audit

12

Request GET /plugins/system/rokbox/jwplayer/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:03 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 514 Keep-Alive: timeout=5, max=94 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/themes Details

Request GET /plugins/system/rokbox/themes/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:51 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 650 Keep-Alive: timeout=5, max=88 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/themes/clean Details

Request GET /plugins/system/rokbox/themes/clean/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/ Acunetix Website Audit

13

Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:03 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 845 Keep-Alive: timeout=5, max=94 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/themes/dark Details

Request GET /plugins/system/rokbox/themes/dark/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:03 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1671 Keep-Alive: timeout=5, max=94 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/themes/light Details

Request GET /plugins/system/rokbox/themes/light/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/light/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response Acunetix Website Audit 14

HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:51 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1717 Keep-Alive: timeout=5, max=87 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/themes/mynxx Details

Request GET /plugins/system/rokbox/themes/mynxx/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1717 Keep-Alive: timeout=5, max=96 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/themes/sample Details

Request GET /plugins/system/rokbox/themes/sample/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 597 Keep-Alive: timeout=5, max=96 Connection: Keep-Alive Acunetix Website Audit 15

/templates/hcarmy/css Details

Request GET /templates/hcarmy/css/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/templates/hcarmy/css/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:52 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 651 Keep-Alive: timeout=5, max=94 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /templates/hcarmy/images Details

Request GET /templates/hcarmy/images/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/templates/hcarmy/images/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:03 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1909 Keep-Alive: timeout=5, max=99 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1

Possible sensitive directories


Severity Type Low Validation 16

Acunetix Website Audit

Reported by module Scripting (Possible_Sensitive_Directories.script) Description

Impact

Recommendation

Affected items /administrator Details Request GET /administrator HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:05:01 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/administrator/ Content-Length: 427 Keep-Alive: timeout=5, max=29 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /administrator/backups Details Request GET /administrator/backups HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:35:30 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/administrator/backups/ Content-Length: 435 Keep-Alive: timeout=5, max=96 Connection: Keep-Alive Acunetix Website Audit 17

/administrator/cache Details Request GET /administrator/cache HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:34:59 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/administrator/cache/ Content-Length: 433 Keep-Alive: timeout=5, max=67 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /administrator/templates/system Details Request GET /administrator/templates/system HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:43:44 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/administrator/templates/system/ Content-Length: 444 Keep-Alive: timeout=5, max=39 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /cache Details Request GET /cache HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Acunetix Website Audit 18

Accept-Encoding: gzip,deflate Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:04:56 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/cache/ Content-Length: 419 Keep-Alive: timeout=5, max=57 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /cgi-bin Details Request GET /cgi-bin HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:04:49 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/cgi-bin/ Content-Length: 421 Keep-Alive: timeout=5, max=91 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /cgi-sys Details Request GET /cgi-sys HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:04:49 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/cgi-sys/ Content-Length: 421 Keep-Alive: timeout=5, max=90 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1

Acunetix Website Audit

19

/logs Details Request GET /logs HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:04:57 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/logs/ Content-Length: 418 Keep-Alive: timeout=5, max=49 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /mailman Details Request GET /mailman HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:04:55 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/mailman/ Content-Length: 421 Keep-Alive: timeout=5, max=60 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /media/system Details Request GET /media/system HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate Acunetix Website Audit 20

Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:26:57 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/media/system/ Content-Length: 426 Keep-Alive: timeout=5, max=7 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /modules/mod_globalnews/scripts Details Request GET /modules/mod_globalnews/scripts HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:22:50 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/modules/mod_globalnews/scripts/ Content-Length: 444 Keep-Alive: timeout=5, max=18 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /plugins/system Details Request GET /plugins/system HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:06:22 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/plugins/system/ Content-Length: 428 Keep-Alive: timeout=5, max=44 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1

Acunetix Website Audit

21

/plugins/tmp Details Request GET /plugins/tmp HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:06:18 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/plugins/tmp/ Content-Length: 425 Keep-Alive: timeout=5, max=64 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /plugins/xmlrpc Details Request GET /plugins/xmlrpc HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:05:51 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/plugins/xmlrpc/ Content-Length: 428 Keep-Alive: timeout=5, max=72 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /templates/system Details Request GET /templates/system HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate Acunetix Website Audit 22

Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:10:33 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/templates/system/ Content-Length: 430 Keep-Alive: timeout=5, max=4 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /tmp Details Request GET /tmp HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:05:19 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/tmp/ Content-Length: 417 Keep-Alive: timeout=5, max=45 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /xmlrpc Details Request GET /xmlrpc HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:04:51 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/xmlrpc/ Content-Length: 420 Keep-Alive: timeout=5, max=82 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1

Acunetix Website Audit

23

/xmlrpc/cache Details Request GET /xmlrpc/cache HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 301 Moved Permanently Date: Fri, 14 Oct 2011 19:40:14 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Location: http://www.hcarmy.net/xmlrpc/cache/ Content-Length: 426 Keep-Alive: timeout=5, max=54 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1

Possible sensitive files


Severity Low Type Validation Reported by module Scripting (Possible_Sensitive_Files.script) Description

Impact

Recommendation

Affected items /plugins/system/debug.php Details Request GET /plugins/system/debug.php HTTP/1.1 Accept: acunetix/wvs Range: bytes=0-99999 Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:06:40 GMT Acunetix Website Audit 24

Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.17 Keep-Alive: timeout=5, max=83 Connection: Keep-Alive Content-Type: text/html

TRACE method is enabled


Severity Low Type Validation Reported by module Scripting (Track_Trace_Server_Methods.script) Description

Impact

Recommendation

Affected items Web Server Details Request TRACE /o1L2Xvjmaw HTTP/1.1 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:37 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Keep-Alive: timeout=5, max=94 Connection: Keep-Alive Content-Type: message/http Content-Length: 171

Broken links
Severity Informational Type Informational Reported by module Crawler Description

Impact

Acunetix Website Audit

25

Recommendation

Affected items /a Details Request GET /a HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 404 Not Found Date: Fri, 14 Oct 2011 19:04:46 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 501 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /www.facebook.com Details Request GET /www.facebook.com HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 404 Not Found Date: Fri, 14 Oct 2011 19:02:45 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 516 Keep-Alive: timeout=5, max=95 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /www.frienndfeed.com/hcarmy Details Request GET /www.frienndfeed.com/hcarmy HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix Website Audit 26

Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 404 Not Found Date: Fri, 14 Oct 2011 19:02:45 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 526 Keep-Alive: timeout=5, max=96 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1 /www.twitter.com Details Request GET /www.twitter.com HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 404 Not Found Date: Fri, 14 Oct 2011 19:02:45 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 515 Keep-Alive: timeout=5, max=97 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1

Email address found


Severity Informational Type Informational Reported by module Scripting (Text_Search.script) Description

Impact

Recommendation

Affected items

Acunetix Website Audit

27

/administrator/templates/khepri/css/general.css Details

Request GET /administrator/templates/khepri/css/general.css HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/administrator/templates/khepri/css/login.css Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:05 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Tue, 05 Apr 2011 14:32:38 GMT ETag: "b558f0-3d90-4a02cbf758d80" Accept-Ranges: bytes Content-Length: 15760 Keep-Alive: timeout=5, max=87 Connection: Keep-Alive Content-Type: text/css /administrator/templates/khepri/css/login.css Details

Request GET /administrator/templates/khepri/css/login.css HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/administrator/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:02 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Tue, 05 Apr 2011 14:32:54 GMT ETag: "b558ea-833-4a02cc069b180" Accept-Ranges: bytes Content-Length: 2099 Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Acunetix Website Audit 28

/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/jquery-wijmo.css Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/jquery-wijmo.css HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:11 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Mon, 19 Sep 2011 05:30:28 GMT ETag: "b65448-e225-4ad44a404c500" Accept-Ranges: bytes Content-Length: 57893 Keep-Alive: timeout=5, max=73 Connection: Keep-Alive Content-Type: text/css /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/jquery-wijmo2.css Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/jquery-wijmo2.css HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:11 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Mon, 19 Sep 2011 05:30:28 GMT ETag: "b6544a-c3f5-4ad44a404c500" Accept-Ranges: bytes Content-Length: 50165 Keep-Alive: timeout=5, max=71 Acunetix Website Audit 29

Connection: Keep-Alive

Error page Web Server version disclosure


Severity Informational Type Configuration Reported by module Scripting (Error_Page_Path_Disclosure.script) Description

Impact

Recommendation

Affected items Web Server Details

Request GET /AoIleWN3In HTTP/1.1 Host: www.hcarmy.net Connection: Keep-alive Accept-Encoding: gzip,deflate User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 404 Not Found Date: Fri, 14 Oct 2011 19:02:37 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 510 Keep-Alive: timeout=5, max=99 Connection: Keep-Alive Content-Type: text/html; charset=iso-8859-1

Files listed in robots.txt but not linked


Severity Informational Type Informational Reported by module Crawler Description

Impact

Recommendation

Affected items

Acunetix Website Audit

30

/administrator Details Request GET /administrator/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:48 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.17 P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Expires: Mon, 1 Jan 2001 00:00:00 GMT Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3; path=/ Last-Modified: Fri, 14 Oct 2011 19:02:48 GMT Keep-Alive: timeout=5, max=74 Connection: Keep-Alive Content-Type: text/html; charset=utf-8 Content-Length: 4752 /cache Details Request GET /cache/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:48 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Sun, 20 Aug 2006 14:37:02 GMT ETag: "b553e0-2c-41b73ed397f80" Accept-Ranges: bytes Content-Length: 44 Keep-Alive: timeout=5, max=91 Connection: Keep-Alive Content-Type: text/html /components Details Request GET /components/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix Website Audit 31

Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:48 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Wed, 14 Sep 2005 17:55:28 GMT ETag: "b3d8be-2f-400bf10d52400" Accept-Ranges: bytes Content-Length: 47 Keep-Alive: timeout=5, max=85 Connection: Keep-Alive Content-Type: text/html /images Details Request GET /images/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/images/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:53 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Wed, 14 Sep 2005 17:55:28 GMT ETag: "b3d9d6-2c-400bf10d52400" Accept-Ranges: bytes Content-Length: 44 Keep-Alive: timeout=5, max=80 Connection: Keep-Alive Content-Type: text/html /includes Details Request GET /includes/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:48 GMT Acunetix Website Audit 32

Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Wed, 14 Sep 2005 17:55:28 GMT ETag: "b3db3f-2f-400bf10d52400" Accept-Ranges: bytes Content-Length: 47 Keep-Alive: timeout=5, max=75 Connection: Keep-Alive /language Details Request GET /language/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:48 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Wed, 14 Sep 2005 17:55:28 GMT ETag: "b3da4d-2f-400bf10d52400" Accept-Ranges: bytes Content-Length: 47 Keep-Alive: timeout=5, max=79 Connection: Keep-Alive Content-Type: text/html /libraries Details Request GET /libraries/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:48 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Wed, 02 Nov 2005 10:29:20 GMT ETag: "b3d725-2f-404928b8f4000" Accept-Ranges: bytes Content-Length: 47 Keep-Alive: timeout=5, max=85 Connection: Keep-Alive Content-Type: text/html /media Details

Acunetix Website Audit

33

Request GET /media/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/media/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:54 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Tue, 25 Apr 2006 23:23:10 GMT ETag: "b3da61-2c-41249a3641380" Accept-Ranges: bytes Content-Length: 44 Keep-Alive: timeout=5, max=46 Connection: Keep-Alive Content-Type: text/html /plugins Details Request GET /plugins/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:50 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Fri, 03 Nov 2006 05:51:26 GMT ETag: "b4edc3-2c-4215153a17380" Accept-Ranges: bytes Content-Length: 44 Keep-Alive: timeout=5, max=69 Connection: Keep-Alive Content-Type: text/html /templates Details Request GET /templates/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/templates/ Acunetix Website Audit

34

Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:52 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Wed, 26 Sep 2007 12:20:46 GMT ETag: "b45a8c-2c-43b08e21a6380" Accept-Ranges: bytes Content-Length: 44 Keep-Alive: timeout=5, max=97 Connection: Keep-Alive Content-Type: text/html /tmp Details Request GET /tmp/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:48 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Fri, 13 Jul 2007 12:48:48 GMT ETag: "b3d78b-2c-4352488428c00" Accept-Ranges: bytes Content-Length: 44 Keep-Alive: timeout=5, max=89 Connection: Keep-Alive Content-Type: text/html /xmlrpc Details Request GET /xmlrpc/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:48 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.17 Acunetix Website Audit 35

P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Set-Cookie: fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; path=/ Keep-Alive: timeout=5, max=92 Connection: Keep-Alive Content-Type: text/html

GHDB: Apache directory listing which show Apache version


Severity Informational Type Informational Reported by module GHDB Description

Impact

Recommendation

Affected items /administrator/templates/khepri/images/h_cherry Details

Request GET /administrator/templates/khepri/images/h_cherry/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/administrator/templates/khepri/images/h_cherry/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:09 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 836 Keep-Alive: timeout=5, max=75 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1

Acunetix Website Audit

36

/administrator/templates/khepri/images/h_green Details

Request GET /administrator/templates/khepri/images/h_green/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/administrator/templates/khepri/images/h_green/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:08 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 834 Keep-Alive: timeout=5, max=75 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /administrator/templates/khepri/images/h_teal Details

Request GET /administrator/templates/khepri/images/h_teal/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/administrator/templates/khepri/images/h_teal/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:09 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 832 Keep-Alive: timeout=5, max=75 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /logo Details

Request GET /logo/ HTTP/1.1 Acunetix Website Audit 37

Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/logo/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:54 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 566 Keep-Alive: timeout=5, max=53 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules Details

Request GET /modules/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:51 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 3432 Keep-Alive: timeout=5, max=69 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu Details

Request GET /modules/mod_artwijmomenu/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Acunetix Website Audit 38

Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 630 Keep-Alive: timeout=5, max=93 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:06 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 615 Keep-Alive: timeout=5, max=82 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/helpers Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/helpers/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:08 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 592 Keep-Alive: timeout=5, max=78 Acunetix Website Audit

39

Connection: Keep-Alive /modules/mod_artwijmomenu/mod_artwijmomenu/stuff Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:08 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 694 Keep-Alive: timeout=5, max=77 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/external Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/external/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:09 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1114 Keep-Alive: timeout=5, max=76 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/external/globinfo Details

Request Acunetix Website Audit 40

GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/external/globinfo/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/external/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:09 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 639 Keep-Alive: timeout=5, max=71 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:09 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 712 Keep-Alive: timeout=5, max=73 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Acunetix Website Audit 41

Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:09 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 757 Keep-Alive: timeout=5, max=74 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/images Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/images/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/aristo/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:11 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 4726 Keep-Alive: timeout=5, max=67 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/midnight Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/midnight/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:09 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Acunetix Website Audit 42

Content-Length: 681 Keep-Alive: timeout=5, max=70 Connection: Keep-Alive /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/midnight/images Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/midnight/images/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/midnight/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:11 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1756 Keep-Alive: timeout=5, max=72 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ui-lightness Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ui-lightness/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:09 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 689 Keep-Alive: timeout=5, max=74 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1

Acunetix Website Audit

43

/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ui-lightness/images Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ui-lightness/images/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ui-lightness/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:11 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1886 Keep-Alive: timeout=5, max=70 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/wijmo Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/wijmo/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:10 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1953 Keep-Alive: timeout=5, max=73 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/wijmo/images Details

Request Acunetix Website Audit 44

GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/wijmo/images/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/themes/wijmo/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:11 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 741 Keep-Alive: timeout=5, max=70 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/wijmo Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/wijmo/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:09 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 2026 Keep-Alive: timeout=5, max=72 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/wijmo/minified Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/stuff/wijmo/minified/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/stuff/wijmo/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Acunetix Website Audit 45

Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:11 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 2100 Keep-Alive: timeout=5, max=71 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_artwijmomenu/mod_artwijmomenu/templates Details

Request GET /modules/mod_artwijmomenu/mod_artwijmomenu/templates/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_artwijmomenu/mod_artwijmomenu/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:08 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 582 Keep-Alive: timeout=5, max=80 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_banners2 Details

Request GET /modules/mod_banners2/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Acunetix Website Audit 46

Content-Length: 546 Keep-Alive: timeout=5, max=95 Connection: Keep-Alive /modules/mod_cool_contact Details

Request GET /modules/mod_cool_contact/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 570 Keep-Alive: timeout=5, max=93 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_jacatslwi Details

Request GET /modules/mod_jacatslwi/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_jacatslwi/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:51 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 646 Keep-Alive: timeout=5, max=99 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1

Acunetix Website Audit

47

/modules/mod_jaslideshow2 Details

Request GET /modules/mod_jaslideshow2/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 692 Keep-Alive: timeout=5, max=94 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_slick_rss Details

Request GET /modules/mod_slick_rss/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 634 Keep-Alive: timeout=5, max=92 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_slick_rss/tmpl Details

Request GET /modules/mod_slick_rss/tmpl/ HTTP/1.1 Acunetix Website Audit 48

Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_slick_rss/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:07 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 504 Keep-Alive: timeout=5, max=82 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_socialmedialinks/icons/default Details

Request GET /modules/mod_socialmedialinks/icons/default/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_socialmedialinks/icons/default/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:53 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 691 Keep-Alive: timeout=5, max=52 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_socialmedialinks/icons/default/size1 Details

Request GET /modules/mod_socialmedialinks/icons/default/size1/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_socialmedialinks/icons/default/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Acunetix Website Audit 49

Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:05 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1965 Keep-Alive: timeout=5, max=88 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_socialmedialinks/icons/default/size2 Details

Request GET /modules/mod_socialmedialinks/icons/default/size2/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_socialmedialinks/icons/default/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:05 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1965 Keep-Alive: timeout=5, max=88 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_socialmedialinks/icons/default/size3 Details

Request GET /modules/mod_socialmedialinks/icons/default/size3/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_socialmedialinks/icons/default/size3/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:53 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 2059 Keep-Alive: timeout=5, max=60 Acunetix Website Audit

50

Connection: Keep-Alive /modules/mod_socialmedialinks/icons/default/size4 Details

Request GET /modules/mod_socialmedialinks/icons/default/size4/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_socialmedialinks/icons/default/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:05 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1965 Keep-Alive: timeout=5, max=90 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_socialmedialinks/icons/default/size5 Details

Request GET /modules/mod_socialmedialinks/icons/default/size5/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_socialmedialinks/icons/default/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:05 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1965 Keep-Alive: timeout=5, max=90 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_the_tranquil Details

Request Acunetix Website Audit 51

GET /modules/mod_the_tranquil/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 734 Keep-Alive: timeout=5, max=93 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /modules/mod_the_tranquil/banner Details

Request GET /modules/mod_the_tranquil/banner/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_the_tranquil/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:07 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 545 Keep-Alive: timeout=5, max=79 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/content/JoomLifebookmarks Details

Request GET /plugins/content/JoomLifebookmarks/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/content/JoomLifebookmarks/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Acunetix Website Audit 52

Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:03 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 634 Keep-Alive: timeout=5, max=96 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox Details

Request GET /plugins/system/rokbox/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:50 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 729 Keep-Alive: timeout=5, max=89 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/jwplayer Details

Request GET /plugins/system/rokbox/jwplayer/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:03 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Acunetix Website Audit 53

Content-Length: 514 Keep-Alive: timeout=5, max=94 Connection: Keep-Alive /plugins/system/rokbox/themes Details

Request GET /plugins/system/rokbox/themes/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:51 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 650 Keep-Alive: timeout=5, max=88 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/themes/clean Details

Request GET /plugins/system/rokbox/themes/clean/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:03 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 845 Keep-Alive: timeout=5, max=94 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1

Acunetix Website Audit

54

/plugins/system/rokbox/themes/dark Details

Request GET /plugins/system/rokbox/themes/dark/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:03 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1671 Keep-Alive: timeout=5, max=94 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/themes/light Details

Request GET /plugins/system/rokbox/themes/light/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/light/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:51 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1717 Keep-Alive: timeout=5, max=87 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/themes/mynxx Details

Request GET /plugins/system/rokbox/themes/mynxx/ HTTP/1.1 Acunetix Website Audit 55

Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1717 Keep-Alive: timeout=5, max=96 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /plugins/system/rokbox/themes/sample Details

Request GET /plugins/system/rokbox/themes/sample/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/plugins/system/rokbox/themes/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 597 Keep-Alive: timeout=5, max=96 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /templates/hcarmy/css Details

Request GET /templates/hcarmy/css/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/templates/hcarmy/css/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Acunetix Website Audit 56

Connection: Keep-alive Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:52 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 651 Keep-Alive: timeout=5, max=94 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1 /templates/hcarmy/images Details

Request GET /templates/hcarmy/images/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/templates/hcarmy/images/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:03 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 1909 Keep-Alive: timeout=5, max=99 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1

GHDB: Possible temporary file/directory


Severity Informational Type Informational Reported by module GHDB Description

Impact

Recommendation

Acunetix Website Audit

57

Affected items /modules/mod_jaslideshow2/tmpl Details

Request GET /modules/mod_jaslideshow2/tmpl/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_jaslideshow2/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:07 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Sun, 11 Sep 2011 11:54:41 GMT ETag: "b4ea76-2c-4aca9135aa240" Accept-Ranges: bytes Content-Length: 44 Keep-Alive: timeout=5, max=81 Connection: Keep-Alive Content-Type: text/html /modules/mod_slick_rss/tmpl Details

Request GET /modules/mod_slick_rss/tmpl/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_slick_rss/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:07 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Content-Length: 504 Keep-Alive: timeout=5, max=82 Connection: Keep-Alive Content-Type: text/html;charset=ISO-8859-1

Acunetix Website Audit

58

/modules/mod_slick_rss/tmpl/default.php Details

Request GET /modules/mod_slick_rss/tmpl/default.php HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/mod_slick_rss/tmpl/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:08 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.17 Keep-Alive: timeout=5, max=78 Connection: Keep-Alive Content-Type: text/html Content-Length: 17 /modules/tmpl Details

Request GET /modules/tmpl/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/modules/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:04 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Thu, 18 Jun 2009 11:33:06 GMT ETag: "b4ea7b-2c-46c9dc57fe080" Accept-Ranges: bytes Content-Length: 44 Keep-Alive: timeout=5, max=89 Connection: Keep-Alive Content-Type: text/html

Acunetix Website Audit

59

/tmp Details

Request GET /tmp/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:48 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Fri, 13 Jul 2007 12:48:48 GMT ETag: "b3d78b-2c-4352488428c00" Accept-Ranges: bytes Content-Length: 44 Keep-Alive: timeout=5, max=89 Connection: Keep-Alive Content-Type: text/html

Password type input with autocomplete enabled


Severity Informational Type Informational Reported by module Crawler Description

Impact

Recommendation

Affected items /administrator Details Request GET /administrator/ HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive Acunetix Website Audit 60

Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:48 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.17 P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Expires: Mon, 1 Jan 2001 00:00:00 GMT Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Set-Cookie: fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3; path=/ Last-Modified: Fri, 14 Oct 2011 19:02:48 GMT Keep-Alive: timeout=5, max=74 Connection: Keep-Alive Content-Type: text/html; charset=utf-8 Content-Length: 4752 /administrator/index.php Details Request GET /administrator/index.php HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/administrator/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:02 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.17 P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Expires: Mon, 1 Jan 2001 00:00:00 GMT Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Last-Modified: Fri, 14 Oct 2011 19:03:03 GMT Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/html; charset=utf-8 Content-Length: 4752 /administrator/index.php (8777c66fca8866ed2d0de75899bcfc7c) Details Request POST /administrator/index.php HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/administrator/ Content-Length: 107 Content-Type: application/x-www-form-urlencoded Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Acunetix Website Audit 61

Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) ee1649ff9f4f5d2ec1315549ff7df348=1&lang=fa-IR&option=com_login&passwd=acUn3t1x&task=login&us Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:02 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.17 P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Expires: Mon, 1 Jan 2001 00:00:00 GMT Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Last-Modified: Fri, 14 Oct 2011 19:03:03 GMT Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/html; charset=utf-8 Content-Length: 5007

Possible server path disclosure (Unix)


Severity Informational Type Informational Reported by module Scripting (Text_Search.script) Description

Impact

Recommendation

Affected items /administrator/index.php Details

Request GET /administrator/index.php HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/administrator/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb; fd4cfc4b5e78b00a78418452a9bd061e=7d14c38b07e3eb8bb238c8dc92969af1; fa6933367c0705d4b4925524fdcb4363=299ad8d6c10bce7bf809e5c4d02fbfc3 Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response Acunetix Website Audit 62

HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:03:02 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.17 P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Expires: Mon, 1 Jan 2001 00:00:00 GMT Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Last-Modified: Fri, 14 Oct 2011 19:03:03 GMT Keep-Alive: timeout=5, max=100 Connection: Keep-Alive Content-Type: text/html; charset=utf-8 Content-Length: 4752 /index.php Details

Request GET /index.php HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Referer: http://www.hcarmy.net/ Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:39 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 X-Powered-By: PHP/5.2.17 P3P: CP="NOI ADM DEV PSAi COM NAV OUR OTRo STP IND DEM" Expires: Mon, 1 Jan 2001 00:00:00 GMT Cache-Control: post-check=0, pre-check=0 Pragma: no-cache Last-Modified: Fri, 14 Oct 2011 19:02:40 GMT Content-Length: 100798 Keep-Alive: timeout=5, max=91 Connection: Keep-Alive Content-Type: text/html; charset=utf-8 /robots.txt Details

Request GET /robots.txt HTTP/1.1 Pragma: no-cache Acunetix-Aspect: enabled Acunetix-Aspect-Password: ***** Acunetix-Aspect-Queries: filelist;aspectalerts Cookie: 716e3115923c8d9d6c5fa73f8a1297de=fd3192e99b0737249f880b4f2ec011bb Host: www.hcarmy.net Connection: Keep-alive User-Agent: Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0) Response Acunetix Website Audit 63

HTTP/1.1 200 OK Date: Fri, 14 Oct 2011 19:02:39 GMT Server: Apache/2.2.20 (Unix) mod_ssl/2.2.20 OpenSSL/0.9.8e-fips-rhel5 mod_auth_passthrough/2.1 mod_bwlimited/1.4 FrontPage/5.0.2.2635 Last-Modified: Mon, 07 Aug 2006 18:51:34 GMT ETag: "b3d546-130-41a71f791d980" Accept-Ranges: bytes Content-Length: 304 Keep-Alive: timeout=5, max=90 Connection: Keep-Alive Content-Type: text/plain

Acunetix Website Audit

64

You might also like