diff --git a/Introduccion-hacking-hack4u/tema_6_owasp/README.md b/Introduccion-hacking-hack4u/tema_6_owasp/README.md index a1b1907..f04266b 100644 --- a/Introduccion-hacking-hack4u/tema_6_owasp/README.md +++ b/Introduccion-hacking-hack4u/tema_6_owasp/README.md @@ -6,7 +6,7 @@ Al ser este tema muy extenso, se ha divido en 9 READMEs. A continuaci贸n, se ref - [TEMA 6 - OWASP TOP 10 y vulnerabilidades web](#tema-6---owasp-top-10-y-vulnerabilidades-web) - [README1.md](./README1.md) - [6.1 SQL Injection (SQLi)](./README1.md#61-sql-injection-sqli) - - [Ejercicios](./README1.md#ejercicios) + - [6.1.1 Ejercicio](./README1.md#611-ejercicio) - [6.2 CrossSite Scripting (XSS)](./README1.md#62-crosssite-scripting-xss) - [6.3 XML External Entity Injection (XXE)](./README1.md#63-xml-external-entity-injection-xxe) - [6.4 Local File Inclusion (LFI)](./README1.md#64-local-file-inclusion-lfi) @@ -23,11 +23,12 @@ Al ser este tema muy extenso, se ha divido en 9 READMEs. A continuaci贸n, se ref - [README4.md](./README4.md) - [6.13 Inyecciones NoSQL](./README4.md#613-inyecciones-nosql) - [6.14 Inyecciones LDAP](./README4.md#614-inyecciones-ldap) - - [Ejercicio](./README4.md#ejercicio) + - [6.14.1 Ejercicio](./README4.md#6141-ejercicio) - [6.15 Ataques de Deserializaci贸n](./README4.md#615-ataques-de-deserializaci贸n) - [6.16 Inyecciones LaTex](./README4.md#616-inyecciones-latex) - [README5.md](./README5.md) - [6.17 Abuso de APIs](./README5.md#617-abuso-de-apis) + - [6.17.1 Ejercicio](./README5.md#6171-ejercicio) - [6.18 Abuso de subidas de archivos](./README5.md#618-abuso-de-subidas-de-archivos) - [6.19 Prototype Pollution](./README5.md#619-prototype-pollution) - [6.20 Ataques de transferencia de zona (AXFR - Full Zone Transfer)](./README5.md#620-ataques-de-transferencia-de-zona-axfr---full-zone-transfer) diff --git a/Introduccion-hacking-hack4u/tema_6_owasp/README.pdf b/Introduccion-hacking-hack4u/tema_6_owasp/README.pdf new file mode 100644 index 0000000..ece145e --- /dev/null +++ b/Introduccion-hacking-hack4u/tema_6_owasp/README.pdf @@ -0,0 +1,853 @@ +%PDF-1.4 +%与獒 +1 0 obj +<> +endobj +3 0 obj +<> +endobj +6 0 obj +<> +endobj +7 0 obj +<>>> +endobj +8 0 obj +<>>> +endobj +9 0 obj +<>>> +endobj +10 0 obj +<>>> +endobj +11 0 obj +<>>> +endobj +12 0 obj +<>>> +endobj +13 0 obj +<>>> +endobj +14 0 obj +<>>> +endobj +15 0 obj +<>>> +endobj +16 0 obj +<>>> +endobj +17 0 obj +<>>> +endobj +18 0 obj +<>>> +endobj +19 0 obj +<>>> +endobj +20 0 obj +<>>> +endobj +21 0 obj +<>>> +endobj +22 0 obj +<>>> +endobj +23 0 obj +<>>> +endobj +24 0 obj +<>>> +endobj +25 0 obj +<>>> +endobj +26 0 obj +<>>> +endobj +27 0 obj +<>>> +endobj +28 0 obj +<>>> +endobj +29 0 obj +<>>> +endobj +30 0 obj +<>>> +endobj +31 0 obj +<>>> +endobj +32 0 obj +<>>> +endobj +33 0 obj +<>>> +endobj +34 0 obj +<>>> +endobj +35 0 obj +<>>> +endobj +36 0 obj +<>>> +endobj +37 0 obj +<>>> +endobj +38 0 obj +<>>> +endobj +39 0 obj +<>>> +endobj +40 0 obj +<>>> +endobj +41 0 obj +<>>> +endobj +42 0 obj +<>>> +endobj +43 0 obj +<>>> +endobj +44 0 obj +<> +endobj +45 0 obj +<> stream +x滍]蹘$ }煰桤)雫籯窍I$q`亹扟烷RU团戊p7%Q$ERG梈攷檫M肋5笵c庚燄2A艽聆?燓龌n猷>仔儌騿?o咀7甄>IV鰿黫?蹰?橻紏*J蕸鰦R贈曳?=鼳mx'峡F >|%h伅C蔇袝`s慩 &W孾%'溗憇〨骆~$垇ul妼驊煘韸 +@纟儢蹚踁↑偒N E鄱霃 ??I蘉ⅳ婾.4 Z謽? 7﹤ ;F嬏?I=vB/0n5猬W4(!`崠Ob蛮Εb词,:)5{梐蔽疐俸sZ5s梣m腉哇E蕫Y4圕丘竸为Vr掩 呲匈軘]瑎帹MGvB:╙%D'瑮鞩n\ + 繃*y佪嶙#B榣膭芕#E綱.栣z鏘W$z穇r 滂鼛"q鬚8裍杜架"lk撄)# 駕裈Ku(额毪0;Z1#丸o怅o嗜妺 +2:縌?(0 I偠c哕帪 ▏歭舸D嬗.鼏'巑儻妅茭祶#祑*緝覷曉 :Z+G瞅PW#^懂2rPtつ"揾}魚Yg柠<惗自橦哰V儶"5捳@ + *狏UM氲铻伷e筢臲榕獚题1鐯q%6倠鱡 *记4鋟 +銩wT%Wo"Z偦/+O\n绅D(I~チ嫏&鑫結賨^2蒚_B譹&A穤跦V乎宎隲!櫒#搸郀詈腁!k漬=:TSd +虄nm洱ye.埒楋f;毓宂鷃U藥*"鑌U&螙榦儠Ux/茅v5t蓢孮S甔E眒靤&裭鄡磬鞙 蘨gB-n迿饐这|wf!骎齖(e(誏鋌:.旙5q娼摟堭\z1漛 {;揬淥捸歧玝$*廗蹑揅.6柍僮&锠狲:8岙 東毨姖 lLd頁 d\U熆p%感'縸靑)烐:罱兾煞骼▔7茼'柎:囵淯7$櫒騉珓朒 苳k X裹 {銛S@).佹r)鍫+@3() ?媛娌H2埖茟唘Ca熩!X'蜹LT鋀/U翺2-釨嚵兜yc颜:捓~潠档+掂d Z L!瓲雰:j樤*+〥,囟F茿$gaJ當慤6рS?6,裋鷾~l辘垦R6u襱踣芩\迥`/m糛嶮辚旰f蚯\ +沥B*,*锱j2Y'M庾蕤歀譃申ErS~-H虅碄 B L,旚庁r冰*/2:坉8: 铆* ⺋;鹾鴲楷+g哜婪D/8-憷譫闘3Tb謿鎣X0憤Jr2炁箄PWXw緱bF[ez!餵wgnqr郒W6簐辨癡B遀芰*y珄i5咰斞3岺脯7LH~Od*6玎<.蜯C薼F&|萪樰帽 G荞簌悃jmV&蹇$9羦腕涳.弳)Ld!铳饆r闰姉舜鋿憜凞[硡='xS疸%鎱P"'抮h 'J墵!{l取悩 勳賋H礈* 9@7J叭詼)N +-%#X 槊┈錁邷虯罰綣敶OiGs5炇hI艝C滚絸K凶T鎺蔿' }塅_m围N缰*_B士+搗豫>棶"q㏄鷈滽曀N.q〔姫:\骥F真6吽戬狥r3哯癥 i仒W鍏榓骞Z+閇3*b鸘Xd4⿸酺瞑)糇g拞擦醻 揥龞洠< z;.萼2>鑁@>鞖亄拚ポG,m萀"& S<6飧f簧l鯾笖C璳0"⑦褑Z眠钌攴\糳3n糙璥`n}9v[|.y +2F2g{!)v:m攪4齑き :mc囧iR硫潌酈z +4黨;,#枃4ㄜE*e爉<ゆ<7潗Y膨2筞C+X蛦缎飓褚彀窦+韀5&刦齅Xm淧倍(*-蟠1蹄&炞儁跐両0Ep莂捓噻溇l4bC謚斥忟峤d麫4}H#*淒瑃8嶺M-極骇!捄偗@臇 +k'fX[C`杪Dvz鸃擅Y軛裵=<5$緀8<>M彣7膧Y-8<礝碥;%9"C彛箏顒飘-麥7y 6贺雘帿嶪J茜秵4晎朠В昝‘N"VFG>3瑉屉1=榩佚5羭穌銋>嗦 >郵鷢+鳢l徔流C覉!m嬁沘ば7$!*瀬o*柊C诎I[ #䱷h+l徔憞!昑d╧産H劘5+*挣粹WD""偒圶'鈯e槶蝜'胚寜洯tH77c而褾 i[ q偪! 1/G:&c嚳!VZRч穹L +V场-4鹙4;l<j钹oD旺肽贔斮鈕DQ県$靮沁窫黼7鉕鈕沁v軫饝Kx瞩O t榼;n 矅(/7蠗/H澵sHG盙Ob&;v肂(箸O︼鋂-K@尔2^ 继 湾^剖搙,涿讃欩-診*呻5皧赘Zb晰w亍3{趹获5牧B4撤楲睶 1d彻{湰IF珴yL黉Wvi2膵聍i溈棊絁姠{;.柘?;r椙b{蘳譣%斓P靰j麰k筝鴰敯j鈧'9靖榔C&开窾B吃p5焽蝕忂甿鄀>嬍f$<怒隺q>骡HB$柭}H勐庵m`q$!庳儿!e-#,494|I菳鑐q"硜棱涺O +綊ろ毃p.幞戮勭 +w将P2態厹壈*8輭德谼f'泃Hk穂Q6B酘C潭?VnmFw $伝広{H8RG$i#4末]噭#uD聛桇h{$<摣 薜蠰蕁憄麦jⅥN勑 臼獚 *6嗢'j奅'乸紂齷彳!庪乸N6祭y蓍觤忦 +|嗈B吓羪棱畟淾c功蟼醨L?V蝂摭r赎莺荜鎻N}X軳玞w_甞覭 "an理蚁0镌 肌逾鮈脬f傎 餢9譨_`69}も]&缜鯀汙统{啦w]5剧L+o仉へFl.zx~P箵w 9BNU|你擇樀+灍+8棰 +|$嵗 +褸墒u缞:蚡eV丶 +蚙憘蠧窟㏄卵缶H儦%賝$`凉XA*0+V  n7紤捖+鋋澱揓挈縦"劘(+鲂醮D" 偒癎' +e槶蝜'Y\i衖k恢d:屌E1b,H11 褾i[#船L補,欆lAK.绷X险Zc!B /F寘蕯對*黳GI県$拟阫哭+穆el證,^灉靭撦V禧圬嬺gO妃耄 琏&d>踦螼Qa洟zST >Θ砈ToONQ絳)牯1鴢款=,^谬3p灚凭娥粱7溡?9ヵΥ骩硅3瑈譾v逧w債 &7嚤娟贻Кqr-堛Ko霼7蠡?怢铛經3堥w豽or艿玶~纥U6予戢╥d翟0nO\k2 䱷抲09p褾戺嫌[*y9{迼漻/巾蝂xs脝牡q榘鏛枕袦t狱滞oK觺846邬崢 跔k栌跢鄄锔活e蝿鉔S娧聎木! -$@ Z` 0E甦DR亏 )劢oH!Z -挾-RG6裋6(譇翠aI%>鞖獲#岖拕 +]v= '慔臖嬥:坴昿6U;矷 Jo Z惗1Z$A3騔;F婽;鯈奛%\磽焙s!#RG6]敇 +tm&7[P#D[Z 谄 +1率q5V页f覷聂請衯"%cIov%泞翐mP釢C闯I韖旯T軍隨襁蒲獁 +iL邧萵E熆xu瘄#(g2 e逕蘷d弲2q寖乒椕飠a.sc^5啸嫾f俅惌;5綦<櫞㎎阙泠囨Z鐝萨h姙祧nO 6錱Uh +1哬r`1妓O赳戂漒k Z 恭楍/b澢T曼%q<邝笼糏創?^3q笽i榽 噃矬7'_j麊9汪=|忲yO鸯%計*颭瞁迾R_7RU彼瓘 嗉'燋Q瀄堿H鑢1迕c|x屵幥?v 竮bIj隧躁*罹鍉@䎱觿魂U=Y议L'钰O蜞]p{緊p| 8>挾{瑼U鉤k$鮷瓚草k嵲菺#i #um颍顏|虬B扦 +2w蚒4氿UQk欧粸V$淗鍰pZ顳\A sGe6閾О御&賈G聮M靂KvmL銰澿閨芯驘al蒗拸蒅趢#i毁#凳陟扅Ln瓢A蜃: 縬B宲蚧5洰 $eL7H魐5~福4x菺暯o vk閝 ?趽@~t恸L罘q:鹄醮.阔歰z栠=09W{缴}湞{7)訑哳谵鏶%'1./r*櫧gt雉e夡P鍋3童嚀N糵僄※斤痯镫暲趸9mW灵."+]珊濎橡?iD骗 +endstream +endobj +47 0 obj +<>>> +endobj +48 0 obj +<>>> +endobj +49 0 obj +<>>> +endobj +50 0 obj +<>>> +endobj +51 0 obj +<>>> +endobj +52 0 obj +<>>> +endobj +53 0 obj +<>>> +endobj +54 0 obj +<>>> +endobj +55 0 obj +<>>> +endobj +56 0 obj +<>>> +endobj +57 0 obj +<>>> +endobj +58 0 obj +<> stream +x滍[蛶6 鞠S鳿 (婜沵6缍 &EH@)鄄(厶3硾深e啿腳憯>Oo1 濁进 R娸?絴冚圂B磊架粊b颍~粽汩鍍隦鼬$C"X,vN?凈S鼬魃篪l\軖B hB宰8h湌f}-8- $嚗鋩K玛壈$槄\;諼MY>珚崱嬱侳 鮝鰎}剜挿]'村胸M蘅飣⺳闙鰙g-q躗犧竽回8孰師匿h溼荾<胖t`#iQ<琹0u鏶鷦堝柜K墄~5*僣仆:1x麡(yZ噃貥餔(^鈩隦鰚濺[w萌;黾y㎎銜zC颚n0 oK)De-/~屢3P +vnZ + 髨败{C槇陥\霕;訢鄪備8鵜-3Xq!昷)l靶4W椧M-ペ姠'晻,U榜珹 蟗)M(諅毧輂1WA飗]o椁g$a惼{.墎熕R塯8剞輞7&鋆互3& +菐i剫?扳^Q?-曐 +/樸 g秐⊿發蘦x-歌'E溿M剏颣 X甾梠|N1q貆8咆 锦墓6]瞡"抏31 D蝫L|庪傁d譻-弭蜠蠒G毜92土袱藷 幊y該[懍\莋莦,㎡<窮:闏@j魻"匟 潐 島埫 BcF陙09譹2羇峰Hs浒,悋臖6[昆柀&爲g t" ︰騡熎@愮櫺5虁1;dY`鬦ud辟+a1宎QC`垐%骴P晬 結"こ5渽"頶內 R,'鱎当躹;鈻鉘耠_н>>M]櫼E欆E謮茤k1'䴕JD阭9K覢婍 滬啻L"蜜RD 4ERm纱骖3=N阖擣级)e宪)?軘j帣汷轣)惃糺氰椽M荹v;庪gS禌于?9辳镫+4衘臛'")Y矬<嬷臚渲灂3籓v榡[豯檇宒控%沀祽l62W隗R殁獇询 蝉^鐂 鎥m绤骱<鏠疢溃yT峺祦苗朊*膇W酖u笕砈堥鼆{榵G薐宕2U恙2nECN2邔Wm\蔧诹簍R@#縕v嵘誯荜au何曽躂方GA穹x帨彥翎l鲈稕d>VoG艋ㄗ讓uP毺鶢屳f臵烘姼崯增m椎芯&]頵A珱|杞瞡"蘧n:e@螹赼N*憕;~[6鑚鯈軴9摔6w镶挨戥ewB-黛溁廮胁7筸顼徙e騲r8,俞~9疑ōz鹮=^线-7憒A澑芎h-7Ez拒鷈l龢2q鷈a 鷈羲 /搚拸羲%钘i, a 鷈h3a鷫釆)誹*艾H晲産ZB強5:W琇Xj聦kL^:峰H~6@縇柀M孝~吱_ΝP縇蹳2350诗v連2u咜1qrD槵Q?蒄妻,憣襓蟍0堒!k辕1曹x矯鈻隦耢蛋劘鲇@'齒╧浌t9歆6s诶棚㈠E4鉂3觞y=U;7方埚@l贳6g#%犽櫕?{眕-Dc@4醜滔椌洵杠誃[科(7(玔珱]j慬娲螨f憒禆唙輿7'樏 +厳iX1[衞 蹱鎧5V,0HP/|i +趽Gz3塖愠h~6W愕o壽珀 |险遱貅\r钓肚壁 @儫1圭濎扯_供蜼z剥 m%=k躆v賒售 鸮SQN璊莛澟冬59ě鑑;贼 м&┋/繭攩瘡j暴咴5/鐮h旁{翴戦;B砂 +endstream +endobj +2 0 obj +<> +/Font <>>> +/MediaBox [0 0 594.95996 841.91998] +/Annots [7 0 R 8 0 R 9 0 R 10 0 R 11 0 R 12 0 R 13 0 R 14 0 R 15 0 R 16 0 R 17 0 R 18 0 R 19 0 R 20 0 R 21 0 R 22 0 R 23 0 R 24 0 R 25 0 R 26 0 R 27 0 R 28 0 R 29 0 R 30 0 R 31 0 R 32 0 R 33 0 R 34 0 R 35 0 R 36 0 R 37 0 R 38 0 R 39 0 R 40 0 R 41 0 R 42 0 R 43 0 R 44 0 R] +/Contents 45 0 R +/StructParents 0 +/Parent 59 0 R>> +endobj +46 0 obj +<> +/Font <>>> +/MediaBox [0 0 594.95996 841.91998] +/Annots [47 0 R 48 0 R 49 0 R 50 0 R 51 0 R 52 0 R 53 0 R 54 0 R 55 0 R 56 0 R 57 0 R] +/Contents 58 0 R +/StructParents 1 +/Parent 59 0 R>> +endobj +59 0 obj +<> +endobj +60 0 obj +<> +endobj +61 0 obj +<> +endobj +62 0 obj +<> stream +x溦X{|T沤忘戊賥$洂7怶 樢% c" 賱亜蔓]洹DYSc-剣4孓^!禴伀笛赹捝凉%档鳢gv矽吸^篼蚾鏈Y`啖0zt蝿'?=侃7~聢1消啴爒o羽 =-j)裺嬫VFS4蝶U/餈YB礫HF朤虤;P鮨 滇匶匲燫隢j踘蚘R2躬`[M<9ヅ厑腍箾赾>笖:溪茜┹硉顐艙看8﹠濘彍S^T8sW牆繇'箙+擲Q櫾鎏+淸[郬*诗t|SbF牯娛鈯辉 '=p∽胟峠3簽: +O!2頎⺗釹 +H孠欠^7郜4勶囷烵鰿缯焆孵O渐]鵺虈茇J8矺捶*咥*碗Zx6脧a;a靺}p幟x>勏闾蒪Y +蟊醠薳3Y 浲姹J稈mfA稄b琴.麗}飘q螡<枾p吻馶>摋鹳|+鵩潲!~湡豳4 +ㄖQ Rvb,諌箎:>z5劾 =勄[逞O鴪鶩艚蛛FQB笧鹉>F>N8;凮' O醀 O 酳剆:眂<俳縮 巤 鐔勷D聐謑+j|H*鵦眙G+W徫肪l +耂Cx>醝!\I齑 ? 醞!紙pa/&<3剹. +幞!紝pq/'\+ +釙凨Cx岵^Mxv1"鷄鸋%<>姧R凍 墒衸茐 甀'螺喷)謼 <慂踹I8/劎 衢勶$沰萊吭s鄄礼 +&樸eB` 2鮙Bt't摙[焱s>_鷊N 7遬*黅P琠SlT.0蹚豋佂11軒'A堉实O4,榦K睬燧韜讧侑埘9c姄mA#OOS3斌壙N#皺 + +|闶.]&穞砞闬vX荊]9Ajê槲導袴縉亷叆C=4Ryja;@#峆脄XH=o睩秹鳔%# 袌 +皅怓颯殳x卼d07薖M +(昗斏J津壱C*)P猉光 |孅< 荨瀩Up坕xR8#l耑窧Vta+靽e47+嘦|烲=o&z 韨r7苯嶎8[桶>霾f颢:提($i紕6閖"鵠Pバ{歒A蚓訥'[3峽虵V戝豲7拐d并G{摰槥8鈢鼆璚挄兪刳,{.c*aK葁,拥驟J珔?*闘引栴質匫&廕$誆&鵷[彌h:5氃q蔃' +觓6> 1[I撫痠埜F抺攱潴V秴_& }燚鶄bM)A飌8獨剛淎?彨巤挈擈<渴O赀M廗踉Av漜墽荆#;O鵸"芥:艣|/鲲7>;蟂>jdH毹倯7%彔蔻n5覡镕雱梸c d;>猥:摇=\a牳.糲垿F$E&x\緉烤@稢 u蓿皫圴\mdg`K陳慈螡揜鳔#/[匎~7囊廍,,琎h d鈐K*M瓣熾5Kc绍\踾絍4=W鱬C%e+-t僤劑&j鞆?mK镍雀hU黥蛘┈譢醝緋团{鵃sAr蒹3魗鏅"亢qC~,"[6蓋6戓46垾杖*鶊 秳-e[t/覜a*yc?2 k^#吱Pc1w7#tg6座駏a9y菆?4骏3$精z鹕Ar鞎0 S!I欻鳓iW善骚Y癔俑洱礘諛1z.衘S茟邱白+&6c5&剴妃夦ぃ讫窧.脯淵慊剐斷j_3.*g邙:w4 v歄9p-煶簒椫-兤骥莜鋳\u┎TT莔圦iO嶲biq/j勇鬲耵I6vm苴鴥p0N咏銬鷃2湧JI頰R訃46&岭m鱎 +'<葘s嫍炏麛笹M嫅Wkkk鼻囃}j膦`州镘辂魨Z D驧)e?艢著枞穿5傖 砙!辒V霳讌駏6蜈a8l>熧锈觮/熛l駞gt:瑴%戤轪;` 銫,#批B +雼冑Dv燒>G.滵播笧9菶 K4[K謷已$9撻补鵯鸆论v 涄V&哇Ay)嵻E㭎洙)4g譅@F 摔黑辤恤宰g/颱Z葉RFG]rG24炃 cE#fa詸T璍柼忾鰪1贋&歴[讏菌歲'R#哣x?4Z褺醶1蚃峉L*I锎hh5姴篊彵皹橥aレn瑕9篁鶘5Ra#:物q豤gl?+寘05yP XTf&(Q,嗙<瀖熍J鵥V蜅cゲH]l蘩6蛘鰸黫 *:'A0 擓I魇eWx苹踘ll析<在棴択冗充yyn #a噀 坩2sD屆%茇/h孻袟尼,右<鶩戜M2瀩{*Kg蒎E(池踌0 蔙- 爬媂4历眓銼r礬)4id]y敩踭郐 +k;擾X敞姖l74鑶[岉阷w僦穀-T蟗]{,=僟o.歬彖邛K禎贛軮^BM5玕c墁?怺歓%霜r4#糷堆 +)^n%2拗韦綣糊}* 42駊匰熂\'温瓚墉FXSx婈QS 5軿茥骵雑綱]k萜f嚿2鞫 b櫂k畏沢[Kh多軫钜斠姠謷喜[批%W5蔝 ⒐蛯譡麏頼1趜149鋣韷/)7裫襊A) +f'd$*;,56E楶矦|擲Xcb韲nk糫I#咧牷痷蝲9噂桢謪h靾圐塅.峘敯 懱停皼/篁靍JQS)O鈆6槒f,"66;M;疹-Kd"抭胨鬩E$%沷熬k鈻藛7诟G_5兌u頉漩;扼換踁蔙*8硙揾~飛[庴控皀輟B锱&7x陱=N1a~蘗蠟!倷撸呟F%兕箝w鵭C嫬釈#壂k讶y-9萆掯&;*4&躓_?欹鍗醒更ヶ窡呔另蹮#痆 +貶f2睵F6~騃#U蔙:萤 趱SL釚00%☉ 瑥;鉘A 3汳贇9,;>;:贅6JM=暀y憺釘燓堅炠=+zn隮C宓蹯鑙/毃H +1役@ZT鷮:仅臩*n=p瑀褨菐n梢p域昕}荥 啕=穙鄘黜~砉 J痢Y3鏦u甃p石辦濅濢MR殞砄'兀爏坣皝闑 茕#|餩'栬;~鏓_tg匰_12}騧贺eK竌瘿崝%zT'a魠R谘魒钟J$彚杝襓錰靪瞘C榿=賣W鑌釚~,牢~&安IW睈 P'噡!尫+穈Agdw涺寗b:_B.潈s潨r┋挒et顨G 燬:鍡Sy6O椩軩珋%$Y(6 ,婅<HFh&q綂j%*劰4r%=Ed#`L钜Ue磰椹彮氼獯 VwY!K誨k夺,c$罂硏击E腫hh+6$ + <廫裉$絜溺!鵵瞊h鞋#媑.淩8*犯勃瑋炃7 mHVy廚夯糱Ie佻炥E}<驹4咸%灛U * 琏髮漌43b蟙潾3垢埠80历-蚜篽Na踯馘骹y +K乣葇Qi峒Y臮灺蔮O嵖勩鱋囡$綠祜骟鲌x<鱪8'褫8壙戻MbS遡L颒lL腳35q&邐塷J|C怆OK|M)壇J<)駝你{+嶪?zB訩+q3v盬3v艹;F 囝].;w桂i+顢鳷!瀿t'焢'{N苻姀o;!椄m雝表n[璴Wl潕[徑窫鈉廔|tn&77徖Mmb7趐ul#〨几^I\稸$p嵞WI魒琝盉瑪竍.嗖淗碧婯%.懜貕嬱Xm艆碽U+V垛黇瑦X.q災9I馁Z枠=$柈繷(慩,1 盚釲墔冒层t売$N晿焔榞>虝x?Y? s"q +s)8賺撈E圛砿x熌\b⒛ .糤鈞8n琄寢辣 1謪cx從袮膽镦莪榰G孏磕J䞍p1軑? ?翘"舆唚9p樐 塁嚫判V2%喐qp篗 va %b}w趧O鉂6Lhh-b 鸞盁}xG焢q麆c颺^褅鲵b娮&R滦k脼%$3)=燹妷銪bO寳讑盰C壯霧戧&1妱0Rb勀pb棬懐Z篤`X(釔h'n{$Z]h慼&6矰諐*DT("憐Q終瘙萛Y= 满膏z鬔(鐇 +endstream +endobj +63 0 obj +<> +endobj +64 0 obj +<> +/W [0 [600.09766 0 0 317.87109] 16 [360.83984 317.87109 336.91406] 19 26 636.23047 36 [684.08203 0 0 770.01953 631.83594] 48 [862.79297] 53 [694.82422] 71 [634.76563] 80 [974.12109]] +/DW 0>> +endobj +65 0 obj +<> stream +x淽懰n0E齄奩0浔@HQ,鶳i?!盩宔虃刊橧S〇@:歿3晒驹H摭 =N沆B嘩cE&A頓5碞$衍,S馈洱( 鶊)6'=v$7{呁坠壾涛}銆6@* +41楗u悙m[隭7a貴蠠鈙q8鉵渊qr瑽呲+2崸傭9濲犝闓vu胶禐詙TЗL珪Q^0潣D *2> +endobj +66 0 obj +<> stream +x滍} x諘罟U軺誡輂U/闙-禆宙n-^ブj啥l啥l佴m蓶7阔尡 ,曝$癕2fB!Bf&揑o哾F d聮d瑍甾顤遑綑y鱍簎:畿s瞎鞫*`褣束~鉧b仑緀-澖岿汕畏謒檫&hp穈z俸莼B緊囔秓懿麉朩7憤齼哿1谑偏鱪戯`8傰7忙-{>qt |骺秈}x者|#蘝 #鸳屉n浂熠s 蔍|;\}醵u龔淆v?嶍鏼檫砞xJ!繦m磉猖囘3汤榐簘坂,8竾吖~{c鬯傦鱞纒+蓾犌痼蹵蘱($?2繶Y庣怴^-崫崘L闩K楣0^< 薎苡5鄟`輟B/ =铣0瓲@ 胻笏餸5怈N烠篞4 Q3,PPU5"Z诶烚皟ND'C赣7Cx/C!1~ CJF蘥亅(@,凚("垿?乥(B,腞(M 1唀C,2 +(G瑒 +*―U坬槚 !嶺 腪∟uP8g纓臋0q蘈f,90睘a#&憆鑧MG幔蛨傌呗\嗧0眱鐿琯"n剈垱`鈌哤缕艨耈 駄貙甃 +堵U堐n嚝w臐5齂刴埢`;5q7霥骼.慕p 鈛pm= 顑綀7 !刘堺a鈍 oo嘄閣喎腶 qnF紞酇駐 顎##亙坵马垷ex軄98岠y8傴駈,=p饨9模饄柠 堶幂=/陆坃b M/x頖2<悀韭皤餎膰酜坃亣叝 儻"gxF| 緰|A|EC|帶$<嗻$|<庿|駃xE|N"瀱'侠S堖d<濥< 纠餥,鈰p%8據{6|馿x;饇 +紑*紙x栣w%淖鄀膶&捯銦j5学氳SM諨熩D焜5学氳/瘔鑘7氨mdcXf阒钠岻  +i*WEV6flll刭xp0墂2)w1iv3脔0I2轸1)蘡2鏶`drbf2懴$ 馒]栏[葂e+b*f(a/e磶1蕱1:3JU0闠2ZT/5痒?AM魖鷒Q~渵 5堰剼桤堄5鸦3醀&5鈒 &j脶擊P滽I!6=b1 +殙眳h轱C+q"o0楕跧8}:H![3圼蓹魆谾緯~稉w惓;慎襙傾.蛎裘p 鵞妮洄榀赖鋗=觃喗錈#縇?讚_Эoo "轍喨8鈤 ~吟螛n,7s拄=p 鏒紩"s侓`勊On銑rラ秽v"齓8呐镟js3覩W弜'讏鳼nn0芘uわ蟩 訃囿茆繇n廨苁苊璅紬[媥斲嘂斧曳例躒窤/r挥7脳鸽鋘L嚫刻輾 |;偗r骖BwO鶩x劵?D<苶%}=A<O_弎O雷筍垙s ~凔fz7<羮+} 宺/#炰緥$鼾鬘8沤侙髯圤so3躉熷轓o冇?し頬膐r縅_ 蟩緼|烕- 蹽楂郲記酔.嶘膝7练y馿迾哚- +oK瘒Wy釿逈^咤榈煆M舂M舂M舂M魲穳枧嵬鉳g舂C鞟鉯 +び靎K8嶼t錏W阌s@嶘Az湡薎=綅瀫垰竺魓z;Ns怿U觭y叚喁H;鶒[堸飴嗦m鎆窶苒糄fq/勞e勤B滟"bB沓u蒝朝6镃 1奣xc籶掏輫簂陠kp记1>峼寰 K迠Q頓蓠 +苙舝エ#f銂 售回Z|囓宔3譠>Hu񎵬$z{.Y茌礹a鐐:阽兜475&赙虨5s启黑毷婒测haA$?瓒k猙枍I:#Pi 岶鸉u袶{{9}忯cD狙F礭榞4郧矃.虣臏$g239憮ā0患, 嵕 &+粄1|GKdEht寘;YXe/f| 嚤Dㄕ僵%4J鶥m7l韐龙N势鍴髗c9Z釬2咶#跲掆z\q胩Hf陟(_刳?0谡蒇阝 嘩8hfu +停"+礄n,{猷∮*嫏"齏魩螨X 遺疣皎-壌寲\鱋n酰e憱盅X+浛x2/T#v>2鰋启gc凚魿燗鷫d卖\皁谻p橏弼覫X/{粄3!X雥挄My)椻琛)鹲)披"a湿志7笹鳢 晽!踬咗F鵫呲u涜HKK唍K{G-H鰃康鮠U%骘锩徹L尚;Z>j4e2`D堯`髵^V$[l赞< +}氩+[[h緽鸝2E簕蠣津紊陳颰-NfdJ歹`锢喲`無錽CㄗM瓳颦堲甠AQGK蘖媛珽V +宽Or2/ /玢WPnaD !4Td{m%>萫肰9h鑲z饏/ln<-谲 g?%_禣QiR]*FL)游e粬蒑;Tj]2﹥Tv0[邾QZdeg{./膽媞V芒(荨Q +鮂諫VDP啋]紧(/壧颺偎笣晵糴咬OC3 +`[虠){熕'^$#:(E/9Hk巇+勑翈Q@慚忄渘庍6To懚﨟H ?澽况嗌d蜞鲋綧3i=憥亙%匠}瑊媨o餧G洺=iSy*煢2襺2IF柆=凢桍炰H +*M鴣ZC8鸙l:胤倞68憪%憐t"' '楩崙鮉7续哃粿鉋d q抮:w痂飌璺$ō句磜柽瘓橳;畣{徔@w^瑹)o旟K剡薘疉o钢p甜2緊|_6丝56;-I薑擶Tk烏3挚汓g毁鰞囥;N六+鑊:鎊瘳驕鰱x秣曺咒甄}.5/l涷_騩蝒' 县?湖秮 鳝Qf=蠼兿粢浚O枉/惬!c礦鋏钭(_"x揊g$暞W綨苑_%窗V剋溰麟s8w疖n, 觭^A锘?伽K崪罤i懣軭"2y_&O射!枆_" 髪L溴XU-瞦篆厗DC偍oノノω#姼#>fw耗 +RS][绮惽娴7-\砯aS<覶鶜䎬My戋確bz.|旊椦+詑値墉{W鲬幙YGt$蛽鐇O鲶氖w<饎铳齊 鯧憤ky堇燂Wu川.@vA,'Gl竣閪鬮vb*蝷悀'閻鋠f裩( 鍱f, +P櫒L:r嵞X<沄U绱g鏋$叀v廕萅I疅頙l0籩趥讶r鋓yzU螴$tO犤孨 +卺d馲,,鳋茺拼)[駘1Y緶2m䁖/+C緹N繑4 楤b嘧A秒;█膙`哽B$?妡I臐* 鑍+.鲠嵉ミC)沽CQ伊徙劤庤x~ k裀n缷T猳 菃oxeZ+Bs讗%3黭LRp*'?诏*虚9潂>m鳯0犘X鉯$RAG伱(氀焳zh朢Z挦*L噭t"@jVX & b貀垀)L<>奻gh.0:}G 76 杒*>#<}燣5钠b鬎S遙廼U@$柦l寣F衣 +.抩棃譻耠穕篂辒9X峍凸'Y鯈鐭絞lXP^綻脤鞊r3叞:t%kx蓓b#!(p X蘷坃򏹤qH銭8瑲B*S棭洗$楲季嘷嘃AaL%R盶漽#泚耞OZD仇bj普錗)Sい芰E澀甄鎠詹踚邱暍S 琋1T蠋H r哦%k猇,^紃60gf漫橱水俜紏辽撲钚+ct7+龉I7;晛Y癙鲥_$蜟 +9/丠漩愊蝙Bsq$p麡b鬒8^|T 橀 '厲Y#fZ礩b - 腴w2Z弤脎穹f 莗牋,尌^權粛Nょ:羪别呓鐜`C_摲秱2眘z鶞ㄦm诤TG#:潕鰈琗8;{~':1m兮铗EJ官3 +酦梳蕨碎(任(^魤狐撲 T=<<藋"A刈C㈨Zg *-sr\XW葨#烵ヤ暕Rq/庤┮A查賂02哩嫥p< ◣M%)挐 Ps笎艴$#魯2:挍h樉駍W埑T浗崙Y嫬]逇庞w^鸑dvS昂8\07琥# 壔z揨04谡T沠踌捤螉鋾%-(7砆x>d瞊槾ZP凟**凗皥聥zぜ3z俗濳Q瘑戗sǎ聬Vb9僑鹻斬q>T蚘V餞1S逬#05IgZ(w翷$」18璕─E+暺Pevヒ甌6*TH0篕!!*歬B惐煨n +~贶鶦欴Unc洟凚G渢偋髴撤(踠e'萔洌J擊T33籾6bc?Ⅲ;*磳r嫢b峙T倛R盿+*迾鱃Y 蔑卢璩#J1莢雪熰7 盡 \鮿滙蟈6絨y涤,q -瑲迺pi﨎覃獭x4?R蒎 佩誉`+ 吺q蛉瘚柶*漑/溵鹱TZ壎V髃,<}萙v趦艓PU伹鄼G獢偁,:刷儳E>Giy晬7抮羷娚橿\杮Y8粧,{ -禊Iф!蘤庰!休?苨昨d氫级塺+暠l-r3Q[誱DN腉%Lq鲫庰4/??鯾櫫G,闧崕*錢5o#澡FYH1%b级篺N蜥脒/H樇M#p乞Y亀"觜IC稹7䥺,t,漜R"8 +q/豶嶡[#0#p.$. +嶦戓P2亭."Y舃誁祙 , i $髖漗:蕻沲Ax俌蹳 已懄⑥姢K豋sx*S^4-*丈馐烆塛殆牯}Qa崡寧wy:駼绯]蟰迏 y鯁nP怉肇啰X&$J,:匪槔*B&+Y c`P愴偓荹mv委磱&襥吗爁瞜&A螈擊n>鋧荧S$k膠x較6菒兎:撝dj&鎃d!c7etj噝V帽尸577H寧芖舣紓x﹉鰷x爕 W悽癏ДDw聒f!"W择 雼蹥 +V45j葟4藯棢茭鼙s=鲕VBu疪/mY\<耀矶岌;H課[v,蕢抐!j羘'蒬3#滻寃V岣r螠I?螥:=跚fL'跩鳀攢 穤凔粜 h`4$5苀銖柒爆O#j蔻BJ殚M2胆{KN驻)筯瞃F4谴iUv{沾*庆蜐e靛s趶帶eq:gF加ZJo豍惉翦Mk*,,N'韫圁8m[cmV肼箾6搸哐_壢yò*驦 嵽襊犇c釶va&钨KP粱蒆I襠m吣搥3舭茄GgrUQ#%^'寵<"嵓货4嫗 U闱嫅讹%韋湬U嘍'l)>呂>tjPh汀┯aな呢氾鵄殟枺仱崠 顙按P,>坭d蟲 汰`Ag| 鮨<^檂B*FR1$曘+ ]嵘䦷=*kV頸壍&BB!?栶瞩謬3椣l顄z膫趘リ娽逅嚡2┆甂癤 仰嵣 舮r梌MヰJ +~8愻踀9v塯荵p賥C依O?破◤*p<攷. K滚Q=lj鮥.f屩鯥zJ:}s b RT?奺h媏'4tP欇C'wd鷨=ルKJ謼0}|热翏r儭湰Zy蓑榟2姳宸屵w切9鱧`~u 5I咳+茽憮宖4荓 {&~/i3l1cq蹴诈硂癳0G頾yt鼪$黰矄{z蒿/丩 l臝tmeV1S鮀喷雧krペ2驎甭.6擏遰珯餴f歅丩朡訑Z.g IJ尤聭c%%I$pIRF枖*憈 2潖6&:(噿&"Z辴钾舝a勊K髗鱥剤N**蘊嶒Nk-*戎J 鎔1c>ND&0S?慛(9ΖP?B;蠚;$咈M&79護*熣V窠瓡誥!栾嬜,煋餆祙V,3^g4奤W:!廨6ON ,W郰 +g@応QC炶彂A䴓巏 Z漿7叢gKh慹苡珂右讷_乓6貃x厎碅 妽貛9替繵貶#峵@(F"碇F貰伸>#[U2戛R蠸cU/I傺@l帰J佉k, +^罩h 騏G蛫纥ǎ9揶孁财BY:昿 +騴N?凭肓4儴鋷 |/i菷葙iU(| 峾<睛镽眃3氷匵矂;叏F惮{勏0泳!麳橕8D鯎 ~狻+.樇蹸躎巉`剜 #朞,躥 @$-q織萇$瞑t\釬$瞃"鑉墂k廻馨哾U熏{閕靫惌啊 P +晚侟>|$徿掲屷}jc詣G曂寜J簡涵荝?J濢[菆禀nLK某嬆${爑_/ >H瓂紿0啠県([鬹tF砨桉兆蟭籫肿鹺虻5z嫓脱鐬穕UwR=>vh宄'復/踫覯档7荽鴠噲m窎靆祃;+&縲'C馍2醗aP曧Z=a蛫q3抆绺倭I鉅針葜t粁咳]'挮D睷$"筜虱Uw桾籘萎V珳↗歕艶 2f祷R5R浮d8y黑揓厬*ZDA1洇9g4蚼k蔥覻y真ThM6琘:噅1~#5ㄎ缬嬟o碅煻員ο蕖珁貔鄅現Mbb歄涛ab钟绯雉檛`DjU倎輽!澩A烮.41n<^騸 眊![P33%1=犿U皃钾撏蔀铺v覌y)m趂勎j珼鲩[q槩0槫K'B俚銐鮟$噾陭篒.#U3kV韒i緑eM褪k沎霎氄SS硉V(4kiMM犀Y礲dUE弄筭闷觫Ⅵ '慄s蠽癅,觚S詸牣9汴=峅鱪FL5鴢A攺{Q4e Z3vhf6鼒螁T垩/~.FP(陦+_詒烜,w}1纸晨d}>铼 k诟绶m澼SOs~鼄s岸锤:h嗜蒤&' 3 綥D礈堨#P 鰖螑%T6Jv帇琶t^<獌Y7槗嵿ed#&Sj;霺ㄅ,栻顿9r嬚吼m锰 +曟棻僦B%J肠 婜. 拈\,觗膮-.MZ桬黣%顨ZR4{^~zMg怠a?#< 痆QgtE塥n佽娢*%V韫$瑿I駼1軅烣ir疍n)#r羘pg嵛-供顷(穅塄謖:澗疮(嗀鞽夁废+兣璲摓#犟$c9'叾ve* 儝萾v %"H !?+櫧~W'琖+*mf焑9Jc閉G;~ZnH磼|{恽e叛卻隴d*朳反%妩峺壱㈥夑0t荬3鬍枰蒐孮rO>寻皰2b%諦S矂>瑮a{ ,z坊愂Gv{悭 紵霨^H +憔&曣=7吻&jD毃v1U'%K{{鮠癁萄w9YO 鷢>犔 睏鈎o9)/n恢v弽[6弒煏盯a虱只礦 0&(!懤) 舙b汰餝;E愢穹`tR觙谈`釼_I眣h罇*.鉪[袳劀y赳骄奩醜K芸oK肍w斜.泪, 曄 懿筏刀H龌V穘 +晣&s讣緇熀褥1 =yQ扣d-埛N[礦V4∷RQR=$绿d乤垰趢n*?8;€@Gt贂塷"耝jQ瀧 Ъ稸мJノ釐qDP"5\酧=紧軆\RZ{7蝒鐶 V$+姼O仯*譅c=DD限5 +嶒>鎸櫜洅r蚊c骒X奩)貿蟎I渀鞱&4d酘o薂2偶9e铪`:ゴc`&95藁i但j~5969s牐鸋菽[睆V鴑瞭D#{T惭B晏s兔f㖞9m$睬@v慢X鵪;&$US瑠:z;弈,3$ 奰粚?铲=5m蝪隣@誸嶜丂E蕼$郜崣}苧g[菙?N盼舃?NV'垛Hl丨$BaB&軯=岽簀璾墉阎ζ黆鶏蚼匴課跿=}~玩K??D +縿萏C滕埇NL戺B$Hu佐 巽&uV/Vr瓉 sd槓麃)8S蘎~?貱I圜=僞枯(熶{(纑鄇5r汧 hvmv勳銶;泵:驕Q'櫏AQgE葺N格鶲疈 H. +窡縪1(I桇驙I睕E祅3=hz履汸祠鞗%=,陥]G6x濦iTtA'4B扭睻[}.q釱椁]欭伉黏a鞻Q珵觅罬桼*H韽疹尞嶰[]tu韚-膟諞嫃/\x|窭復励%nt&KM萫+Q褞赹憘'I.涭磦mQソ燔锅 鏭M蹴硉}(C箪] F.自腴gq蚷io怺 峬瓖抉冗s浖+汁(_襒7癮踱磰b蒏黼鳬RS彔 +#鮓轭墪jE桪!1/U2dg^湞 +Sd:轂矡 謶x偸蹬h 觼 5k榸锳.秔I`mI翀NLZI's噸h皧I*骒諍YDQ醓尼韼W$.壶v-犊曎騷%细,鏱/M渧)屪终&qt~菬 毐<洙,&+V贛壁哷偌贎dvW%喑雽掾倞VM.m鎢麟E雠嬋_鹝:势熴DAo-J柷辏V%央*8蘠'6t莥y 缍0< el蘷1 x◢9@鞒;%朤 で"榹H=憃]hs帹鏈"0g櫥肵懦4*Z潐蔿Duew瀑20跮E4稳4栺雔禊iuZf'K暻抵蜷薵 [鷉7凴朌t﨡礰Fq4⿷dwq靻鮩Q珌z瓹'甗U軚饆-(鯄麸 (aax 2U`)f<洺6YO瘹滍﨟CdQ剫$g;6姹3、{苌uJ9齝嵹/=!爫3腈]y5gg03鉄X#颋誓+夢A睤A亏凫诬鶇瘳-(L^7琲 E挬懚惷Q\改V挰(湱櫏@4f*n_7{鯜G壣既hZ缓-畛H Q霄2G巍,X:廜P觞O蚕O瀿q)CcA!`弋睴VOD$J含*鸢O蝺c繖穗y,r2晽!#0]櫻匩鸯蓐B試l翜 蛣廏熺^匧 'J敆蒣朜yHKF媑+鏕朤h爍v_Kap鲵殄瓜怩'趭Wu埽9裛嵍璷=衈鞏砊=J"餺g衠y?蔷S倭B煐,暷)*窔癃_b{鳥nu藕贫推質で +n+"楤M淅5缊%6廧LG+*lOqF唀*炔奁v氰9qe翸v:贗$#`尙叺Qv+Q艽瑋髒2䜣皒f同踉冬K蓏8#4-咂緐cK﨧 +6﹞&-4豄谧mm桷W詤p;J Z抋潔H榵囇傏女38z%J@q刧5, 搙v!7u栁螳SdbH鳬倅盏腤2摔櫴B嵳朲薑&} 蠞]緋紞芈8蹷~速 屦3P溼hQ柮,g櫀P袤=:骚'魄鸌 P'恪翼*舔:υ[)dLFwヰ尿J"淹;t鼶j&で*芫[\ 砿┡羭T竇!Z⒓tX濰盽浽#)j6絩UIjUY秌 糿 瘗~f8萉/囦狖t?Ar鉎—)u穳旧詜C0╪jX蓌0;輺盎@覭pP#跺jw 剄r憨CAc檿崦鄤!誥W:U┃H'-j驫;檕V埘y猧萺络霵U:鑀歈瀯y鷜鏼{墮tg3Vx紊`雊撟dn 簂8+蛵3韀u畴驲)魈閝W硖Y$鄇Y塼4O俘丣\=sv澝3{ 儚圜HS$m$D'UBw倓恴 蘈氆挬]薤釵橍 jB0瓁嘻6v蒛Aj/t凌邧掸$k纈溱鎞壅sG\珌橡徢y 蔍8〦鑕g√鋿裃栰6><=珫3獠*薒匙M7T)瘧j碖*]菜洈/}}秊]鼋扤蠤Uc +曩m獯]飕撕P嶩<蓹曮K+-Y{?k霕IL鳸k蔌ij蟗&饹躀蓡10.%绮選 h 葴龣9k 3蒃龟憜\宱.7讐鋵\8牥%雽3嬛N)敛*忓K鞊%鎄E6龍椗x铢ゥ墥文糝贗]檭h6: c袷 塴Y獸c6帢"5冭骙W襌Y:e?s2讌SY煋鹋$:a*阤冥s嬣dNgn勵A +i趑盃费9茒搳`Q魳签8=8䜩<")獪(&x-g沲z甗'塑鴟騕[)F熶M錮&=p揝fYf鋈LU嗢狑駽趫笔咼扠+訶衼K缆幐:睪\碡寯u踋#6 3枩⒙;⒕UY.赗工咸蒽G衍剖&o0{3阩u蓬 轿波_覕dy袻朝8痯f夡猽 -氌{L烖狧k穅旞.I 5j带 +呿骪B椑%蘇H鰏情朤倿JO儑穮(83浻皖v砱憞甬! 穳器P7寴U夘t#K韛q眯亰顄稊薽锝;汙Qg?l;8惐龅篏_}珍.p&孷K[yMk〇猡咃%&洰St鴍U7誠O虸鄝甦Xpc棜坢Hq滀8醶袳孋 Ы眯a0A-8&褫姑n*鬬O?箎:-A~3骒舚gj鯸%攪髩傆Iry )蚥庣9騦vO娂搜U濹樚蓹 哉=Z投曪4J豐硾谫3Z尬Dy炌賜稓%,:砃蔿*亻2-(岛'鑞棯鉻偻浀C;t篪y 7cR琊灱撣墶赂bH髎K鼃y穐蟠ビ6 樎匭M哅渢坐锂紥橆毝m藛忖 [禡蔑发2靠~覑?]╮操煓蔿pS挏re巤fM喵6跟bz澸bw鲎処=辔腀伢)醒O笿I#5Y@ Hi{S +÷鰸$Y蠻蠾莱(沛j/鵅C{ -*晽鑪G<,o3S{迗犚Fz衊~n8謣瓤; 软@n7徠=餘認臱褂m蜦)X3鋞'4顡S 諕+N,硡1 (ns6闢霫瓝铚#'''骨撣$N藏I跍澉N驅搥隅饬蜟僶憦c为%靾H先夓鉊j鈭磏寗蜤"%1壌CHD睭たI渑襊D噄(趰FQ萊)]'竤N撁蒷犄煵赮鸿@?兺,跱炮韧-a@郮 [qP9T!3钪)#{緭|q笣!$淐 MJG籣 矁A瀝尖囝v悕蔡A姹缚r鉥猚旒欣/庾/?嘌m9嗙术╋珳4掛裨聜y釒P嚦莽╠@荪r1<罁;xr=烯<簂r嚤CD 位l32沨lg.3"wd舵物骏v発缥I崍"&v0.査v%+.忷c,zv鳲霙贾FgN襉 螓>⒎h罉蘔磒纆4xaM 囼寎E韌未o$已虱[7D+7_当紎鉛+秐<:茰C磲傘蓚6;萱S]歎V]b笔 +dv褥鬩噶7斲郤&陡巷 e鲻\烍y髄礐閻象)窇澵披揗<秶Gv(蕩iU擌飱凥黠嗗P簇f+. 蓕扊o辸煤cU#乌=3j-w$?~鏅?蹔咄/鸹C疳餯\$vtEY&To&G瑷T圚狧- "裇 Bns賂f栈鬑剧圬類-墆l6簗g3"墏AEq渾奐2v儬WC欣I嗮浭;墅 +z +麳确樢蕡觟咼t[5c缯<2鹠捏c&檊蟧8JKjb若(f虝Y艥穿,衉瓴#69⒄調 攘h;:萦W袥扒K悈6]哭0璶1,叽ukb[>7铗芌;8*U'懞4& 僥垶x術~l-乩F$臽祤2瑅袈皥俻钲t+褊t+quJ};曽 <=熇貽肴qG"t銉疃選歕K^v-莅=卑眷释┬Bl坘!硏 x槥巊l岜I濶=櫝l/Qu蕊T绢齳,妤詢缯橕鐬W盰报幪海r?鼹mビ蠦?構B%覒臬%扺"犗 蟛終烚j墫郒+袦\lzm乐)u4'鏇 熜|紹蠼複 >洀y态九檤3鮵騋雟q0k檡8G;樤炅 ~垳衑亳钴悌齱需9⑹!蟑寡K盀 M (J個  $僪絼( +檪偁,企o犲tz綘G)譕鵢 昏窉圾K  椚鯚縳0覥/N\4E$$B! $蕵!/婹z,,"デ曰wY +!N沽 0蒜(( 郋e僎2J鴉8O$$%夌E潓A壱c掽L釟=膵谣)7xa奩:o式4q2M孎賭N", &A孴(儊%澷梹觿埦窃賣Y +^褽閱)7xa*n替鑑樃t&d肈窝胔2鉀亊y禵忻xSg)7xa歜8OA`.觿,洂2 `PLfヽmI毒讶滲酸2Rz7毅Ri4忻f3^H=闑y猗潗&揈6欰0⒔iQL娚4睓Lr +娱寊晼C"-e樅鴁v刔奝摽>驍渱槔N閼#}遗0#= =瑠jR筒裝稒'鑱CH朙&A0 +V^8Lw舾珼裏钁I7M沽 踦劁篝犼徱4q3M-f$[p閍Fz=餐&P8瞦赈;%zW獒r. 竽E1(奅5L`瞛V嬚b2梑1g +ⅣX蘕LL⑤l盭桁c訪譬嬶e%闞0]攏檙夺︳5%IzX&.!觿(毰2z5玝S&MEzd73z`v,:i9'撏$用|Q楖"z/ΚV媃 fдωTFu╞-=恴FF弶4呺縃e ^貑蟝9UhU晧K4a4洟XA皜舖w蚥暴>M6彛IU尓"循鈪闡59,&箦Z眷uY峴)zX.JWк鄥m鋆:q墮&lV彤*6髫潥营(6浵猠洤*V舃ⅷHUG#d侦癤徦幇KM氖E橼及 縊9咴彘a:4諉颐岵簮vJ弆髪f諸Y=4糳O震敾tYz\j #0tzDz槾塊4a焚vJ甄Dz豑蚢筚r鬇韇誏*颐j禋衏蜩葇剈 N綝 閬精:qI&凰9翣傛wyl籪s:倂[秠.6f34_j迟:眏U澓z滑=磱襪Sn鹇6翧砑 D6qI&慧fEzhH纷顄Xm.G衋6翔a我儢3+f涙蝇SWoazD傊 锳齎EZmN忀珹徬醩nW蓴)h)莕领1hw8誦幅舾=;鄥mFl鐩㈡颐鈽 &全,* 棦),L儥倅!O(玩廃-= E隼xfz^饪铫鼭R乻霥婆 [:踰a殐C鈇48T飼@~z,饙 ]覣0仈g$ 髳Ot侔nR=析焏嬬佽ql葐 鎅 -葐y)諱剩g#X|T>J`v6 +顕峏.@X 譧.,嗸榸 骘嚌鵀馒蒭毐揄c7c嶮B蚚羽/劑龢彾直~劜mW*唅鼁LDZ唅牖熬醣嵳冯傄隭緄Xk詹;7o槥h榭z锥瓭闥{椭]讋x驼;Y巐8撘糾潧7n奧Mj钸簃腈u齏嚢tE(碻蠛鮗劗:皛gh爪豕鄱m輹I^>4 +&掇臃愧K壽钌仩贖.剋煍.>脊鬕榐;m4>8[ !瀨$&R [把E$笓埿C|皓千閁I冦E 4迀Sioq=i颩禵滫桐)䦃'_|扠庌9(7M~騫稍痵汕雥岋;A:A}X +>傳v婺郬9>鴷/ /I>勏 縃t幘#x呓7廱辿构羬竫痤蟴僟 料顟噻 轊剂O鹞庙#倠搈噰sO&擅觛娓;儑n!x;~蛄[陜 G啈t谩岐a緆竜槪蔺0択iu+v靿[^煎佛穚$x髜O穰蟶/x`钁鄃萲笼唵Vw戕D饐腚傷蕛譨sk鰊鬯礤=<羕1竰p x ! 凯op _眰7n胭q泠濵玍鮨\郸g锚T侠獣=隫]殉v諍炥鎒=藳{z栜儋厨矽=輜坞楹常g褲 {*;~褢钹绠j頸[赵雍g[#Y轰4丼N'濗O瞲缘j攲.靆9*寣B鲜U' 9尖;顎&黁掁褔+鎻禼 I1䲟NhZ嬃`,艰g!划a堩蔈d遡V朒豮l惥d忣落昫whZ*⊿隹|) +endstream +endobj +67 0 obj +<> +endobj +68 0 obj +<> +/W [0 [500 0 0 231] 11 12 324 15 [246 299 246 384] 19 28 564 29 [246 0 0 0 564 0 0 663 643 620 713 571 537 672 0 269 500 0 519 871 728 778 608 778 629 532 565 688 656 929 631 598 573] 68 [522 589 465 589 559 386 578 571 253 253 522 273 861 574 590 589 589 386 446 402 574 502 777 511 497 471] 168 [269] 188 [522] 200 [253] 206 [590]] +/DW 0>> +endobj +69 0 obj +<> stream +x淽捽j0 嗭眷.J溍J!泻)鋌栱R[ 媍"o?G +-虗凮I菼dsj <!疝X韆o^坷誜杅\V路:菕hn)佬貇de蓎砈3魓'柤{ 挢+遼6r{s皝 VU\C+絭瞽'h6:鍹樂洋P|x啘4j0筃侊X)猢xy帶b`蹩鼛\梌齮誽T 憠j,E蔾っI瀽㎞$錴噬闇c系譪#U述gDAID3[},^(H鰘 捊 3w: 瞝e菇胀m糱\蟛`c狺秆-s:熉 +endstream +endobj +5 0 obj +<> +endobj +xref +0 70 +0000000000 65535 f +0000000015 00000 n +0000021546 00000 n +0000000154 00000 n +0000028713 00000 n +0000048401 00000 n +0000000191 00000 n +0000000267 00000 n +0000000522 00000 n +0000000792 00000 n +0000001057 00000 n +0000001339 00000 n +0000001631 00000 n +0000001914 00000 n +0000002170 00000 n +0000002454 00000 n +0000002737 00000 n +0000003027 00000 n +0000003318 00000 n +0000003574 00000 n +0000003868 00000 n +0000004163 00000 n +0000004487 00000 n +0000004767 00000 n +0000005023 00000 n +0000005300 00000 n +0000005572 00000 n +0000005839 00000 n +0000006130 00000 n +0000006401 00000 n +0000006657 00000 n +0000006927 00000 n +0000007194 00000 n +0000007482 00000 n +0000007761 00000 n +0000008079 00000 n +0000008335 00000 n +0000008666 00000 n +0000008937 00000 n +0000009244 00000 n +0000009558 00000 n +0000009815 00000 n +0000010086 00000 n +0000010360 00000 n +0000010658 00000 n +0000010827 00000 n +0000022061 00000 n +0000016077 00000 n +0000016383 00000 n +0000016639 00000 n +0000016943 00000 n +0000017267 00000 n +0000017585 00000 n +0000017883 00000 n +0000018139 00000 n +0000018419 00000 n +0000018732 00000 n +0000019049 00000 n +0000019348 00000 n +0000022391 00000 n +0000022454 00000 n +0000022555 00000 n +0000022618 00000 n +0000027732 00000 n +0000027969 00000 n +0000028353 00000 n +0000028848 00000 n +0000047304 00000 n +0000047489 00000 n +0000048020 00000 n +trailer +<> +startxref +48532 +%%EOF \ No newline at end of file diff --git a/Introduccion-hacking-hack4u/tema_6_owasp/README1.md b/Introduccion-hacking-hack4u/tema_6_owasp/README1.md index acee148..cf8b94c 100644 --- a/Introduccion-hacking-hack4u/tema_6_owasp/README1.md +++ b/Introduccion-hacking-hack4u/tema_6_owasp/README1.md @@ -3,7 +3,7 @@ 脥ndice de subtermas: - [README1.md](#readme1md) - [6.1 SQL Injection (SQLi)](#61-sql-injection-sqli) - - [Ejercicios](#ejercicios) + - [6.1.1 Ejercicio](#611-ejercicio) - [6.2 CrossSite Scripting (XSS)](#62-crosssite-scripting-xss) - [6.3 XML External Entity Injection (XXE)](#63-xml-external-entity-injection-xxe) - [6.4 Local File Inclusion (LFI)](#64-local-file-inclusion-lfi) @@ -38,7 +38,7 @@ A continuaci贸n, se proporciona el enlace a la utilidad online de 鈥楨xtendsClas - ExtendsClass MySQL Online: https://extendsclass.com/mysql-online.html -### Ejercicios +### 6.1.1 Ejercicio - Levantar apache y mysql - Crear una base de datos con una tabla diff --git a/Introduccion-hacking-hack4u/tema_6_owasp/README1.pdf b/Introduccion-hacking-hack4u/tema_6_owasp/README1.pdf new file mode 100644 index 0000000..981cc21 Binary files /dev/null and b/Introduccion-hacking-hack4u/tema_6_owasp/README1.pdf differ diff --git a/Introduccion-hacking-hack4u/tema_6_owasp/README4.md b/Introduccion-hacking-hack4u/tema_6_owasp/README4.md index c50d21b..3e03d6a 100644 --- a/Introduccion-hacking-hack4u/tema_6_owasp/README4.md +++ b/Introduccion-hacking-hack4u/tema_6_owasp/README4.md @@ -4,7 +4,7 @@ - [README4.md](#README4.md) - [6.13 Inyecciones NoSQL](#613-inyecciones-nosql) - [6.14 Inyecciones LDAP](#614-inyecciones-ldap) - - [Ejercicio](#ejercicio) + - [6.14.1 Ejercicio](#6141-ejercicio) - [6.15 Ataques de Deserializaci贸n](#615-ataques-de-deserializaci贸n) - [6.16 Inyecciones LaTex](#616-inyecciones-latex) @@ -46,7 +46,7 @@ A continuaci贸n, se proporciona el enlace directo al proyecto de Github que nos - LDAP: Qu茅 es y para qu茅 se utiliza este protocolo https://www.profesionalreview.com/2019/01/05/ldap/ -### Ejercicio +### 6.14.1 Ejercicio Instalamos openldap con docker: ``` diff --git a/Introduccion-hacking-hack4u/tema_6_owasp/README4.pdf b/Introduccion-hacking-hack4u/tema_6_owasp/README4.pdf new file mode 100644 index 0000000..2c4a6ab Binary files /dev/null and b/Introduccion-hacking-hack4u/tema_6_owasp/README4.pdf differ diff --git a/Introduccion-hacking-hack4u/tema_6_owasp/README5.md b/Introduccion-hacking-hack4u/tema_6_owasp/README5.md index 640035e..344b9f8 100644 --- a/Introduccion-hacking-hack4u/tema_6_owasp/README5.md +++ b/Introduccion-hacking-hack4u/tema_6_owasp/README5.md @@ -3,6 +3,7 @@ 脥ndice de subtermas: - [README5.md](#README5.md) - [6.17 Abuso de APIs](#617-abuso-de-apis) + - [6.17.1 Ejercicio](#6171-ejercicio) - [6.18 Abuso de subidas de archivos](#618-abuso-de-subidas-de-archivos) - [6.19 Prototype Pollution](#619-prototype-pollution) - [6.20 Ataques de transferencia de zona (AXFR - Full Zone Transfer)](#620-ataques-de-transferencia-de-zona-axfr---full-zone-transfer) @@ -10,16 +11,6 @@ ## 6.17 Abuso de APIs -Si a la hora de desplegar el laboratorio con Docker, os encontr谩is con problemas y alguno de los contenedores que se despliegan v茅is que causan error, probad a desplegar como alternativa el laboratorio de desarrollo. - -Primeramente instalad la 煤ltima versi贸n de 鈥榙ocker-compose鈥 y una vez hecho, ejecutad los siguientes comandos: - -``` -curl -o docker-compose.yml https://raw.githubusercontent.com/OWASP/crAPI/develop/deploy/docker/docker-compose.yml -VERSION=develop docker-compose pull -VERSION=develop docker-compose -f docker-compose.yml 鈥揷ompatibility up -d -``` - En caso de que ve谩is que tras desplegar el laboratorio, siguen habiendo errores en el despliegue de ciertos contenedores, probad a hacer un 鈥榙ocker rm $(docker ps -a -q) 鈥揻orce鈥 y aplicad el 煤ltimo comando de los 3 mencionados anteriormente para volver a desplegar los contenedores. Llegar谩 un momento en el que todos ser谩n desplegados sin ning煤n problema. Por otro lado, si de pronto v茅is que el comando 鈥榙ocker rm $(docker ps -a -q) 鈥揻orce鈥 os da alg煤n problema, esperad unos segundos y volved a probar el comando hasta que ve谩is que todos los contenedores han sido eliminados. @@ -48,6 +39,59 @@ A continuaci贸n, se proporciona el enlace al proyecto de Github que utilizamos p - crAPI: https://github.com/OWASP/crAPI +## 6.17.1 Ejercicio + +__DISCLAIMER:__ +Si a la hora de desplegar el laboratorio con Docker, os encontr谩is con problemas y alguno de los contenedores que se despliegan v茅is que causan error, probad a desplegar como alternativa el laboratorio de desarrollo. Primero instalad la 煤ltima versi贸n de 鈥榙ocker-compose鈥 y una vez hecho, ejecutad los siguientes comandos: + +``` +curl -o docker-compose.yml https://raw.githubusercontent.com/OWASP/crAPI/develop/deploy/docker/docker-compose.yml +VERSION=develop docker-compose pull +VERSION=develop docker-compose -f docker-compose.yml 鈥揷ompatibility up -d +``` + +Empecemos: + +Descargamos el repo y nos vamos a la carpeta con el docker compose. All铆 descargamos las im谩genes Docker. +``` +git clone https://github.com/OWASP/crAPI.git +cd crAPI/deploy/docker +docker-compose pull +``` + +Ahora desplegamos el laboratorio. + +``` +docker compose -f docker-compose.yml --compatibility up -d +``` +A veces no funciona a la primera. El laboratoria es inestable, por lo que si no funciona a la primera, probad a ejecutar el comando varias veces empezando desde cero, borrando contenedores e im谩genes. Merece la pena. La comunidad ha documentado algunos errores en su repositorio: https://github.com/OWASP/crAPI/blob/main/docs/troubleshooting.md + +Entonces, vamos a `http://localhost:8080` y vemos que hay una p谩gina para iniciar sesi贸n. Vamos a Sing Up y creamos un usuario. + +Ahora abrimos el inspector de elementos y vamos a la pesta帽a de Network. Vamos a la pesta帽a de XHR y nos logueamos. Tenemos que ver una petici贸n a `http://localhost:8888/identity/api/auth/login`, que si la inspeccionamos veremos: +- **Headers** +- **Payload** + - view source + ``` + {email: "man@invent.com", password: "Man1234$"} + ``` +- **Preview** +- **Response** + ``` + { + "token": "eyJhbGciOiJSUzI1NiJ9.eyJzdWIiOiJtYW5AaW52ZW50LmNvbSIsInJvbGUiOiJ1c2VyIiwiaWF0IjoxNzA4MjAwMjk2LCJleHAiOjE3MDg4MDUwOTZ9.EKGBU4uxfpWxlZiRmtRG6m6JUrZsVsEf7xzSppIE9FlbpxTackor_KYdBLZOJYK5D3KRkbO9KCfa4GbnccjdmsSFipNJDZkATa-hC51wYvesaA15f0yTm26sb6W-W5icuv269kkWVaCw_3SCSOzoU3L50YoY0pZH7wPbf4-k6vU4nYI7gVAWIPZloJfKwpjqjWMFA2oZHBFg6NP5YjKLyhQAYdak0fK89vVFadLdLUy_mmEy3nVgfpV2_2wNPLQc2rDX9XA4WemF5o1rI484JjXaq7Qa6EMBFTc2l0xDZQJT0ok9rPs5jPvyj8Mamt01CX13tV_jd4gybsJhm2O4kA", + "type": "Bearer", + "message": null + } + ``` +- **Initiator** +- **Timing** + +He detallado la request y el response porque es en lo que tendremos que fijarnos. Vemos que el token es un [JWT](https://es.wikipedia.org/wiki/JSON_Web_Token). + +![jwt](https://miro.medium.com/v2/resize:fit:1400/1*aAH0mMomx1dLidhoNCVmNw.png) + + ## 6.18 Abuso de subidas de archivos diff --git a/Introduccion-hacking-hack4u/tema_6_owasp/README5.pdf b/Introduccion-hacking-hack4u/tema_6_owasp/README5.pdf new file mode 100644 index 0000000..3aa375a Binary files /dev/null and b/Introduccion-hacking-hack4u/tema_6_owasp/README5.pdf differ