Someone hacked my apache2 server

Someone hacked my apache2 server

am 03.04.2010 23:20:21 von Oleg Goryunov

--0016e6dbded802cadd04835bab59
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: base64

SGVsbG8gYWxsLApJdCBsb29rcyBsaWtlIHNvbWVvbmUgaGFja2VkIG15IGFw YWNoZTIgc2VydmVy
IGFuZCBJIGFtIHRyeWluZyB0byB1bmRlcnN0YW5kCmhvdyB0aGlzIGNvdWxk IGhhdmUgaGFwcGVu
ZWQuClRoaXMgaXMgd2hhdCBoYXBwZW5lZDoKQWxsIG9mIGEgc3VkZGVuIHRo ZSBzZXJ2ZXIgLSBp
biByZXNwb25zZSB0byBhIHdlYi1icm93c2VyIHJlcXVlc3QgZm9yIGEgcGFn ZQotIHN0YXJ0ZWQg
dG8gZ2l2ZSBhIGZ1bGwgc2NyZWVuIG9mIHVua25vd24gY2hhcmFjdGVycyAo bG9va2VkIGxpa2Ug
YSBsb25nCnRleHQgd2l0aCBlbmNvZGluZyBtaXNtYXRjaCkuClRoZSBvdXRw dXQgd2FzIGltbWVk
aWF0ZSBhbmQgdGhlIHNhbWUgZm9yIGFsbCB0aGUgd2ViLXNpdGVzIGxvY2F0 ZWQgb24gdGhlCnNl
cnZlci4KTG9va2luZyBhdCB0aGUgcGFnZSBzb3VyY2Ugb2YgdGhlIG91dHB1 dCBJIHNlZSB0aGUg
Zm9sbG93aW5nOgo9PT09PT09PT0KCjxpZnJhbWUgc3JjPSAgaHR0cDovL2Eg eiBzIHggZCBlIDUg
NSAuIDkgOSA2IDYgLiBvcmc6ODgwMC9hazQ3LzI5Lmh0bWwKd2lkdGg9MSBo ZWlnaHQ9MT48L2lm
cmFtZT4g0Jsg77+977+977+977+977+977+9INGNW9GBbuKWiDgg4pag4paM 77+94oiaIFwt4paR
eyDilZjQpiAn4paIJnEg4pSkSSDRiV3ilZnRhOKVpWx74oia0LvQsCTilIwK ZkPQoSpJ4pSY0ZHR
gSDRhtCu0YXQrtGMZijilanQpiA5TuKWky3QvuKVl3DQkOKUgCA54oSWZjjQ rCAg0JfilanQgeKI
mtCj0ZTRg9C74paALl7QodCZTSDilaPCsNGX0YXQq+KVq+KVnyTRiNCU0YHQ l+KUtHEg0K5c0K3Q
oCDQrl7QreKVnAohwqRu0J9caSoKCuKVllxJKuKUrNCB4pWS4paI0JAgIGvi lILCpDDQrOKVkGbi
lozilJjQsNC70Ic44pWd4pWRIG8g0LvQn9CTwqTilavQntC90JzRjCY2ICAg ICAg0J7QltCe4paA
TSrQtDlsQdGJ0Y/RjdGNINCT0JPQs9C94oia4pWZIuKVpOKVm9CwcnwgMOKU mEcK0Lk9ICDQs+KV
lOKVpCAh4pSc0JggRibQqtCdINCg0KLilZDilZFUUOKVkNCd0LDQodGJ4pWe KgpN0K5lSuKWiG4g
IOKVkdCRKeKUgtCk0YDQoCDiiJrQrNGU0YlhICtp0KnilKQgO+KVp1hA4oSW 4pWZYWDilJjQnQpx
0YAg0JknVCBmIHM70Yo80L/RgUjQquKWk+KUnEDQu0hZUyDilaZl4pSsbtCu 0KLQoSBC4pWQWiBc
4pSC4oiZTNGJ0LQ60YTQo1LQudCwT+KVlOKWgOKWhGfilaYg4pWm0L3QuOKV qdGe0Y7ilavQm9Cb
0ZTilabQuyBK0KrilojQmeKVpSDilaVJCuKVqSU34paR0Jog4paIbwoKSNCo 0Jk14pWncH0r0LMK
SeKVmycgYifQnCRz0LDRhTFBfVJB0Kggc+KVlCDQpUk50JDQtFTilaUxS9GR 0LvQqSDilabilaUg
TmMm0KnQp9GCINCvfncgeNCtZ0zQoncq4pWrMSPilZ8g4oiZbNCRXEI6ZSB5 ICDilJzRgiA7CtCn
4pWr4paQLEIgISDilZgyIC7ilZAiIOKVpCkg4pWTXcKwICDilZDilIBhYEBZ NuKVrC3ilLTQjtCQ
0LAg4pSUCtC24pSUMeKVndGJIG0g4pWZQknQruKUlNCp4pWfJzrQtUVrQNCc 0J7QkWfilakgTuKU
nGLilqDRgScg0LZKWdC10JTRiX4y0YA0YUHihJZo4pSk0KjilZFFatCQbSDi lIIuJmPRh9CS0Kkg
ICAgICBj0JBx0KdiU3kK0YzilKxTUNCl4pSAPeKUnNC0ICAgICAgICBS4pSc INC/ROKWjCDQltCV
IG8KCiPQpeKVoNCR4pWQ4pWU0YvRniQg4pWYQHxIKdCnQeKVnCk3TNCvMdCp 0LM5QC/ilZnilagg
ZDhSOiU0Rn3QkCxMNtCsINCcbtCy0KLilJwgUyAkLtC8Tygw4pSM0JBwaOKV nuKVpCAgXNCE4pWk
bOKEliA0I8K3CtCjJ0MuM+KUpCAgICAgINCwTVUi4pWe0IQj0JrQkTjilZI5 0KXilZrilaY+0J/R
hUZH0YomIFTilapq4pSQ0YEgIMK3fiBGWuKImWTvv70wS0ou0Y4gICAgICBi ReKVlNC50YzilZzi
lLxnICAgICAg0YwKOC7ilZ/QvdGC0LPilLTQs+KVpSDilKTRiTlNeNCiMFnQ hFnQjuKWkNGCNNC1
IiDQmjkz0K7ilavQtdC3JWfQvGTQlyBpaSjilpE4INCdMyXilLTQk0NURSDQ utCWeOKUgHTilatv
IEgg0YnilojQliEtINCkXiAgQQrilJgj0JDilZUgdEk5a9CX4paSVU7ilZFt fuKVqdCXOz8g0JB2
IFzilZog4pWfOEvilZDRl2LQpDfQsDVDNOKUguKVo17ilpN6M3jilojQn09f TmPiiJnQn9Cs0K5e
4pSM0Yhk4pWn4oSW0I5hV158eNCv0L/ilLzQktGPSTJgCuKVnOKVnOKUtG5v d9Ge4pSYKOKUjOKU
mOKWkNGJ0Y8k4pWUXiDRjSDilaLiiJrilZTQkksg0LHQliHilIzilaPRlDjQ gdC34pWRV1nQpdCx
UyAg4pS80IHilojRjyDiloBw0LVx0Lcg0IR00YzQk1DQu9Cr0ZQw0YrQnuKI mWhhIDoiViDRgdCz
4pWeaQrilZZaQCBZ0Z7ilqDQlVks0KBgLSBGRTTQrmEuINGRINCWdjDQuCAg 0IcgXtCOZFTRg9GG
4pSsQeKVrD504pWo4pWh4pSYICDQqdCc4pWp0LPilZnRlOKUglcgfdGRK+KW kyBmVVjQl9GecyAg
LXfQslIgRuKWkQriiJnQneKVlTXilpBkIOKWkdCn4pWb4paSCgoKfiDRkVkg 0LLQoiDQsFkgdGxr
0LDRh9C+0K1g4oiaLeKWhCDilLxt0YHQgeKVoCAu4paIICAg4pWj0L3ilIzQ k+KWoHsg0YU/0Yog
IHXRjjRk4pWQ4pSkStCE4pWVLtGC4pWS0YkrcnF5ftCE0YvRkeKVkuKWjOKV keKWhG0gIOKVo9Cs
KgozNWV64pWpYeKWktC60YDQv9GFe9GMI2XRhzrRhT5f4pS00JPRinggIDHC sC/QuzF4UdGJ4pWV
IOKVndCy0KPQtkXQpCwiLmDQveKVntCzXOKVkdC90LxhIEUnWdCH0L7Qq+KV muKWkAouWtGFINCQ
OtGNbC7Qm+KWkHvilILilJjRjtC9YNGDUtCtIOKUgNCsIMKwS+KVqXTilaDQ udGIJGhIIOKUguKV
luKVkSAgLdC04pWa0KosaeKVlNCidtCtIMKk4pWhIkgg0L/Rh8Kk0I7ihJbC sCBM4pWWVzDQnXNj
4pS0IHUgUiUK0Yo04pWqWWbilJw14pWs4pWf0K7QoiwoK3nRlDrQjtCTINGM JeKUguKWkdGJXXdS
JTHRkeKUrNCVLnLilZ4g0YvilZYgIFlS4oiZPH0g4paIINGOINCe4pWV0LTi laUtcSDilZZf4pWp
4pWsezJZ0YXRhuKVleKVlCDilLTilKTRidGA0JEKQStR4pWW4paE4paT0KfC sOKWkHvQl+KVl9GH
0J8KCnfQqEHilLzilaPilZPRjjRS0Z5z4pWgRtC34pWg4pWje+KVmSBr4pWU 0LnRh+KWkTjilZvi
loQg4pag4pWi0KvQkeKUnCPQldC90JHRj+KEln4gb+KVl+KVo9Cr0KTQsCAm MjgKXuKVq0BPfdGD
OuKVqGYgLUHQv9C10KogICAgICDQptCcINCu4pSYa+KVmiDQv9CO4paEe9GJ wrfilZwv4pWWVdGX
0KtxJGHQudC64pWUeNCE0YrRjHzilZAgNSAgMeKWhCDQmCDQr9GU0YbRhnwg IOKUgHfiloRv0Y8g
NArRg9C9Y++/veKVnz/ilZ5kTE0j0LN44pWWbOKUkOKUkErilZbilJDQsErQ q2EK4pWZdirRh9GX
OHh+dtGR0YLRjW93K3bilahcINCfIOKVpWRKISAg4pSCwrfilaBfLNCq4pWr 0KjRitCwIOKVmkvR
gNCkINCTINGMKtGKWeKVpOKVoiBy4pS80Lwx0KE00J04POKVl2th0IHilohD 0ITRl9Cn0J/ilZDi
lavQs0cK0YbRi+KVpOKWjOKImcK3Ik8g0KfilaQg4pSC0ZcgUl/iiJpZ0KAu JiB8ICDQn9C2dFjQ
nkjCsOKUpOKVpMKk0JbQndCQROKWhOKUmNCZINGO4pWVciDCpAoKS1Yk0Kcg ICAgICDilZnQqNC7
V9CdJzh64paS0KDilogg0JZr4pWbWUV44pSc0YV1cERCUtCz0Jg00LNJ0LzR lDQycCTilaLQoyDQ
rdCTINGXwqRm4pWmID4g0JYgPz4gINGLJ2NpINCy4pWrae+/vQrQmdC50Jxh 0YkgftCWViDQok3Q
gTDilanilZ/ilaXilJggKirRlEHilZ4g0KPilpEgI21nRFMu0YbiiJogdtC+ IDLQsdC3WCLQrOKV
pdCT0LBOICvQsdCHPuKImdCx0Yd+INCYO9GeTCAgT9GMPtChcOKVmtC10YLQ kAo4PNC80JPRjNCj
4pagIOKVlyDQnNGPbtGRfDzilajQtF/Qo+KWiHc/4pWn0Yw6WSDiiJlsLdCb INC4U0bilaHQqCBm
YSxWV9GN0JRaV9CQwqTQrNCTLtGN0KzCsF3QpSDiloTRidGB0JzilJwKCtCx 0LjilZ050YHQuSvi
laxCICBBJiDilZQt0Kdu0LRVWOKWknV1INCyRiDQkiApT2TRhArRgSBiNtCp INCla0J50JrQn1Yh
4pWU0KQn4pWgIUTilpFV0KFMQSDilIDQpS8l0JDRl9GHKGTilaDilZHQm3g2 0Yk70K3Qp9C6SNC5
IHPilaNPem7QluKUnEjQo9CB0Ygg4pWq4pSkTCBT0JDQlCggICAgICDQvNC8 CibilZdaM052SuKV
o3Ag0Yho4pWWd+KUrF0g4pWmCiDQoeKWjOKUtOKEluKUkCBp0Y/Rj9CQbSA0 4pSAN9GIYtC1enHi
lZFo0JrQpNCV4pSk4pWcTibilJQtCiAqWDtU0YPQnNChRNGNey7ilaNY4pWf 0LbQmlnilZPRgCBu
Ymds4pWm4pWQReKUgiRTINCj4pWQ0JfRgCBxICAgICAgSyPQmjNG0LE64pWa wrcxICDQlyDRkXHQ
vl3Qn+KWiHLQkCBuOuKWgNCQ4pWoINCr4pWU0JUKO9CbeuKVpjDilZXilak1 0KHilaTQlOKVpFLi
lZwgICAgICDQq3IKCuKUkNCveXk04pSCIOKUrD7ilZrQgdCdKeKVn3vQldCp KNGFNOKVmOKVqCAg
INGFIOKWoCDQoyB80IdZOMKweeKVlnrQh+KUgEAkRCBz4oSW4paS0Lli4paS 0LYx0JPQv9GB4pSC
4pWm0JBQcV/iiJnQo9C9OHEg4pWSaiDilZLilaJC4pWRCuKVodGMPCDilarR jSrQq9CT0JFlINCV
a1R84pSU0Y0gLdCO77+94pS0WiDilZ3ilavilaDiloQ9IDTilZBR4pSc4pWb QNCB4pWYIOKUlNCu
ItCb0J3ilLxMeNCmQeKVqtC14pWe0L0g0YbQvNCSWSDRkUrRhOKVotCq0Ifi lZMg4paS4pWl0YHi
lZvCsArQvNGJ0ITRhuKVpeKVlz5uR35DSChkIuKVktCTY9Cb0KDQtcKk4oSW YSAg4paT4paQICA2
OeKVliAgINCQb1g7d9GGINGLbNGN4pWhcyAgIFnQmEzQqEAgICDilZcg4oia QyBa0Ywg0YAiwrDQ
hNCRUGPQpwphKWfQo2XRhdC0NE5I4pSQICAv4pWQIWPQodCU0LXQoOKUpCDQ ueKVlNCz0KRD0Yog
Ljkr0ZTQq+KUkOKVqiAgICAgINGENVgg0YAgNjzRh+KWkuKUvO+/vdCqJOKV qNGC4pWl4paS0JjQ
odCE4pWlIOKElnXilZ5h0Jx00ITQpV7QgQpXP0vRnuKVljIg0LnQvNCj0YDi lZM00KAgRQoKPT09
PT09PT09PT09PT09PT09ClRoZSBhZGRyZXNzIGluZGljYXRlZCBpbiB0aGUg YmVnaW5pbmcgb2Yg
dGhlIHBhZ2UgY29kZSBsZWFkcyB0byBzb21lIGNoaW5lc2UKc2VydmVyLgoK ClNvLCBzb21laG93
IGl0IGhhcHBlbmVkIHRoYXQgdGhlIG91dHB1dCBvZiB0aGUgYXBhY2hlIHNl cnZlciB3YXMgc3Vi
c3RpdHV0ZWQKYnkgdGhpcyBwYWdlLCB3aGljaCByZWRpcmVjdGVkIHZpc2l0 b3JzIHRvIHNvbWUg
Y2hpbmVzZSBzZXJ2ZXIuIEl0IGlzIHRoZQpzZWNvbmQgdGltZSBJIGFtIHBv c3RpbmcgdG8gdGhl
IG1haWxpbmcgbGlzdCwgdGhlIGZpcnN0IHRpbWUgdGhlIG1haWxpbmcKbGlz dCB2aXJ1cyBzY2Fu
bmVyIGlkZW50aWZpZWQgdGhlIGNvbnRlbnQgYXMgaGF2aW5nIHRoZSBUcm9q L0Z1amlmLUdlbgp2
aXJ1cywgdGh1cywgdGhpcyB0aW1lIEkgcmVtb3ZlZCBhY3RpdmUgbGlua3Mg ZnJvbSB0aGUgbWVz
c2FnZSBib2R5IHNvIGl0IGlzCm5vdCBleGFjdGx5IHdoYXQgSSByZWNlaXZl ZCkuCgpCdXQgdGhl
IG1vc3Qgc3RyYW5nZSB0aGluZyB3YXMgdGhhdCB0aGUgcHJvYmxlbSBkaXNz YXBlYXJlZCBpdHNl
bGYhIFNvLCBpdApsYXN0IGZvciAxMCBtaW51dGVzIHRoZW4gZGlzYXBwZWFy ZWQhIEFuZCB0aGUg
YWdhaW4gc3RhcnRlZCBhbmQgYWdhaW4KZGlzc2FwZWFyZWQuIEZpbmFsbHks IEkgdHVybmVkIGRv
d24gYXBhY2hlIHVudGlsbCBJIHVuZGVyc3RhbmQgd2hhdCBpcyBnb2luZwpv bi4uLgoKQW55IGlk
ZWEgaG93IGNvdWxkIHRoYXQgaGFwcGVuPyAgSG93IHRvIHJlcHJvZHVjZSB0 aGlzPyBIb3cgdG8g
cHJldmVudD8KV2hlcmUgdG8gbG9vayBmb3IgbG9ncz8gSSBoYXZlIGNoZWNr IGJvdGggc3NoIGxv
Z3MgYW5kIGFwYWNoZSBsb2dzLCB0aGVyZSBpcwpub3RoaW5nIHRoYXQgY291 bGQgc2VlbSB1bnVz
dWFsIHRoZXJlLi4uCgpBbnkgaGVscCBpcyBhcHByZWNpYXRlZC4KT2xlZy4K
--0016e6dbded802cadd04835bab59
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable










/Caches/TemporaryItems/msoclip/0/clip_filelist.xml">






>Hello all,

It looks like someone hacked my apache2 server and I am trying to understan=
d
how this could have happened.

This is what happened:

All of a sudden the server - in response to a web-browser request for a pag=
e -
started to give a full screen of unknown characters (looked like a long tex=
t
with encoding mismatch).

The output was immediate and the same for all the web-sites located on the
server.

Looking at the page source of the output I see the following:

=========3D



ly: Courier;"><iframe
src=3D 
z s x d e 5 5 . 9 9 6 6 . org:8800/ak47/29.html width=3D1
height=3D1></iframe>
amily: "Times New Roman";">Л 10pt; font-family: Courier;"> family: "Menlo Regular";">����=EF=
¿½ï¿=BD
"> n";">э ;">[ an";">с r;">n man";">â–=88 urier;">8 ew Roman";">■▌ ont-family: "Menlo Regular";">ï¿=BD -size: 10pt; font-family: Courier;">âˆ=9A \- size: 10pt; font-family: "Times New Roman";">â–=91 n style=3D"font-size: 10pt; font-family: Courier;">{ font-size: 10pt; font-family: "Times New Roman";">╘Ð=A6=
'=
=
â–=88
&=
;q
n";">â”=A4 ier;">I Roman";">щ urier;">] w Roman";">╙ф╥ pt; font-family: Courier;">l{âˆ=9A ; font-family: "Times New Roman";">ла =3D"font-size: 10pt; font-family: Courier;">$ e: 10pt; font-family: "Times New Roman";">â”=8C tyle=3D"font-size: 10pt; font-family: Courier;">fC t-size: 10pt; font-family: "Times New Roman";">С style=3D"font-size: 10pt; font-family: Courier;">*I ont-size: 10pt; font-family: "Times New Roman";">┘Ñ=91=
с
> >цЮхЮь family: Courier;">f( ot;Times New Roman";">╩Ð=A6 10pt; font-family: Courier;"> 9N -family: "Times New Roman";">â–=93 size: 10pt; font-family: Courier;">- font-family: "Times New Roman";">оâ•=97 e=3D"font-size: 10pt; font-family: Courier;">p ze: 10pt; font-family: "Times New Roman";">Аâ”=80=
9â„=96f8=
=
Ь
tyle=3D"">  "Times New Roman";">З╩Ð=81 ont-size: 10pt; font-family: Courier;">âˆ=9A size: 10pt; font-family: "Times New Roman";">Уєу=
лâ–=80
">.^ an";">СЙ Courier;">M New Roman";">â•=A3 ily: Courier;">° uot;Times New Roman";">їхЫ╫╟ n style=3D"font-size: 10pt; font-family: Courier;">$ ont-size: 10pt; font-family: "Times New Roman";">шД=D1=
Ð—â”´
er;">q Roman";">Ю rier;">\ Roman";">ЭР ly: Courier;"> mes New Roman";">Ю ily: Courier;">^ imes New Roman";">Эâ•=9C ; font-family: Courier;">!¤n t-family: "Times New Roman";">П ze: 10pt; font-family: Courier;">\i*



 

uot;;">â•=96 ;">\I* oman";">┬Ё╒█Ð=90 ont-size: 10pt; font-family: Courier;">  k an> ;">â”=82=
¤0
Roman";">Ьâ•=90 mily: Courier;">f Times New Roman";">▌┘алЇ yle=3D"font-size: 10pt; font-family: Courier;">8 size: 10pt; font-family: "Times New Roman";">╝║ span> o style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
»ÐŸÐ=93
">¤ Roman";">╫ОнМÑ=8C size: 10pt; font-family: Courier;">&6  =C2=
 Â Â=A0
"Times New Roman";">ОЖОâ–=80 =3D"font-size: 10pt; font-family: Courier;">M* ze: 10pt; font-family: "Times New Roman";">д le=3D"font-size: 10pt; font-family: Courier;">9lA -size: 10pt; font-family: "Times New Roman";">щяэ=
э
> >ГГгн : Courier;">âˆ=9A uot;Times New Roman";">â•=99 font-family: Courier;">" amily: "Times New Roman";">╤╛а tyle=3D"font-size: 10pt; font-family: Courier;">r| 0 ont-size: 10pt; font-family: "Times New Roman";">â”=98=
G e=3D"font-size: 10pt; font-family: "Times New Roman";">й an>=3D "">  Times New Roman";">г╔╤ size: 10pt; font-family: Courier;"> ! font-family: "Times New Roman";">├Ð=98 le=3D"font-size: 10pt; font-family: Courier;"> F& font-size: 10pt; font-family: "Times New Roman";">ЪН pan> yle=3D"font-size: 10pt; font-family: "Times New Roman";">Р=
Т═║
Courier;">TP s New Roman";">═НаСщ╞ style=3D"font-size: 10pt; font-family: Courier;">*



M
quot;;">Ю >eJ n";">â–=88 ier;">n  ; font-family: "Times New Roman";">║Ð=91 yle=3D"font-size: 10pt; font-family: Courier;">) size: 10pt; font-family: "Times New Roman";">│ФÑ=
€Ð=A0
=E2=
ˆš
oman";">Ьєщ family: Courier;">a +i quot;Times New Roman";">Щâ”=A4 : 10pt; font-family: Courier;"> ; t-family: "Times New Roman";">â•=A7 -size: 10pt; font-family: Courier;">X@â„=96 ize: 10pt; font-family: "Times New Roman";">â•=99 style=3D"font-size: 10pt; font-family: Courier;">a`
ont-size: 10pt; font-family: "Times New Roman";">┘Ð=9D<=
/span>



q
quot;;">р > ";">Й ">'T f
s;
";">ъ ">< oman";">пс : Courier;">H s New Roman";">Ъ▓├ : 10pt; font-family: Courier;">@ -family: "Times New Roman";">л e: 10pt; font-family: Courier;">HYS font-family: "Times New Roman";">â•=A6 ont-size: 10pt; font-family: Courier;">e pt; font-family: "Times New Roman";">┠=3D"font-size: 10pt; font-family: Courier;">n e: 10pt; font-family: "Times New Roman";">ЮТС
n> B le=3D"font-size: 10pt; font-family: "Times New Roman";">â•=90=
Z \ an style=3D"font-size: 10pt; font-family: "Times New Roman";">=E2=
”‚âˆ=
=99L
an";">щд Courier;">: New Roman";">фУ amily: Courier;">R ;Times New Roman";">йа font-family: Courier;">O : "Times New Roman";">╔▀â–=84 le=3D"font-size: 10pt; font-family: Courier;">g ize: 10pt; font-family: "Times New Roman";">â•=A6 style=3D"font-size: 10pt; font-family: Courier;"> nt-size: 10pt; font-family: "Times New Roman";">╦Ð=BD=
и╩ўю╫ЛЛє╠¦Ð=BB
> J e=3D"font-size: 10pt; font-family: "Times New Roman";">Ъ=E2=
–ˆÐ™â•=A5
urier;"> w Roman";">â•=A5 : Courier;"> I es New Roman";">â•=A9 amily: Courier;">%7 t;Times New Roman";">░Ð=9A 0pt; font-family: Courier;"> mily: "Times New Roman";">â–=88 e: 10pt; font-family: Courier;">o



 

H
quot;;">ШЙ rier;">5 Roman";">â•=A7 Courier;">p}+ es New Roman";">г ly: Courier;">



I
quot;;">â•=9B r;">' b' imes New Roman";">М mily: Courier;">$s ;Times New Roman";">ах font-family: Courier;">1A}RA mily: "Times New Roman";">Ш 10pt; font-family: Courier;"> s family: "Times New Roman";">â•=94 ize: 10pt; font-family: Courier;"> ont-family: "Times New Roman";">Ð¥ size: 10pt; font-family: Courier;">I9 font-family: "Times New Roman";">Ад =3D"font-size: 10pt; font-family: Courier;">T e: 10pt; font-family: "Times New Roman";">â•=A5 tyle=3D"font-size: 10pt; font-family: Courier;">1K t-size: 10pt; font-family: "Times New Roman";">ёлЩ=
style=3D"font-size: 10pt; font-family: "Times New Roman";">=E2=
•¦â•=A5 ">
Nc&
Roman";">ЩЧт -family: Courier;"> ot;Times New Roman";">Я t-family: Courier;">~w x "Times New Roman";">Э font-family: Courier;">gL y: "Times New Roman";">Т t; font-family: Courier;">w* ily: "Times New Roman";">â•=AB : 10pt; font-family: Courier;">1# t-family: "Times New Roman";">â•=9F -size: 10pt; font-family: Courier;"> âˆ=99l ize: 10pt; font-family: "Times New Roman";">Б yle=3D"font-size: 10pt; font-family: Courier;">\B:e
y 
-family: "Times New Roman";">├Ñ=82 "font-size: 10pt; font-family: Courier;"> ; : 10pt; font-family: "Times New Roman";">Ч╫▐=
,B ! <=
span style=3D"font-size: 10pt; font-family: "Times New Roman";">=
â•=982 .<=
/span> ot;;">â•=90 ">" w Roman";">â•=A4 : Courier;">) es New Roman";">â•=93 amily: Courier;">]°  =3D"font-size: 10pt; font-family: "Times New Roman";">â•=90=
â”=80
a`@Y=
6
quot;;">╠r;">- man";">┴ЎАа t; font-family: Courier;"> ly: "Times New Roman";">â”=94 10pt; font-family: Courier;">



uot;;">жâ”=94 ourier;">1 ew Roman";">╝Ñ=89 -family: Courier;"> m quot;Times New Roman";">â•=99 ; font-family: Courier;">BI ly: "Times New Roman";">Ю└Щ╟ n style=3D"font-size: 10pt; font-family: Courier;">':
=3D"font-size: 10pt; font-family: "Times New Roman";">е
n>Ek@ yle=3D"font-size: 10pt; font-family: "Times New Roman";">М=
ОБ
g=
uot;;">â•=A9 ;"> N man";">â”=9C urier;">b w Roman";">■Ñ=81 family: Courier;">' "Times New Roman";">ж font-family: Courier;">JY y: "Times New Roman";">еДщ nt-size: 10pt; font-family: Courier;">~2 pt; font-family: "Times New Roman";">р font-size: 10pt; font-family: Courier;">4aAâ„=96h font-size: 10pt; font-family: "Times New Roman";">┤Ð=A8=
â•=91
Ej span> t;;">Аm =
uot;;">â”=82 ;">.&c ew Roman";">чВЩ ont-family: Courier;">      n>c n";">А ;">q an";">Ч r;"> bSy Roman";">ь┠amily: Courier;">SP t;Times New Roman";">Ð¥â”=80 0pt; font-family: Courier;">=3D family: "Times New Roman";">├Ð=B4 font-size: 10pt; font-family: Courier;">   =C2=
 Â Â=A0
 R
"font-size: 10pt; font-family: "Times New Roman";">â”=9C n> e=3D"font-size: 10pt; font-family: "Times New Roman";">п an>D le=3D"font-size: 10pt; font-family: "Times New Roman";">â–=8C=
style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
–Ð=95
o r>


 

#
quot;;">Х╠Б═╔ыÑ=9E le=3D"font-size: 10pt; font-family: Courier;">$ size: 10pt; font-family: "Times New Roman";">â•=98 n style=3D"font-size: 10pt; font-family: Courier;">@|H)
=3D"font-size: 10pt; font-family: "Times New Roman";">Ч n>A e=3D"font-size: 10pt; font-family: "Times New Roman";">â•=9C<=
/span>)7L n style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
=AF
1 pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
Щг
9=
@/
";">╙╨ ly: Courier;"> d8R:%4F} ily: "Times New Roman";">А 0pt; font-family: Courier;">,L6 family: "Times New Roman";">Ь : 10pt; font-family: Courier;"> -family: "Times New Roman";">М e: 10pt; font-family: Courier;">n t-family: "Times New Roman";">вТâ”=9C tyle=3D"font-size: 10pt; font-family: Courier;"> S $. font-size: 10pt; font-family: "Times New Roman";">м pan style=3D"font-size: 10pt; font-family: Courier;">O(0
=3D"font-size: 10pt; font-family: "Times New Roman";">â”=8C=
А
ph n> ">╞╤ rier;">
 \
Roman";">Єâ•=A4 mily: Courier;">lâ„=96 4#· ont-family: "Times New Roman";">У size: 10pt; font-family: Courier;">'C.3 10pt; font-family: "Times New Roman";">â”=A4 le=3D"font-size: 10pt; font-family: Courier;">  =
   
y: "Times New Roman";">а t; font-family: Courier;">MU" nt-family: "Times New Roman";">╞Ð=84 =3D"font-size: 10pt; font-family: Courier;"># e: 10pt; font-family: "Times New Roman";">КБ n style=3D"font-size: 10pt; font-family: Courier;">8
ont-size: 10pt; font-family: "Times New Roman";">â•=92=
9 =3D"font-size: 10pt; font-family: "Times New Roman";">Ð¥=E2=
•šâ•=A6
">> oman";">Пх : Courier;">FG es New Roman";">ъ ly: Courier;">& T uot;Times New Roman";">â•=AA font-family: Courier;">j : "Times New Roman";">┐Ñ=81 ize: 10pt; font-family: Courier;">  ·~ FZâˆ=99d tyle=3D"font-size: 10pt; font-family: "Menlo Regular";">ï¿=BD=
0KJ. pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
ю
tyle=3D"">      bE t-size: 10pt; font-family: "Times New Roman";">╔йÑ=
Œâ•œâ”=BC
urier;">g      n style=3D"font-size: 10pt; font-family: "Times New Roman";">=D1=
=8C8.<=
span style=3D"font-size: 10pt; font-family: "Times New Roman";">=
╟нтг┴гâ•=A5 nt-size: 10pt; font-family: Courier;"> t; font-family: "Times New Roman";">┤Ñ=89 tyle=3D"font-size: 10pt; font-family: Courier;">9Mx nt-size: 10pt; font-family: "Times New Roman";">Т n style=3D"font-size: 10pt; font-family: Courier;">0Y font-size: 10pt; font-family: "Times New Roman";">Є pan style=3D"font-size: 10pt; font-family: Courier;">Y "font-size: 10pt; font-family: "Times New Roman";">Ўâ–=
Ñ=82
4
pan> ;;">е&qu=
ot;
an";">К r;">93 oman";">Ю╫еÐ=B7 pt; font-family: Courier;">%g mily: "Times New Roman";">м 10pt; font-family: Courier;">d amily: "Times New Roman";">З 10pt; font-family: Courier;"> ii( nt-family: "Times New Roman";">â–=91 t-size: 10pt; font-family: Courier;">8 t; font-family: "Times New Roman";">Н ont-size: 10pt; font-family: Courier;">3% 0pt; font-family: "Times New Roman";">┴Ð=93 style=3D"font-size: 10pt; font-family: Courier;">CTE "font-size: 10pt; font-family: "Times New Roman";">кЖ span>x tyle=3D"font-size: 10pt; font-family: "Times New Roman";">â”=
=80
t pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
â•=AB
o H =
uot;;">щ█Ð=96 ily: Courier;">!- ;Times New Roman";">Ф family: Courier;">^  A nt-size: 10pt; font-family: "Times New Roman";">â”=98<=
span style=3D"font-size: 10pt; font-family: Courier;"># =3D"font-size: 10pt; font-family: "Times New Roman";">А=E2=
••
tI9k span> t;;">Зâ–=92 rier;">UN w Roman";">â•=91 : Courier;">m~ es New Roman";">╩Ð=97 font-family: Courier;">;? y: "Times New Roman";">А t; font-family: Courier;">v \ mily: "Times New Roman";">â•=9A e: 10pt; font-family: Courier;"> t-family: "Times New Roman";">â•=9F -size: 10pt; font-family: Courier;">8K ; font-family: "Times New Roman";">═Ñ=97 yle=3D"font-size: 10pt; font-family: Courier;">b size: 10pt; font-family: "Times New Roman";">Ф tyle=3D"font-size: 10pt; font-family: Courier;">7 -size: 10pt; font-family: "Times New Roman";">а style=3D"font-size: 10pt; font-family: Courier;">5C4 ont-size: 10pt; font-family: "Times New Roman";">│â=95=
=A3
^ pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
â–=93
z3x<=
/span> ot;;">█Ð=9F urier;">O_Ncâˆ=99 uot;Times New Roman";">ПЬЮ ze: 10pt; font-family: Courier;">^ nt-family: "Times New Roman";">┌Ñ=88 =3D"font-size: 10pt; font-family: Courier;">d e: 10pt; font-family: "Times New Roman";">â•=A7 tyle=3D"font-size: 10pt; font-family: Courier;">â„=96 =3D"font-size: 10pt; font-family: "Times New Roman";">Ў
n>aW^|x style=3D"font-size: 10pt; font-family: "Times New Roman";">Я=
п┼ВÑ=8F
ly: Courier;">I2` Times New Roman";">╜╜â”=B4 nt-size: 10pt; font-family: Courier;">now 0pt; font-family: "Times New Roman";">ўâ”=98 style=3D"font-size: 10pt; font-family: Courier;">( nt-size: 10pt; font-family: "Times New Roman";">┌â=94=
˜â–Ñ‰Ñ
Courier;">$ New Roman";">â•=94 ily: Courier;">^ Times New Roman";">э amily: Courier;"> ;Times New Roman";">â•=A2 nt-family: Courier;">âˆ=9A amily: "Times New Roman";">╔Ð=92 ont-size: 10pt; font-family: Courier;">K 0pt; font-family: "Times New Roman";">бЖ yle=3D"font-size: 10pt; font-family: Courier;">! size: 10pt; font-family: "Times New Roman";">┌╣=
є
8
> >Ёзâ•=91 ourier;">WY New Roman";">Хб amily: Courier;">S  -size: 10pt; font-family: "Times New Roman";">┼Ёâ=
–ˆÑ
=
uot;;">â–=80 ;">p an";">е r;">q man";">з er;"> oman";">Є ier;">t Roman";">ьГ y: Courier;">P es New Roman";">лЫє t; font-family: Courier;">0 ly: "Times New Roman";">ъО ze: 10pt; font-family: Courier;">âˆ=99ha :"V "font-size: 10pt; font-family: "Times New Roman";">сг=
â•=9E
i span> t;;">â•=96 >Z@ Y ew Roman";">ў■Ð=95 ; font-family: Courier;">Y, ly: "Times New Roman";">Р pt; font-family: Courier;">`- FE4 t-family: "Times New Roman";">Ю ze: 10pt; font-family: Courier;">a. font-family: "Times New Roman";">ё -size: 10pt; font-family: Courier;"> font-family: "Times New Roman";">Ж t-size: 10pt; font-family: Courier;">v0 t; font-family: "Times New Roman";">и ont-size: 10pt; font-family: Courier;"> 
n> ">Ї ^ pan> ;;">ЎdT<=
/span> ot;;">уц┠ly: Courier;">A mes New Roman";">╠family: Courier;">>t "Times New Roman";">╨╡â”=98 =3D"font-size: 10pt; font-family: Courier;">  =
uot;;">ЩМ╩г╙єâ”=82 e=3D"font-size: 10pt; font-family: Courier;">W } size: 10pt; font-family: "Times New Roman";">ё tyle=3D"font-size: 10pt; font-family: Courier;">+ -size: 10pt; font-family: "Times New Roman";">â–=93 an style=3D"font-size: 10pt; font-family: Courier;"> fUX
=3D"font-size: 10pt; font-family: "Times New Roman";">З=D1=
=9E
s le=3D"">  -w "Times New Roman";">в font-family: Courier;">R F ly: "Times New Roman";">â–=91 10pt; font-family: Courier;">âˆ=99 t; font-family: "Times New Roman";">Нâ•=95 tyle=3D"font-size: 10pt; font-family: Courier;">5 -size: 10pt; font-family: "Times New Roman";">â–=90 an style=3D"font-size: 10pt; font-family: Courier;">d
"font-size: 10pt; font-family: "Times New Roman";">░Ð=
§â•›â–=92
urier;">



 

 

~
";">ё ">Y an";">вТ Courier;"> New Roman";">а Courier;">Y tlk imes New Roman";">ачоЭ ize: 10pt; font-family: Courier;">`âˆ=9A- e: 10pt; font-family: "Times New Roman";">â–=84 tyle=3D"font-size: 10pt; font-family: Courier;"> -size: 10pt; font-family: "Times New Roman";">â”=BC an style=3D"font-size: 10pt; font-family: Courier;">m font-size: 10pt; font-family: "Times New Roman";">сЁ=E2=
• 
. n> ">â–=88 pan style=3D"">  
Roman";">╣н┌Гâ–=A0 font-size: 10pt; font-family: Courier;">{ 10pt; font-family: "Times New Roman";">х =3D"font-size: 10pt; font-family: Courier;">? e: 10pt; font-family: "Times New Roman";">ъ e=3D"font-size: 10pt; font-family: Courier;">  >u ";">ю ">4d an";">═┤ mily: Courier;">J Times New Roman";">Єâ•=95 t; font-family: Courier;">. ly: "Times New Roman";">т╒Ñ=89 =3D"font-size: 10pt; font-family: Courier;">+rqy~ -size: 10pt; font-family: "Times New Roman";">Єыё=
╒▌║▄
font-family: Courier;">m  =3D"font-size: 10pt; font-family: "Times New Roman";">â•=A3=
Ь
*
35ez
an";">â•=A9 rier;">a Roman";">▒крпÑ=85 size: 10pt; font-family: Courier;">{ font-family: "Times New Roman";">ь -size: 10pt; font-family: Courier;">#e ; font-family: "Times New Roman";">ч nt-size: 10pt; font-family: Courier;">: t; font-family: "Times New Roman";">х ont-size: 10pt; font-family: Courier;">>_ : 10pt; font-family: "Times New Roman";">┴ГÑ=8A pan>x ">  1°/ "Times New Roman";">л font-family: Courier;">1xQ ly: "Times New Roman";">щâ•=95 -size: 10pt; font-family: Courier;"> font-family: "Times New Roman";">╝вУÐ=B6
an>E le=3D"font-size: 10pt; font-family: "Times New Roman";">Ф pan>,".`=
=
н╞Ð=B3
urier;">\ w Roman";">║нÐ=BC font-family: Courier;">a E'Y t-family: "Times New Roman";">ЇоЫ╚â=96=
=90




..Z
";">х "> n";">А ;">: an";">э r;">l. oman";">Лâ–=90 ily: Courier;">{ imes New Roman";">│┘юн font-size: 10pt; font-family: Courier;">` 0pt; font-family: "Times New Roman";">у "font-size: 10pt; font-family: Courier;">R 10pt; font-family: "Times New Roman";">Э =3D"font-size: 10pt; font-family: Courier;"> e: 10pt; font-family: "Times New Roman";">─Ð<=
span style=3D"font-size: 10pt; font-family: Courier;"> °K
style=3D"font-size: 10pt; font-family: "Times New Roman";">â•=
=A9
t pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
╠йÑ=88 urier;">$hH New Roman";">│╖â•=91 ze: 10pt; font-family: Courier;">  - an style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
´â•šÐª er;">,i Roman";">╔Ð=A2 mily: Courier;">v Times New Roman";">Э amily: Courier;"> ¤ "Times New Roman";">â•=A1 pt; font-family: Courier;">"H ont-family: "Times New Roman";">пч "font-size: 10pt; font-family: Courier;">¤ ize: 10pt; font-family: "Times New Roman";">Ў yle=3D"font-size: 10pt; font-family: Courier;">№° L n style=3D"font-size: 10pt; font-family: "Times New Roman";">=E2=
•–W0
n> ">Нsc
pan> ;;">â”=B4=
u R%
man";">ъ er;">4 oman";">â•=AA ourier;">Yf New Roman";">â”=9C ly: Courier;">5 mes New Roman";">╬╟ЮТ ont-size: 10pt; font-family: Courier;">,(+y 10pt; font-family: "Times New Roman";">є =3D"font-size: 10pt; font-family: Courier;">: e: 10pt; font-family: "Times New Roman";">ЎГ n style=3D"font-size: 10pt; font-family: Courier;"> ont-size: 10pt; font-family: "Times New Roman";">ь an style=3D"font-size: 10pt; font-family: Courier;">% font-size: 10pt; font-family: "Times New Roman";">│â=96=
‘Ñ=89
]wR%=
1
quot;;">ё┬Ð=95 mily: Courier;">.r ;Times New Roman";">â•=9E nt-family: Courier;"> quot;Times New Roman";">ыâ•=96 : 10pt; font-family: Courier;">  YRâˆ=99&l=
t;}
uot;;">â–=88 ;"> an";">ю r;"> man";">О╕д╥ 10pt; font-family: Courier;">-q -family: "Times New Roman";">â•=96 size: 10pt; font-family: Courier;">_ font-family: "Times New Roman";">╩╬ tyle=3D"font-size: 10pt; font-family: Courier;">{2Y nt-size: 10pt; font-family: "Times New Roman";">хц=E2=
••â•=94
"> n";">┴┤щрБ ze: 10pt; font-family: Courier;">A+Q font-family: "Times New Roman";">╖▄▓Ð=
=A7
°
an> ;">â–=90{=
uot;;">З╗чÐ=9F nt-family: Courier;">



 

w
quot;;">Ш >A ";">┼╣╓Ñ=8E 10pt; font-family: Courier;">4R family: "Times New Roman";">ў : 10pt; font-family: Courier;">s -family: "Times New Roman";">â•=A0 size: 10pt; font-family: Courier;">F font-family: "Times New Roman";">з╠╣<=
span style=3D"font-size: 10pt; font-family: Courier;">{ =3D"font-size: 10pt; font-family: "Times New Roman";">â•=99 span> k style=3D"font-size: 10pt; font-family: "Times New Roman";">â•=
”йч░
Courier;">8 New Roman";">╛▄ font-family: Courier;"> : "Times New Roman";">■╢ЫБâ”=9C an># le=3D"font-size: 10pt; font-family: "Times New Roman";">Е=D0=
½Ð‘Ñ=8F
">â„=96~ o es New Roman";">╗╣ЫФа =3D"font-size: 10pt; font-family: Courier;"> &28



^
quot;;">â•=AB r;">@O} Roman";">у rier;">: Roman";">â•=A8 Courier;">f -A mes New Roman";">пеЪ pt; font-family: Courier;">      =
Roman";">ЦМ y: Courier;"> es New Roman";">Юâ”=98 font-family: Courier;">k "Times New Roman";">â•=9A pt; font-family: Courier;"> ily: "Times New Roman";">пЎâ–=84 =3D"font-size: 10pt; font-family: Courier;">{ e: 10pt; font-family: "Times New Roman";">щ e=3D"font-size: 10pt; font-family: Courier;">· nt-size: 10pt; font-family: "Times New Roman";">â•=9C<=
span style=3D"font-size: 10pt; font-family: Courier;">/
=3D"font-size: 10pt; font-family: "Times New Roman";">â•=96 span>U tyle=3D"font-size: 10pt; font-family: "Times New Roman";">ї=
Ы
q$a an> ;">йкâ•=94 Courier;">x New Roman";">Єъь font-family: Courier;">| : "Times New Roman";">â•=90 0pt; font-family: Courier;"> 5  1 style=3D"font-size: 10pt; font-family: "Times New Roman";">â–=
=84
pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
И
> >Яєцц : Courier;">|  : 10pt; font-family: "Times New Roman";">â”=80 yle=3D"font-size: 10pt; font-family: Courier;">w size: 10pt; font-family: "Times New Roman";">â–=84 n style=3D"font-size: 10pt; font-family: Courier;">o ont-size: 10pt; font-family: "Times New Roman";">я an style=3D"font-size: 10pt; font-family: Courier;"> 4
"font-size: 10pt; font-family: "Times New Roman";">ун span>c tyle=3D"font-size: 10pt; font-family: "Menlo Regular";">ï¿=BD=
uot;;">â•=9F ;">? an";">â•=9E rier;">dLM# New Roman";">г Courier;">x New Roman";">â•=96 ily: Courier;">l imes New Roman";">┐┐ 0pt; font-family: Courier;">J mily: "Times New Roman";">╖┐а yle=3D"font-size: 10pt; font-family: Courier;">J size: 10pt; font-family: "Times New Roman";">Ы tyle=3D"font-size: 10pt; font-family: Courier;">a



uot;;">â•=99 ;">v* man";">чї Courier;">8x~v mes New Roman";">ётэ pt; font-family: Courier;">ow+v family: "Times New Roman";">â•=A8 ize: 10pt; font-family: Courier;">\ font-family: "Times New Roman";">П -size: 10pt; font-family: Courier;"> font-family: "Times New Roman";">â•=A5 font-size: 10pt; font-family: Courier;">dJ!  <=
/span> ot;;">â”=82 ">· Roman";">â•=A0 Courier;">_, s New Roman";">Ъ╫Шъа font-size: 10pt; font-family: Courier;"> 0pt; font-family: "Times New Roman";">â•=9A =3D"font-size: 10pt; font-family: Courier;">K e: 10pt; font-family: "Times New Roman";">рФ n style=3D"font-size: 10pt; font-family: Courier;">
ont-size: 10pt; font-family: "Times New Roman";">Г an style=3D"font-size: 10pt; font-family: Courier;">
font-size: 10pt; font-family: "Times New Roman";">ь pan style=3D"font-size: 10pt; font-family: Courier;">*
"font-size: 10pt; font-family: "Times New Roman";">ъ<=
span style=3D"font-size: 10pt; font-family: Courier;">Y =3D"font-size: 10pt; font-family: "Times New Roman";">â•=A4=
â•=A2
r span> t;;">┼Ð=BC rier;">1 Roman";">С urier;">4 w Roman";">Н ourier;">8< es New Roman";">â•=97 amily: Courier;">ka t;Times New Roman";">Ёâ–=88 0pt; font-family: Courier;">C mily: "Times New Roman";">ЄїЧП═â=95=
«Ð=B3
G pan> ;;">цы╤▌ nt-family: Courier;">∙Â=B7"O : 10pt; font-family: "Times New Roman";">Чâ•=A4 pan style=3D"font-size: 10pt; font-family: Courier;"> "font-size: 10pt; font-family: "Times New Roman";">│Ñ=
=97
R_âˆ=
=9AY
an";">Р r;">.&
| 
-family: "Times New Roman";">Пж nt-size: 10pt; font-family: Courier;">tX pt; font-family: "Times New Roman";">О font-size: 10pt; font-family: Courier;">H° ize: 10pt; font-family: "Times New Roman";">┤╤ pan>¤ an style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
–НÐ=90
">D n";">▄┘Й nt-family: Courier;"> quot;Times New Roman";">юâ•=95 : 10pt; font-family: Courier;">r ¤



 

KV$
n";">Ч ;">      e=3D"font-size: 10pt; font-family: "Times New Roman";">â•=99=
Шл
W=
uot;;">Н=
'8z
Roman";">▒Р█ ; font-family: Courier;"> y: "Times New Roman";">Ж t; font-family: Courier;">k ly: "Times New Roman";">â•=9B 10pt; font-family: Courier;">YEx t-family: "Times New Roman";">├Ñ=85 =3D"font-size: 10pt; font-family: Courier;">upDBR -size: 10pt; font-family: "Times New Roman";">гИ=
4 =3D"font-size: 10pt; font-family: "Times New Roman";">г
n>I e=3D"font-size: 10pt; font-family: "Times New Roman";">м=D1=
=94
42p$ > >╢Ð=A3 ;"> an";">ЭГ Courier;"> New Roman";">ї Courier;">¤f ;Times New Roman";">â•=A6 nt-family: Courier;"> >
uot;;">Ж=
?> 
Roman";">ы rier;">'ci mes New Roman";">вâ•=AB font-family: Courier;">i : "Menlo Regular";">ï¿=BD t; font-family: "Times New Roman";">ЙйМ n style=3D"font-size: 10pt; font-family: Courier;">a
ont-size: 10pt; font-family: "Times New Roman";">щ an style=3D"font-size: 10pt; font-family: Courier;"> ~ "font-size: 10pt; font-family: "Times New Roman";">Ж<=
span style=3D"font-size: 10pt; font-family: Courier;">V =3D"font-size: 10pt; font-family: "Times New Roman";">Т n>M e=3D"font-size: 10pt; font-family: "Times New Roman";">Ё
an>0 le=3D"font-size: 10pt; font-family: "Times New Roman";">â•=A9=
╟╥â”=98
ly: Courier;"> ** Times New Roman";">є amily: Courier;">A ;Times New Roman";">â•=9E nt-family: Courier;"> quot;Times New Roman";">Уâ–=91 : 10pt; font-family: Courier;"> #mgDS. ; font-family: "Times New Roman";">ц nt-size: 10pt; font-family: Courier;">âˆ=9A v -size: 10pt; font-family: "Times New Roman";">о style=3D"font-size: 10pt; font-family: Courier;"> 2 nt-size: 10pt; font-family: "Times New Roman";">бз n>X" n style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
¬â•¥Ð“а
Courier;">N + es New Roman";">бЇ t-family: Courier;">>âˆ=99 t-family: "Times New Roman";">бч ont-size: 10pt; font-family: Courier;">~ 0pt; font-family: "Times New Roman";">И "font-size: 10pt; font-family: Courier;">; 10pt; font-family: "Times New Roman";">ў =3D"font-size: 10pt; font-family: Courier;">L  >O ";">ь ">> oman";">С ier;">p Roman";">╚етÐ=90 0pt; font-family: Courier;">8< t-family: "Times New Roman";">мГьУâ–=A0 span> tyle=3D"font-size: 10pt; font-family: "Times New Roman";">â•=
=97
pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
Мя
n=
uot;;">ё=
|<
man";">╨Ð=B4 ly: Courier;">_ mes New Roman";">Уâ–=88 font-family: Courier;">w? y: "Times New Roman";">╧Ñ=8C size: 10pt; font-family: Courier;">:Y
âˆ=99l-
New Roman";">Л Courier;"> New Roman";">и : Courier;">SF es New Roman";">╡Ð=A8 font-family: Courier;">
fa,VW
man";">эД Courier;">ZW s New Roman";">А y: Courier;">¤ t;Times New Roman";">ЬГ ; font-family: Courier;">. y: "Times New Roman";">эЬ e: 10pt; font-family: Courier;">°] t; font-family: "Times New Roman";">Ð¥ ont-size: 10pt; font-family: Courier;"> pt; font-family: "Times New Roman";">▄щсÐ=9C=
â”=9C




 

uot;;">биâ•=9D ily: Courier;">9 imes New Roman";">сй ont-family: Courier;">+ "Times New Roman";">╠t; font-family: Courier;">B 
A&
es New Roman";">â•=94 amily: Courier;">- ;Times New Roman";">Ч family: Courier;">n t;Times New Roman";">д -family: Courier;">UX uot;Times New Roman";">â–=92 font-family: Courier;">uu ly: "Times New Roman";">в pt; font-family: Courier;">F mily: "Times New Roman";">В 10pt; font-family: Courier;"> )Od t-family: "Times New Roman";">ф ze: 10pt; font-family: Courier;">



uot;;">с=
b6
n";">Щ ;"> an";">Ð¥ r;">kBy Roman";">КП y: Courier;">V! mes New Roman";">╔Ð=A4 font-family: Courier;">' mily: "Times New Roman";">â•=A0 e: 10pt; font-family: Courier;">!D nt-family: "Times New Roman";">â–=91 t-size: 10pt; font-family: Courier;">U ; font-family: "Times New Roman";">С nt-size: 10pt; font-family: Courier;">LA 0pt; font-family: "Times New Roman";">─Ð=A5 style=3D"font-size: 10pt; font-family: Courier;">/%
ont-size: 10pt; font-family: "Times New Roman";">Аї=D1=
=87
(d<=
span style=3D"font-size: 10pt; font-family: "Times New Roman";">=
╠║Л Courier;">x6 s New Roman";">щ y: Courier;">; es New Roman";">ЭЧк t; font-family: Courier;">H ly: "Times New Roman";">й pt; font-family: Courier;"> s mily: "Times New Roman";">â•=A3 e: 10pt; font-family: Courier;">Ozn ont-family: "Times New Roman";">Жâ”=9C =3D"font-size: 10pt; font-family: Courier;">H e: 10pt; font-family: "Times New Roman";">УЁш n> e=3D"font-size: 10pt; font-family: "Times New Roman";">â•=AA=
â”=A4
L S<=
/span> ot;;">АД er;">(      tyle=3D"font-size: 10pt; font-family: "Times New Roman";">м=
м
& span> t;;">â•=97 >Z3NvJ oman";">â•=A3 ourier;">p New Roman";">ш Courier;">h New Roman";">â•=96 ily: Courier;">w imes New Roman";">┠-family: Courier;">] uot;Times New Roman";">â•=A6 font-family: Courier;">



 
amily: "Times New Roman";">С▌┴ tyle=3D"font-size: 10pt; font-family: Courier;">â„=96 =3D"font-size: 10pt; font-family: "Times New Roman";">â”=90 span> i<=
span style=3D"font-size: 10pt; font-family: "Times New Roman";">=
яяА
er;">m 4 Roman";">â”=80 Courier;">7 New Roman";">ш : Courier;">b s New Roman";">е y: Courier;">zq mes New Roman";">â•=91 family: Courier;">h t;Times New Roman";">КФЕ┤╜ style=3D"font-size: 10pt; font-family: Courier;">N& =3D"font-size: 10pt; font-family: "Times New Roman";">â”=94 span>-



 *X;T
nt-family: "Times New Roman";">уМС le=3D"font-size: 10pt; font-family: Courier;">D ize: 10pt; font-family: "Times New Roman";">э yle=3D"font-size: 10pt; font-family: Courier;">{. -size: 10pt; font-family: "Times New Roman";">â•=A3 an style=3D"font-size: 10pt; font-family: Courier;">X
font-size: 10pt; font-family: "Times New Roman";">╟Ð=B6=
К
Y > >╓Ñ=80 ;"> nbgl Roman";">╦═ t-family: Courier;">E uot;Times New Roman";">â”=82 font-family: Courier;">$S ly: "Times New Roman";">У═ЗÑ=80 tyle=3D"font-size: 10pt; font-family: Courier;"> q =
    
K#
nt-family: "Times New Roman";">К ize: 10pt; font-family: Courier;">3F font-family: "Times New Roman";">б -size: 10pt; font-family: Courier;">: font-family: "Times New Roman";">â•=9A font-size: 10pt; font-family: Courier;">·1  an> n";">З ;"> an";">ё r;">q man";">о er;">] oman";">Пâ–=88 ily: Courier;">r imes New Roman";">А mily: Courier;"> n: t;Times New Roman";">▀А╨ t-size: 10pt; font-family: Courier;"> ; font-family: "Times New Roman";">Ы╔Ð=95 pan style=3D"font-size: 10pt; font-family: Courier;">; "font-size: 10pt; font-family: "Times New Roman";">Л<=
span style=3D"font-size: 10pt; font-family: Courier;">z
=3D"font-size: 10pt; font-family: "Times New Roman";">â•=A6 span>0 tyle=3D"font-size: 10pt; font-family: "Times New Roman";">â•=
•â•©
5=
uot;;">С╤Д╤ font-family: Courier;">R : "Times New Roman";">â•=9C 0pt; font-family: Courier;">     =
Roman";">Ы urier;">r





uot;;">┐Ð=AF ourier;">yy4 New Roman";">â”=82 ily: Courier;"> imes New Roman";">┠-family: Courier;">> "Times New Roman";">╚ЁÐ=9D nt-size: 10pt; font-family: Courier;">) t; font-family: "Times New Roman";">â•=9F =3D"font-size: 10pt; font-family: Courier;">{ e: 10pt; font-family: "Times New Roman";">ЕЩ n style=3D"font-size: 10pt; font-family: Courier;">(
ont-size: 10pt; font-family: "Times New Roman";">х an style=3D"font-size: 10pt; font-family: Courier;">4
font-size: 10pt; font-family: "Times New Roman";">ԃ=95=
=A8
e=3D"">   ly: "Times New Roman";">х pt; font-family: Courier;"> ily: "Times New Roman";">â–=A0 : 10pt; font-family: Courier;"> -family: "Times New Roman";">У e: 10pt; font-family: Courier;"> | nt-family: "Times New Roman";">Ї ize: 10pt; font-family: Courier;">Y8°y 10pt; font-family: "Times New Roman";">â•=96 le=3D"font-size: 10pt; font-family: Courier;">z ize: 10pt; font-family: "Times New Roman";">Їâ”=80 >@$D sâ„=96 n> ">▒Ð=B9 r;">b man";">▒Ð=B6 ly: Courier;">1 mes New Roman";">Гпс│╦А n style=3D"font-size: 10pt; font-family: Courier;">Pq_âˆ=99 style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
£Ð=BD
8q <=
/span> ot;;">â•=92 ">j an";">╒╢ mily: Courier;">B Times New Roman";">â•=91 t-family: Courier;">  nt-size: 10pt; font-family: "Times New Roman";">╡Ñ=8C span>< an style=3D"font-size: 10pt; font-family: "Times New Roman";">=E2=
•ªÑ
*=
uot;;">ЫГБ : Courier;">e es New Roman";">Е ly: Courier;">kT| Times New Roman";">└Ñ=8D t; font-family: Courier;"> - ily: "Times New Roman";">Ў 0pt; font-family: "Menlo Regular";">ï¿=BD =3D"font-size: 10pt; font-family: "Times New Roman";">â”=B4 span>Z style=3D"font-size: 10pt; font-family: "Times New Roman";">â•=
â•«â• â–„
amily: Courier;">=3D 4 quot;Times New Roman";">â•=90 ; font-family: Courier;">Q y: "Times New Roman";">├╛ nt-size: 10pt; font-family: Courier;">@ t; font-family: "Times New Roman";">Ёâ•=98 tyle=3D"font-size: 10pt; font-family: Courier;"> -size: 10pt; font-family: "Times New Roman";">└Ð=AE an>" n style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
›Ðâ”¼
er;">Lx Roman";">Ц rier;">A Roman";">╪е╞н e: 10pt; font-family: Courier;"> t-family: "Times New Roman";">цмВ e=3D"font-size: 10pt; font-family: Courier;">Y ize: 10pt; font-family: "Times New Roman";">ё yle=3D"font-size: 10pt; font-family: Courier;">J size: 10pt; font-family: "Times New Roman";">ф╢Ð=
ªÐ‡â•“
er;"> oman";">▒╥сâ•=9B ze: 10pt; font-family: Courier;">° t; font-family: "Times New Roman";">мщЄц=E2=
•¥â•=97
">>nG~CH(d" t;Times New Roman";">╒Ð=93 0pt; font-family: Courier;">c mily: "Times New Roman";">ЛРе "font-size: 10pt; font-family: Courier;">¤â„=96a=
 
es New Roman";">▓▐ t; font-family: Courier;">  69 le=3D"font-size: 10pt; font-family: "Times New Roman";">â•=96=
  n> ">АoX;w<=
/span> ot;;">ц =
uot;;">ы=
l
quot;;">эâ•=A1 Courier;">s  
Y
Roman";">И urier;">L w Roman";">Ш ourier;">@  
Roman";">â•=97 Courier;"> âˆ=9AC Z ily: "Times New Roman";">ь 0pt; font-family: Courier;"> mily: "Times New Roman";">р 10pt; font-family: Courier;">"° 0pt; font-family: "Times New Roman";">ЄБ yle=3D"font-size: 10pt; font-family: Courier;">Pc -size: 10pt; font-family: "Times New Roman";">Ч style=3D"font-size: 10pt; font-family: Courier;">a)g ont-size: 10pt; font-family: "Times New Roman";">У an style=3D"font-size: 10pt; font-family: Courier;">e
font-size: 10pt; font-family: "Times New Roman";">хд pan>4NH style=3D"font-size: 10pt; font-family: "Times New Roman";">â”=
=90
e=3D"">  / quot;Times New Roman";">â•=90 ; font-family: Courier;">!c ly: "Times New Roman";">СДеРâ”=A4<=
span style=3D"font-size: 10pt; font-family: Courier;">
=3D"font-size: 10pt; font-family: "Times New Roman";">й=E2=
•”гФ
er;">C oman";">ъ ier;"> .9+ ew Roman";">єЫ┐╪ ize: 10pt; font-family: Courier;">    =
 
es New Roman";">ф ly: Courier;">5X Times New Roman";">р amily: Courier;">
6<
man";">ч▒┼ font-family: "Menlo Regular";">ï¿=BD t-size: 10pt; font-family: "Times New Roman";">Ъ style=3D"font-size: 10pt; font-family: Courier;">$
nt-size: 10pt; font-family: "Times New Roman";">Х=82=
╥▒ИСЄâ•=A5
e: 10pt; font-family: Courier;"> â„=96u 10pt; font-family: "Times New Roman";">â•=9E le=3D"font-size: 10pt; font-family: Courier;">a ize: 10pt; font-family: "Times New Roman";">М yle=3D"font-size: 10pt; font-family: Courier;">t size: 10pt; font-family: "Times New Roman";">ЄХ<=
span style=3D"font-size: 10pt; font-family: Courier;">^
=3D"font-size: 10pt; font-family: "Times New Roman";">Ё n>W?K yle=3D"font-size: 10pt; font-family: "Times New Roman";">ў=
â•=96
2 span> t;;">ймУрâ•=93 ; font-family: Courier;">4 y: "Times New Roman";">Р t; font-family: Courier;"> E





>==================

The address indicated in the begining of the page code leads to some chines=
e
server.

t; font-family: Times;">

=3D"font-size: 10pt; font-family: Times;">
So, somehow it happened that the output of the apache server was substitute=
d by
this page, which redirected visitors to some chinese server.
tyle=3D"font-size: 10pt; font-family: Times;">It is the second
time I am posting to the mailing list, the first time the mailing list
virus scanner identified the content as having the Troj/Fujif-Gen
virus, thus, this time I removed active links from the message body so
it is not exactly what I received).

t; font-family: Times;">


But the most strange thing was that the problem dissapeared itself! So, it =
last
for 10 minutes then disappeared! And the again started and again dissapeare=
d.
Finally, I turned down apache untill I understand what is going on...



Any idea how could that happen?  How to reproduce this? How to prevent=
?

Where to look for logs? I have check both ssh logs and apache logs, there i=
s
nothing that could seem unusual there...



Any help is appreciated.

Oleg.





--0016e6dbded802cadd04835bab59--

Re: Someone hacked my apache2 server

am 04.04.2010 00:05:54 von Nick Kew

On 3 Apr 2010, at 22:20, Oleg Goryunov wrote:

> Hello all,
> It looks like someone hacked my apache2 server and I am trying to =
understand how this could have happened.
> This is what happened:

Yep, someone's been there. Take it off the 'net, if you haven't =
already!
And get someone competent to look: anyone on a list like this
can only speculate!

First question, who has non-WWW access, particularly a shell?
If the offending files are owned by a user other than the webserver,
it's not likely to have happened through the server. And if that's
happened, you may want to reinstall the server starting with a clean
operating system install.

If it did happen through the server, what apps let you upload contents?
The usual suspect in cases like this is some shoddy PHP app. You might =
also
want to fire the admin who left contents space writable by the web user!

--=20
Nick Kew=

------------------------------------------------------------ ---------
The official User-To-User support forum of the Apache HTTP Server Project.
See for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
" from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org

Re: Someone hacked my apache2 server

am 04.04.2010 00:24:25 von Oleg Goryunov

--0015175cad8c20e23504835c9011
Content-Type: text/plain; charset=ISO-8859-1

Nick,
Thanks for your reply.
THe problem is that I do not see any files changed on the server (and thus
cannot check the owner of them). Where should I look for the possible
evidence of someone else being there?

On Sun, Apr 4, 2010 at 2:05 AM, Nick Kew wrote:

>
> On 3 Apr 2010, at 22:20, Oleg Goryunov wrote:
>
>
>
> Yep, someone's been there. Take it off the 'net, if you haven't already!
> And get someone competent to look: anyone on a list like this
> can only speculate!
>
> First question, who has non-WWW access, particularly a shell?
> If the offending files are owned by a user other than the webserver,
> it's not likely to have happened through the server. And if that's
> happened, you may want to reinstall the server starting with a clean
> operating system install.
>
> If it did happen through the server, what apps let you upload contents?
> The usual suspect in cases like this is some shoddy PHP app. You might
> also
> want to fire the admin who left contents space writable by the web user!
>
> --
> Nick Kew
> ------------------------------------------------------------ ---------
> The official User-To-User support forum of the Apache HTTP Server Project.
> See for more info.
> To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
> " from the digest: users-digest-unsubscribe@httpd.apache.org
> For additional commands, e-mail: users-help@httpd.apache.org
>
>

--0015175cad8c20e23504835c9011
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Nick,
Thanks for your reply.
THe problem is that I do not see any fil=
es changed on the server (and thus cannot check the owner of them). Where s=
hould I look for the possible evidence of someone else being there?



On Sun, Apr 4, 2010 at 2:05 AM, Nick Kew ir=3D"ltr"><&g=
t;
wrote:
1px solid rgb(204, 204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex=
;">



On 3 Apr 2010, at 22:20, Oleg Goryunov wrote:







Yep, someone's been there. =A0Take it off the 'net, if you ha=
ven't already!

And get someone competent to look: anyone on a list like this

can only speculate!



First question, who has non-WWW access, particularly a shell?

If the offending files are owned by a user other than the webserver,

it's not likely to have happened through the server. =A0And if that'=
;s

happened, you may want to reinstall the server starting with a clean

operating system install.



If it did happen through the server, what apps let you upload contents?

The usual suspect in cases like this is some shoddy PHP app. =A0You might a=
lso

want to fire the admin who left contents space writable by the web user! >


--

Nick Kew

------------------------------------------------------------ ---------

The official User-To-User support forum of the Apache HTTP Server Project.<=
br>
See <URL: lank">http://httpd.apache.org/userslist.html> for more info.

To unsubscribe, e-mail: g">users-unsubscribe@httpd.apache.org

=A0 " =A0 from the digest: @httpd.apache.org">users-digest-unsubscribe@httpd.apache.org

For additional commands, e-mail: org">users-help@httpd.apache.org






--0015175cad8c20e23504835c9011--

Re: Someone hacked my apache2 server

am 04.04.2010 01:28:49 von Morgan Gangwere

On 4/3/2010 4:24 PM, Oleg Goryunov wrote:
>
> THe problem is that I do not see any files changed on the server (and
> thus cannot check the owner of them). Where should I look for the
> possible evidence of someone else being there?

Do you have Tripwire installed?
If so, just look at its logs :)

Otherwise, I'd look carefully at the dates that things were modified.
you *do* have backups, right?

--
Morgan Gangwere

>> Why?
> Because it breaks the logical flow of conversation, plus makes
messages unreadable.
>>> Top-Posting is evil.

------------------------------------------------------------ ---------
The official User-To-User support forum of the Apache HTTP Server Project.
See for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
" from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org

Re: Someone hacked my apache2 server

am 04.04.2010 04:48:12 von xiazhengxin

Yes,the hacker is from China.

the subfix "9966.org" is provided by the biggest DynDNS ISP of China.

Best regards,
Sharl.Jimh.Tsin

------------------------------------------------------------ ---------
The official User-To-User support forum of the Apache HTTP Server Project.
See for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
" from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org

Re: Someone hacked my apache2 server

am 04.04.2010 04:55:11 von vidals

--0016361e89b053d4340483605739
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: base64

T2xlZywKCldoYXQga2luZCBvZiB3ZWIgYXBwbGljYXRpb24gZmlyZXdhbGwg KFdBRikgYXJlIHlv
dSBydW5uaW5nIG9uIHlvdXIgd2ViCnNlcnZlcnM/IElmIHRoZSBhbnN3ZXIg aXMgIm5vbmUiLCB0
aGVuIHlvdSB3aWxsIGhhdmUgbWFueSBwcm9ibGVtcyB3aXRoCm1hbHdhcmUg YW5kIGhhY2tlcnMu
ICBZb3UgbXVzdCBoYXZlIHByb3BlciBzZWN1cml0eS4gR29vZ2xlICJtb2Rf c2VjdXJpdHkiCm9y
IGhpcmUgYSB3ZWIgc2VjdXJpdHkgZ3V5IHRvIHRha2UgY2FyZSBvZiB5b3Vy IHNlcnZlcnMgZm9y
IHlvdS4KCkdpbCBWaWRhbHMKd3d3LnZtcmFja3MuY29tCgpPbiBTYXQsIEFw ciAzLCAyMDEwIGF0
IDI6MjAgUE0sIE9sZWcgR29yeXVub3YgPG9sZWcuZ29yeXVub3ZAZ21haWwu Y29tPndyb3RlOgoK
PiBIZWxsbyBhbGwsCj4gSXQgbG9va3MgbGlrZSBzb21lb25lIGhhY2tlZCBt eSBhcGFjaGUyIHNl
cnZlciBhbmQgSSBhbSB0cnlpbmcgdG8KPiB1bmRlcnN0YW5kIGhvdyB0aGlz IGNvdWxkIGhhdmUg
aGFwcGVuZWQuCj4gVGhpcyBpcyB3aGF0IGhhcHBlbmVkOgo+IEFsbCBvZiBh IHN1ZGRlbiB0aGUg
c2VydmVyIC0gaW4gcmVzcG9uc2UgdG8gYSB3ZWItYnJvd3NlciByZXF1ZXN0 IGZvciBhCj4gcGFn
ZSAtIHN0YXJ0ZWQgdG8gZ2l2ZSBhIGZ1bGwgc2NyZWVuIG9mIHVua25vd24g Y2hhcmFjdGVycyAo
bG9va2VkIGxpa2UgYQo+IGxvbmcgdGV4dCB3aXRoIGVuY29kaW5nIG1pc21h dGNoKS4KPiBUaGUg
b3V0cHV0IHdhcyBpbW1lZGlhdGUgYW5kIHRoZSBzYW1lIGZvciBhbGwgdGhl IHdlYi1zaXRlcyBs
b2NhdGVkIG9uIHRoZQo+IHNlcnZlci4KPiBMb29raW5nIGF0IHRoZSBwYWdl IHNvdXJjZSBvZiB0
aGUgb3V0cHV0IEkgc2VlIHRoZSBmb2xsb3dpbmc6Cj4gPT09PT09PT09Cj4K PiA8aWZyYW1lIHNy
Yz0gIGh0dHA6Ly9hIHogcyB4IGQgZSA1IDUgLiA5IDkgNiA2IC4gb3JnOjg4 MDAvYWs0Ny8yOS5o
dG1sCj4gd2lkdGg9MSBoZWlnaHQ9MT48L2lmcmFtZT4g0Jsg77+977+977+9 77+977+977+9INGN
W9GBbuKWiDgg4pag4paM77+94oiaIFwt4paReyDilZjQpiAn4paIJnEg4pSk SSDRiV3ilZnRhOKV
pWx74oia0LvQsAo+ICTilIxmQ9ChKknilJjRkdGBINGG0K7RhdCu0YxmKOKV qdCmIDlO4paTLdC+
4pWXcNCQ4pSAIDnihJZmONCsICDQl+KVqdCB4oia0KPRlNGD0LviloAuXtCh 0JlNIOKVo8Kw0ZfR
hdCr4pWr4pWfJNGI0JTRgdCX4pS0cSDQrlzQrdCgINCuCj4gXtCt4pWcIcKk btCfXGkqCj4KPiDi
lZZcSSrilKzQgeKVkuKWiNCQICBr4pSCwqQw0KzilZBm4paM4pSY0LDQu9CH OOKVneKVkSBvINC7
0J/Qk8Kk4pWr0J7QvdCc0YwmNiAgICAgINCe0JbQnuKWgE0q0LQ5bEHRidGP 0Y3RjSDQk9CT0LPQ
veKImuKVmSLilaTilZvQsHJ8Cj4gMOKUmCBHINC5PSAg0LPilZTilaQgIeKU nNCYIEYm0KrQnSDQ
oNCi4pWQ4pWRVFDilZDQndCw0KHRieKVnioKPiBN0K5lSuKWiG4gIOKVkdCR KeKUgtCk0YDQoCDi
iJrQrNGU0YlhICtp0KnilKQgO+KVp1hA4oSW4pWZYWDilJjQnQo+IHHRgCDQ mSdUIGYgczvRijzQ
v9GBSNCq4paT4pScQNC7SFlTIOKVpmXilKxu0K7QotChIELilZBaIFzilILi iJlM0YnQtDrRhNCj
UtC50LBP4pWU4paA4paEZ+KVpiDilabQvdC44pWp0Z7RjuKVq9Cb0JvRlOKV ptC7IErQquKWiNCZ
4pWlCj4g4pWlIEnilaklN+KWkdCaIOKWiG8KPgo+IEjQqNCZNeKVp3B9K9Cz Cj4gSeKVmycgYifQ
nCRz0LDRhTFBfVJB0Kggc+KVlCDQpUk50JDQtFTilaUxS9GR0LvQqSDilabi laUgTmMm0KnQp9GC
INCvfncgeNCtZ0zQoncq4pWrMSPilZ8g4oiZbNCRXEI6ZSB5ICDilJzRgjsK PiDQp+KVq+KWkCxC
ICEg4pWYMiAu4pWQIiDilaQpIOKVk13CsCAg4pWQ4pSAYWBAWTbilawt4pS0 0I7QkNCwIOKUlAo+
INC24pSUMeKVndGJIG0g4pWZQknQruKUlNCp4pWfJzrQtUVrQNCc0J7QkWfi lakgTuKUnGLilqDR
gScg0LZKWdC10JTRiX4y0YA0YUHihJZo4pSk0KjilZFFatCQbSDilIIuJmPR h9CS0KkgICAgICBj
0JBx0KdiU3kKPiDRjOKUrFNQ0KXilIA94pSc0LQgICAgICAgIFLilJwg0L9E 4paMINCW0JUgbwo+
Cj4gI9Cl4pWg0JHilZDilZTRi9GeJCDilZhAfEgp0KdB4pWcKTdM0K8x0KnQ szlAL+KVmeKVqCBk
OFI6JTRGfdCQLEw20Kwg0Jxu0LLQouKUnCBTICQu0LxPKDDilIzQkHBo4pWe 4pWkICBc0ITilaRs
4oSWCj4gNCPCt9CjJ0MuM+KUpCAgICAgINCwTVUi4pWe0IQj0JrQkTjilZI5 0KXilZrilaY+0J/R
hUZH0YomIFTilapq4pSQ0YEgIMK3fiBGWuKImWTvv70wS0ou0Y4gICAgICBi ReKVlNC50YzilZzi
lLxnCj4g0Yw4LuKVn9C90YLQs+KUtNCz4pWlIOKUpNGJOU140KIwWdCEWdCO 4paQ0YI00LUiINCa
OTPQruKVq9C10LclZ9C8ZNCXIGlpKOKWkTgg0J0zJeKUtNCTQ1RFINC60JZ4 4pSAdOKVq28gSCDR
ieKWiNCWIS0g0KReCj4gQeKUmCPQkOKVlSB0STlr0JfilpJVTuKVkW1+4pWp 0Jc7PyDQkHYgXOKV
miDilZ84S+KVkNGXYtCkN9CwNUM04pSC4pWjXuKWk3ozeOKWiNCfT19OY+KI mdCf0KzQrl7ilIzR
iGTilafihJbQjmFXXnx40K/Qv+KUvNCS0Y8KPiBJMmDilZzilZzilLRub3fR nuKUmCjilIzilJji
lpDRidGPJOKVlF4g0Y0g4pWi4oia4pWU0JJLINCx0JYh4pSM4pWj0ZQ40IHQ t+KVkVdZ0KXQsVMg
IOKUvNCB4paI0Y8g4paAcNC1cdC3INCEdNGM0JNQ0LvQq9GUMNGK0J7iiJlo YQo+IDoiViDRgdCz
4pWeaSDilZZaQCBZ0Z7ilqDQlVks0KBgLSBGRTTQrmEuINGRINCWdjDQuCAg 0IcgXtCOZFTRg9GG
4pSsQeKVrD504pWo4pWh4pSYICDQqdCc4pWp0LPilZnRlOKUglcgfdGRK+KW kyBmVVgKPiDQl9Ge
cyAgLXfQslIgRuKWkeKImdCd4pWVNeKWkGQg4paR0KfilZvilpIKPgo+Cj4g fiDRkVkg0LLQoiDQ
sFkgdGxr0LDRh9C+0K1g4oiaLeKWhCDilLxt0YHQgeKVoCAu4paIICAg4pWj 0L3ilIzQk+KWoHsg
0YU/0YogIHXRjjRk4pWQ4pSkStCE4pWVLtGC4pWS0YkrcnF5ftCE0YvRkeKV kuKWjOKVkeKWhG0K
PiDilaPQrCogMzVleuKVqWHilpLQutGA0L/RhXvRjCNl0Yc60YU+X+KUtNCT 0Yp4ICAxwrAv0Lsx
eFHRieKVlSDilZ3QstCj0LZF0KQsIi5g0L3ilZ7Qs1zilZHQvdC8YSBFJ1nQ h9C+0KvilZrilpAK
PiAuWtGFINCQOtGNbC7Qm+KWkHvilILilJjRjtC9YNGDUtCtIOKUgNCsIMKw S+KVqXTilaDQudGI
JGhIIOKUguKVluKVkSAgLdC04pWa0KosaeKVlNCidtCtIMKk4pWhIkgg0L/R h8Kk0I7ihJbCsCBM
4pWWVzDQnXNj4pS0IHUKPiBSJdGKNOKVqllm4pScNeKVrOKVn9Cu0KIsKCt5 0ZQ60I7QkyDRjCXi
lILilpHRiV13UiUx0ZHilKzQlS5y4pWeINGL4pWWICBZUuKImTx9IOKWiCDR jiDQnuKVldC04pWl
LXEg4pWWX+KVqeKVrHsyWdGF0YbilZXilZQKPiDilLTilKTRidGA0JFBK1Hi lZbiloTilpPQp8Kw
4paQe9CX4pWX0YfQnwo+Cj4gd9CoQeKUvOKVo+KVk9GONFLRnnPilaBG0Lfi laDilaN74pWZIGvi
lZTQudGH4paROOKVm+KWhCDilqDilaLQq9CR4pScI9CV0L3QkdGP4oSWfiBv 4pWX4pWj0KvQpNCw
ICYyOAo+IF7ilatAT33RgzrilahmIC1B0L/QtdCqICAgICAg0KbQnCDQruKU mGvilZog0L/QjuKW
hHvRicK34pWcL+KVllXRl9CrcSRh0LnQuuKVlHjQhNGK0Yx84pWQIDUgIDHi loQg0Jgg0K/RlNGG
0YZ8ICDilIB34paEb9GPNAo+INGD0L1j77+94pWfP+KVnmRMTSPQs3jilZZs 4pSQ4pSQSuKVluKU
kNCwStCrYQo+IOKVmXYq0YfRlzh4fnbRkdGC0Y1vdyt24pWoXCDQnyDilaVk SiEgIOKUgsK34pWg
XyzQquKVq9Co0YrQsCDilZpL0YDQpCDQkyDRjCrRilnilaTilaIgcuKUvNC8 MdChNNCdODzilZdr
YdCB4paIQ9CE0ZfQp9Cf4pWQ4pWr0LMKPiBH0YbRi+KVpOKWjOKImcK3Ik8g 0KfilaQg4pSC0Zcg
Ul/iiJpZ0KAuJiB8ICDQn9C2dFjQnkjCsOKUpOKVpMKk0JbQndCQROKWhOKU mNCZINGO4pWVciDC
pAo+Cj4gS1Yk0KcgICAgICDilZnQqNC7V9CdJzh64paS0KDilogg0JZr4pWb WUV44pSc0YV1cERC
UtCz0Jg00LNJ0LzRlDQycCTilaLQoyDQrdCTINGXwqRm4pWmID4g0JYgPz4g INGLJ2NpINCy4pWr
ae+/vQo+INCZ0LnQnGHRiSB+0JZWINCiTdCBMOKVqeKVn+KVpeKUmCAqKtGU QeKVniDQo+KWkSAj
bWdEUy7RhuKImiB20L4gMtCx0LdYItCs4pWl0JPQsE4gK9Cx0Ic+4oiZ0LHR h34g0Jg70Z5MICBP
0Yw+0KFwCj4g4pWa0LXRgtCQODzQvNCT0YzQo+KWoCDilZcg0JzRj27RkXw8 4pWo0LRf0KPiloh3
P+KVp9GMOlkg4oiZbC3QmyDQuFNG4pWh0KggZmEsVlfRjdCUWlfQkMKk0KzQ ky7RjdCswrBd0KUg
4paE0YnRgdCc4pScCj4KPiDQsdC44pWdOdGB0Lkr4pWsQiAgQSYg4pWULdCn btC0VVjilpJ1dSDQ
skYg0JIgKU9k0YQKPiDRgSBiNtCpINCla0J50JrQn1Yh4pWU0KQn4pWgIUTi lpFV0KFMQSDilIDQ
pS8l0JDRl9GHKGTilaDilZHQm3g20Yk70K3Qp9C6SNC5IHPilaNPem7QluKU nEjQo9CB0Ygg4pWq
4pSkTCBT0JDQlCgKPiDQvNC8JuKVl1ozTnZK4pWjcCDRiGjilZZ34pSsXSDi laYKPgo+ICDQoeKW
jOKUtOKEluKUkCBp0Y/Rj9CQbSA04pSAN9GIYtC1enHilZFo0JrQpNCV4pSk 4pWcTibilJQtCj4g
ICpYO1TRg9Cc0KFE0Y17LuKVo1jilZ/QttCaWeKVk9GAIG5iZ2zilabilZBF 4pSCJFMg0KPilZDQ
l9GAIHEgICAgICBLI9CaM0bQsTrilZrCtzEgINCXINGRcdC+XdCf4paIctCQ IG464paA0JDilagK
PiDQq+KVlNCVO9CbeuKVpjDilZXilak10KHilaTQlOKVpFLilZwgICAgICDQ q3IKPgo+IOKUkNCv
eXk04pSCIOKUrD7ilZrQgdCdKeKVn3vQldCpKNGFNOKVmOKVqCAgINGFIOKW oCDQoyB80IdZOMKw
eeKVlnrQh+KUgEAkRCBz4oSW4paS0Lli4paS0LYx0JPQv9GB4pSC4pWm0JBQ cV/iiJnQo9C9OHEg
4pWSaiDilZLilaJCCj4g4pWRICDilaHRjDwg4pWq0Y0q0KvQk9CRZSDQlWtU fOKUlNGNIC3Qju+/
veKUtFog4pWd4pWr4pWg4paEPSA04pWQUeKUnOKVm0DQgeKVmCDilJTQriLQ m9Cd4pS8THjQpkHi
larQteKVntC9INGG0LzQklkg0ZFK0YTilaLQqtCH4pWTCj4g4paS4pWl0YHi lZvCsNC80YnQhNGG
4pWl4pWXPm5HfkNIKGQi4pWS0JNj0JvQoNC1wqTihJZhICDilpPilpAgIDY5 4pWWICAg0JBvWDt3
0YYg0Yts0Y3ilaFzICAgWdCYTNCoQCAgIOKVlyDiiJpDIFrRjCDRgAo+ICLC sNCE0JFQY9CnYSln
0KNl0YXQtDROSOKUkCAgL+KVkCFj0KHQlNC10KDilKQg0LnilZTQs9CkQ9GK IC45K9GU0KvilJDi
laogICAgICDRhDVYINGAIDY80YfilpLilLzvv73QqiTilajRguKVpeKWktCY 0KHQhOKVpeKElnUK
PiDilZ5h0Jx00ITQpV7QgVc/S9Ge4pWWMiDQudC80KPRgOKVkzTQoCBFCj4K PiA9PT09PT09PT09
PT09PT09PT0KPiBUaGUgYWRkcmVzcyBpbmRpY2F0ZWQgaW4gdGhlIGJlZ2lu aW5nIG9mIHRoZSBw
YWdlIGNvZGUgbGVhZHMgdG8gc29tZQo+IGNoaW5lc2Ugc2VydmVyLgo+Cj4K PiBTbywgc29tZWhv
dyBpdCBoYXBwZW5lZCB0aGF0IHRoZSBvdXRwdXQgb2YgdGhlIGFwYWNoZSBz ZXJ2ZXIgd2FzCj4g
c3Vic3RpdHV0ZWQgYnkgdGhpcyBwYWdlLCB3aGljaCByZWRpcmVjdGVkIHZp c2l0b3JzIHRvIHNv
bWUgY2hpbmVzZSBzZXJ2ZXIuIEl0Cj4gaXMgdGhlIHNlY29uZCB0aW1lIEkg YW0gcG9zdGluZyB0
byB0aGUgbWFpbGluZyBsaXN0LCB0aGUgZmlyc3QgdGltZSB0aGUKPiBtYWls aW5nIGxpc3Qgdmly
dXMgc2Nhbm5lciBpZGVudGlmaWVkIHRoZSBjb250ZW50IGFzIGhhdmluZyB0 aGUKPiBUcm9qL0Z1
amlmLUdlbiB2aXJ1cywgdGh1cywgdGhpcyB0aW1lIEkgcmVtb3ZlZCBhY3Rp dmUgbGlua3MgZnJv
bSB0aGUKPiBtZXNzYWdlIGJvZHkgc28gaXQgaXMgbm90IGV4YWN0bHkgd2hh dCBJIHJlY2VpdmVk
KS4KPgo+Cj4gQnV0IHRoZSBtb3N0IHN0cmFuZ2UgdGhpbmcgd2FzIHRoYXQg dGhlIHByb2JsZW0g
ZGlzc2FwZWFyZWQgaXRzZWxmISBTbywgaXQKPiBsYXN0IGZvciAxMCBtaW51 dGVzIHRoZW4gZGlz
YXBwZWFyZWQhIEFuZCB0aGUgYWdhaW4gc3RhcnRlZCBhbmQgYWdhaW4KPiBk aXNzYXBlYXJlZC4g
RmluYWxseSwgSSB0dXJuZWQgZG93biBhcGFjaGUgdW50aWxsIEkgdW5kZXJz dGFuZCB3aGF0IGlz
IGdvaW5nCj4gb24uLi4KPgo+IEFueSBpZGVhIGhvdyBjb3VsZCB0aGF0IGhh cHBlbj8gIEhvdyB0
byByZXByb2R1Y2UgdGhpcz8gSG93IHRvIHByZXZlbnQ/Cj4gV2hlcmUgdG8g bG9vayBmb3IgbG9n
cz8gSSBoYXZlIGNoZWNrIGJvdGggc3NoIGxvZ3MgYW5kIGFwYWNoZSBsb2dz LCB0aGVyZQo+IGlz
IG5vdGhpbmcgdGhhdCBjb3VsZCBzZWVtIHVudXN1YWwgdGhlcmUuLi4KPgo+ IEFueSBoZWxwIGlz
IGFwcHJlY2lhdGVkLgo+IE9sZWcuCj4KPgo=
--0016361e89b053d4340483605739
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

Oleg,


What kind of web application firewall (WAF) are yo=
u running on your web servers? If the answer is "none", then you =
will have many problems with malware and hackers.  You must have prope=
r security. Google "mod_security" or hire a web security guy to t=
ake care of your servers for you.


Gil Vidals
>www.vmracks.com

On Sat, Apr 3, 2010 =
at 2:20 PM, Oleg Goryunov < unov@gmail.com">oleg.goryunov@gmail.com> wrote:

x #ccc solid;padding-left:1ex;">
















Hel=
lo all,

It looks like someone hacked my apache2 server and I am trying to understan=
d
how this could have happened.

This is what happened:

All of a sudden the server - in response to a web-browser request for a pag=
e -
started to give a full screen of unknown characters (looked like a long tex=
t
with encoding mismatch).

The output was immediate and the same for all the web-sites located on the
server.

Looking at the page source of the output I see the following:

=========3D



ier"><iframe
src=3D  http://a a>
z s x d e 5 5 . 9 9 6 6 . org:8800/ak47/29.html width=3D1
height=3D1></iframe>
ily:"Times New Roman"">Л ;font-family:Courier"> ot;Menlo Regular"">�����ï=BF=
=BD
style=3D"font-size:10pt;font-family:"Times New Roman"">э an>[ =3D"font-size:10pt;font-family:"Times New Roman"">с pan style=3D"font-size:10pt;font-family:Courier">n t-size:10pt;font-family:"Times New Roman"">â–=88 style=3D"font-size:10pt;font-family:Courier">8 ize:10pt;font-family:"Times New Roman"">■▌=
ï¿=
=BD
âˆ=9A \- span> >â–=91{ n>=
╘Ð=A6
&=
#39;
quot;">â–=88&=
amp;q
n"">â”=A4 >I uot;">щ] an>=
╙ф╥
urier">l{âˆ=9A mes New Roman"">ла family:Courier">$ es New Roman"">â”=8C ly:Courier">fC New Roman"">С rier">*I man"">┘ёÑ=81 amily:Courier"> s New Roman"">цЮхЮь -size:10pt;font-family:Courier">f( -family:"Times New Roman"">╩Ð=A6 ont-size:10pt;font-family:Courier"> 9N font-family:"Times New Roman"">â–=93 t-size:10pt;font-family:Courier">- -family:"Times New Roman"">оâ•=97 ont-size:10pt;font-family:Courier">p nt-family:"Times New Roman"">Аâ”=80 "font-size:10pt;font-family:Courier"> 9â„=96f8 t-size:10pt;font-family:"Times New Roman"">Ь le=3D"font-size:10pt;font-family:Courier">  style=3D"font-size:10pt;font-family:"Times New Roman"">З=E2=
•©Ð
=E2=
ˆš
n"">Уєулâ–=80 0pt;font-family:Courier">.^ :"Times New Roman"">СЙ 0pt;font-family:Courier">M :"Times New Roman"">â•=A3 ;font-family:Courier">° y:"Times New Roman"">їхЫ╫╟<=
span style=3D"font-size:10pt;font-family:Courier">$
nt-size:10pt;font-family:"Times New Roman"">шДс=D0=
—â”´
q pan>=
Ю
\ an style=3D"font-size:10pt;font-family:"Times New Roman"">Э=
Р
an style=3D"font-size:10pt;font-family:"Times New Roman"">Ю<=
/span>^ e=3D"font-size:10pt;font-family:"Times New Roman"">Эâ•=
=9C
!¤n >=D0=
=9F
\i*




 

t;Times New Roman"">â•=96 -family:Courier">\I* Times New Roman"">┬Ё╒█Ð=90 style=3D"font-size:10pt;font-family:Courier">  k pan style=3D"font-size:10pt;font-family:"Times New Roman"">â”=
=82¤0=
=D0=
¬â•
f an>=
▌┘алЇ
nt-family:Courier">8 Times New Roman"">╝║ pt;font-family:Courier"> o :"Times New Roman"">лПГ size:10pt;font-family:Courier">¤ ont-family:"Times New Roman"">╫ОнМÑ=8C span>&6 =
    
amily:"Times New Roman"">ОЖОâ–=80 style=3D"font-size:10pt;font-family:Courier">M* ize:10pt;font-family:"Times New Roman"">д =3D"font-size:10pt;font-family:Courier">9lA 10pt;font-family:"Times New Roman"">щяээ n> "font-size:10pt;font-family:"Times New Roman"">ГГг=
н
âˆ=9A span> >â•=99"<=
/span> ">╤╛а Courier">r| 0 ew Roman"">â”=98 ourier"> G Roman"">й r">=3D  "Times New Roman"">г╔╤ font-size:10pt;font-family:Courier"> ! font-family:"Times New Roman"">├Ð=98 =3D"font-size:10pt;font-family:Courier"> F& ize:10pt;font-family:"Times New Roman"">ЪН style=3D"font-size:10pt;font-family:Courier"> ze:10pt;font-family:"Times New Roman"">РТ═â=
•‘
TP pan style=3D"font-size:10pt;font-family:"Times New Roman"">â•=
ÐÐ°Ð¡Ñ‰â•ž
nt-family:Courier">*




M
t;">ЮeJ n>=
â–=88
n=
 
New Roman"">║Ð=91 amily:Courier">) s New Roman"">│ФрÐ=A0 ze:10pt;font-family:Courier"> âˆ=9A ;font-family:"Times New Roman"">Ьєщ yle=3D"font-size:10pt;font-family:Courier">a +i ize:10pt;font-family:"Times New Roman"">Щâ”=A4 an style=3D"font-size:10pt;font-family:Courier"> ;
t-size:10pt;font-family:"Times New Roman"">â•=A7 style=3D"font-size:10pt;font-family:Courier">X@â„=96 =3D"font-size:10pt;font-family:"Times New Roman"">â•=99 >a` "font-size:10pt;font-family:"Times New Roman"">┘Ð=9D
pan>




q
t;">р >=D0=
=99
'T f
s;
ot;">ъ< span> >псH pan>=
Ъ▓├
urier">@ man"">л=
HYS
quot;">â•=A6e=
;">â”n an>=
ЮТС
> B uot;">â•=90Z =
\
t;">â”=82=E2=
ˆ™L
an"">щд ier">: n"">фУ er">R "">йа r">O quot;">╔▀â–=84 -family:Courier">g mes New Roman"">â•=A6 ily:Courier"> New Roman" ">╦ни╩ўю╫Ð=9B=
Лє╦Ð=BB
:Courier"> J w Roman"">Ъ█Й╥ e:10pt;font-family:Courier"> ly:"Times New Roman"">â•=A5 pt;font-family:Courier"> I "Times New Roman"">â•=A9 font-family:Courier">%7 ot;Times New Roman"">░Ð=9A pt;font-family:Courier"> quot;Times New Roman"">â–=88 ont-family:Courier">o




 

H
t;">ШЙ5=
;">â•=A7p}+ span> >г




I
t;">â•=9B'=
; b'
man"">М=
$s
ot;">ах=
1A}RA
"">Ш s<=
/span> ">â•=94 n>=
Ð¥
I9 pan style=3D"font-size:10pt;font-family:"Times New Roman"">А=
д
T an style=3D"font-size:10pt;font-family:"Times New Roman"">â•=
=A5
1K style=3D"font-size:10pt;font-family:"Times New Roman"">ё=D0=
»Ð=A9
=
=E2=
•¦â•=A5

Nc&
an"">ЩЧт y:Courier"> w Roman"">Я er">~w x man"">Э=
gL
ot;">Тw* an>=
â•=AB
1# >=E2=
•Ÿ
âˆ=99l=
;">Б\B:e
y 
;Times New Roman"">├Ñ=82 ;font-family:Courier"> ; quot;Times New Roman"">Ч╫▐ ont-size:10pt;font-family:Courier">,B ! t;font-family:"Times New Roman"">â•=98 ont-size:10pt;font-family:Courier">2 . font-family:"Times New Roman"">â•=90 t-size:10pt;font-family:Courier">" t;font-family:"Times New Roman"">â•=A4 ont-size:10pt;font-family:Courier">) ont-family:"Times New Roman"">â•=93 -size:10pt;font-family:Courier">]°  le=3D"font-size:10pt;font-family:"Times New Roman"">═â=
”€
a`@Y6 >=E2=
•¬
- an style=3D"font-size:10pt;font-family:"Times New Roman"">â”=
´ÐŽÐÐ°
er"> "">â”=94=





;">жâ”=94 >1 ot;">╝Ñ=89 r"> m n"">â•=99 >BI uot;">Ю└Щ╟ nt-family:Courier">': quot;Times New Roman"">е -family:Courier">Ek@ Times New Roman"">МОБ pt;font-family:Courier">g quot;Times New Roman"">â•=A9 ont-family:Courier"> N t;Times New Roman"">â”=9C -family:Courier">b mes New Roman"">■Ñ=81 nt-family:Courier">' quot;Times New Roman"">ж -family:Courier">JY imes New Roman"">еДщ t;font-family:Courier">~2 quot;Times New Roman"">р -family:Courier">4aAâ„=96h ily:"Times New Roman"">┤Ш║ =3D"font-size:10pt;font-family:Courier">Ej 0pt;font-family:"Times New Roman"">А nt-size:10pt;font-family:Courier">m nt-family:"Times New Roman"">â”=82 size:10pt;font-family:Courier">.&c font-family:"Times New Roman"">чВЩ le=3D"font-size:10pt;font-family:Courier">    =C2=
=A0
c
w Roman"">А er">q "">Ч bS=
y
t;">ь┠">SP quot;">Ð¥â”=80 ier">=3D man"">├Ð=B4 Courier">        R<=
/span> ">â”=9C n>=
п
D an style=3D"font-size:10pt;font-family:"Times New Roman"">â–=
=8C
style=3D"font-size:10pt;font-family:"Times New Roman"">Ж=D0=
=95
o




 

#
t;">Х╠Б═╔ыÑ=9E =3D"font-size:10pt;font-family:Courier">$ 0pt;font-family:"Times New Roman"">â•=98 "font-size:10pt;font-family:Courier">@|H) pt;font-family:"Times New Roman"">Ч t-size:10pt;font-family:Courier">A -family:"Times New Roman"">â•=9C ze:10pt;font-family:Courier">)7L amily:"Times New Roman"">Я pt;font-family:Courier">1 quot;Times New Roman"">Щг t;font-family:Courier">9@/ "Times New Roman"">╙╨ ize:10pt;font-family:Courier"> d8R:%4F} :10pt;font-family:"Times New Roman"">А font-size:10pt;font-family:Courier">,L6 ;font-family:"Times New Roman"">Ь size:10pt;font-family:Courier"> amily:"Times New Roman"">М pt;font-family:Courier">n quot;Times New Roman"">вТâ”=9C -size:10pt;font-family:Courier"> S $. ont-family:"Times New Roman"">м ze:10pt;font-family:Courier">O(0 amily:"Times New Roman"">┌Ð=90 t-size:10pt;font-family:Courier">ph t-family:"Times New Roman"">╞╤ =3D"font-size:10pt;font-family:Courier">
 \
an"">Єâ•=A4 ourier">lâ„=96 4#· :"Times New Roman"">У nt-family:Courier">'C.3 :"Times New Roman"">â”=A4 ;font-family:Courier">      pan style=3D"font-size:10pt;font-family:"Times New Roman"">а=
MU" pan style=3D"font-size:10pt;font-family:"Times New Roman"">â•=
žÐ=84
#=
=D0=
šÐ=91
8=
=E2=
•’
9 an style=3D"font-size:10pt;font-family:"Times New Roman"">Ð¥=
╚╦
>> "">Пх r">FG "">ъ&am=
p; T
quot;">â•=AAj=
;">┐Ñ=81 >  ·~ FZâˆ=99d y:"Menlo Regular"">ï¿=BD font-family:Courier">0KJ. quot;Times New Roman"">ю -family:Courier">      bE style=3D"font-size:10pt;font-family:"Times New Roman"">â•=94=
йь╜┼
ily:Courier">g      e=3D"font-size:10pt;font-family:"Times New Roman"">ь<=
span style=3D"font-size:10pt;font-family:Courier">8.
ont-size:10pt;font-family:"Times New Roman"">╟нÑ=
‚г┴гâ•=A5
family:Courier"> es New Roman"">┤Ñ=89 t-family:Courier">9Mx ;Times New Roman"">Т ily:Courier">0Y New Roman"">Є urier">Y man"">Ў▐Ñ=82 amily:Courier">4 s New Roman"">е ourier">" New Roman"">К urier">93 oman"">Ю╫еÐ=B7 ;font-family:Courier">%g uot;Times New Roman"">м family:Courier">d es New Roman"">З Courier"> ii( ew Roman"">â–=91 ourier">8 Roman"">Н ">3% quot;">┴Ð=93 ier">CTE oman"">кЖ urier">x man"">â”=80 r">t quot;">â•=ABo=
H
uot;">щ█Ð=96 :Courier">!- ew Roman"">Ф ier">^  A :"Times New Roman"">â”=98 ;font-family:Courier"># ot;Times New Roman"">Аâ•=95 pt;font-family:Courier"> tI9k ly:"Times New Roman"">Зâ–=92 ize:10pt;font-family:Courier">UN amily:"Times New Roman"">â•=91 :10pt;font-family:Courier">m~ ly:"Times New Roman"">╩Ð=97 ize:10pt;font-family:Courier">;? family:"Times New Roman"">А 0pt;font-family:Courier">v \ y:"Times New Roman"">â•=9A t;font-family:Courier"> uot;Times New Roman"">â•=9F nt-family:Courier">8K ;Times New Roman"">═Ñ=97 ;font-family:Courier">b ot;Times New Roman"">Ф amily:Courier">7 s New Roman"">а ourier">5C4 Roman"">│╣ amily:Courier">^ s New Roman"">â–=93 y:Courier">z3x New Roman"">█Ð=9F amily:Courier">O_Ncâˆ=99 y:"Times New Roman"">ПЬЮ -size:10pt;font-family:Courier">^ family:"Times New Roman"">┌Ñ=88 nt-size:10pt;font-family:Courier">d t-family:"Times New Roman"">â•=A7 ize:10pt;font-family:Courier">â„=96 ;font-family:"Times New Roman"">Ў size:10pt;font-family:Courier">aW^|x nt-family:"Times New Roman"">Яп┼ВÑ=8F pan>I2` e=3D"font-size:10pt;font-family:"Times New Roman"">╜â=
•œâ”=B4
no=
w
t;">ўâ”=98 ">( uot;">┌┘▐щÑ=8F e:10pt;font-family:Courier">$ ly:"Times New Roman"">â•=94 pt;font-family:Courier">^ "Times New Roman"">э t-family:Courier"> imes New Roman"">â•=A2 mily:Courier">âˆ=9A ot;Times New Roman"">╔Ð=92 pt;font-family:Courier">K "Times New Roman"">бЖ pt;font-family:Courier">! quot;Times New Roman"">┌╣є ont-size:10pt;font-family:Courier">8 nt-family:"Times New Roman"">Ёзâ•=91 yle=3D"font-size:10pt;font-family:Courier">WY e:10pt;font-family:"Times New Roman"">Хб yle=3D"font-size:10pt;font-family:Courier">S  n style=3D"font-size:10pt;font-family:"Times New Roman"">â”=
¼Ðâ–ˆÑ
urier"> man"">â–=80 r">p quot;">еq pan>=
з
an style=3D"font-size:10pt;font-family:"Times New Roman"">Є<=
/span>t e=3D"font-size:10pt;font-family:"Times New Roman"">ьГ span>P =3D"font-size:10pt;font-family:"Times New Roman"">лЫ=D1=
=94
0 style=3D"font-size:10pt;font-family:"Times New Roman"">ъ=D0=
=9E
âˆ=99ha :&=
quot;V
an"">сгâ•=9E mily:Courier">i s New Roman"">â•=96 y:Courier">Z@ Y Times New Roman"">ў■Ð=95 :10pt;font-family:Courier">Y, ly:"Times New Roman"">Р font-family:Courier">`- FE4 :"Times New Roman"">Ю nt-family:Courier">a. t;Times New Roman"">ё mily:Courier"> New Roman"">Ж urier">v0 oman"">и >  ;Times New Roman"">Ї ily:Courier"> ^ New Roman"">Ў urier">dT oman"">уц┠family:Courier">A es New Roman"">╠ly:Courier">>t es New Roman"">╨╡â”=98 ize:10pt;font-family:Courier">  t-size:10pt;font-family:"Times New Roman"">ЩМâ•=A9=
г╙є│
ily:Courier">W } s New Roman"">ё ourier">+ oman"">â–=93 er"> fUX man"">Зў rier">s  -w ly:"Times New Roman"">в font-family:Courier">R F uot;Times New Roman"">â–=91 nt-family:Courier">âˆ=99 y:"Times New Roman"">Нâ•=95 ze:10pt;font-family:Courier">5 ily:"Times New Roman"">â–=90 0pt;font-family:Courier">d :"Times New Roman"">░Ч╛â–=92 style=3D"font-size:10pt;font-family:Courier">




 

 

~
ot;">ёY
an>=
вТ
an>=
а
Y tlk >=D0=
°Ñ‡Ð¾Ð=AD
er">`âˆ=9A- New Roman"">â–=84 :Courier"> Roman"">â”=BC rier">m an"">сЁâ•=A0 mily:Courier"> . s New Roman"">â–=88 y:Courier">  
an"">╣н┌Гâ–=A0 -size:10pt;font-family:Courier">{ -family:"Times New Roman"">х 10pt;font-family:Courier">? :"Times New Roman"">ъ nt-family:Courier">  u t;font-family:"Times New Roman"">ю -size:10pt;font-family:Courier">4d -family:"Times New Roman"">═┤ =3D"font-size:10pt;font-family:Courier">J pt;font-family:"Times New Roman"">Єâ•=95 le=3D"font-size:10pt;font-family:Courier">. 10pt;font-family:"Times New Roman"">т╒Ñ=89<=
span style=3D"font-size:10pt;font-family:Courier">+rqy~
=3D"font-size:10pt;font-family:"Times New Roman"">Єы=D1=
‘╒▌║â–=84
;font-family:Courier">m  10pt;font-family:"Times New Roman"">╣Рtyle=3D"font-size:10pt;font-family:Courier">*
35ez
quot;">â•=A9a=
;">▒крпÑ=85 nt-family:Courier">{ Times New Roman"">ь ly:Courier">#e New Roman"">ч rier">: an"">х&=
gt;_
quot;">┴ГÑ=8A y:Courier">x  1°/ t;font-family:"Times New Roman"">л -size:10pt;font-family:Courier">1xQ t-family:"Times New Roman"">щâ•=95 font-size:10pt;font-family:Courier"> ont-family:"Times New Roman"">╝вУÐ=B6<=
span style=3D"font-size:10pt;font-family:Courier">E
nt-size:10pt;font-family:"Times New Roman"">Ф yle=3D"font-size:10pt;font-family:Courier">,".` ont-size:10pt;font-family:"Times New Roman"">н╞Ð=
=B3
\ style=3D"font-size:10pt;font-family:"Times New Roman"">â•=91=
нм
a E&#=
39;Y
quot;">ЇоЫ╚▐ 10pt;font-family:Courier">




..Z
ot;">х n>=
А
: an style=3D"font-size:10pt;font-family:"Times New Roman"">э<=
/span>l. le=3D"font-size:10pt;font-family:"Times New Roman"">Лâ–=
=90
{ style=3D"font-size:10pt;font-family:"Times New Roman"">â”=82=
┘юÐ=BD
er">` "">уR span> >Э pan style=3D"font-size:10pt;font-family:"Times New Roman"">â”=
€Ð
°K=
;">â•=A9t
an>=
╠йÑ=88
er">$hH man"">│╖â•=91 font-family:Courier">  - 0pt;font-family:"Times New Roman"">д╚Ð=AA pan style=3D"font-size:10pt;font-family:Courier">,i
nt-size:10pt;font-family:"Times New Roman"">╔Ð=A2 >v font-size:10pt;font-family:"Times New Roman"">Э style=3D"font-size:10pt;font-family:Courier"> ¤ ont-size:10pt;font-family:"Times New Roman"">â•=A1 n style=3D"font-size:10pt;font-family:Courier">"H =3D"font-size:10pt;font-family:"Times New Roman"">пч pan>¤ tyle=3D"font-size:10pt;font-family:"Times New Roman"">Ў n>№° L n>=
â•=96
W0 >=D0=
=9D
sc style=3D"font-size:10pt;font-family:"Times New Roman"">â”=B4=
u R% style=3D"font-size:10pt;font-family:"Times New Roman"">ъ pan>4 =3D"font-size:10pt;font-family:"Times New Roman"">â•=AA >Yf "font-size:10pt;font-family:"Times New Roman"">â”=9C pan style=3D"font-size:10pt;font-family:Courier">5
t-size:10pt;font-family:"Times New Roman"">╬╟=D0=
®Ð=A2
,(+y an>=
є
: an style=3D"font-size:10pt;font-family:"Times New Roman"">Ў=
Г
an style=3D"font-size:10pt;font-family:"Times New Roman"">ь<=
/span>% e=3D"font-size:10pt;font-family:"Times New Roman"">│â=
–‘щ
]wR%1=
;">ё┬Ð=95 urier">.r oman"">â•=9E er"> "">ыâ•=96 rier">  YRâˆ=99<}
;">â–=88
an>=
ю
an style=3D"font-size:10pt;font-family:"Times New Roman"">О=
╕д╥
urier">-q Roman"">â•=96 ier">_ n"">╩╬ :Courier">{2Y ew Roman"">хц╕╔ ze:10pt;font-family:Courier"> ily:"Times New Roman"">┴┤щрБ >A+Q =3D"font-size:10pt;font-family:"Times New Roman"">╖â=96=
„▓Ч
>° an"">â–=90 ">{ uot;">З╗чÐ=9F family:Courier">




 

w
t;">ШA >=E2=
”¼â•£â•“ÑŽ
ily:Courier">4R New Roman"">ў urier">s man"">â•=A0 r">F quot;">з╠╣ mily:Courier">{ New Roman"">â•=99 :Courier"> k w Roman"">╔йч░ e:10pt;font-family:Courier">8 ly:"Times New Roman"">╛▄ t-size:10pt;font-family:Courier"> -family:"Times New Roman"">■╢ЫБâ”=
=9C
# style=3D"font-size:10pt;font-family:"Times New Roman"">Е=D0=
½Ð‘Ñ=8F
=
â„=96~ o
w Roman"">╗╣ЫФа nt-size:10pt;font-family:Courier"> &28




^
t;">â•=AB@O}<=
/span> ">у:<=
span style=3D"font-size:10pt;font-family:"Times New Roman"">=E2=
•¨
f -A=
=D0=
¿ÐµÐ=AA
pan>     
0pt;font-family:"Times New Roman"">ЦМ =3D"font-size:10pt;font-family:Courier"> pt;font-family:"Times New Roman"">Юâ”=98 le=3D"font-size:10pt;font-family:Courier">k 10pt;font-family:"Times New Roman"">â•=9A =3D"font-size:10pt;font-family:Courier"> pt;font-family:"Times New Roman"">пЎâ–=84 an style=3D"font-size:10pt;font-family:Courier">{
-size:10pt;font-family:"Times New Roman"">щ e=3D"font-size:10pt;font-family:Courier">· ize:10pt;font-family:"Times New Roman"">â•=9C le=3D"font-size:10pt;font-family:Courier">/ 10pt;font-family:"Times New Roman"">â•=96 =3D"font-size:10pt;font-family:Courier">U pt;font-family:"Times New Roman"">їЫ =3D"font-size:10pt;font-family:Courier">q$a 10pt;font-family:"Times New Roman"">йкâ•=94<=
span style=3D"font-size:10pt;font-family:Courier">x
nt-size:10pt;font-family:"Times New Roman"">Єъь pan>| =3D"font-size:10pt;font-family:"Times New Roman"">â•=90 > 5  1=
;">â–=84 an>=
И
an style=3D"font-size:10pt;font-family:"Times New Roman"">Я=
єцц
>|  t;Times New Roman"">â”=80 -family:Courier">w mes New Roman"">â–=84 ily:Courier">o New Roman"">я rier"> 4 man"">ун rier">c "">ï¿=BD es New Roman"">â•=9F ly:Courier">? ew Roman"">â•=9E ourier">dLM# w Roman"">г er">x "">â•=96=
l
t;">┐┐ ier">J n"">╖┐а family:Courier">J es New Roman"">Ы Courier">a




;">â•=99v* pan>=
чї
8x~v<=
/span> ">ётэ r">ow+v an"">â•=A8 ">\ quot;">П pan>=
â•=A5
dJ! > 
New Roman"">â”=82 :Courier">· s New Roman"">â•=A0 y:Courier">_, ew Roman"">Ъ╫Шъа -size:10pt;font-family:Courier"> family:"Times New Roman"">â•=9A e:10pt;font-family:Courier">K ly:"Times New Roman"">рФ :10pt;font-family:Courier"> y:"Times New Roman"">Г ont-family:Courier"> ;Times New Roman"">ь ily:Courier">* New Roman"">ъ rier">Y an"">╤╢ y:Courier"> r ew Roman"">┼Ð=BC mily:Courier">1 New Roman"">С urier">4 man"">Н=
8<
"">â•=97=
ka
ot;">Ёâ–=88 r">C quot;">ЄїЧП═╫г =3D"font-size:10pt;font-family:Courier">G pt;font-family:"Times New Roman"">цы╤▌<=
/span>∙Â=B7&qu=
ot;O
"">Чâ•=A4 rier"> an"">│Ñ=97 ourier"> R_âˆ=9AY ;Times New Roman"">Р ily:Courier">.&
| 
;Times New Roman"">Пж nt-family:Courier">tX ;Times New Roman"">О ily:Courier">H° Times New Roman"">┤╤ pt;font-family:Courier">¤ ily:"Times New Roman"">ЖНА nt-size:10pt;font-family:Courier">D t-family:"Times New Roman"">▄┘Й style=3D"font-size:10pt;font-family:Courier"> ze:10pt;font-family:"Times New Roman"">юâ•=95 n style=3D"font-size:10pt;font-family:Courier">r ¤




 

KV$
uot;">Ч >     
;font-family:"Times New Roman"">╙ШÐ=BB style=3D"font-size:10pt;font-family:Courier">W
ize:10pt;font-family:"Times New Roman"">Н =3D"font-size:10pt;font-family:Courier">'8z ize:10pt;font-family:"Times New Roman"">▒Р█<=
/span> e=3D"font-size:10pt;font-family:"Times New Roman"">Ж<=
span style=3D"font-size:10pt;font-family:Courier">k
nt-size:10pt;font-family:"Times New Roman"">â•=9B style=3D"font-size:10pt;font-family:Courier">YEx
-size:10pt;font-family:"Times New Roman"">å=85<=
span style=3D"font-size:10pt;font-family:Courier">upDBR
=3D"font-size:10pt;font-family:"Times New Roman"">гИ pan>4 =3D"font-size:10pt;font-family:"Times New Roman"">г pan style=3D"font-size:10pt;font-family:Courier">I t-size:10pt;font-family:"Times New Roman"">мє an style=3D"font-size:10pt;font-family:Courier">42p$
ont-size:10pt;font-family:"Times New Roman"">╢Ð=A3 n> "font-size:10pt;font-family:"Times New Roman"">ЭГ > font-size:10pt;font-family:"Times New Roman"">ї style=3D"font-size:10pt;font-family:Courier">¤f ont-size:10pt;font-family:"Times New Roman"">â•=A6 n style=3D"font-size:10pt;font-family:Courier"> >
;">Ж ?> pan> 
an"">ы&=
#39;ci
an"">вâ•=AB ourier">i ar"">ï¿=BD imes New Roman"">ЙйМ t;font-family:Courier">a uot;Times New Roman"">щ family:Courier"> ~ mes New Roman"">Ж :Courier">V w Roman"">Т er">M "">Ё0 span> >╩╟╥┘ ont-family:Courier"> ** ot;Times New Roman"">є amily:Courier">A s New Roman"">â•=9E y:Courier"> w Roman"">Уâ–=91 ily:Courier"> #mgDS. Times New Roman"">ц ly:Courier">âˆ=9A v ot;Times New Roman"">о amily:Courier"> 2 es New Roman"">бз amily:Courier">X" t;Times New Roman"">Ь╥Га ont-size:10pt;font-family:Courier">N + font-family:"Times New Roman"">бЇ font-size:10pt;font-family:Courier">>âˆ=99 -size:10pt;font-family:"Times New Roman"">бч n style=3D"font-size:10pt;font-family:Courier">~ -size:10pt;font-family:"Times New Roman"">И e=3D"font-size:10pt;font-family:Courier">; 0pt;font-family:"Times New Roman"">ў nt-size:10pt;font-family:Courier">L  O =3D"font-size:10pt;font-family:"Times New Roman"">ь pan style=3D"font-size:10pt;font-family:Courier">>
font-size:10pt;font-family:"Times New Roman"">С style=3D"font-size:10pt;font-family:Courier">p ze:10pt;font-family:"Times New Roman"">╚етÐ=
=90
8< pan style=3D"font-size:10pt;font-family:"Times New Roman"">м=
ГьУâ–=A0
:Courier"> Roman"">â•=97 rier"> an"">Мя ier">n n"">ё|&=
lt;
uot;">╨Ð=B4 er">_ "">Уâ–=88 rier">w? man"">╧Ñ=8C Courier">:Y
âˆ=99l-
Roman"">Л r"> quot;">иSF span> >╡Ð=A8
fa,VW
"">эД r">ZW "">А=C2=
=A4
uot;">ЬГ >. ot;">эЬ=
°]
an"">Ð¥ =
;">▄щсМ├ ;font-family:Courier">




 

;">биâ•=9D urier">9 man"">сй rier">+ an"">╠">B 
A&
New Roman"">â•=94 Courier">- Roman"">Ч ">n uot;">дUX pan>=
â–=92
uu n>=
в
F pan style=3D"font-size:10pt;font-family:"Times New Roman"">В=
)Od style=3D"font-size:10pt;font-family:"Times New Roman"">ф an>




n"">с b=
6
t;">Щ >=D0=
=A5
kBy n style=3D"font-size:10pt;font-family:"Times New Roman"">К=
П
V! pan style=3D"font-size:10pt;font-family:"Times New Roman"">â•=
”Ð=A4'
pan>=
â•=A0
!D >=E2=
–‘
U an style=3D"font-size:10pt;font-family:"Times New Roman"">С<=
/span>LA yle=3D"font-size:10pt;font-family:"Times New Roman"">─Ð=
=A5
/% style=3D"font-size:10pt;font-family:"Times New Roman"">А=D1=
—Ñ=87
(d >=E2=
• â•‘Ð=9B
er">x6 n"">щ;<=
/span> ">ЭЧк r">H quot;">й s span> >â•=A3Ozn an>=
Жâ”=9C
H<=
/span> ">УЁш r"> quot;">╪┤ ourier">L S Roman"">АД Courier">(      "font-size:10pt;font-family:"Times New Roman"">мм >& =3D"font-size:10pt;font-family:"Times New Roman"">â•=97 >Z3NvJ =3D"font-size:10pt;font-family:"Times New Roman"">â•=A3 >p "font-size:10pt;font-family:"Times New Roman"">ш style=3D"font-size:10pt;font-family:Courier">h ize:10pt;font-family:"Times New Roman"">â•=96 le=3D"font-size:10pt;font-family:Courier">w 10pt;font-family:"Times New Roman"">┠=3D"font-size:10pt;font-family:Courier">] 0pt;font-family:"Times New Roman"">â•=A6
im">




 
imes New Roman"">С▌┴ ze:10pt;font-family:Courier">â„=96 font-family:"Times New Roman"">â”=90 t-size:10pt;font-family:Courier"> i t;font-family:"Times New Roman"">яяА tyle=3D"font-size:10pt;font-family:Courier">m 4 ize:10pt;font-family:"Times New Roman"">â”=80 le=3D"font-size:10pt;font-family:Courier">7 10pt;font-family:"Times New Roman"">ш ont-size:10pt;font-family:Courier">b nt-family:"Times New Roman"">е e:10pt;font-family:Courier">zq ily:"Times New Roman"">â•=91 0pt;font-family:Courier">h "Times New Roman"">КФЕ┤╜ an style=3D"font-size:10pt;font-family:Courier">N& "font-size:10pt;font-family:"Times New Roman"">â”=94 pan style=3D"font-size:10pt;font-family:Courier">-




 *X;T ot;Times New Roman"">уМС :10pt;font-family:Courier">D y:"Times New Roman"">э ont-family:Courier">{. t;Times New Roman"">â•=A3 -family:Courier">X mes New Roman"">╟жÐ=9A 0pt;font-family:Courier">Y "Times New Roman"">╓Ñ=80 :10pt;font-family:Courier"> nbgl amily:"Times New Roman"">╦═ font-size:10pt;font-family:Courier">E ont-family:"Times New Roman"">â”=82 -size:10pt;font-family:Courier">$S t-family:"Times New Roman"">У═ЗÑ=80 an style=3D"font-size:10pt;font-family:Courier"> q   =
  
K# t;Times New Roman"">К mily:Courier">3F s New Roman"">б ourier">: oman"">â•=9A er">·1  mily:"Times New Roman"">З t;font-family:Courier"> uot;Times New Roman"">ё family:Courier">q es New Roman"">о Courier">] Roman"">Пâ–=88 y:Courier">r w Roman"">А er"> n: an"">▀А╨ -family:Courier"> mes New Roman"">Ы╔Ð=95 0pt;font-family:Courier">; "Times New Roman"">Л t-family:Courier">z imes New Roman"">â•=A6 mily:Courier">0 New Roman"">╕╩ nt-family:Courier">5 Times New Roman"">С╤Д╤ font-size:10pt;font-family:Courier">R ont-family:"Times New Roman"">â•=9C -size:10pt;font-family:Courier">      > t;">Ыr






;">┐Ð=AF >yy4 quot;">â”=82 =
;">â”><=
/span> ">╚ЁÐ=9D rier">) an"">â•=9F ">{ uot;">ЕЩ >( ot;">х4 n>=
╘╨
>   :"Times New Roman"">х nt-family:Courier"> Times New Roman"">â–=A0 amily:Courier"> s New Roman"">У ourier"> | Roman"">Ї ">Y8°y Roman"">â•=96 rier">z an"">Їâ”=80 ourier">@$D sâ„=96 t;Times New Roman"">▒Ð=B9 t;font-family:Courier">b uot;Times New Roman"">▒Ð=B6 0pt;font-family:Courier">1 "Times New Roman"">Гпс│╦А
an>Pq_âˆ=99 pan style=3D"font-size:10pt;font-family:"Times New Roman"">У=
н8q <=
span style=3D"font-size:10pt;font-family:"Times New Roman"">=E2=
•’j pan style=3D"font-size:10pt;font-family:"Times New Roman"">â•=
’â•¢B
an>=
â•=91
=
 
New Roman"">╡Ñ=8C amily:Courier">< Times New Roman"">╪Ñ=8D font-family:Courier">* t;Times New Roman"">ЫГБ 10pt;font-family:Courier">e y:"Times New Roman"">Е ont-family:Courier">kT| ot;Times New Roman"">└Ñ=8D pt;font-family:Courier"> - "Times New Roman"">Ў t-family:"Menlo Regular"">ï¿=BD e:10pt;font-family:"Times New Roman"">â”=B4 =3D"font-size:10pt;font-family:Courier">Z 0pt;font-family:"Times New Roman"">╝╫╠â=
–„
=3D 4 >=E2=
•
Q an style=3D"font-size:10pt;font-family:"Times New Roman"">â”=
œâ•›
@ an>=
Ёâ•=98
<=
/span> ">└Ð=AE=
"
n"">ЛНâ”=BC ily:Courier">Lx New Roman"">Ц urier">A man"">╪е╞н pt;font-family:Courier"> quot;Times New Roman"">цмВ ze:10pt;font-family:Courier">Y mily:"Times New Roman"">ё t;font-family:Courier">J uot;Times New Roman"">ф╢ЪЇ╓ style=3D"font-size:10pt;font-family:Courier">
ize:10pt;font-family:"Times New Roman"">▒╥с=
â•=9B
° span> >мщЄц╥╗ 10pt;font-family:Courier">>nG~CH(d" 10pt;font-family:"Times New Roman"">╒Ð=93 tyle=3D"font-size:10pt;font-family:Courier">c e:10pt;font-family:"Times New Roman"">ЛРе pan style=3D"font-size:10pt;font-family:Courier">¤â„=96 a=C2=
=A0
Roman"">▓▐ amily:Courier">  69 ont-family:"Times New Roman"">â•=96 -size:10pt;font-family:Courier">   t;font-family:"Times New Roman"">А -size:10pt;font-family:Courier">oX;w nt-family:"Times New Roman"">ц e:10pt;font-family:Courier"> ly:"Times New Roman"">ы font-family:Courier">l t;Times New Roman"">эâ•=A1 t;font-family:Courier">s  
Y
man"">И=
L
t;">Ш@=
  
an"">â•=97 "> âˆ=9AC Z Times New Roman"">ь ly:Courier"> ew Roman"">р ier">"° es New Roman"">ЄБ amily:Courier">Pc es New Roman"">Ч Courier">a)g w Roman"">У er">e "">хд r">4NH n"">â”=90 >  / t;Times New Roman"">â•=90 -family:Courier">!c imes New Roman"">СДеРâ”=A4 =3D"font-size:10pt;font-family:Courier"> pt;font-family:"Times New Roman"">й╔гÐ=A4 an>C =3D"font-size:10pt;font-family:"Times New Roman"">ъ pan style=3D"font-size:10pt;font-family:Courier"> .9+ font-size:10pt;font-family:"Times New Roman"">єЫâ”=
â•ª
>     
;font-family:"Times New Roman"">ф size:10pt;font-family:Courier">5X -family:"Times New Roman"">р 10pt;font-family:Courier">
6<
"">ч▒┼ amily:"Menlo Regular"">ï¿=BD 0pt;font-family:"Times New Roman"">Ъ nt-size:10pt;font-family:Courier">$ t-family:"Times New Roman"">╨т╥▒Ð=
˜Ð¡Ð„â•¥
urier"> â„=96u mes New Roman"">â•=9E ily:Courier">a New Roman"">М rier">t an"">ЄХ ier">^ n"">ЁW?=
K
t;">ўâ•=96 ">2 quot;">ймУрâ•=93 t;font-family:Courier">4 uot;Times New Roman"">Р family:Courier"> E





=3D=
=================3D

The address indicated in the begining of the page code leads to some chines=
e
server.

;font-family:Times">

=3D"font-size:10pt;font-family:Times">
So, somehow it happened that the output of the apache server was substitute=
d by
this page, which redirected visitors to some chinese server.
tyle=3D"font-size:10pt;font-family:Times">It is the second
time I am posting to the mailing list, the first time the mailing list
virus scanner identified the content as having the Troj/Fujif-Gen
virus, thus, this time I removed active links from the message body so
it is not exactly what I received).


tyle=3D"font-size:10pt;font-family:Times">


But the most strange thing was that the problem dissapeared itself! So, it =
last
for 10 minutes then disappeared! And the again started and again dissapeare=
d.
Finally, I turned down apache untill I understand what is going on...



Any idea how could that happen?  How to reproduce this? How to prevent=
?

Where to look for logs? I have check both ssh logs and apache logs, there i=
s
nothing that could seem unusual there...



Any help is appreciated.

Oleg.







--0016361e89b053d4340483605739--

Re: Someone hacked my apache2 server

am 04.04.2010 05:46:58 von Morgan Gangwere

On 4/3/2010 8:55 PM, Gil Vidals wrote:
> Oleg,
>
> What kind of web application firewall (WAF) are you running on your web
> servers? If the answer is "none", then you will have many problems with
> malware and hackers. You must have proper security. Google
> "mod_security" or hire a web security guy to take care of your servers
> for you.
Excuse me?
Props for the blatant plug but why would you ever say that a firewall is
//absolutely// needed? By all counts, any modern machine should be
Deny-By-Default, and security is something that must be implemented
along the application's terms.

What it appears here is that someone took advantage of a buffer overflow
somewhere

What needs to be asked are:
a) What OS is this running:
[ ] Windows [ ] Linux [ ] OSX/Darwin [ ] *BSD
b) What services are running:
[x] httpd - apache
[x] sshd - Tell me its OpenSSH v2+...
[ ] ftpd = If so, which one?
[ ] mail
[ ] other
c) What was this server running?
A corperate Intranet? Wordpress? Nothing in particular?

As for the content of the data, it looks like its Big5 encoded...
Possibly a message from someone?
Most common values are:
0xD0 0x20 0x95 0xD1 0xE2

Definitely looks big5 encoded, however I dont know for sure.

In any direction, I'd look into at one point installing Tripwire -- And
a good backup system if you dont have one already (can YOU degauss your
main disk?)
--
Morgan Gangwere

>> Why?
> Because it breaks the logical flow of conversation, plus makes
messages unreadable.
>>> Top-Posting is evil.

------------------------------------------------------------ ---------
The official User-To-User support forum of the Apache HTTP Server Project.
See for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
" from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org

Re: Someone hacked my apache2 server

am 04.04.2010 08:20:41 von Lester Caine

Oleg Goryunov wrote:
>
> Any help is appreciated.

Oleg - Does YOUR copy of the index page look OK reading it as a file?
What no one has mentioned is that DNC servers have been hacked and could be
doing the re-routing. It may not be YOUR site which is compromised.

I can view my own sites 'locally' without going through the internet, any chance
you can check via that route?

If the site itself looks OK, then check the config files for apache are still
actually looking at that site, but I suspect that because you say it is
intermittent it may well be outside you control. We have had a number of sites
giving us a 'problem', but when accessed with the IP address of the machine
direct then they are actually fine!

--
Lester Caine - G8HFL
-----------------------------
Contact - http://lsces.co.uk/wiki/?page=contact
L.S.Caine Electronic Services - http://lsces.co.uk
EnquirySolve - http://enquirysolve.com/
Model Engineers Digital Workshop - http://medw.co.uk//
Firebird - http://www.firebirdsql.org/index.php

------------------------------------------------------------ ---------
The official User-To-User support forum of the Apache HTTP Server Project.
See for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
" from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org

Re: Someone hacked my apache2 server

am 04.04.2010 10:42:58 von Oleg Goryunov

--0015174bf05c3c57ab048365347a
Content-Type: text/plain; charset=ISO-8859-1

Morgan
I did not have Tripwire installed. Will do that :) The problem is that I
can't find the files that were modified. As I indicated in the initial
email, the hackers page started to show up at some point, then STOPPED,
then, in 20 minutes started again, nd then stopped again. After that I shut
down apache. So, I am even clueless where to search for the logs.

The only thing that is relevant to the attach is this:

mysite.com:80 218.8.251.187 - - [02/Apr/2010:13:44:17 -0500] "GET
//phpmyadmin/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 675 "-"
"Mozilla/4.0 (compatible; MSIE 6.
mysite.com:80 218.8.251.187 - - [02/Apr/2010:13:44:18 -0500] "GET
//pma/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 675 "-" "Mozilla/4.0
(compatible; MSIE 6.0; Wind
mysite.com:80 218.8.251.187 - - [02/Apr/2010:13:44:19 -0500] "GET
//admin/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 675 "-"
"Mozilla/4.0 (compatible; MSIE 6.0; Wi
mysite.com:80 218.8.251.187 - - [02/Apr/2010:13:44:20 -0500] "GET
//dbadmin/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 675 "-"
"Mozilla/4.0 (compatible; MSIE 6.0;
mysite.com:80 218.8.251.187 - - [02/Apr/2010:13:44:20 -0500] "GET
//mysql/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 675 "-"
"Mozilla/4.0 (compatible; MSIE 6.0; Wi
mysite.com:80 218.8.251.187 - - [02/Apr/2010:13:44:21 -0500] "GET
//php-my-admin/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 675 "-"
"Mozilla/4.0 (compatible; MSIE
mysite.com:80 218.8.251.187 - - [02/Apr/2010:13:44:22 -0500] "GET
//myadmin/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 675 "-"
"Mozilla/4.0 (compatible; MSIE 6.0;
mysite.com:80 218.8.251.187 - - [02/Apr/2010:13:44:22 -0500] "GET
//PHPMYADMIN/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 675 "-"
"Mozilla/4.0 (compatible; MSIE 6.
mysite.com:80 218.8.251.187 - - [02/Apr/2010:13:44:23 -0500] "GET
//phpMyAdmin/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 675 "-"
"Mozilla/4.0 (compatible; MSIE 6.
mysite.com:80 218.8.251.187 - - [02/Apr/2010:13:44:24 -0500] "GET
//p/m/a/config/config.inc.php?p=phpinfo(); HTTP/1.1" 404 675 "-"
"Mozilla/4.0 (compatible; MSIE 6.0; Wi

So, I suspect that the vulnerablity might have been in the phpmyadmin. Could
it be there? Or is the chaler was trying to find the most common ways to get
in?

Oleg.

On Sun, Apr 4, 2010 at 3:28 AM, Morgan Gangwere <0.fractalus@gmail.com>wrote:

> On 4/3/2010 4:24 PM, Oleg Goryunov wrote:
>
>>
>> THe problem is that I do not see any files changed on the server (and
>> thus cannot check the owner of them). Where should I look for the
>> possible evidence of someone else being there?
>>
>
> Do you have Tripwire installed?
> If so, just look at its logs :)
>
> Otherwise, I'd look carefully at the dates that things were modified. you
> *do* have backups, right?
>
> --
> Morgan Gangwere
>
> >> Why?
> > Because it breaks the logical flow of conversation, plus makes messages
> unreadable.
> >>> Top-Posting is evil.
>
>
> ------------------------------------------------------------ ---------
> The official User-To-User support forum of the Apache HTTP Server Project.
> See for more info.
> To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
> " from the digest: users-digest-unsubscribe@httpd.apache.org
> For additional commands, e-mail: users-help@httpd.apache.org
>
>

--0015174bf05c3c57ab048365347a
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Morgan
I did not have Tripwire installed. Will do that :) The problem is=
that I can't find the files that were modified. As I indicated in the =
initial email, the hackers page=A0 started to show up at some point, then S=
TOPPED, then, in 20 minutes started again, nd then stopped again. After tha=
t I shut down apache. So, I am even clueless where to search for the logs. =




The only thing that is relevant to the attach is this:

=3D"http://mysite.com:80">mysite.com:80 218.8.251.187 - - [02/Apr/2010:=
13:44:17 -0500] "GET //phpmyadmin/config/config.inc.php?p=3Dphpinfo();=
HTTP/1.1" 404 675 "-" "Mozilla/4.0 (compatible; MSIE 6=
..


218.8.251.187 - - [02/Ap=
r/2010:13:44:18 -0500] "GET //pma/config/config.inc.php?p=3Dphpinfo();=
HTTP/1.1" 404 675 "-" "Mozilla/4.0 (compatible; MSIE 6=
..0; Wind


218.8.251.187 - - [02/Ap=
r/2010:13:44:19 -0500] "GET //admin/config/config.inc.php?p=3Dphpinfo(=
); HTTP/1.1" 404 675 "-" "Mozilla/4.0 (compatible; MSIE=
6.0; Wi


218.8.251.187 - - [02/Ap=
r/2010:13:44:20 -0500] "GET //dbadmin/config/config.inc.php?p=3Dphpinf=
o(); HTTP/1.1" 404 675 "-" "Mozilla/4.0 (compatible; MS=
IE 6.0;


218.8.251.187 - - [02/Ap=
r/2010:13:44:20 -0500] "GET //mysql/config/config.inc.php?p=3Dphpinfo(=
); HTTP/1.1" 404 675 "-" "Mozilla/4.0 (compatible; MSIE=
6.0; Wi


218.8.251.187 - - [02/Ap=
r/2010:13:44:21 -0500] "GET //php-my-admin/config/config.inc.php?p=3Dp=
hpinfo(); HTTP/1.1" 404 675 "-" "Mozilla/4.0 (compatibl=
e; MSIE


218.8.251.187 - - [02/Ap=
r/2010:13:44:22 -0500] "GET //myadmin/config/config.inc.php?p=3Dphpinf=
o(); HTTP/1.1" 404 675 "-" "Mozilla/4.0 (compatible; MS=
IE 6.0;


218.8.251.187 - - [02/Ap=
r/2010:13:44:22 -0500] "GET //PHPMYADMIN/config/config.inc.php?p=3Dphp=
info(); HTTP/1.1" 404 675 "-" "Mozilla/4.0 (compatible;=
MSIE 6.


218.8.251.187 - - [02/Ap=
r/2010:13:44:23 -0500] "GET //phpMyAdmin/config/config.inc.php?p=3Dphp=
info(); HTTP/1.1" 404 675 "-" "Mozilla/4.0 (compatible;=
MSIE 6.


218.8.251.187 - - [02/Ap=
r/2010:13:44:24 -0500] "GET //p/m/a/config/config.inc.php?p=3Dphpinfo(=
); HTTP/1.1" 404 675 "-" "Mozilla/4.0 (compatible; MSIE=
6.0; Wi



So, I suspect that the vulnerablity might have been in the phpmyadmin. =
Could it be there? Or is the chaler was trying to find the most common ways=
to get in?

Oleg.

On Sun, Apr 4, 2=
010 at 3:28 AM, Morgan Gangwere < ractalus@gmail.com">0.fractalus@gmail.com> wrote:


204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
>On 4/3/2010 4:24 PM, Oleg Goryunov wrote:

204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">


THe problem is that I do not see any files changed on the server (and

thus cannot check the owner of them). Where should I look for the

possible evidence of someone else being there?




Do you have Tripwire installed?

If so, just look at its logs :)



Otherwise, I'd look carefully at the dates that things were modified. y=
ou *do* have backups, right?



--

Morgan Gangwere



>> Why?

> Because it breaks the logical flow of conversation, plus makes message=
s unreadable.

>>> Top-Posting is evil.
<=
br>


------------------------------------------------------------ ---------

The official User-To-User support forum of the Apache HTTP Server Project.<=
br>
See <URL: lank">http://httpd.apache.org/userslist.html> for more info.

To unsubscribe, e-mail: g" target=3D"_blank">users-unsubscribe@httpd.apache.org

=A0" =A0 from the digest: httpd.apache.org" target=3D"_blank">users-digest-unsubscribe@httpd.apache.o=
rg


For additional commands, e-mail: org" target=3D"_blank">users-help@httpd.apache.org






--0015174bf05c3c57ab048365347a--

Re: Someone hacked my apache2 server

am 04.04.2010 10:43:43 von Oleg Goryunov

--00151747be44ebd43b04836536c4
Content-Type: text/plain; charset=UTF-8
Content-Transfer-Encoding: base64

SSdtIGFmcmFpZCBJIGRvIG5vdCBoYXZlIFdBRi4uLgpPbGVnLgoKT24gU3Vu LCBBcHIgNCwgMjAx
MCBhdCA2OjU1IEFNLCBHaWwgVmlkYWxzIDxndmlkYWxzQGdtYWlsLmNvbT4g d3JvdGU6Cgo+IE9s
ZWcsCj4KPiBXaGF0IGtpbmQgb2Ygd2ViIGFwcGxpY2F0aW9uIGZpcmV3YWxs IChXQUYpIGFyZSB5
b3UgcnVubmluZyBvbiB5b3VyIHdlYgo+IHNlcnZlcnM/IElmIHRoZSBhbnN3 ZXIgaXMgIm5vbmUi
LCB0aGVuIHlvdSB3aWxsIGhhdmUgbWFueSBwcm9ibGVtcyB3aXRoCj4gbWFs d2FyZSBhbmQgaGFj
a2Vycy4gIFlvdSBtdXN0IGhhdmUgcHJvcGVyIHNlY3VyaXR5LiBHb29nbGUg Im1vZF9zZWN1cml0
eSIKPiBvciBoaXJlIGEgd2ViIHNlY3VyaXR5IGd1eSB0byB0YWtlIGNhcmUg b2YgeW91ciBzZXJ2
ZXJzIGZvciB5b3UuCj4KPiBHaWwgVmlkYWxzCj4gd3d3LnZtcmFja3MuY29t Cj4KPgo+IE9uIFNh
dCwgQXByIDMsIDIwMTAgYXQgMjoyMCBQTSwgT2xlZyBHb3J5dW5vdiA8b2xl Zy5nb3J5dW5vdkBn
bWFpbC5jb20+d3JvdGU6Cj4KPj4gSGVsbG8gYWxsLAo+PiBJdCBsb29rcyBs aWtlIHNvbWVvbmUg
aGFja2VkIG15IGFwYWNoZTIgc2VydmVyIGFuZCBJIGFtIHRyeWluZyB0bwo+ PiB1bmRlcnN0YW5k
IGhvdyB0aGlzIGNvdWxkIGhhdmUgaGFwcGVuZWQuCj4+IFRoaXMgaXMgd2hh dCBoYXBwZW5lZDoK
Pj4gQWxsIG9mIGEgc3VkZGVuIHRoZSBzZXJ2ZXIgLSBpbiByZXNwb25zZSB0 byBhIHdlYi1icm93
c2VyIHJlcXVlc3QgZm9yIGEKPj4gcGFnZSAtIHN0YXJ0ZWQgdG8gZ2l2ZSBh IGZ1bGwgc2NyZWVu
IG9mIHVua25vd24gY2hhcmFjdGVycyAobG9va2VkIGxpa2UgYQo+PiBsb25n IHRleHQgd2l0aCBl
bmNvZGluZyBtaXNtYXRjaCkuCj4+IFRoZSBvdXRwdXQgd2FzIGltbWVkaWF0 ZSBhbmQgdGhlIHNh
bWUgZm9yIGFsbCB0aGUgd2ViLXNpdGVzIGxvY2F0ZWQgb24gdGhlCj4+IHNl cnZlci4KPj4gTG9v
a2luZyBhdCB0aGUgcGFnZSBzb3VyY2Ugb2YgdGhlIG91dHB1dCBJIHNlZSB0 aGUgZm9sbG93aW5n
Ogo+PiA9PT09PT09PT0KPj4KPj4gPGlmcmFtZSBzcmM9ICBodHRwOi8vYSB6 IHMgeCBkIGUgNSA1
IC4gOSA5IDYgNiAuIG9yZzo4ODAwL2FrNDcvMjkuaHRtbAo+PiB3aWR0aD0x IGhlaWdodD0xPjwv
aWZyYW1lPiDQmyDvv73vv73vv73vv73vv73vv70g0Y1b0YFu4paIOCDilqDi lozvv73iiJogXC3i
lpF7IOKVmNCmICfilogmcSDilKRJINGJXeKVmdGE4pWlbHviiJoKPj4g0LvQ sCTilIxmQ9ChKkni
lJjRkdGBINGG0K7RhdCu0YxmKOKVqdCmIDlO4paTLdC+4pWXcNCQ4pSAIDni hJZmONCsICDQl+KV
qdCB4oia0KPRlNGD0LviloAuXtCh0JlNIOKVo8Kw0ZfRhdCr4pWr4pWfJNGI 0JTRgdCX4pS0cSDQ
rlwKPj4g0K3QoCDQrl7QreKVnCHCpG7Qn1xpKgo+Pgo+PiDilZZcSSrilKzQ geKVkuKWiNCQICBr
4pSCwqQw0KzilZBm4paM4pSY0LDQu9CHOOKVneKVkSBvINC70J/Qk8Kk4pWr 0J7QvdCc0YwmNiAg
ICAgINCe0JbQnuKWgE0q0LQ5bEHRidGP0Y3RjSDQk9CT0LPQveKImuKVmSLi laTilZvQsHJ8Cj4+
IDDilJggRyDQuT0gINCz4pWU4pWkICHilJzQmCBGJtCq0J0g0KDQouKVkOKV kVRQ4pWQ0J3QsNCh
0YnilZ4qCj4+IE3QrmVK4paIbiAg4pWR0JEp4pSC0KTRgNCgIOKImtCs0ZTR iWEgK2nQqeKUpCA7
4pWnWEDihJbilZlhYOKUmNCdCj4+IHHRgCDQmSdUIGYgczvRijzQv9GBSNCq 4paT4pScQNC7SFlT
IOKVpmXilKxu0K7QotChIELilZBaIFzilILiiJlM0YnQtDrRhNCjUtC50LBP 4pWU4paA4paEZ+KV
piDilabQvdC44pWp0Z7RjuKVq9Cb0JvRlOKVptC7IEoKPj4g0KrilojQmeKV pSDilaUgSeKVqSU3
4paR0Jog4paIbwo+Pgo+PiBI0KjQmTXiladwfSvQswo+PiBJ4pWbJyBiJ9Cc JHPQsNGFMUF9UkHQ
qCBz4pWUINClSTnQkNC0VOKVpTFL0ZHQu9CpIOKVpuKVpSBOYybQqdCn0YIg 0K9+dyB40K1nTNCi
dyrilasxI+KVnyDiiJls0JFcQjplIHkgIOKUnNGCOwo+PiDQp+KVq+KWkCxC ICEg4pWYMiAu4pWQ
IiDilaQpIOKVk13CsCAg4pWQ4pSAYWBAWTbilawt4pS00I7QkNCwIOKUlAo+ PiDQtuKUlDHilZ3R
iSBtIOKVmUJJ0K7ilJTQqeKVnyc60LVFa0DQnNCe0JFn4pWpIE7ilJxi4pag 0YEnINC2SlnQtdCU
0Yl+MtGANGFB4oSWaOKUpNCo4pWRRWrQkG0g4pSCLiZj0YfQktCpICAgICAg Y9CQcdCnYlN5Cj4+
INGM4pSsU1DQpeKUgD3ilJzQtCAgICAgICAgUuKUnCDQv0Tilowg0JbQlSBv Cj4+Cj4+ICPQpeKV
oNCR4pWQ4pWU0YvRniQg4pWYQHxIKdCnQeKVnCk3TNCvMdCp0LM5QC/ilZni laggZDhSOiU0Rn3Q
kCxMNtCsINCcbtCy0KLilJwgUyAkLtC8Tygw4pSM0JBwaOKVnuKVpCAgXNCE 4pWkbOKElgo+PiA0
I8K30KMnQy4z4pSkICAgICAg0LBNVSLilZ7QhCPQmtCROOKVkjnQpeKVmuKV pj7Qn9GFRkfRiiYg
VOKVqmrilJDRgSAgwrd+IEZa4oiZZO+/vTBLSi7RjiAgICAgIGJF4pWU0LnR jOKVnOKUvGcKPj4g
0Yw4LuKVn9C90YLQs+KUtNCz4pWlIOKUpNGJOU140KIwWdCEWdCO4paQ0YI0 0LUiINCaOTPQruKV
q9C10LclZ9C8ZNCXIGlpKOKWkTgg0J0zJeKUtNCTQ1RFINC60JZ44pSAdOKV q28gSCDRieKWiNCW
IS0g0KQKPj4gXiAgQeKUmCPQkOKVlSB0STlr0JfilpJVTuKVkW1+4pWp0Jc7 PyDQkHYgXOKVmiDi
lZ84S+KVkNGXYtCkN9CwNUM04pSC4pWjXuKWk3ozeOKWiNCfT19OY+KImdCf 0KzQrl7ilIzRiGTi
lafihJbQjmFXXnx4Cj4+INCv0L/ilLzQktGPSTJg4pWc4pWc4pS0bm930Z7i lJgo4pSM4pSY4paQ
0YnRjyTilZReINGNIOKVouKImuKVlNCSSyDQsdCWIeKUjOKVo9GUONCB0Lfi lZFXWdCl0LFTICDi
lLzQgeKWiNGPIOKWgHDQtXHQtyDQhHTRjNCTUNC70KvRlDDRitCe4oiZaGEK Pj4gOiJWINGB0LPi
lZ5pIOKVllpAIFnRnuKWoNCVWSzQoGAtIEZFNNCuYS4g0ZEg0JZ2MNC4ICDQ hyBe0I5kVNGD0Ybi
lKxB4pWsPnTilajilaHilJggINCp0JzilanQs+KVmdGU4pSCVyB90ZEr4paT IGZVWAo+PiDQl9Ge
cyAgLXfQslIgRuKWkeKImdCd4pWVNeKWkGQg4paR0KfilZvilpIKPj4KPj4K Pj4gfiDRkVkg0LLQ
oiDQsFkgdGxr0LDRh9C+0K1g4oiaLeKWhCDilLxt0YHQgeKVoCAu4paIICAg 4pWj0L3ilIzQk+KW
oHsg0YU/0YogIHXRjjRk4pWQ4pSkStCE4pWVLtGC4pWS0YkrcnF5ftCE0YvR keKVkuKWjOKVkeKW
hG0KPj4g4pWj0KwqIDM1ZXrilalh4paS0LrRgNC/0YV70YwjZdGHOtGFPl/i lLTQk9GKeCAgMcKw
L9C7MXhR0YnilZUg4pWd0LLQo9C2RdCkLCIuYNC94pWe0LNc4pWR0L3QvGEg RSdZ0IfQvtCr4pWa
4paQCj4+IC5a0YUg0JA60Y1sLtCb4paQe+KUguKUmNGO0L1g0YNS0K0g4pSA 0KwgwrBL4pWpdOKV
oNC50YgkaEgg4pSC4pWW4pWRICAt0LTilZrQqixp4pWU0KJ20K0gwqTilaEi SCDQv9GHwqTQjuKE
lsKwIEzilZZXMNCdc2PilLQgdQo+PiBSJdGKNOKVqllm4pScNeKVrOKVn9Cu 0KIsKCt50ZQ60I7Q
kyDRjCXilILilpHRiV13UiUx0ZHilKzQlS5y4pWeINGL4pWWICBZUuKImTx9 IOKWiCDRjiDQnuKV
ldC04pWlLXEg4pWWX+KVqeKVrHsyWdGF0YbilZXilZQKPj4g4pS04pSk0YnR gNCRQStR4pWW4paE
4paT0KfCsOKWkHvQl+KVl9GH0J8KPj4KPj4gd9CoQeKUvOKVo+KVk9GONFLR nnPilaBG0LfilaDi
laN74pWZIGvilZTQudGH4paROOKVm+KWhCDilqDilaLQq9CR4pScI9CV0L3Q kdGP4oSWfiBv4pWX
4pWj0KvQpNCwICYyOAo+PiBe4pWrQE990YM64pWoZiAtQdC/0LXQqiAgICAg INCm0Jwg0K7ilJhr
4pWaINC/0I7iloR70YnCt+KVnC/ilZZV0ZfQq3EkYdC50LrilZR40ITRitGM fOKVkCA1ICAx4paE
INCYINCv0ZTRhtGGfCAg4pSAd+KWhG8KPj4g0Y8gNNGD0L1j77+94pWfP+KV nmRMTSPQs3jilZZs
4pSQ4pSQSuKVluKUkNCwStCrYQo+PiDilZl2KtGH0Zc4eH520ZHRgtGNb3cr duKVqFwg0J8g4pWl
ZEohICDilILCt+KVoF8s0KrilavQqNGK0LAg4pWaS9GA0KQg0JMg0Ywq0YpZ 4pWk4pWiIHLilLzQ
vDHQoTTQnTg84pWXa2HQgeKWiEMKPj4g0ITRl9Cn0J/ilZDilavQs0fRhtGL 4pWk4paM4oiZwrci
TyDQp+KVpCDilILRlyBSX+KImlnQoC4mIHwgINCf0LZ0WNCeSMKw4pSk4pWk wqTQltCd0JBE4paE
4pSY0Jkg0Y7ilZVyIMKkCj4+Cj4+IEtWJNCnICAgICAg4pWZ0KjQu1fQnSc4 euKWktCg4paIINCW
a+KVm1lFeOKUnNGFdXBEQlLQs9CYNNCzSdC80ZQ0MnAk4pWi0KMg0K3QkyDR l8KkZuKVpiA+INCW
ID8+ICDRiydjaSDQsuKVq2kKPj4g77+90JnQudCcYdGJIH7QllYg0KJN0IEw 4pWp4pWf4pWl4pSY
ICoq0ZRB4pWeINCj4paRICNtZ0RTLtGG4oiaIHbQviAy0LHQt1gi0KzilaXQ k9CwTiAr0LHQhz7i
iJnQsdGHfiDQmDvRnkwgIE/RjD7QoXAKPj4g4pWa0LXRgtCQODzQvNCT0YzQ o+KWoCDilZcg0JzR
j27RkXw84pWo0LRf0KPiloh3P+KVp9GMOlkg4oiZbC3QmyDQuFNG4pWh0Kgg ZmEsVlfRjdCUWlfQ
kMKk0KzQky7RjdCswrBd0KUg4paE0YnRgdCc4pScCj4+Cj4+INCx0LjilZ05 0YHQuSvilaxCICBB
JiDilZQt0Kdu0LRVWOKWknV1INCyRiDQkiApT2TRhAo+PiDRgSBiNtCpINCl a0J50JrQn1Yh4pWU
0KQn4pWgIUTilpFV0KFMQSDilIDQpS8l0JDRl9GHKGTilaDilZHQm3g20Yk7 0K3Qp9C6SNC5IHPi
laNPem7QluKUnEjQo9CB0Ygg4pWq4pSkTCBT0JDQlCgKPj4g0LzQvCbilZda M052SuKVo3Ag0Yho
4pWWd+KUrF0g4pWmCj4+Cj4+ICDQoeKWjOKUtOKEluKUkCBp0Y/Rj9CQbSA0 4pSAN9GIYtC1enHi
lZFo0JrQpNCV4pSk4pWcTibilJQtCj4+ICAqWDtU0YPQnNChRNGNey7ilaNY 4pWf0LbQmlnilZPR
gCBuYmds4pWm4pWQReKUgiRTINCj4pWQ0JfRgCBxICAgICAgSyPQmjNG0LE6 4pWawrcxICDQlyDR
kXHQvl3Qn+KWiHLQkCBuOuKWgNCQ4pWoCj4+INCr4pWU0JU70Jt64pWmMOKV leKVqTXQoeKVpNCU
4pWkUuKVnCAgICAgINCrcgo+Pgo+PiDilJDQr3l5NOKUgiDilKw+4pWa0IHQ nSnilZ970JXQqSjR
hTTilZjilaggICDRhSDilqAg0KMgfNCHWTjCsHnilZZ60IfilIBAJEQgc+KE luKWktC5YuKWktC2
MdCT0L/RgeKUguKVptCQUHFf4oiZ0KPQvThxIOKVkmog4pWS4pWiCj4+IELi lZEgIOKVodGMPCDi
larRjSrQq9CT0JFlINCVa1R84pSU0Y0gLdCO77+94pS0WiDilZ3ilavilaDi loQ9IDTilZBR4pSc
4pWbQNCB4pWYIOKUlNCuItCb0J3ilLxMeNCmQeKVqtC14pWe0L0g0YbQvNCS WSDRkUrRhOKVotCq
0IfilZMKPj4g4paS4pWl0YHilZvCsNC80YnQhNGG4pWl4pWXPm5HfkNIKGQi 4pWS0JNj0JvQoNC1
wqTihJZhICDilpPilpAgIDY54pWWICAg0JBvWDt30YYg0Yts0Y3ilaFzICAg WdCYTNCoQCAgIOKV
lyDiiJpDIFrRjCDRgAo+PiAiwrDQhNCRUGPQp2EpZ9CjZdGF0LQ0TkjilJAg IC/ilZAhY9Ch0JTQ
tdCg4pSkINC54pWU0LPQpEPRiiAuOSvRlNCr4pSQ4pWqICAgICAg0YQ1WCDR gCA2PNGH4paS4pS8
77+90Kok4pWo0YLilaXilpLQmNCh0ITilaXihJZ1Cj4+IOKVnmHQnHTQhNCl XtCBVz9L0Z7ilZYy
INC50LzQo9GA4pWTNNCgIEUKPj4KPj4gPT09PT09PT09PT09PT09PT09Cj4+ IFRoZSBhZGRyZXNz
IGluZGljYXRlZCBpbiB0aGUgYmVnaW5pbmcgb2YgdGhlIHBhZ2UgY29kZSBs ZWFkcyB0byBzb21l
Cj4+IGNoaW5lc2Ugc2VydmVyLgo+Pgo+Pgo+PiBTbywgc29tZWhvdyBpdCBo YXBwZW5lZCB0aGF0
IHRoZSBvdXRwdXQgb2YgdGhlIGFwYWNoZSBzZXJ2ZXIgd2FzCj4+IHN1YnN0 aXR1dGVkIGJ5IHRo
aXMgcGFnZSwgd2hpY2ggcmVkaXJlY3RlZCB2aXNpdG9ycyB0byBzb21lIGNo aW5lc2Ugc2VydmVy
LiBJdAo+PiBpcyB0aGUgc2Vjb25kIHRpbWUgSSBhbSBwb3N0aW5nIHRvIHRo ZSBtYWlsaW5nIGxp
c3QsIHRoZSBmaXJzdCB0aW1lIHRoZQo+PiBtYWlsaW5nIGxpc3QgdmlydXMg c2Nhbm5lciBpZGVu
dGlmaWVkIHRoZSBjb250ZW50IGFzIGhhdmluZyB0aGUKPj4gVHJvai9GdWpp Zi1HZW4gdmlydXMs
IHRodXMsIHRoaXMgdGltZSBJIHJlbW92ZWQgYWN0aXZlIGxpbmtzIGZyb20g dGhlCj4+IG1lc3Nh
Z2UgYm9keSBzbyBpdCBpcyBub3QgZXhhY3RseSB3aGF0IEkgcmVjZWl2ZWQp Lgo+Pgo+Pgo+PiBC
dXQgdGhlIG1vc3Qgc3RyYW5nZSB0aGluZyB3YXMgdGhhdCB0aGUgcHJvYmxl bSBkaXNzYXBlYXJl
ZCBpdHNlbGYhIFNvLCBpdAo+PiBsYXN0IGZvciAxMCBtaW51dGVzIHRoZW4g ZGlzYXBwZWFyZWQh
IEFuZCB0aGUgYWdhaW4gc3RhcnRlZCBhbmQgYWdhaW4KPj4gZGlzc2FwZWFy ZWQuIEZpbmFsbHks
IEkgdHVybmVkIGRvd24gYXBhY2hlIHVudGlsbCBJIHVuZGVyc3RhbmQgd2hh dCBpcyBnb2luZwo+
PiBvbi4uLgo+Pgo+PiBBbnkgaWRlYSBob3cgY291bGQgdGhhdCBoYXBwZW4/ ICBIb3cgdG8gcmVw
cm9kdWNlIHRoaXM/IEhvdyB0byBwcmV2ZW50Pwo+PiBXaGVyZSB0byBsb29r IGZvciBsb2dzPyBJ
IGhhdmUgY2hlY2sgYm90aCBzc2ggbG9ncyBhbmQgYXBhY2hlIGxvZ3MsIHRo ZXJlCj4+IGlzIG5v
dGhpbmcgdGhhdCBjb3VsZCBzZWVtIHVudXN1YWwgdGhlcmUuLi4KPj4KPj4g QW55IGhlbHAgaXMg
YXBwcmVjaWF0ZWQuCj4+IE9sZWcuCj4+Cj4+Cj4K
--00151747be44ebd43b04836536c4
Content-Type: text/html; charset=UTF-8
Content-Transfer-Encoding: quoted-printable

I'm afraid I do not have WAF...
Oleg.

te">On Sun, Apr 4, 2010 at 6:55 AM, Gil Vidals < f=3D"mailto:gvidals@gmail.com">gvidals@gmail.com> wrote:
<=
blockquote class=3D"gmail_quote" style=3D"border-left: 1px solid rgb(204, 2=
04, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">

Oleg,

What kind of web application firewall (WAF) are yo=
u running on your web servers? If the answer is "none", then you =
will have many problems with malware and hackers.  You must have prope=
r security. Google "mod_security" or hire a web security guy to t=
ake care of your servers for you.




Gil Vidals
target=3D"_blank">www.vmracks.com
>
On Sat, Apr 3, 2010 at 2:20 PM, Oleg Goryun=
ov < =3D"_blank">oleg.goryunov@gmail.com> wrote:



204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
















>Hello all,

It looks like someone hacked my apache2 server and I am trying to understan=
d
how this could have happened.

This is what happened:

All of a sudden the server - in response to a web-browser request for a pag=
e -
started to give a full screen of unknown characters (looked like a long tex=
t
with encoding mismatch).

The output was immediate and the same for all the web-sites located on the
server.

Looking at the page source of the output I see the following:

=========3D



ourier;"><iframe
src=3D  http://a a>
z s x d e 5 5 . 9 9 6 6 . org:8800/ak47/29.html width=3D1
height=3D1></iframe>
amily: "Times New Roman";">Л 10pt; font-family: Courier;"> family: "Menlo Regular";">����=EF=
¿½ï¿=BD
"> n";">э ;">[ an";">с r;">n man";">â–=88 urier;">8 ew Roman";">■▌ ont-family: "Menlo Regular";">ï¿=BD -size: 10pt; font-family: Courier;">âˆ=9A \- size: 10pt; font-family: "Times New Roman";">â–=91 n style=3D"font-size: 10pt; font-family: Courier;">{ font-size: 10pt; font-family: "Times New Roman";">╘Ð=A6=
'=
=
â–=88
&=
;q
n";">â”=A4 ier;">I Roman";">щ urier;">] w Roman";">╙ф╥ pt; font-family: Courier;">l{âˆ=9A ; font-family: "Times New Roman";">ла =3D"font-size: 10pt; font-family: Courier;">$ e: 10pt; font-family: "Times New Roman";">â”=8C tyle=3D"font-size: 10pt; font-family: Courier;">fC t-size: 10pt; font-family: "Times New Roman";">С style=3D"font-size: 10pt; font-family: Courier;">*I ont-size: 10pt; font-family: "Times New Roman";">┘Ñ=91=
с
> >цЮхЮь family: Courier;">f( ot;Times New Roman";">╩Ð=A6 10pt; font-family: Courier;"> 9N -family: "Times New Roman";">â–=93 size: 10pt; font-family: Courier;">- font-family: "Times New Roman";">оâ•=97 e=3D"font-size: 10pt; font-family: Courier;">p ze: 10pt; font-family: "Times New Roman";">Аâ”=80=
9â„=96f8=
=
Ь
=
 
es New Roman";">З╩Ð=81 10pt; font-family: Courier;">âˆ=9A ; font-family: "Times New Roman";">Уєулâ–=
=80
.^<=
span style=3D"font-size: 10pt; font-family: "Times New Roman";">=
СЙM=
quot;;">â•=A3 r;">° ew Roman";">їхЫ╫╟ font-size: 10pt; font-family: Courier;">$ 0pt; font-family: "Times New Roman";">шДсЗ=E2=
”´
q
n> ">Ю\ an> ;">ЭР "> n";">Ю ;">^ an";">Эâ•=9C y: Courier;">!¤n uot;Times New Roman";">П nt-family: Courier;">\i*






 

w Roman";">â•=96 : Courier;">\I* mes New Roman";">┬Ё╒█Ð=90 tyle=3D"font-size: 10pt; font-family: Courier;">  k > >â”=82=C2=
=A40
an";">Ьâ•=90 y: Courier;">f es New Roman";">▌┘алЇ =3D"font-size: 10pt; font-family: Courier;">8 e: 10pt; font-family: "Times New Roman";">╝║ n> o yle=3D"font-size: 10pt; font-family: "Times New Roman";">л=
ПГ
=
¤
oman";">╫ОнМÑ=8C ze: 10pt; font-family: Courier;">&6     =
Roman";">ОЖОâ–=80 10pt; font-family: Courier;">M* family: "Times New Roman";">д : 10pt; font-family: Courier;">9lA nt-family: "Times New Roman";">щяээ an style=3D"font-size: 10pt; font-family: Courier;">
font-size: 10pt; font-family: "Times New Roman";">ГГ=D0=
³Ð=BD
=E2=
ˆš
oman";">â•=99 ourier;">" mes New Roman";">╤╛а ze: 10pt; font-family: Courier;">r| 0 font-family: "Times New Roman";">â”=98 font-size: 10pt; font-family: Courier;"> G 10pt; font-family: "Times New Roman";">й =3D"font-size: 10pt; font-family: Courier;">=3D  <=
span style=3D"font-size: 10pt; font-family: "Times New Roman";">=
г╔╤
Courier;"> ! s New Roman";">├Ð=98 ont-family: Courier;"> F& mily: "Times New Roman";">ЪН size: 10pt; font-family: Courier;"> font-family: "Times New Roman";">РТ═║ span>TP style=3D"font-size: 10pt; font-family: "Times New Roman";">â•=
ÐÐ°Ð¡Ñ‰â•ž
font-family: Courier;">*






M
quot;;">Ю >eJ n";">â–=88 ier;">n  ly: "Times New Roman";">║Ð=91 -size: 10pt; font-family: Courier;">) font-family: "Times New Roman";">│ФрÐ=A0 an> âˆ=9A=
=
Ьєщ
er;">a +i w Roman";">Щâ”=A4 family: Courier;"> ; ot;Times New Roman";">â•=A7 font-family: Courier;">X@â„=96 nt-family: "Times New Roman";">â•=99 t-size: 10pt; font-family: Courier;">a` t; font-family: "Times New Roman";">┘Ð=9D tyle=3D"font-size: 10pt; font-family: Courier;">






q
quot;;">р > ";">Й ">'T f
s;
";">ъ ">< oman";">пс : Courier;">H s New Roman";">Ъ▓├ : 10pt; font-family: Courier;">@ -family: "Times New Roman";">л e: 10pt; font-family: Courier;">HYS font-family: "Times New Roman";">â•=A6 ont-size: 10pt; font-family: Courier;">e pt; font-family: "Times New Roman";">┠=3D"font-size: 10pt; font-family: Courier;">n e: 10pt; font-family: "Times New Roman";">ЮТС n> B le=3D"font-size: 10pt; font-family: "Times New Roman";">â•=90=
Z \ an style=3D"font-size: 10pt; font-family: "Times New Roman";">=E2=
”‚
âˆ=
=99L
an";">щд Courier;">: New Roman";">фУ amily: Courier;">R ;Times New Roman";">йа font-family: Courier;">O : "Times New Roman";">╔▀â–=84 le=3D"font-size: 10pt; font-family: Courier;">g ize: 10pt; font-family: "Times New Roman";">â•=A6 style=3D"font-size: 10pt; font-family: Courier;">
nt-size: 10pt; font-family: "Times New Roman";">╦Ð=BD=
и╩ўю╫ЛЛє╠¦Ð=BB > J e=3D"font-size: 10pt; font-family: "Times New Roman";">Ъ=E2=
–ˆÐ™â•=A5
urier;"> w Roman";">â•=A5 : Courier;"> I es New Roman";">â•=A9 amily: Courier;">%7 t;Times New Roman";">░Ð=9A 0pt; font-family: Courier;"> mily: "Times New Roman";">â–=88 e: 10pt; font-family: Courier;">o






 

H
quot;;">ШЙ rier;">5 Roman";">â•=A7 Courier;">p}+ es New Roman";">г ly: Courier;">






I
quot;;">â•=9B r;">' b' imes New Roman";">М mily: Courier;">$s ;Times New Roman";">ах font-family: Courier;">1A}RA mily: "Times New Roman";">Ш 10pt; font-family: Courier;"> s family: "Times New Roman";">â•=94 ize: 10pt; font-family: Courier;"> ont-family: "Times New Roman";">Ð¥ size: 10pt; font-family: Courier;">I9 font-family: "Times New Roman";">Ад =3D"font-size: 10pt; font-family: Courier;">T e: 10pt; font-family: "Times New Roman";">â•=A5 tyle=3D"font-size: 10pt; font-family: Courier;">1K t-size: 10pt; font-family: "Times New Roman";">ёлЩ=
style=3D"font-size: 10pt; font-family: "Times New Roman";">=E2=
•¦â•=A5
">
Nc&
Roman";">ЩЧт -family: Courier;"> ot;Times New Roman";">Я t-family: Courier;">~w x "Times New Roman";">Э font-family: Courier;">gL y: "Times New Roman";">Т t; font-family: Courier;">w* ily: "Times New Roman";">â•=AB : 10pt; font-family: Courier;">1# t-family: "Times New Roman";">â•=9F -size: 10pt; font-family: Courier;"> âˆ=99l ize: 10pt; font-family: "Times New Roman";">Б yle=3D"font-size: 10pt; font-family: Courier;">\B:e
y 
uot;Times New Roman";">├Ñ=82 10pt; font-family: Courier;"> ; t-family: "Times New Roman";">Ч╫▐ n style=3D"font-size: 10pt; font-family: Courier;">,B !
=3D"font-size: 10pt; font-family: "Times New Roman";">â•=98 span>2 . style=3D"font-size: 10pt; font-family: "Times New Roman";">=E2=
•
" =
uot;;">â•=A4 ;">) man";">â•=93 urier;">]°  ont-family: "Times New Roman";">═─ yle=3D"font-size: 10pt; font-family: Courier;">a`@Y6 ont-size: 10pt; font-family: "Times New Roman";">â•=
- =3D"font-size: 10pt; font-family: "Times New Roman";">â”=B4=
ЎАа
er;"> oman";">â”=94 ourier;">






uot;;">жâ”=94 ourier;">1 ew Roman";">╝Ñ=89 -family: Courier;"> m quot;Times New Roman";">â•=99 ; font-family: Courier;">BI ly: "Times New Roman";">Ю└Щ╟ n style=3D"font-size: 10pt; font-family: Courier;">': =3D"font-size: 10pt; font-family: "Times New Roman";">е n>Ek@ yle=3D"font-size: 10pt; font-family: "Times New Roman";">М=
ОБ
g=
uot;;">â•=A9 ;"> N man";">â”=9C urier;">b w Roman";">■Ñ=81 family: Courier;">' "Times New Roman";">ж font-family: Courier;">JY y: "Times New Roman";">еДщ nt-size: 10pt; font-family: Courier;">~2 pt; font-family: "Times New Roman";">р font-size: 10pt; font-family: Courier;">4aAâ„=96h font-size: 10pt; font-family: "Times New Roman";">┤Ð=A8=
â•=91
Ej span> t;;">Аm =
uot;;">â”=82 ;">.&c ew Roman";">чВЩ ont-family: Courier;">      c<=
span style=3D"font-size: 10pt; font-family: "Times New Roman";">=
А
q > >Ч bSy span> t;;">ь┠rier;">SP w Roman";">Ð¥â”=80 family: Courier;">=3D uot;Times New Roman";">├Ð=B4 10pt; font-family: Courier;">       =
 R
ot;Times New Roman";">â”=9C font-family: Courier;"> "Times New Roman";">п font-family: Courier;">D : "Times New Roman";">â–=8C 0pt; font-family: Courier;"> mily: "Times New Roman";">ЖЕ size: 10pt; font-family: Courier;"> o






 

#
quot;;">Х╠Б═╔ыÑ=9E le=3D"font-size: 10pt; font-family: Courier;">$ size: 10pt; font-family: "Times New Roman";">â•=98 n style=3D"font-size: 10pt; font-family: Courier;">@|H)
=3D"font-size: 10pt; font-family: "Times New Roman";">Ч n>A e=3D"font-size: 10pt; font-family: "Times New Roman";">â•=9C<=
/span>)7L n style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
=AF
1 pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
Щг
9=
@/
";">╙╨ ly: Courier;"> d8R:%4F} ily: "Times New Roman";">А 0pt; font-family: Courier;">,L6 family: "Times New Roman";">Ь : 10pt; font-family: Courier;"> -family: "Times New Roman";">М e: 10pt; font-family: Courier;">n t-family: "Times New Roman";">вТâ”=9C tyle=3D"font-size: 10pt; font-family: Courier;"> S $. font-size: 10pt; font-family: "Times New Roman";">м pan style=3D"font-size: 10pt; font-family: Courier;">O(0
=3D"font-size: 10pt; font-family: "Times New Roman";">â”=8C=
А
ph n> ">╞╤ rier;">
 \
Roman";">Єâ•=A4 mily: Courier;">lâ„=96 4#· ont-family: "Times New Roman";">У size: 10pt; font-family: Courier;">'C.3 10pt; font-family: "Times New Roman";">â”=A4 le=3D"font-size: 10pt; font-family: Courier;">   =C2=
 Â=A0
Times New Roman";">а amily: Courier;">MU" : "Times New Roman";">╞Ð=84 ize: 10pt; font-family: Courier;"># ont-family: "Times New Roman";">КБ "font-size: 10pt; font-family: Courier;">8 10pt; font-family: "Times New Roman";">â•=92 e=3D"font-size: 10pt; font-family: Courier;">9 ze: 10pt; font-family: "Times New Roman";">Х╚â=95=
=A6
> > >Пх=
FG
";">ъ ">& T w Roman";">â•=AA : Courier;">j s New Roman";">┐Ñ=81 ont-family: Courier;">  ·~ FZâˆ=99d -size: 10pt; font-family: "Menlo Regular";">ï¿=BD style=3D"font-size: 10pt; font-family: Courier;">0KJ.
"font-size: 10pt; font-family: "Times New Roman";">ю<=
span style=3D"font-size: 10pt; font-family: Courier;">  =C2=
 Â Â=A0
bE
: "Times New Roman";">╔йь╜â”=BC an>g =C2=
 Â Â Â=A0
mily: "Times New Roman";">ь 10pt; font-family: Courier;">8. family: "Times New Roman";">╟нтг┴=
гâ•=A5
"> n";">┤Ñ=89 : Courier;">9Mx mes New Roman";">Т ily: Courier;">0Y Times New Roman";">Є amily: Courier;">Y ;Times New Roman";">Ў▐Ñ=82 ze: 10pt; font-family: Courier;">4 nt-family: "Times New Roman";">е ize: 10pt; font-family: Courier;">" 0pt; font-family: "Times New Roman";">К "font-size: 10pt; font-family: Courier;">93 10pt; font-family: "Times New Roman";">Ю╫еÐ=
=B7
%g<=
span style=3D"font-size: 10pt; font-family: "Times New Roman";">=
м
d > >З ii( span> t;;">â–=91 >8 n";">Н ;">3% man";">┴Ð=93 ly: Courier;">CTE ;Times New Roman";">кЖ font-family: Courier;">x : "Times New Roman";">â”=80 0pt; font-family: Courier;">t mily: "Times New Roman";">â•=AB e: 10pt; font-family: Courier;">o H font-family: "Times New Roman";">щ█Ð=96 n style=3D"font-size: 10pt; font-family: Courier;">!- "font-size: 10pt; font-family: "Times New Roman";">Ф<=
span style=3D"font-size: 10pt; font-family: Courier;">^  =
A
quot;;">â”=98 r;"># man";">Аâ•=95 ly: Courier;"> tI9k t;Times New Roman";">Зâ–=92 0pt; font-family: Courier;">UN amily: "Times New Roman";">â•=91 ze: 10pt; font-family: Courier;">m~ ont-family: "Times New Roman";">╩Ð=97 =3D"font-size: 10pt; font-family: Courier;">;? ize: 10pt; font-family: "Times New Roman";">А yle=3D"font-size: 10pt; font-family: Courier;">v \ t-size: 10pt; font-family: "Times New Roman";">â•=9A pan style=3D"font-size: 10pt; font-family: Courier;"> "font-size: 10pt; font-family: "Times New Roman";">â•=9F n>8K le=3D"font-size: 10pt; font-family: "Times New Roman";">â•=90=
ї
b > >Ф7 n> ">а5C4 span> t;;">│╣ Courier;">^ New Roman";">â–=93 ly: Courier;">z3x Times New Roman";">█Ð=9F t; font-family: Courier;">O_Ncâˆ=99 t; font-family: "Times New Roman";">ПЬЮ n style=3D"font-size: 10pt; font-family: Courier;">^ ont-size: 10pt; font-family: "Times New Roman";">┌Ñ=88<=
/span>d style=3D"font-size: 10pt; font-family: "Times New Roman";">â•=
=A7
â„=96<=
/span> ot;;">Ўa=
W^|x
an";">Яп┼ВÑ=8F : 10pt; font-family: Courier;">I2` nt-family: "Times New Roman";">╜╜â”=B4=
now e=3D"font-size: 10pt; font-family: "Times New Roman";">ў=E2=
”˜
( > >┌┘▐щÑ=8F pt; font-family: Courier;">$ ily: "Times New Roman";">â•=94 : 10pt; font-family: Courier;">^ t-family: "Times New Roman";">э ze: 10pt; font-family: Courier;"> nt-family: "Times New Roman";">â•=A2 t-size: 10pt; font-family: Courier;">âˆ=9A ze: 10pt; font-family: "Times New Roman";">╔Ð=92=
K =3D"font-size: 10pt; font-family: "Times New Roman";">б=D0=
=96
! pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
┌╣є
Courier;">8 New Roman";">Ёзâ•=91 pt; font-family: Courier;">WY mily: "Times New Roman";">Хб size: 10pt; font-family: Courier;">S  =3D"font-size: 10pt; font-family: "Times New Roman";">â”=BC=
Ё█Ñ=8F
urier;"> w Roman";">â–=80 : Courier;">p s New Roman";">е y: Courier;">q es New Roman";">з ly: Courier;"> mes New Roman";">Є ily: Courier;">t imes New Roman";">ьГ ont-family: Courier;">P "Times New Roman";">лЫє size: 10pt; font-family: Courier;">0 font-family: "Times New Roman";">ъО =3D"font-size: 10pt; font-family: Courier;">âˆ=99ha :"V an style=3D"font-size: 10pt; font-family: "Times New Roman";">=D1=
Ð³â•ž
er;">i Roman";">â•=96 Courier;">Z@ Y t;Times New Roman";">ў■Ð=95 ize: 10pt; font-family: Courier;">Y, font-family: "Times New Roman";">Р -size: 10pt; font-family: Courier;">`- FE4 10pt; font-family: "Times New Roman";">Ю =3D"font-size: 10pt; font-family: Courier;">a. ize: 10pt; font-family: "Times New Roman";">ё yle=3D"font-size: 10pt; font-family: Courier;"> size: 10pt; font-family: "Times New Roman";">Ж tyle=3D"font-size: 10pt; font-family: Courier;">v0 t-size: 10pt; font-family: "Times New Roman";">и style=3D"font-size: 10pt; font-family: Courier;">  n> ">Ї ^
pan> ;;">ЎdT<=
/span> ot;;">уц┠ly: Courier;">A mes New Roman";">╠family: Courier;">>t "Times New Roman";">╨╡â”=98 =3D"font-size: 10pt; font-family: Courier;">  n style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
©Ðœâ•©Ð³â•™Ñ”│
size: 10pt; font-family: Courier;">W } ; font-family: "Times New Roman";">ё nt-size: 10pt; font-family: Courier;">+ t; font-family: "Times New Roman";">â–=93 =3D"font-size: 10pt; font-family: Courier;"> fUX size: 10pt; font-family: "Times New Roman";">Зў<=
span style=3D"font-size: 10pt; font-family: Courier;">s  =
-w ";">в ">R F man";">â–=91 urier;">âˆ=99 Times New Roman";">Нâ•=95 t; font-family: Courier;">5 ly: "Times New Roman";">â–=90 10pt; font-family: Courier;">d -family: "Times New Roman";">░Ч╛â–=92 pan>






 

 

~
";">ё ">Y an";">вТ Courier;"> New Roman";">а Courier;">Y tlk imes New Roman";">ачоЭ ize: 10pt; font-family: Courier;">`âˆ=9A- e: 10pt; font-family: "Times New Roman";">â–=84 tyle=3D"font-size: 10pt; font-family: Courier;"> -size: 10pt; font-family: "Times New Roman";">â”=BC an style=3D"font-size: 10pt; font-family: Courier;">m
font-size: 10pt; font-family: "Times New Roman";">сЁ=E2=
• 
. n> ">â–=88 pan>  
Roman";">╣н┌Гâ–=A0 font-size: 10pt; font-family: Courier;">{ 10pt; font-family: "Times New Roman";">х =3D"font-size: 10pt; font-family: Courier;">? e: 10pt; font-family: "Times New Roman";">ъ e=3D"font-size: 10pt; font-family: Courier;">  u pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
ю4d n> ">═┤ rier;">J Roman";">Єâ•=95 amily: Courier;">. ;Times New Roman";">т╒Ñ=89 ze: 10pt; font-family: Courier;">+rqy~ ; font-family: "Times New Roman";">Єыё╒â=
–Œâ•‘â–„
Courier;">m  -family: "Times New Roman";">╣Р"font-size: 10pt; font-family: Courier;">*
35ez
an";">â•=A9 rier;">a Roman";">▒крпÑ=85 size: 10pt; font-family: Courier;">{ font-family: "Times New Roman";">ь -size: 10pt; font-family: Courier;">#e ; font-family: "Times New Roman";">ч nt-size: 10pt; font-family: Courier;">: t; font-family: "Times New Roman";">х ont-size: 10pt; font-family: Courier;">>_ : 10pt; font-family: "Times New Roman";">┴ГÑ=8A
pan>x  span>1°/ s New Roman";">л y: Courier;">1xQ imes New Roman";">щâ•=95 ; font-family: Courier;"> y: "Times New Roman";">╝вУÐ=B6 yle=3D"font-size: 10pt; font-family: Courier;">E size: 10pt; font-family: "Times New Roman";">Ф tyle=3D"font-size: 10pt; font-family: Courier;">,".` =3D"font-size: 10pt; font-family: "Times New Roman";">н=E2=
•žÐ³
\=
uot;;">║нÐ=BC ily: Courier;">a E'Y "Times New Roman";">ЇоЫ╚▐<=
span style=3D"font-size: 10pt; font-family: Courier;">






..Z
";">х "> n";">А ;">: an";">э r;">l. oman";">Лâ–=90 ily: Courier;">{ imes New Roman";">│┘юн font-size: 10pt; font-family: Courier;">` 0pt; font-family: "Times New Roman";">у "font-size: 10pt; font-family: Courier;">R 10pt; font-family: "Times New Roman";">Э =3D"font-size: 10pt; font-family: Courier;"> e: 10pt; font-family: "Times New Roman";">─Ð<=
span style=3D"font-size: 10pt; font-family: Courier;"> °K style=3D"font-size: 10pt; font-family: "Times New Roman";">â•=
=A9
t pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
╠йÑ=88 urier;">$hH New Roman";">│╖â•=91 ze: 10pt; font-family: Courier;">  - "font-size: 10pt; font-family: "Times New Roman";">дâ•=
šÐ=AA
,i span> t;;">╔Ð=A2 rier;">v Roman";">Э urier;"> ¤ mes New Roman";">â•=A1 family: Courier;">"H y: "Times New Roman";">пч e: 10pt; font-family: Courier;">¤ ; font-family: "Times New Roman";">Ў nt-size: 10pt; font-family: Courier;">№° L =3D"font-size: 10pt; font-family: "Times New Roman";">â•=96 span>W0 style=3D"font-size: 10pt; font-family: "Times New Roman";">Н=
sc n style=3D"font-size: 10pt; font-family: "Times New Roman";">=E2=
”´
u R% span> t;;">ъ4<=
/span> ot;;">â•=AA ">Yf an";">â”=9C rier;">5 Roman";">╬╟ЮТ e: 10pt; font-family: Courier;">,(+y font-family: "Times New Roman";">є -size: 10pt; font-family: Courier;">: font-family: "Times New Roman";">ЎГ =3D"font-size: 10pt; font-family: Courier;"> e: 10pt; font-family: "Times New Roman";">ь e=3D"font-size: 10pt; font-family: Courier;">% ze: 10pt; font-family: "Times New Roman";">│░=D1=
=89
]wR%1 n> ">ё┬Ð=95 Courier;">.r New Roman";">â•=9E ily: Courier;"> imes New Roman";">ыâ•=96 ; font-family: Courier;">  YRâˆ=99<}
uot;;">â–=88 ;"> an";">ю r;"> man";">О╕д╥ 10pt; font-family: Courier;">-q -family: "Times New Roman";">â•=96 size: 10pt; font-family: Courier;">_ font-family: "Times New Roman";">╩╬ tyle=3D"font-size: 10pt; font-family: Courier;">{2Y nt-size: 10pt; font-family: "Times New Roman";">хц=E2=
••â•=94
"> n";">┴┤щрБ ze: 10pt; font-family: Courier;">A+Q font-family: "Times New Roman";">╖▄▓Ð=
=A7
° an> ;">â–=90{=
uot;;">З╗чÐ=9F nt-family: Courier;">






 

w
quot;;">Ш >A ";">┼╣╓Ñ=8E 10pt; font-family: Courier;">4R family: "Times New Roman";">ў : 10pt; font-family: Courier;">s -family: "Times New Roman";">â•=A0 size: 10pt; font-family: Courier;">F font-family: "Times New Roman";">з╠╣<=
span style=3D"font-size: 10pt; font-family: Courier;">{
=3D"font-size: 10pt; font-family: "Times New Roman";">â•=99 span> k style=3D"font-size: 10pt; font-family: "Times New Roman";">â•=
”йч░
Courier;">8 New Roman";">╛▄ font-family: Courier;"> : "Times New Roman";">■╢ЫБâ”=9C an># le=3D"font-size: 10pt; font-family: "Times New Roman";">Е=D0=
½Ð‘Ñ=8F
">â„=96~ o es New Roman";">╗╣ЫФа =3D"font-size: 10pt; font-family: Courier;"> &28






^
quot;;">â•=AB r;">@O} Roman";">у rier;">: Roman";">â•=A8 Courier;">f -A mes New Roman";">пеЪ pt; font-family: Courier;">      an> ;">ЦМ "> n";">Юâ”=98 : Courier;">k s New Roman";">â•=9A mily: Courier;"> Times New Roman";">пЎâ–=84 e: 10pt; font-family: Courier;">{ t-family: "Times New Roman";">щ ze: 10pt; font-family: Courier;">· t; font-family: "Times New Roman";">â•=9C =3D"font-size: 10pt; font-family: Courier;">/ e: 10pt; font-family: "Times New Roman";">â•=96 tyle=3D"font-size: 10pt; font-family: Courier;">U -size: 10pt; font-family: "Times New Roman";">їЫ=
q$a e=3D"font-size: 10pt; font-family: "Times New Roman";">й=D0=
ºâ•”
x=
uot;;">Єъь : Courier;">| s New Roman";">â•=90 mily: Courier;"> 5  1 t; font-family: "Times New Roman";">â–=84 =3D"font-size: 10pt; font-family: Courier;"> e: 10pt; font-family: "Times New Roman";">И e=3D"font-size: 10pt; font-family: Courier;"> ze: 10pt; font-family: "Times New Roman";">Яєц=D1=
=86
|=C2=
=A0
New Roman";">â”=80 ly: Courier;">w mes New Roman";">â–=84 family: Courier;">o t;Times New Roman";">я -family: Courier;"> 4 uot;Times New Roman";">ун pt; font-family: Courier;">c ily: "Menlo Regular";">ï¿=BD 10pt; font-family: "Times New Roman";">â•=9F e=3D"font-size: 10pt; font-family: Courier;">? ze: 10pt; font-family: "Times New Roman";">â•=9E style=3D"font-size: 10pt; font-family: Courier;">dLM# font-size: 10pt; font-family: "Times New Roman";">г pan style=3D"font-size: 10pt; font-family: Courier;">x
"font-size: 10pt; font-family: "Times New Roman";">â•=96 n>l e=3D"font-size: 10pt; font-family: "Times New Roman";">â”=90=
â”=90
J
pan> ;;">╖┐а ily: Courier;">J imes New Roman";">Ы mily: Courier;">a






uot;;">â•=99 ;">v* man";">чї Courier;">8x~v mes New Roman";">ётэ pt; font-family: Courier;">ow+v family: "Times New Roman";">â•=A8 ize: 10pt; font-family: Courier;">\ font-family: "Times New Roman";">П -size: 10pt; font-family: Courier;"> font-family: "Times New Roman";">â•=A5 font-size: 10pt; font-family: Courier;">dJ!  style=3D"font-size: 10pt; font-family: "Times New Roman";">=E2=
”‚·<=
/span> ot;;">â•=A0 ">_, an";">Ъ╫Шъа : 10pt; font-family: Courier;"> -family: "Times New Roman";">â•=9A size: 10pt; font-family: Courier;">K font-family: "Times New Roman";">рФ =3D"font-size: 10pt; font-family: Courier;"> e: 10pt; font-family: "Times New Roman";">Г e=3D"font-size: 10pt; font-family: Courier;"> ze: 10pt; font-family: "Times New Roman";">ь le=3D"font-size: 10pt; font-family: Courier;">* ize: 10pt; font-family: "Times New Roman";">ъ yle=3D"font-size: 10pt; font-family: Courier;">Y size: 10pt; font-family: "Times New Roman";">╤╢ span> r style=3D"font-size: 10pt; font-family: "Times New Roman";">â”=
¼Ð=BC
1 pan> ;;">С4 span> t;;">Н8&=
lt;
n";">â•=97 ier;">ka Roman";">Ёâ–=88 amily: Courier;">C ;Times New Roman";">ЄїЧП═╫г span>G tyle=3D"font-size: 10pt; font-family: "Times New Roman";">ц=
ы╤▌
Courier;">∙Â=B7"O nt-family: "Times New Roman";">Чâ•=A4 =3D"font-size: 10pt; font-family: Courier;"> e: 10pt; font-family: "Times New Roman";">│Ñ=97<=
span style=3D"font-size: 10pt; font-family: Courier;"> R_âˆ=9AY
<=
span style=3D"font-size: 10pt; font-family: "Times New Roman";">=
Р
.&
| 
uot;Times New Roman";">Пж pt; font-family: Courier;">tX mily: "Times New Roman";">О 10pt; font-family: Courier;">H° font-family: "Times New Roman";">┤╤ tyle=3D"font-size: 10pt; font-family: Courier;">¤ "font-size: 10pt; font-family: "Times New Roman";">ЖН=
А
D
> >▄┘Й : Courier;"> s New Roman";">юâ•=95 ont-family: Courier;">r ¤






 

KV$
n";">Ч ;">      ize: 10pt; font-family: "Times New Roman";">╙ШÐ=BB=
W style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
=9D'8z pan> ;;">▒Р█ ily: Courier;"> imes New Roman";">Ж mily: Courier;">k Times New Roman";">â•=9B t-family: Courier;">YEx "Times New Roman";">├Ñ=85 e: 10pt; font-family: Courier;">upDBR font-family: "Times New Roman";">гИ =3D"font-size: 10pt; font-family: Courier;">4 e: 10pt; font-family: "Times New Roman";">г e=3D"font-size: 10pt; font-family: Courier;">I ze: 10pt; font-family: "Times New Roman";">мє an style=3D"font-size: 10pt; font-family: Courier;">42p$ =3D"font-size: 10pt; font-family: "Times New Roman";">â•=A2=
У
> >ЭГ=
quot;;">ї >¤f Roman";">â•=A6 Courier;"> >
uot;;">Ж=
?> 
Roman";">ы rier;">'ci mes New Roman";">вâ•=AB font-family: Courier;">i : "Menlo Regular";">ï¿=BD t; font-family: "Times New Roman";">ЙйМ n style=3D"font-size: 10pt; font-family: Courier;">a ont-size: 10pt; font-family: "Times New Roman";">щ an style=3D"font-size: 10pt; font-family: Courier;"> ~ "font-size: 10pt; font-family: "Times New Roman";">Ж<=
span style=3D"font-size: 10pt; font-family: Courier;">V =3D"font-size: 10pt; font-family: "Times New Roman";">Т
n>M e=3D"font-size: 10pt; font-family: "Times New Roman";">Ё an>0 le=3D"font-size: 10pt; font-family: "Times New Roman";">â•=A9=
╟╥â”=98
ly: Courier;"> ** Times New Roman";">є amily: Courier;">A ;Times New Roman";">â•=9E nt-family: Courier;"> quot;Times New Roman";">Уâ–=91 : 10pt; font-family: Courier;"> #mgDS. ; font-family: "Times New Roman";">ц nt-size: 10pt; font-family: Courier;">âˆ=9A v -size: 10pt; font-family: "Times New Roman";">о style=3D"font-size: 10pt; font-family: Courier;"> 2 nt-size: 10pt; font-family: "Times New Roman";">бз n>X" n style=3D"font-size: 10pt; font-family: "Times New Roman";">=D0=
¬â•¥Ð“а
Courier;">N + es New Roman";">бЇ t-family: Courier;">>âˆ=99 t-family: "Times New Roman";">бч ont-size: 10pt; font-family: Courier;">~ 0pt; font-family: "Times New Roman";">И "font-size: 10pt; font-family: Courier;">; 10pt; font-family: "Times New Roman";">ў =3D"font-size: 10pt; font-family: Courier;">L  O pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
ь
> pan> ;;">Сp span> t;;">╚етÐ=90 -family: Courier;">8< "Times New Roman";">мГьУâ–=A0 n style=3D"font-size: 10pt; font-family: Courier;"> ont-size: 10pt; font-family: "Times New Roman";">â•=97=
=3D"font-size: 10pt; font-family: "Times New Roman";">М=D1=
=8F
n pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
ё
|< span> t;;">╨Ð=B4 rier;">_ Roman";">Уâ–=88 amily: Courier;">w? t;Times New Roman";">╧Ñ=8C 0pt; font-family: Courier;">:Y
âˆ=99l-
New Roman";">Л Courier;"> New Roman";">и : Courier;">SF es New Roman";">╡Ð=A8 font-family: Courier;">
fa,VW
man";">эД Courier;">ZW s New Roman";">А y: Courier;">¤ t;Times New Roman";">ЬГ ; font-family: Courier;">. y: "Times New Roman";">эЬ e: 10pt; font-family: Courier;">°] t; font-family: "Times New Roman";">Ð¥ ont-size: 10pt; font-family: Courier;"> pt; font-family: "Times New Roman";">▄щсÐ=9C=
â”=9C







 

uot;;">биâ•=9D ily: Courier;">9 imes New Roman";">сй ont-family: Courier;">+ "Times New Roman";">╠t; font-family: Courier;">B 
A&
es New Roman";">â•=94 amily: Courier;">- ;Times New Roman";">Ч family: Courier;">n t;Times New Roman";">д -family: Courier;">UX uot;Times New Roman";">â–=92 font-family: Courier;">uu ly: "Times New Roman";">в pt; font-family: Courier;">F mily: "Times New Roman";">В 10pt; font-family: Courier;"> )Od t-family: "Times New Roman";">ф ze: 10pt; font-family: Courier;">






oman";">с ier;"> b6 w Roman";">Щ ourier;"> ew Roman";">Ð¥ Courier;">kBy s New Roman";">КП -family: Courier;">V! uot;Times New Roman";">╔Ð=A4 10pt; font-family: Courier;">' ont-family: "Times New Roman";">â•=A0 nt-size: 10pt; font-family: Courier;">!D pt; font-family: "Times New Roman";">â–=91 =3D"font-size: 10pt; font-family: Courier;">U e: 10pt; font-family: "Times New Roman";">С e=3D"font-size: 10pt; font-family: Courier;">LA size: 10pt; font-family: "Times New Roman";">─Ð=A5 n>/% le=3D"font-size: 10pt; font-family: "Times New Roman";">А=D1=
—Ñ=87
(d span> t;;">╠║Л mily: Courier;">x6 ;Times New Roman";">щ family: Courier;">; t;Times New Roman";">ЭЧк : 10pt; font-family: Courier;">H -family: "Times New Roman";">й e: 10pt; font-family: Courier;"> s nt-family: "Times New Roman";">â•=A3 t-size: 10pt; font-family: Courier;">Ozn pt; font-family: "Times New Roman";">Жâ”=9C style=3D"font-size: 10pt; font-family: Courier;">H t-size: 10pt; font-family: "Times New Roman";">УЁш=
style=3D"font-size: 10pt; font-family: "Times New Roman";">=E2=
•ªâ”=A4
">L S man";">АД Courier;">(      =3D"font-size: 10pt; font-family: "Times New Roman";">м=D0=
=BC
& n> ">â•=97Z3=
NvJ
n";">â•=A3 ier;">p Roman";">ш urier;">h w Roman";">â•=96 : Courier;">w s New Roman";">┠mily: Courier;">] ;Times New Roman";">â•=A6







 
t;Times New Roman";">С▌┴ t-size: 10pt; font-family: Courier;">â„=96 ze: 10pt; font-family: "Times New Roman";">â”=90 style=3D"font-size: 10pt; font-family: Courier;"> i =3D"font-size: 10pt; font-family: "Times New Roman";">я=D1=
Ð=90
m 4<=
/span> ot;;">â”=80 ">7 n";">ш ;">b an";">е r;">zq oman";">â•=91 ourier;">h ew Roman";">КФЕ┤╜ font-size: 10pt; font-family: Courier;">N& ze: 10pt; font-family: "Times New Roman";">â”=94 style=3D"font-size: 10pt; font-family: Courier;">-






 *X;T
"Times New Roman";">уМС size: 10pt; font-family: Courier;">D font-family: "Times New Roman";">э -size: 10pt; font-family: Courier;">{. ; font-family: "Times New Roman";">â•=A3 "font-size: 10pt; font-family: Courier;">X 10pt; font-family: "Times New Roman";">╟жÐ=9A n>Y e=3D"font-size: 10pt; font-family: "Times New Roman";">â•=93=
р
nbgl span> t;;">╦═ Courier;">E New Roman";">â”=82 ly: Courier;">$S Times New Roman";">У═ЗÑ=80 nt-size: 10pt; font-family: Courier;"> q    =C2=
=A0
K#
s New Roman";">К y: Courier;">3F mes New Roman";">б ily: Courier;">: imes New Roman";">â•=9A -family: Courier;">·1  ze: 10pt; font-family: "Times New Roman";">З le=3D"font-size: 10pt; font-family: Courier;"> ize: 10pt; font-family: "Times New Roman";">ё yle=3D"font-size: 10pt; font-family: Courier;">q size: 10pt; font-family: "Times New Roman";">о tyle=3D"font-size: 10pt; font-family: Courier;">] -size: 10pt; font-family: "Times New Roman";">Пâ–=88 an>r le=3D"font-size: 10pt; font-family: "Times New Roman";">А pan> n: style=3D"font-size: 10pt; font-family: "Times New Roman";">â–=
€Ðâ•¨
er;"> oman";">Ы╔Ð=95 nt-family: Courier;">; quot;Times New Roman";">Л ont-family: Courier;">z "Times New Roman";">â•=A6 t; font-family: Courier;">0 ly: "Times New Roman";">╕╩ ont-size: 10pt; font-family: Courier;">5 pt; font-family: "Times New Roman";">С╤Дâ=95=
=A4
R pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
â•=9C
n>     
pt; font-family: "Times New Roman";">Ы font-size: 10pt; font-family: Courier;">r








uot;;">┐Ð=AF ourier;">yy4 New Roman";">â”=82 ily: Courier;"> imes New Roman";">┠-family: Courier;">> "Times New Roman";">╚ЁÐ=9D nt-size: 10pt; font-family: Courier;">) t; font-family: "Times New Roman";">â•=9F =3D"font-size: 10pt; font-family: Courier;">{ e: 10pt; font-family: "Times New Roman";">ЕЩ n style=3D"font-size: 10pt; font-family: Courier;">(
ont-size: 10pt; font-family: "Times New Roman";">х an style=3D"font-size: 10pt; font-family: Courier;">4
font-size: 10pt; font-family: "Times New Roman";">ԃ=95=
=A8
=C2=
 Â=A0
Times New Roman";">х amily: Courier;"> ;Times New Roman";">â–=A0 nt-family: Courier;"> quot;Times New Roman";">У ont-family: Courier;"> | "Times New Roman";">Ї font-family: Courier;">Y8°y t-family: "Times New Roman";">â•=96 -size: 10pt; font-family: Courier;">z font-family: "Times New Roman";">Їâ”=80 le=3D"font-size: 10pt; font-family: Courier;">@$D sâ„=96 yle=3D"font-size: 10pt; font-family: "Times New Roman";">â–=
’Ð=B9
b pan> ;;">▒Ð=B6 ier;">1 Roman";">Гпс│╦А =3D"font-size: 10pt; font-family: Courier;">Pq_âˆ=99 =3D"font-size: 10pt; font-family: "Times New Roman";">У=D0=
=BD
8q =
=
â•=92
j span> t;;">╒╢ Courier;">B New Roman";">â•=91 ly: Courier;">  nt-family: "Times New Roman";">╡Ñ=8C =3D"font-size: 10pt; font-family: Courier;">< -size: 10pt; font-family: "Times New Roman";">╪Ñ=8D an>* le=3D"font-size: 10pt; font-family: "Times New Roman";">Ы=D0=
“Ð=91
e span> t;;">ЕkT=
|
quot;;">└Ñ=8D Courier;"> - New Roman";">Ў : "Menlo Regular";">ï¿=BD t; font-family: "Times New Roman";">â”=B4 =3D"font-size: 10pt; font-family: Courier;">Z ze: 10pt; font-family: "Times New Roman";">╝╫=E2=
• â–=84
">=3D 4 Roman";">â•=90 Courier;">Q New Roman";">├╛ font-family: Courier;">@ "Times New Roman";">Ёâ•=98 ze: 10pt; font-family: Courier;"> nt-family: "Times New Roman";">└Ð=AE =3D"font-size: 10pt; font-family: Courier;">" t-size: 10pt; font-family: "Times New Roman";">ЛНâ”=
=BC
Lx<=
span style=3D"font-size: 10pt; font-family: "Times New Roman";">=
Ц
A > >╪е╞н family: Courier;"> t;Times New Roman";">цмВ : 10pt; font-family: Courier;">Y t-family: "Times New Roman";">ё ze: 10pt; font-family: Courier;">J nt-family: "Times New Roman";">ф╢ЪЇâ=95=
=93
pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
▒╥сâ•=9B
t-family: Courier;">° y: "Times New Roman";">мщЄц╥╗=
>nG~CH(d&q=
uot;
an";">╒Ð=93 y: Courier;">c es New Roman";">ЛРе t; font-family: Courier;">¤â„=96a  style=3D"font-size: 10pt; font-family: "Times New Roman";">â–=
“▐
<=
span> 
69
uot;Times New Roman";">â•=96 font-family: Courier;">   -family: "Times New Roman";">А e: 10pt; font-family: Courier;">oX;w font-family: "Times New Roman";">ц -size: 10pt; font-family: Courier;"> font-family: "Times New Roman";">ы t-size: 10pt; font-family: Courier;">l ; font-family: "Times New Roman";">эâ•=A1 yle=3D"font-size: 10pt; font-family: Courier;">s  
Y
Roman";">И urier;">L w Roman";">Ш ourier;">@  
Roman";">â•=97 Courier;"> âˆ=9AC Z ily: "Times New Roman";">ь 0pt; font-family: Courier;"> mily: "Times New Roman";">р 10pt; font-family: Courier;">"° 0pt; font-family: "Times New Roman";">ЄБ yle=3D"font-size: 10pt; font-family: Courier;">Pc -size: 10pt; font-family: "Times New Roman";">Ч style=3D"font-size: 10pt; font-family: Courier;">a)g ont-size: 10pt; font-family: "Times New Roman";">У an style=3D"font-size: 10pt; font-family: Courier;">e
font-size: 10pt; font-family: "Times New Roman";">хд pan>4NH style=3D"font-size: 10pt; font-family: "Times New Roman";">â”=
=90
=C2=
=A0
/
New Roman";">â•=90 ily: Courier;">!c Times New Roman";">СДеРâ”=A4 =3D"font-size: 10pt; font-family: Courier;"> e: 10pt; font-family: "Times New Roman";">й╔Ð=B3=
Ф
C > >ъ .9+ span> t;;">єЫ┐╪ ont-family: Courier;">      pan style=3D"font-size: 10pt; font-family: "Times New Roman";">=
ф
5X an> ;">р
6<
man";">ч▒┼ font-family: "Menlo Regular";">ï¿=BD t-size: 10pt; font-family: "Times New Roman";">Ъ style=3D"font-size: 10pt; font-family: Courier;">$
nt-size: 10pt; font-family: "Times New Roman";">Х=82=
╥▒ИСЄâ•=A5
e: 10pt; font-family: Courier;"> â„=96u 10pt; font-family: "Times New Roman";">â•=9E le=3D"font-size: 10pt; font-family: Courier;">a ize: 10pt; font-family: "Times New Roman";">М yle=3D"font-size: 10pt; font-family: Courier;">t size: 10pt; font-family: "Times New Roman";">ЄХ<=
span style=3D"font-size: 10pt; font-family: Courier;">^
=3D"font-size: 10pt; font-family: "Times New Roman";">Ё n>W?K yle=3D"font-size: 10pt; font-family: "Times New Roman";">ў=
â•=96
2 span> t;;">ймУрâ•=93 ; font-family: Courier;">4 y: "Times New Roman";">Р t; font-family: Courier;"> E







>==================

The address indicated in the begining of the page code leads to some chines=
e
server.

t; font-family: Times;">

tyle=3D"font-size: 10pt; font-family: Times;">
So, somehow it happened that the output of the apache server was substitute=
d by
this page, which redirected visitors to some chinese server.
tyle=3D"font-size: 10pt; font-family: Times;">It is the second
time I am posting to the mailing list, the first time the mailing list
virus scanner identified the content as having the Troj/Fujif-Gen
virus, thus, this time I removed active links from the message body so
it is not exactly what I received).


size: 10pt; font-family: Times;">


But the most strange thing was that the problem dissapeared itself! So, it =
last
for 10 minutes then disappeared! And the again started and again dissapeare=
d.
Finally, I turned down apache untill I understand what is going on...



Any idea how could that happen?  How to reproduce this? How to prevent=
?

Where to look for logs? I have check both ssh logs and apache logs, there i=
s
nothing that could seem unusual there...



Any help is appreciated.

Oleg.









--00151747be44ebd43b04836536c4--

Re: Someone hacked my apache2 server

am 04.04.2010 10:48:47 von Oleg Goryunov

--001517447f1e0ab90904836549b6
Content-Type: text/plain; charset=ISO-8859-1

Lester,
Yes, I assume it might be a third party problem, not my server problem, but
I need to be sure.
If it was not my local DNS hack, since at least two people from different
networks, from different cities (me and another person) observed the same
behavior. Another point is that the hacked page showed up irrespective of
the site name (I have three sites running on a dedicated server in US colo)
on all the sites that are on that server.
Could they have rerouted traffic somewhere closer to the datacenter? I
doubt...
Now, the site looks OK. But I think it can happen again.
Oleg.


On Sun, Apr 4, 2010 at 10:20 AM, Lester Caine wrote:

> Oleg Goryunov wrote:
>
>>
>> Any help is appreciated.
>>
>
> Oleg - Does YOUR copy of the index page look OK reading it as a file?
> What no one has mentioned is that DNC servers have been hacked and could be
> doing the re-routing. It may not be YOUR site which is compromised.
>
> I can view my own sites 'locally' without going through the internet, any
> chance you can check via that route?
>
> If the site itself looks OK, then check the config files for apache are
> still actually looking at that site, but I suspect that because you say it
> is intermittent it may well be outside you control. We have had a number of
> sites giving us a 'problem', but when accessed with the IP address of the
> machine direct then they are actually fine!
>
> --
> Lester Caine - G8HFL
> -----------------------------
> Contact - http://lsces.co.uk/wiki/?page=contact
> L.S.Caine Electronic Services - http://lsces.co.uk
> EnquirySolve - http://enquirysolve.com/
> Model Engineers Digital Workshop - http://medw.co.uk//
> Firebird - http://www.firebirdsql.org/index.php
>
>
> ------------------------------------------------------------ ---------
> The official User-To-User support forum of the Apache HTTP Server Project.
> See for more info.
> To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
> " from the digest: users-digest-unsubscribe@httpd.apache.org
> For additional commands, e-mail: users-help@httpd.apache.org
>
>

--001517447f1e0ab90904836549b6
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

Lester,
Yes, I assume it might be a third party problem, not my server p=
roblem, but I need to be sure.
If it was not my local DNS hack, since at=
least two people from different networks, from different cities (me and an=
other person) observed the same behavior. Another point is that the hacked =
page showed up irrespective of the site name (I have three sites running on=
a dedicated server in US colo) on all the sites that are on that server. r>

Could they have rerouted traffic somewhere closer to the datacenter? I doub=
t...
Now, the site looks OK. But I think it can happen again.
Oleg. r>

On Sun, Apr 4, 2010 at 10:20 AM, Leste=
r Caine <
lester@=
lsces.co.uk
> wrote:


204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
>Oleg Goryunov wrote:

204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">


Any help is appreciated.




Oleg - Does YOUR copy of the index page look OK reading it as a file?

What no one has mentioned is that DNC servers have been hacked and could be=
doing the re-routing. It may not be YOUR site which is compromised.



I can view my own sites 'locally' without going through the interne=
t, any chance you can check via that route?



If the site itself looks OK, then check the config files for apache are sti=
ll actually looking at that site, but I suspect that because you say it is =
intermittent it may well be outside you control. We have had a number of si=
tes giving us a 'problem', but when accessed with the IP address of=
the machine direct then they are actually fine!





--

Lester Caine - G8HFL

-----------------------------

Contact - ank">http://lsces.co.uk/wiki/?page=3Dcontact

L.S.Caine Electronic Services - lank">http://lsces.co.uk

EnquirySolve - http:=
//enquirysolve.com/


Model Engineers Digital Workshop - =3D"_blank">http://medw.co.uk//

Firebird - k">http://www.firebirdsql.org/index.php
s=3D"h5">



------------------------------------------------------------ ---------

The official User-To-User support forum of the Apache HTTP Server Project.<=
br>
See <URL: lank">http://httpd.apache.org/userslist.html> for more info.

To unsubscribe, e-mail: g" target=3D"_blank">users-unsubscribe@httpd.apache.org

=A0" =A0 from the digest: httpd.apache.org" target=3D"_blank">users-digest-unsubscribe@httpd.apache.o=
rg


For additional commands, e-mail: org" target=3D"_blank">users-help@httpd.apache.org






--001517447f1e0ab90904836549b6--

Re: Someone hacked my apache2 server

am 04.04.2010 11:41:29 von Oleg Goryunov

--000325554072818112048366056a
Content-Type: text/plain; charset=ISO-8859-1

A good explanation I received from a datacenter where I have the server:

"we classify this sort of issue as "Stealing the gateway". basically
what someone does is they send out false arp packets(flooding the entire
network segment) causing all servers and switching to think their server is
the
gateway instead of our router. they can then insert their own frame inside
of
all web traffic. this sort of issue is usually resolved within a few minutes
when we terminate the server. most likely this is what happened and explains
why the issue started and then suddenly went away without any evidence on
your
server of being hacked."
Unfortunately, they said they did not have a database of registered events
of this kind. :(
Oleg.

On Sun, Apr 4, 2010 at 12:48 PM, Oleg Goryunov wrote:

> Lester,
> Yes, I assume it might be a third party problem, not my server problem, but
> I need to be sure.
> If it was not my local DNS hack, since at least two people from different
> networks, from different cities (me and another person) observed the same
> behavior. Another point is that the hacked page showed up irrespective of
> the site name (I have three sites running on a dedicated server in US colo)
> on all the sites that are on that server.
> Could they have rerouted traffic somewhere closer to the datacenter? I
> doubt...
> Now, the site looks OK. But I think it can happen again.
> Oleg.
>
>
>
> On Sun, Apr 4, 2010 at 10:20 AM, Lester Caine wrote:
>
>> Oleg Goryunov wrote:
>>
>>>
>>> Any help is appreciated.
>>>
>>
>> Oleg - Does YOUR copy of the index page look OK reading it as a file?
>> What no one has mentioned is that DNC servers have been hacked and could
>> be doing the re-routing. It may not be YOUR site which is compromised.
>>
>> I can view my own sites 'locally' without going through the internet, any
>> chance you can check via that route?
>>
>> If the site itself looks OK, then check the config files for apache are
>> still actually looking at that site, but I suspect that because you say it
>> is intermittent it may well be outside you control. We have had a number of
>> sites giving us a 'problem', but when accessed with the IP address of the
>> machine direct then they are actually fine!
>>
>> --
>> Lester Caine - G8HFL
>> -----------------------------
>> Contact - http://lsces.co.uk/wiki/?page=contact
>> L.S.Caine Electronic Services - http://lsces.co.uk
>> EnquirySolve - http://enquirysolve.com/
>> Model Engineers Digital Workshop - http://medw.co.uk//
>> Firebird - http://www.firebirdsql.org/index.php
>>
>>
>> ------------------------------------------------------------ ---------
>> The official User-To-User support forum of the Apache HTTP Server Project.
>> See for more info.
>> To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
>> " from the digest: users-digest-unsubscribe@httpd.apache.org
>> For additional commands, e-mail: users-help@httpd.apache.org
>>
>>
>

--000325554072818112048366056a
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable

A good explanation I received from a datacenter where I have the server: >
"we classify this sort of issue as "Stealing the gateway&quo=
t;. basically

what someone does is they send out false arp packets(flooding the entire >
network segment) causing all servers and switching to think their server is=
the

gateway instead of our router. they can then insert their own frame inside =
of

all web traffic. this sort of issue is usually resolved within a few minute=
s

when we terminate the server. most likely this is what happened and explain=
s

why the issue started and then suddenly went away without any evidence on y=
our

server of being hacked."
Unfortunately, they said they did not have=
a database of registered events of this kind. :(
Oleg.

s=3D"gmail_quote">On Sun, Apr 4, 2010 at 12:48 PM, Oleg Goryunov =3D"ltr"><oleg.goryunov@gmail=
..com
>
wrote:


204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">Lester,
Yes, I=
assume it might be a third party problem, not my server problem, but I nee=
d to be sure.


If it was not my local DNS hack, since at least two people from different n=
etworks, from different cities (me and another person) observed the same be=
havior. Another point is that the hacked page showed up irrespective of the=
site name (I have three sites running on a dedicated server in US colo) on=
all the sites that are on that server.



Could they have rerouted traffic somewhere closer to the datacenter? I doub=
t...
Now, the site looks OK. But I think it can happen again.
olor=3D"#888888">Oleg.





On Sun, Apr 4, 2010 at 10:20 AM, Lester Caine pan dir=3D"ltr">< >lester@lsces.co.uk> wrote:

204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">
Oleg Goryuno=
v wrote:

204, 204); margin: 0pt 0pt 0pt 0.8ex; padding-left: 1ex;">


Any help is appreciated.




Oleg - Does YOUR copy of the index page look OK reading it as a file?

What no one has mentioned is that DNC servers have been hacked and could be=
doing the re-routing. It may not be YOUR site which is compromised.



I can view my own sites 'locally' without going through the interne=
t, any chance you can check via that route?



If the site itself looks OK, then check the config files for apache are sti=
ll actually looking at that site, but I suspect that because you say it is =
intermittent it may well be outside you control. We have had a number of si=
tes giving us a 'problem', but when accessed with the IP address of=
the machine direct then they are actually fine!






--

Lester Caine - G8HFL

-----------------------------

Contact - ank">http://lsces.co.uk/wiki/?page=3Dcontact

L.S.Caine Electronic Services - lank">http://lsces.co.uk

EnquirySolve - http:=
//enquirysolve.com/


Model Engineers Digital Workshop - =3D"_blank">http://medw.co.uk//

Firebird - k">http://www.firebirdsql.org/index.php




------------------------------------------------------------ ---------

The official User-To-User support forum of the Apache HTTP Server Project.<=
br>
See <URL: lank">http://httpd.apache.org/userslist.html> for more info.

To unsubscribe, e-mail: g" target=3D"_blank">users-unsubscribe@httpd.apache.org

=A0" =A0 from the digest: httpd.apache.org" target=3D"_blank">users-digest-unsubscribe@httpd.apache.o=
rg


For additional commands, e-mail: org" target=3D"_blank">users-help@httpd.apache.org








--000325554072818112048366056a--

Re: Someone hacked my apache2 server

am 04.04.2010 12:17:35 von Lester Caine

Oleg Goryunov wrote:
> A good explanation I received from a datacenter where I have the server:
>
> "we classify this sort of issue as "Stealing the gateway". basically
> what someone does is they send out false arp packets(flooding the entire
> network segment) causing all servers and switching to think their server
> is the
> gateway instead of our router. they can then insert their own frame
> inside of
> all web traffic. this sort of issue is usually resolved within a few minutes
> when we terminate the server. most likely this is what happened and explains
> why the issue started and then suddenly went away without any evidence
> on your
> server of being hacked."
> Unfortunately, they said they did not have a database of registered
> events of this kind. :(

The problem is detecting the problem TO log it. Often it's outside the actual
data centre. Firebird had it's website being redirected, but only on a couple of
DNS servers, everybody else saw the correct IP address. Your description of 'all
sites' simply confirms that your users are getting the wrong DNS lookup, rather
than YOUR site having been compromised.

--
Lester Caine - G8HFL
-----------------------------
Contact - http://lsces.co.uk/wiki/?page=contact
L.S.Caine Electronic Services - http://lsces.co.uk
EnquirySolve - http://enquirysolve.com/
Model Engineers Digital Workshop - http://medw.co.uk//
Firebird - http://www.firebirdsql.org/index.php

------------------------------------------------------------ ---------
The official User-To-User support forum of the Apache HTTP Server Project.
See for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
" from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org

Re: Someone hacked my apache2 server

am 04.04.2010 18:10:16 von Morgan Gangwere

On 4/4/2010 4:17 AM, Lester Caine wrote:
[a bunch of CHARs]

Looking that the logs that were posted, there's nothing out of the
ordinary, just people hammering a server for attempts in.

This is more and more looking like a DNS attack.
--

Morgan Gangwere

>> Why?
> Because it breaks the logical flow of conversation, plus makes
messages unreadable.
>>> Top-Posting is evil.

------------------------------------------------------------ ---------
The official User-To-User support forum of the Apache HTTP Server Project.
See for more info.
To unsubscribe, e-mail: users-unsubscribe@httpd.apache.org
" from the digest: users-digest-unsubscribe@httpd.apache.org
For additional commands, e-mail: users-help@httpd.apache.org