From 4c6b672eaae2f9d0fecaffd2114d84cc69b497bd Mon Sep 17 00:00:00 2001 From: CPol Date: Wed, 24 Jan 2024 01:05:56 +0000 Subject: [PATCH] GITBOOK-544: change request with no subject merged in GitBook --- .gitbook/assets/image (141).png | Bin 0 -> 53076 bytes SUMMARY.md | 1 + .../gcp-iam-and-org-policies-enum.md | 6 + ...principals-and-org-unauthenticated-enum.md | 119 ++++++++++++++++++ 4 files changed, 126 insertions(+) create mode 100644 .gitbook/assets/image (141).png create mode 100644 pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-iam-principals-and-org-unauthenticated-enum.md diff --git a/.gitbook/assets/image (141).png b/.gitbook/assets/image (141).png new file mode 100644 index 0000000000000000000000000000000000000000..c70d393c15225366840b9a0faf1ba80d28f559f2 GIT binary patch literal 53076 zcmeFZRa70@7A=Ye3l1T;ThN8OdvJ#koP`93g}b}EyCsC+5D0F;VL@;S?izwaUa|K+ z`<(XP&-=U|m)2-iRMqrRV~){#FCtZyWzkWIP+?$T(BKBOG;9xIy+cc+k#S77BTRiC z)tGv7QNyfwarq%gJC#<9_;bUwbw(UfWItVB&o%Ss<@T1+6R$`8k%gh(yJ08o3ZJMy zuH>*j{7%;#i`vfMFe;TSt201G2sK-(zVOs(=}#*Ux%O4wxt-jV%3~7|=G4Gm*I$?6 z1Xm%8q9EZ)d(}noLiKm%FrThnwdq7y>g8L5QHu7^I3zP*@60#J{conpO>p}$cx-6o z*NfPxqNrkNg_IGKvBXUbPWD3{bNqL8CP`lO4yy9Jo5cUL&Wtfe|KhU^%E8+D2RXu~ z^W+Z{I_p(eho05K;luC~-g%)P$vnKzzNNcNcnbzy$hM68!r1fApo2|UuL7C`0EjfjWCt2k}8FygEN?dhZV#Mq7p%+pr8oqZTaD@m{Q9U>G@6X@;1bbNjw!$UukivDN)U?=4(jX`~x})IdkOv{*qtr2$0i}apqK5!c0?e7{p*kw&{d%n(OdlQ z1>m|Ew&OrAQxNq}WInjK0N}ud4r?ith1e*&^`9$zaN`~xr2j1xSVs9XMs~X3D&n7d zpAUqXU*P{L|5r7WTnIVmRzx#oiT|ybZ*$%Ce>)Qvz)7YQyh!c*pYD+W4S&PbfranS)Aj1 z)IN9nIPm+af@=Dknbdocu$3MO18gxz&*J~#IKo--o%d%E4Vf7ANf z$cLT8Wt4rL{Lf7|2RT@AkbgI)*ppIJMda4Jxup3AwQJ0xkwnAGgV~~J*2O0=uS69( z*q_~B=qKwZM6%1StLn!OP~@vq2a;7p_?esLP2aJdcHE!5^CNPdiQyws(jdLw&2=|? zw-Yb=@f4U{QY}t(aq^PbZwB~!A%Rw(E>jz8^N4f7+w%N>6(VvSEw&}YcPpV$= z6M12SKuZ~EYt3tZOH8OiD3pqLb6+~{7~gxWhvw#evFMxHk9^|pI_>-;!s0UANv{!a z_`&o3xVbma`-G6p=d8N{%_7UXtY(17CZszUDI69aF~p(cmhRiHaY07zmWyGgUjL_G z`2i5~;#eM3`dmm72W90h>$ls7UlYCDbMK4UyB-upZnq2wvXPFTO;2n>!nk2d=4JgD zkG{uNqAb_C%Q(Mfxn%*cbY4Z?CIP}}=QkVCY(1@q)x;uCH)bsO1hLfdLUpQ|t*c&# zp(}1nEF|7Xwd+s?HuTXnOySGPnm!zbklI1AwvlLj``;DCaj3;H9B*|!w^Q4MMB@K4 z&cM7dnB?wgwhmo-3!5+PZs|0gKzs5%-f9Ivdwg37lImsfxfmH3X`tZ>|36O$7}mWt zCcQnPe{LtrK%^zs!*9ybB*W0&DCGIOJX>~w3N@%7Pb0*@eWg)>-AabUAS=)i%Oif~ zyyfv~saH$Kp!BR5&F$fQP=|xmNl&fzOWTQnK~&`0efxjk9S92?3-$TU-QgFl+PzH6 zJd|wPI{Ctr7bjOM?nct!qDVT_@*L;4#w*oo!^v^q{yg1RLf^C*mt}qU*kioV5O=mUmUvAX%P1mrGIf@v=2762bg(s;voGwFzv!f4iHH zxz|@CjlS~QjkBt0@k1kxh}C4VY%kCDoRPmle*v@I;|_198v5mO4DZ>+4;>?|eq&G( z+THKN*JYU&SvAnNOrf;t@72@GiIA(IZ!&})&Uz2VhY7(fZbE8hdkBe$m!Xq2Mi!Z1 z#@;^I5&u7TbDeOmH!JRI=rhIWEADDeVP z?UwpCSvJ*`ErYP<$8{sD(?WsdoUM8mnbPMr=D9gwg^l8zHJ@K&0U-&kt>XfRR=%;D zF{i(vDt#{v-n8bM)`yD``s-zv z2{}JcN;Itl9U`sj?2qYncD#w=Z0PiH+1@5;N$b7guMw$V@$uj76(E*K{J1->rD zTrOI5q%FVl$^b8ZKH9gtcW$^e%a*_FCzfpMm8ejmPFVZxq0);(Ykv2~yy}@Jz`|F0 z+lv5}C6y-ka+7+sj&BJ;`wS+I3SDVWg_-<3)vNjbq>a9(g|@-uUK{KEMHf6KO;1hv z$!NPlclMQpuNB)+K{m3aCP6r;bcob_xzKfXL-@Q8*QNL{^7qAzhKkZJ)=`6OpZ;S5 zf}^cPn=dR?^(mn_nI(3WN)#8W_~BoV(Tq2dR1|DHjNIaXZf3`{GPmS^W>8HTDWy%(3|9OF<5ksu(nl==P=tsBb3$1*ojxX4nJ#Mg!OPB@N9)H zq-+NhqU*olUGs5CHQWjXpN2%LEicH#+D}F?RaeyW-H-D~UM6P{Qjy}(8HiH0o6tq{ z!JF;`!!?4M?{cnryAg0hrj-R*kTpsKyBsC?0Skg!3$L%(HLsM_+hOc5Q6IdtE>@)c zL|;pO5CwV#D^Davl)#**vWS8@kLBcig%K{y{g%UVk5D9MLChac@2e`$a?!VI^UZrI(;F@yi;Bvk7Fe1Z5CEjhUBblnW&}Q`9x;@@0L}tT+u-PetiE zHa$*wh7}vJeT&Hf;*d!(&8X%G;=;;?<25L6z!M#nC+_{?9CBluhY+-CNz(* zb^6c@y#mt)8xhe%2V{^@PN|}qlkSi-^y(C95oPnbMYC6hB4t%Rr-PvpE$#a4!hnBU zx_o&_JR=O+kQKy{X;xB8=@0B3@2OTQ;m5o@oL!Y?!ttTmmT3^poTt6?UEr8_E0m=s z%VLo06nf}Dn3O4hF+l8)QZ|UFzz?dLG4K{~!`~ENu5)W{WPXM+xk8+S^+8RyS)t4s7>me$LlrGr{$eI9>VA#y_1+X z#A$mPefdkvBSY=hS-PtcgrDXqw_zpUF5U#X8U#gh%LKu`g(#u6Mr{1D0E5FvrQ83xCIl&wd)(MzmP^N8P5v2dxZ5N1=0u#e?aZs&{u!=|ZH=-FU$P~anu z)M0Me$(2ws4sZ`Lj1m?$q{_~BuiN5WEFwDveVWmF<(}`klerJoFeLDQ*d(7Wg-?qY z$i|v}dOY=?FuQEseM8=%9d^)1)s&g^kRdy``o-6=S#M zIfB5fQ)6!4m!yteNCO15NUwcodE}pBRCkz)fbd`RY=pXREoTa*wxlO1iRF{|N^mkr za^FVKhs{^bxi^kCt+Jr=>Gzk9R=Qg`xbaRJQaO&cgBqJ@;C?CzO3y)3_nC=H4TiB< z%Cx;I`+CK&8)22(+!~JwsMP{&NPDSan#o{Ng-PyioFq+b-SO<|u0b1Wo9%m!+bMLU zZB9 z%G5yeoXy>@sDfu#I=LD!d776umXg(z*7PdYeI3yKJpwjhJi)9~@GVKG?fGPZ6r%q#Fn!8ZEkFq@Req& zn+#5JvjSS{OcR1p?;%CD(KfE87V&kNZ%X?2!EGr=ALK19M!f`rRY4pQnT=7ZUR+T~ z5*8&4E0MbDgcx{QnT2)juV`5jF$ltCBJHvmp2R`=TBOJ)dss1Y#SuiuwY_tUVSyO1 z+p-olqw}!|6uKfr?92mQR0>Lr=O+3_hL$}PMp7mH$d$<2anTG-1GYE;Ld^^$bCfk3 z55y%}kR1jQi^>@5s8`>mF&X=Y=N24~7E(@BK`$JV2^OxueUf)KMlR2FTNI+VTUDD& zEZC91+TfZN-A>iX?kWmz5tjZU+uC?}QTS0L%W@cP-y+RRqkVLT#ZN}OCB}F>=D+hK zawlHg3RV`S7W5p|_p*~ARiZvD$xbs7svxQBC|ihPQsT*vm^T(mpqjk>v9DWa0{P9U zh{t1Ys>TG5Sg(Z$%AiB^5jY>G8F#74#9f~~zF|h69a{Qj^mLKlRi!tZ&?`&sTOw%A zx7#z$R>*AbYcx?&u`$mwYMWIzu~WUbm`92sZF0Wa@N;B&%NO^>_emMg>_NrkD-I#EQRHulb?MwrEA1MMeMHTH zAG_a-Q`m1_eORlr9u>)M`)1Q5y#00EAO^f5Uh&-^#!00*U0Qd+yQDu?$sp9gP+(t$ za#3L=63>+@{`~vw(2s=_VeVlNZC<^foBUoYV4tb(KkggS{KXCErgBPwg=%CXg z4jrg7%9X6-Qyi*@^LDYBYdNZ|54o(uX4J>2ciiCHxLmw0vPoRx6S~YKdQ<ynEB>_=t;|Cr@$QPH8#y>ASFVV=+#~ zWYYq)H(8JSk*-CAM&4mo>vLbzBFoOnqlY)nu)HbXh7)}Mh1U;6aV!Z2ECN>Uzy=5o z3zi|00&kfQw5We5T09SjqdQD^ph(F~m@SA1ML^0$7ue=_Asx*lf{t(fR;AGh_wZf8 zFV%Fu@NNc--c|1Vx8?MLRw?4uQN%CIi)GSCMpZb6^X}~J0;V+%nI|S^yD8!~e2RFx zI22W|A215Gbs};C~r}C_uG*LH!8IuBC72Z+_fqO>bR%KJJ!cqts@O4+>O1Wm!TBU6XA-8h)z^u z{qu`$I!Y>q!)J8=b7x7PiDqW*I%&{h^BzABEjp)8f67qz+t%F4vt~zNNCT#CN+TxG ze{RVjj|;0WP=jXjd5(~!7QMVjv+l3PfCXMVT9DPGG>0Kce(7pb!b>Gp?N`;@M>V|HeTIgi9r~L+G zzstNb(>tqu<`j<-F5dyUarFm(Tg?Q{_s;ceF#=h{PDqAsOq=4CJ%+Y6QXmrNF4fOR zj(81k<_ak%7GP`L91JPYu=c1Po~}FRB+RiAB(2oT2?*+3MJ&qpOt!EEg`(olWbkZ8 zh)E9hXZCB~&%6TWn&>uwU}gbTzt5+JH087<*re9gzJ%7e&j|{-0|$R(CqAmKP=DZL z-p{b!ngl|L^8%Hui=RF{d0>aveN=MS|h8*cfB za|1=;dosJv|F8XCt5!?bch5hvsUM*c0rvXd~Nv<&Sv)8%UbD z@jGLht(HTW>!G@sH^`a()uRY@q#0a=!KU@^dyH!=JtKnazuT-l3^=8%;EF)6 zK6YnjgBm|>X~%{!)L*AiSkvoHh7Of9O? zvYQ&>B$jzUOc8b2N5dd(f`wVXd$XnLGU9zT$SGI3%|N z3=L6@L+1EqijX6kGm$+8mXsC#b&QxLPLV!nT}lQKO99>q>kB)vP%;}MucEFZ2q$L~ zwt9=W5=WE(<^n6cyGb~$jffHvCj;$eezMSQKcBt_ND4%e^R)0GM3+29t?I?=zH>KJ zT24LU8hKvNVv&WTrdJm|dL*Dt&;rCmj^}1O6@Ur`ArHy+qE( zrj--Cx}_GJZAfH(2oDd>U{_UVZE*NiF?Z#)$_N}ZH0K$zeL6cBJ{{|cs||Qkvi;n! zpl$#x5pCGjs9SXH)op zf1$^6&8;(T+3*!u+VpbG>e6IBe0B3D=F7jQ7)zw z;pLik)IIIV|K%MTMBrA&JqV<12_@5mSzK*P%@lI~=k_Hl0uWN}8Ps^$|Cb7+zznos z_>q*3<-hx12C%%Zc9e|f?Gzf}>mUt3PO>>+c-bsc``tVUW?;$4B5jPvhmdP~HHZ;1TU<2q!% z%|z+G{Cj3N09Cf*+bam}0dQb!k;ltvyztrqBBoJ*o%*0-)&1hN;@W-e-<=iPM7|j+ zjWyc=AbmK1e{`A$aME4?lGo2@a~dF|&jE-w*xpd(e<;yo$pU@Ccpy9CvTa^*%enxv zxi_|7x6_VCLhqds1Oi}Y6WQf%hMB%tF#x2Z>|bmnK%5ba{CW802#{>yg_7Z601GOe z{+<<}6lwr2)SW`+`rt2~Y)!gAKmDEG!@2D7eBd8|h*DW&c`@PHOa-H1qBsaJWMlyU zQ568`wORnDqyL%^^}jhZ`a@JvudCrU&^vkl>8~NhQvPgvN7OrFa4mr_089X=7mX7E z!XGDi(!!${4t76ooYUqN5#o(7I~gK zAYj@Le*y2r7ky&S4DXY#y_y_|%pfRrL3U88C_chfL;Q!`}#hF_lAf z*$CC_?EpWy4ongTTgQ#*%~AaX+!DWKuIp?Kz#+aG$b7v9(7&(kznu@90X$-8yvQ9x z!W97gve>q)hndt3(M1>Ay2P)d3koE_F$46}-7(NXG=L%VrBIAm_ybIQ@%8!IGtPXGRb5F$74-b%0bu zrpXz6Up@hGJ+e(ztxTam0WqSk6+k1SS>`y&6fPBEVv5`t z&jX|Zy!BY|Gf3wyRs3-Rjgo=`ZhzE(f*BNB%0F?NfL1y(X0(1nLp*pKCGPn<75sfCn1rt?dGoeOco>l zH@)ON=|+B)kr~dzZ?rbLx<+FD0PMTkJ`x&wFiljLG(4etvgp%!{CZ(H8MMYY0y&=W z5sBQVAo!Nd`>0SI-C}P5(nZ2t_nnFe)5-7g_gvs{-VsbI0Q$bPTmlI`)7u)6IQvQ~0V;J`X$x&!2H!oEg#cZKF`TetG?RKZ zz`N`J@&pKp%9(Y5)*_a74n~Oi2D}X_L|o9cXL1Z{4dC`aCy~3QlQ@5;Gy!Hx8?g%t z7{92MXJ9lo6!}5JqGTQ5Pk)pq0(^k#7vmXZ!0^0>BYGeSbY>C6D7`BJf7{7JQ~+dL ziI(s^4x#yPdd_{RzMpqX0No9}_DK(C{%-ec3yaQyGiSN_|3#iyXX; z-wsf-Wp@T?DL8s$QxNQO5Njmbw@8rUkXgKN*~w6Nj&EWZeYgW{4^63w6ZMFBq#UX` z@3V3v`&6i^0s8iC1@wBSB9?ggeTwLh*dtc!;0eHt62D($`z8P4#xc?4%EgDVPTNkG zA^^F<^H3SoPNeGS-Mu|T05k4-Xx=#?{o}m*kwHvHJgoq!?g}c9OkZ#{5yI?nE4!32K2~M-_mFmZkKBb7oY_3zp@mD?tzo8Dq z?ivGB7x^8{*?c01R(f@{D%1wjr_^BQGkUL=cFP2t;_n|=0alD>Z4*gvRc;zHd5|Js z7Q{eo*PwQw4G~wjESgJgE+#2J1AC}Wjp!NS*4U~V z^UkO$O*a%!x;6VB zwP086ED4O8!X9k}ycn1d7ZJ3?5Yd7_c%%a!%{0hG#5M{)qhXg}oT~4Ab zL&FKM$$cGB1SrAJ14d6Y(lY7udxFfg*`E? z+d#pDGvFW*5>sBdE$Rv^kRr4LBzkIhPr}0az5?r4bK-$YXuaS+(kKS00*?}=OQ@h| zfvt7O1?AfUR}|?fA=8&{qLQRT;L5OLWC>$MpKkUo^;+dlH;HMG>V$AQhudW(raJxo z!N&7<@1(%xE(0D0kSXa__%a3(ZwEA7)K)ot<57wd*?6Igh_^1F$$|J>0oz?LQp(;; zg?eRZvOAa_XSle8iHTc$2p_B=NcwuGB+6JfX5LPNW{jQp-<>)f*r_`=Qov+&6JW>1 zfGpSP?|PWhON#X-X~OC9I(1KuBlt#$W^OSx2HbQRL3NidO>Y%rf4(s5BBX8N;;@>e zNL7spa%wrOZiBpuq#nJ^1@t(uWzj5EAO_}7eNwvg`95_|G3&;+h$z@?!Ma(dyXY}W z)aGb}XoJAEx*DP5e)xAls2cR#l^{;QmjjX+*BP}`&ZC*yWld7sS8d0`-umhlxJaX6 z*zm5!c$@v}hRm{D5_&S>y{pC?1ZR3XVjIT#0Sn5bP?QmgoEJfPQP^%;PXNYqxCyZJ zq*6|rnJKyw-EQwL)e=S{sA@b}+KbxY6IGhd{u6;iFyMsa&KcfWfcTCe^4`_nvFX}; zLeVZXU^?Xt+^k_Zvb^hS zgJ>w1#Ai=x9d0}L!@S0}2jvUaU|lgAoD-KH*>oZKHfANtsDeQjuqLUu@2v_$54@b* z|8Zd4SbN$7)OkvE_(oEDFa(*m&falf7?=TxLgV?T#cP}DuNEK0zISQUCRq;lrq%T) zt&o0}%HhcpHsDewU*og;5#iGut~x6v0NY)mWv3?X)r}8UW{oY?1}QjeN00?iL{@uB z3B%e@^T#MTBpzi1efZ)09f%`zqM}2Ob^aM{H4vo|VoLp#0mJhR%-R~8EZI!K&>{&{ z@~!mPZoPeHOU$ywQmbb=SZ3L~PT+{B))cxCNBZis#JrBUeEnV(=6DgPjh&e-GdJU^ zB>(dltTrj0RSz@aJRvrcIPO6f+2Z6TV9Vup4dXI9ZNJu*N0&{c?*C4G$rUq+6sRh| zO&tIdl}4>L#>uBPT~9I4TkQssH$hBgDo5l0R%&%&SI87B5n?X!vrE{f7L#_JYI{z$s;0_v~2;C!Psv==^1%!ZyCoxwH3OKLBeKYkSm$aY@nG6usQAU^H z@MNLn@Ak+W{`n76(ytp!+zx+SYJ#wk%xGjgJ{1Z=#{~IT-=EVaG8hf3?WOKIq=1nv zB$cl;=~G@H&J$GVok+|f44_-UZ+>V(2y2|5pG8^IoefCv!rlQQI^qgUtSiSZ5>j;J zeOX(Y$#EiaiN=0>{R)IAfgVhYEkN`4Qt+rIm;)1xAIg1Z^rt4~WpR){+OJentk?Iy zy#HB{4+yPVUsJl{3Hh`QDKX;edW%6b__zbJHR>Z(X~&<=#mtu&76QA};g?tmZHZ|i z@~kaCgD(5treW4xqEbRFLD7-867hT+5jR@RtI=bxxsS(LF`G&+g1h+B0=m9GGv$>F z_g8dTj*&0R;#-VG2r6#3*ZW}&83M8{qdc740m<8^Lf#BCP&n+?ARz-NO$L;b^Mmrr z;wY7^-X9ql7;O@^Ms9mrM_=~HUP#AXT3nIj4-j&a9(kGkvJ%-5PuVwN>I3o6P~;W&JXJAtn;Ux0d4lYe=)ycHeX%fTg4)T0_RHfBq_DCDYG1jbINDp*jhF3aT;rPUf{oY4DNac&{cvV_`f# zt}K$PMyOklB!#-XxF|oEER6kymQw+y!~#|S&noN^nv(3Aj}bTLO!zk3e{NoFdL1va zD!!MSJ?PUeNOIgjFKLz)etTS;$?arum73$I5AGFy{pnR3v=k^|LB5e z#ej@{mH|m6^xur09t+6mRq*O9q5o#|=+7B_tn-=XzZtzRT%f)1V6h6ta)_cc2wz`r zq3PgXRHK0duH#c_s>0y(&VS&9OAZ8|%F^^#6_$hl)(U>EbsKu#@Gs2Lj`j>W=mmPY z{Rf)})RqA{sLe{MlKpQ7N1i+Qf2;aGVy;?4&u{k2^LyAjAE3uA&k)KwpwT_Jf|%o; z0s3Z6Ac_!Km|MB{1_WW@I)eHN=O2Yd;#Vm>m5+O!B+@SOJ{{Vi!`3otm*slYBNtynkR6&0nax;Jn5PLm`kl1 zDb@@k`}C#5t7Rw4h7mVB7@JxqWXYkkJ#9&b^znY}4@SP+&P;5@G}D<4xB1 za%BXE_TSn!Kvy*et;@gO0s%k|pdz2MUUvoa$MY;&nZ&RURHV+zEYG6UQ1kf$3H&;s zn?n};^Wc(Ov8)u*HO9L}V*EW@dO^f7MNMW(K-M=%1W;n00YJdMujL#&I@d4R_Dt7V zz20YW*zHDqoR~0z%$MD&`}e|t2y#71fmIEo?OuJIT@daT*|xSH|CZc&m1l!z(7U`N zXnhq(oq9fe`iyT2b2x)6RHH0Ov4o_|F+{Tth}4JCI|*HF0ad|?W~8~j%merffKt+s zu@~t8X+GcWR&p;2eGV4BkiM6H+?%--%@Kmvr-9_j*^M4NAYra!OTa`Zn8EDyBJud*r zSp9{)0m9bL)~&})OLfZ5`9p$yN5D212sr}QcpZ>3J8a_rC8T>)&I3TE%uB(iM4t0! zEkCCJ-E=-&{o1pDiWz{`)}IxG9)S2#<9hj7|C6P??9li_dmYG>R62K4UyuXFc~Jul zHXNvi-nMDMqSSPu?X*MC7RXk!457h&^kp)&EKHU?(ph~M$iIKOci!iw)v`Q3XAV*5 z1R7}(DGtD+XOohcp@3YN`T-D8PYGD>-_LbEy^0gQ()H!)e3ty_T9>9mv}5*`N>FQ; zK0E`QNZrYSfCJ7zVpHGn<{R7L^v8{f-ek}{ zqpRSic)1&(EBa_fiWt&u2S{U}-3j8E-Hk?_ekOqE6}^6xBRXwbfvvp+e*0&4aB3g{ z@EJg3ovNob9;9GG_&NuJg3C4{%4Z{zK5RQpUwH*cnCndd+2viVD59V~XJa}rC(0f` z9{U^Hi9Ti=(8|A71`rGophC93nSG<72LNkiq>}`Fgx?4eE+R0@0E}%8L_m}N?!z1O zXf7>m&ov-tO*JtwzJ0ns?S(}mN$@Hb|Ai(g<3~wAqTkvjitZQsN?X+evn<3rO+#7u zw5du= zSwoq>G%S7z_*8}Yaa@UdUOScZ7QuTMDQ8yClJqmufRGO`4uKnvt||6jpNDNWf3@ak zG4;If^~x(9v+=GUv#sX}mP(mH?75uqSgi!AM@@{R2b6c8diKM~{U!wv24*GzxAcD6 zY1MOAy71xJ?PFyb>Zhu@D3Qti-T-k>%{dNv@DT9fMUkr_sg%FgId>HGafCSjfEj@B zVgQ&PxCQX5jbzv?>)m^Q*8V&iJp++&!C);ShF$=T79|1RGgy*m5jU66!6SgZeZ(a_ z;Kre#W6BkunXBtyi0cK#rE~5_XCRA9`%>V(rbE+_?UL`7;uHT>?58J#_mP>#dr#?iOq5~`34FbDNYL}0|+??2N! zaED|#06dQ#iVSt9vXe7M=SU0`TN{E&%5ht?-gn0#abAV1v6{;(Z#NOv(en2L;PyKYC2)S6XP~q2T^x5`e2x zv%~|o_a?EM$8}=to1B`nsJ<`DVYF%dR;;MGb}Q7Hn6@)~u(2ShZNomj_D&->M#0i9!{9N%ICu?bNU z@O_WgN{UG?;>98Q{;MIA?71F<4|g7VTK{;r?^0BiV3twCyQ~g*x(|0bul=<0wO{$; zPjGFBcyW3$IlhzQu+7cf#>^{)XH;4QK3z%o3zy6@4nj$BX-XHOc9x0i!U=*jFzVHu z_R*t{kuiPgGpUzy8C8UpK!}^6&10AIg*wRbW{eF=Wo7KwD4K@sO+3uE6){2ai^YQx zD~kv@WlCPiS?Q8RMCu8WG$%qJZp3APe3*jN{v!oHu)!l)j74C4Ry-re9YH_8P=1fk zAe0ma0N^!aIG8sS+{4h9Y~KnLl+L}SHk*`Wja|>D5i`t(aKYHXx~sl7{H{=81DaYtVyr6 zf7zmm{&vCV7qIO!u)gf;1hJsy0B_1Iu6&emnNH8p%QX_NAiG@WvTF15Lip19MlZZg zNr3}n^Zm~~&}FUC-sJ@#O6Uph9-9?+O91~eGjZE`N8e%lO^eTBi5`u96x~TpX6Bx6 z^dnan1rUw3iv4@=IF`e#LIHW#H1;DyHaS)B(~)SDyEI^>%r6mM9^1!+RQ9sY*O{t`}ze z1u=E!OT29Z>vQ|l2Yuw>*5{W$Y?cyRrPT_08H<5%owLRenSQ(q#q_Lr+JrQHK)hcD z30|6tIxjIy%<&A(c`row1^XjxZF*WQ2RN_f4<8Rh#> zp|gj}UQwvf!<_yEThv~JyrTB;Ai8e7SFu|&Q9HY2Yn?1zgD0lQ5@P)QREF3N&lCmT zq#IIj566jE=olj+i(NP!f`^M18z}Do(i#<*Yi7Ngv&v6<7X;X>OD_A~#4On|za;a6 zL`)Q8NN2d|Li9c!OcTY568jnXoVaa687KAdJplSvGc%FUjtrfIPgQyyjUi%jVY^58 z6Jk1XwkXM%wIuF;(9NYJBy|G81}L8>yc7e_CeqMy-^hR7?9&v zkkGJ>78$6Z0qW!gPzIBb@0@5-X=pkr&0ViXH%UceP4%_LnK!X8+bRe$q{$^uGjA6! z-txp6oG)7md~`H5E@Z7+mVKmifE+Q{?_zsOzXjr}>q-w&Ugk=*PHWK=?)nz04_qBZ zjvLn?6b9nDwjiEB9O`3tAjFHyExp#VHg=S*U39Z?TzwHk&}m(st9_4m0B464DYo2M zKoUh|gPo`iCHRBfsceK7F8@xqbqfa6gWwG%)yNeAxj9@jd`%K{D++`aMbsfsqk|nV z*D$ie1ot7J(hX%$T_}l~X@)g^jr;;imDAf}(u+cHIN;ON;&I|z=FK8cb4@T+?QEfH z7Y|&<^QvF}^?tUTo5XP|kG@!D z3<=}WM^4o3GVU@czE$ZD-h;vFhMrFuW2dVx*vbb6;+G+^I7+2Q1T5THCm{%UY?R{$ zu8XTklNFL#VAG8 z@}}eBb2V(2?CH3(;uv!#V+*KXcrT4fWt$9S%g($^Bc0@=`U8p@^)sn{qd#n?fc<%Q zOdI9P)XfDn!B^HR(RLDpAY>u))u9r2MW-~->*cR#&E!@jGx6+_&(zpb7vig)VJ5Fa z$GA{Se9-D<`h_-#V^kCy*bnTqjPUN)^B{G-Q42i3NtZWE;{|+;c@*;&ULh1?D=wE%gki3|POCbFzKv8Rm1?!;ZB}#Cx?%`KND@N4a^f3oT#li>WcWIk(RUG_({ue-HB4nmpo?wfoO@H`; zzJ4WfdAJ}ez{ubOO-B)E;fJZ<*ZD$lTSL^cL-&xQ3T!%xdja3-C8RPkM*Hv7zIxQRB}SCF(ty?8M!K(KX_Gy*urLz8r1!Q{ z@vGo%2yE4yEpMcMYCXT=aW76N6dAPh3JEws}a_hB`M17#IQ7D%-mG8P6ye@ z4d3Eq*O>7q8vn)B1hE|>Wlx!PCQ_*su*KG2wMVt;Pk8eZ`Et6C zdt8n=U%&rHzQ6~!5){DJ2zhx#R{3vDyw9Q_hqSic#s7ePd-wp@w}(G3to}EY4fM-_ z>Sqkl1NXmrph-bt$)nkFHUYqulVr~*=Fcr5cHYmPU8WlV>G31)0Wyy{7;UyxKo1ef zX>|wwU4Sd!1ew@1MSv2ja%yO6-Rke(UQjFlp8d*s$i|kY^6k+`2(6vq@HhHRitv*C zp%H1%pO>0$OXiUp0f2Vn&(R^Pw|&Xyfk)YN+KOm6d%}TW>WE_x=cXAaE_e5Y{xP>N z+Vr+;jzX;(6H+kVj089#e>Y+}Kl_;$$dmGj-23vr0|KD;bJ_MtI~mTSFC7thE%5o? z5+`2@r}8NqD3hO54yjDXrdq_Hnx@k#%s2M*y^yUK4B2)*nsWT+U0;#dM08C~s+6BY zL2Tdocom1JvE;9?_~DHpXQ$iv;=Uu0=b*lR?chR5F9cvr zABtaO)3~B+Cd|`k0no+|L_F;}_FqpuFWEu>`IMnuk#TS7_n!tU9?J&z*j*j7z(?;h zR)!>~VO+J!d9)b6$pj!)AI^pD+j)h}Do&q)sIaeuw+Hxp?FX_&DU z$b)3wRU)S7uW$#L-xyC0F{eZM9k*DuP1xzoITbO5IkKME>oG|I!wd@EPhkhwBEQFP;+b{jZ{5>nZU(&>Lte?l@g5ueZK<78&;3X4rW0Mq>|!z|94nu^xwTQ8Jx zJ5XG(s!76gznU?)?o!Vq1JTk=Aq(qpkV>EVR{c*GHgzZg`ABigs!59tfK*!jijGa4 z61j=no&~<4l#4z3e;9kKs63V~TsKH?cZcAbd`NJ2cbDMq1b2eFy9T%5?oM!bhd_|v z?x$J*$~xnmu`l*jGJ1S;cXd^F&6@ST&+OM%or`CB#rc!hreTs}EkEFN0E`0!zzLkS z-2q6_Xx8_zrK11}g!SpHE&{{Ad{_xrok9e=!7L&w+x!jcoqaQ}9l z+31bUm@PYF6=dgV3l8Q;j#|g6vVoE^=cX z82Kl4ZxdCy*1iy9E0k*4^spK2xh%uRRkm7Lqn&ZynGGdugC3?&u9a0iaOajz(7nUw zCrhmJ;`lU{mcr_Ds`v*pBilXVR8HUAg>?h$#Sf_hl!G}1p7X{BuOnL0*_=xTqn`B3 z3YN%8e+WaB3)6!r4Ujlv2V%v=lEsB)^D`W$B|`T-_jv~L0-D7GhQ#}fT)rs~dm9)t zqDs|-Vn~xpOOP^02y;SQ`^U0@v7s`WIsof`DyAkXAk?wE03zT6mlE+%^&aWII3v=% z19bD4P{)J^8TL+LPVn|*Tq#nBV(;W`idf)(NnGgFb|oA4WM6tntw~EI^BpW(?t%m; zsy9=9cExi8iRe&uA(?#iIl7I4DXKTr0;#_fDTG(eNy`!CG{?C)Ioh7IeayJlPArmG zc7Z|h3axYvSdzZ)7UdZxe9I8vU5$Se_6z}Bk?-edQ3!=$Me0}5!gb}wT^?02;~><~ z*lo?kSI#@M3REYsr#?kXQV0XmNYx$mfx!&&o=M7{42tPg@@Zc*)N0Be-^1HB$K*r- zl?NC(;kr#-d*D zzfQwKts3%2w2-S7$G>H;ngJ~py8h34A^?TbiWdlyHoyP*u9AInFqZhBuHI`W#?E+B zkuN|(r|?IJiaMeaj`8P|pzrKY-!O%FlKm7O(X$u}#hT->QwuD#D0EOxg%5LWni?CV zTXL1oFH1@3b_U{O_7fw<9aruTn=rzuScOR0Pr%0FVVWa}| zS?#PS;p+2>*E*;>0uTk$_@NxXXX6Um<8kAivA9Rd$+kEsQ{LmXj@GbLh!MGwKTDgw z`|7(p;rb2*wFC*H`dT;zl2gP(ESQEliiMsN9FHTw2Zw}Hk}P(eoC$qOY>Nqf3v{dm z&e{`LIB|~X-4~u6E+pbWn%A#!~&^_s@zxl zR|fVc28p)KZ(W}3rQ6El5OgnI7$Z<`(3n2y*?<1DW^62<$P14wx&ULckfKgsKHc0W zY#6*1v>ioO;Zp4}{SICH;R6V}MB)&V(&T2zRE{C&pD)*}PYN`Y57~uTL|pqwYmbq9 zVLM$h#If^EF9L^Ls}R-_9udJcG)n+_0^F~(s>RqMk4MP zJuBRp2(t;$6XO(C#8!b$kFp@?wYc}I+{4b$-;C({LvsZNCX9Mv* z5m9PHiNb4C#$rdJ8;Q!0)eot-W>2K%lcq2E`cUPDCZTplNoa3M+pBnSZWe}+5)=V} z{0VV#I)PD+BeE9_wFr^&kPwA=(r3j<0d{$rGDqQ-h;QJ^NgV*$gJjhfWk~V?HjpE! zG@=y5=%OuwZ7d%ErXQP?qCT$&+m(b0fOzOt=EK(Ph=Vl}Ut8`5?0>$)ghIfH=@7Jv zCIxNF;coT-$N@riDYhC;zq^dxHmjDA;T&48#k3qxXhb}tsrSRWDKK7HRy9M8_aacU zB-0I`gZ%g)8UQtuUl2R{buWmemb|+L;)Uc8?-aGNmIVZ8dEajfNDtSSW+mKH(c>mK z!p0Yn9pX#6sf4YElm&KA7JM23_f}U8F#EbM^%Js(_lWs8xJ7jBTfm1&Iv*uz#y|t} zPp*`m^1yeZm8EmZQX|!PEso8(xylGN9sy4vMbj(Lfan?g3Ydi~QtgqULh2*s^@Ky$ zdyJ^i-57IE(6EGGLl)C_36t#9!vc$Y>5ppYMKZfrHP0CnSFyde zK}hL8HL1{AD(wZ)nKK+s7_88ZRiN8*j+|(Kn;gXRrgo$hAS7KFmi^3}6CLg;nfc#@ zm8&Ckz9^V2@|@2bmqhWz+#;GsnJ_68)GY?zZC@5%SizrJf6`VhxG0lWnQ2; zx6|)SV93*G$rpWY9RA1K(~Uiz2~yZ;7nPJgqB79W5jOkpTQ=uYV0*_;p(CZVuWskR zw(yI1!oe~>XMWI+{lvLOzYdCK;f+l&8zd}hEk`Jw7UK!yT4B#zttE;Yhj4ngr=Fc45Y~m4Nj!gMtv7&tZ4^xCJjosBtU){LdHzF|hvrfa$LyxJu9rSEpM=0=)xOmK z^PIBMIY;uMJCcy*>|PgYxdG2d@Lc+PRbhLMew)%^3g>heT~!l}TRqA3nrHru8}q_c z%1o;+3}zaAP|;XVNL3T6kyC!Q*-C`la*~;5HoWW^b zAIsZL|FM^B<>impdVOro_@(Z3#X$r#v!IF96BH6b@qr=h&+^=l-D^`RDTp}VRcsJL zPDcT16m#xO5!g&sEPF&uYT%eMn8v(@iooRRSL3Rj9g2^ZqomV{?MNZPK@nL8)fbb+r54$jSaDP=bw(jm{-BWX@#zcHU^ORQm5(Yf`1i7{hE)YT zB#2Cc5-E=SvpnSTC|*dzhtgHWWsWyBR(aN0E$)*7(B}9Caga9l_<7!%?FG@K1RA2S zxmvklxgd5BlenbWV?MlKO~ALW9wp^6{m%|69#K2C&Y2-Q6)j?ieu@m!w|}rSpMbfQ z2EIsE%Q|1~Q+OF1^5ZzW>8!X$dbVgq9_w}!^C}V%w>my81ShkgcY}X{&7EW0=+)v- zPuzQH1iTe98=+BJ6p^r=B4@i%e)b#$q`2;Qzr;K9{Se5dL;(?&y`E_>Hfd-H=y$y& zM+WW_qkY1ud#tC!(uwS-&*;edRh6%!%oEDLb6E-vtXCBLvG}AVvLHn;IQ*%5OPk`W zP!Oj%a8>jTPJp!mzd8b`W6J2f-twYF|D$N}Tc2TzMvmi*QoCsUp4|oIoBfiS@2|Jg z7mmfNvJ4>v7g1J)I+oBSK#urqjARH|Ek{IO79s#igTvKX%=c^V@MqnOY}vK~z=z5< z#xao-Rk_X|<=X<;g;gXnt%x^@cQSULkHdveRP=>AbGLpM$JP%q$U|z|^exV29aNkI z%nKE_0pTpA3WsLREO^9T@NRiN-+8J$e7m!`h4OIIX!Xkm$4(5CqP~S?+tqr3&7TU`Flr6NQ2EFfP9PceBriT*)p?Jf?o!U zz*sr@Qqzv3>8Zw-0`3&YDx;)=sJdA8@)|okwSVIFvhA>$M3)IBs*!?Ox(C0~nsNBN zSQnXOSCR{%O1~c!Eb3Vr?p3KCnSHfma?aZORxtx1uGs_ToXF*JGu_p@5uY7|&zl-? z;UeChD;=Ov^n`#?j6;$9>uOYF6DXZX498g4qmr)C`N*7&_3~%*e0@_Q$>w|)k)#KO z)=?!CH*+D=M_m5^JMS%+VSaurdC5JhpM=xoF)0Cn3?EK86GB&DDr>DmgUC0=$a<@H z(Y=k2rB98}x@U%1q8c;$HODiKoW)WgC&wo%d?P(W9YX2w;&O!L_zrd=yiXA*wcd^v zIKH(lV$~k4!CQIS=GctYDsdWYXpDy+5NI=#sY46KOAjSdeH_6S8)R|xpn8RujT;l4 zB|*X>RB$u%?1SL2u-EYgxDB2w{8G3IAFVhF+rKf4GBbCImgMbDn|UG>A}H=_$`7iq zlXdDr#1b#Voh&kqUf}SNEz2kEqj$j%fVXvl(O^Hnn?|P;x#B=Mj&koUPr48i(+7+& z$~?HsOxEZJ3je%p`l|J&Pz+FxhvZIxJcJbACFA4|kGT+bq=wh}g^ry2T;*4xv-I)t})9+bcH=T;&%kUGrHN=ryuqUz(5w4t&@+4dT_$N4JhJ z8l?}irh>f;n!yphd1U;tW$oq^nWL)vMm2r(!F3>^;dtl16I_J5DcD~MDp|GO!=M}s zl3js5%i8tw*Om$6d#VV|yWDr95ouuI08jSH{p!Pm;W0k_h+{D6Z_XKdI)BcC@ZRv# z)W~k~x!Ab=m*Eo$WVc#Bo}-4hP@)K_d$oF0&l&P!aCDTz_rUz~Hyie$J%dxW%-e}rwM~`8oM*4e;*mGWL~>zXbdCA z$KKo;R=(qAz}JOtZ0v9@~R+d&uGNZ9+JRsT)3+t&&4FAosk{~p#gDFE7-%3 zmq#v&Ukn9EqKQp@?UWIDS0Iw)W5B4VguWTe0S;)}Y?a!}`8~v)flSzk_q#)me<_;o z5a48%MmIs)ZbW}|Z$N&G;w_0r5#Eo!`=5wT_AQB)xqI0BpXE>!4N%N!)~ItUMDZKK zEDAV8-a9P(Bl%+?_9Gf{wZlOcb8SqnvhIS7L=hwYI-KLOdT-`%hfLM&V5eqF8P!^0 z*!H89@#nl3(nF6oGF8(T`+iLKE50D8%oZZQigM=P8DC|$XsVYo+=!C^&z%;bpN&4Z zXavr8XS!v0Br%NNgicy)+_G`M97RHYqy{9rpy{ujx!1M=dd?%*r0V9!^%UJd8+zqc zb2M7F6I`d@$E?e)^>MK4yc=YB z-AmIeinVw!!7a|Bq zly55k=#j|9Gx5GI{b(tdT6Fq`bTp1bZd8-+Gr1=vPK7h?iebd_?S}HAc{R66fBT$- zwai^A&`b!-P!Opr_Wi`$Yecoy1+><~8dyR0)wnFrigxFUpqd`B7OmeDeJpchz z*_?U=t3LhP%FJd55k4Q_wx!`Y_1LL!Gk39E0RD``mcaq&A{GM>H0sTJZ0($2)l>+2 zr8t|YsDZxEg&mQg3l^(I&}aVOeSEr%(JFQuyk5(2`kIiS$bN-98P+9Xh695qL_>R= z_+Ci{s1o*PAYp+l%@Ds0jZcAdNLs1B)&Ees)t6`*ajH)TZs=&tj6|PP0odx&J|bx7 z2aNvQ-r|A^*><&?Nj+#_KejLqQ=pFsQy}h|G${k1r}=n{Ot;z^?qrd`qy~G``U~FB z5(lL(NL<=@R~7qrx=o8jB*ws2jZq*NWidTchd-mLRJBnUjqT4v-W$T=;6(-Y-2|np zEK~1l1*Yv@64HC}b*_GkTGVqx#-xHeOf_wV71U||ytcdJbe+)bUE-cW{#8H^Sf*B6 zAf#C}Y$=?PkIF?Rj|sImQNa{bVlNVLI#pOLZ!O%q3`o&GGt?oMF)zw@*L)OCy(F?= zIVt5dw5F`Io^I&Meu?VPd$UH)BLCTt@4)#S5h*u4kuqmbQw>!%x-ud{Sd`CLf8z*CLuRmsZkL`tWBLxs~LRGcv&nil~KE1Gjt~&Zh z1tHR2c%o;`9vyb5s?t6IUnbX1_gjkdwG07|);cCAN!xkJI21=gvaiEWl0RRcvc@JY zQDoGLM7?x!$km+%$G z)e<=oVEwaWn&7@H)-n+iH|WDNCEY8J2fU*eoJP$8o#BX3PIU7^=ubmkSs_jm&jTAK z>DGn%@L%I$AaZNz7_GC!p;O<;prMYOq3Q%OMkM0TqbxJhp^gtjfIcoegyvkBK9bS^ zoeXt=E><)pB(O&qhsp_f1{+jN?yEP2nI4lQ=^DdGz$VJv52w^FvD z&o6&&ewAwp&WnJh6m@;&i2hPDCcqNg80(slsHKz9uk22$8i0-qGo24t3+PqyCyebk z-$e{Hf;u&c-AtXbxu?DFK4PU@XPI7*OVi7uGoB@j52nHx<`~mQXfPd>*HYHx=Wmqo z^|VoLN_Z97e9Kb+kU)`TAu09aFuk#$N9;n5STGd|_+Ny%9n(<}eNCy}*lQSGDuI6Y zJHw-K4!Myt^CEImjP8IQZ5G!l^M=|#Xb-kA0rS3q=fio^er|Xi;9(V8V?%RM$tx`?a^pOxnd%N|ZjTk>L`9tIZ$ zIwd{y+j76eW9wTPn!4*MHjxX?< zi}bbcm+y1oL<7>xkIx@fsp@NMqhgWY+)5qsxY;dvQ<}ZM-eamte>q}%F=9=B6Qw>N z$g;fS^dw6`NWokmilB*24f2vS3X0(d`u5pI)r)wAo~1qQv}Mc7H^lRyQe*1AEYwyME3+h?LX6{XB7 z)=+zXoNo$Piwm4pJxTqL2w}Wal<(x^1MV zs?^40C{Z920$*@BZ5+TIe_JBd9J|DC(dloDk;RBS8ii1TVWBd!nioQmS;o`QY@niO z5@Rjh^=4plB9jgZYbdZUrZJROG)&4gCOi4A4jb`GKOp?rTz}wf!amEJG*m=m&up$PaE27UI(06je~|WmPy^$d}d2SPQvrg#`vGC`%iWrOCJKv@T?3B+=hE9 zXd7GD(Rt5F6tROotl{>dr6F9@ABt*cZ(q$fQxVSwrWhF7lFH1md}s&;n8vg!RRwDi zZ0oKM74+VA`B{C#<(p<)11!FAowON0ywp+XcdAC~0g&k;9cI5)x&dyWF>_L~IP^&J zn}hn0wZoj{gwv_8d~7m!$_8+)ImkfW$%48eTgWXAa*qc`s&2CA3WtFdSVBi`G)fSe zR|EcqN>Y^QN*V|uQ&H|{TZY(Dm`G$$n)na-;WXXthXRZS0pLI%ilH&`EV&KvKDOh}{m`418R#n8qc^8{&&<1r-}7d&?utQ6{-OljF45@o>ytWE$OL7ZDS3ai&8%-z=lIHe^qlfjww`NY!%iY3Ngjt zsD*5d%(alVYgV@4R(`ezmiW{}hn z-!ivINBBzlX-RF{0SSL}X+lU3_Pua7h6!v*2x=4Pa@b(JE5ztKEfIXtNj=Y2sF~)3 zYIQ2xiU1?`C)$MtVHOQtTw&=$pER76FhQD$pJ`sHgOGkB(s+Ov2ia$SSTs+O zx*t=@{rctyKNH!h4NYD|9dl><-!v$xNE)4T1$@-Qq2BQvKia(@p{$GLi1Lbvmz z`p*xQQCIrM{aoqerK~b;N!M#CPE=9R&cozlj)l|Ss!6SeRL!?ZYP?BvkJ=Mne|C%4 zVs(YD5QrQF#VHo+yZC$JAV=PT2+f8^-0g$o8xKp%pcJTQjNyP(ZF#LDEY&AH9LRhy z1SIXLI4tA#u8(jb<7q6t+$0yq&~OKzNQLvvHhSqN1%@@7PTEi?ev*DFI7KB!zXiMl zIXFXUmFvt${;_&DE!Xo}MXh>^gbu-9{(C4+iQdead&|fF1p+L{#xHNQ!^w-}AKm0-PGb@vZi!r$%3>w6-S%#h-1h%K- zW|qxXgNzk2&E*K$2skg7vm6uZ>qYIuE(Q6J*Tus*(U5>;`9Wz%Yw1bf0TH`h&P}DX zBZ;$dcNMlmgUwb&`8sysO!B%5{7yF~nLkBhV3b9dFBoT)-NXYMCyrgls3xZ*aGlDa ziSp>G14xl-5ZfY4eLnlra z&!@&iq%joJo%Y^$ADIwoo+ws2WIK^bob@Q+AP1FX?8CFwEzh5-UI*N0ubU;R5Qp?} zq9u3unL$-U&flf3l5r`IB|KXSY+aEpz8}F6LdMK+x-@vdF$$#l3I~JzEH35!ep>~o z=MVV<`@(+M=3-c_(~bN<&45j~!yz~H`aWKPZ@!&}-|!{(l3&9gU8~N`L=~ZXwb!#} zatN2w+VOj?9-OUy-%<|(nP{d^DNZs3k$y`I=k$8X>wYW_GtdRI5YrP49^^5(XGPn# zGfRT*WWy_X$oC@9;EgC!PV`*4#61o3|IEF|B|B+VvM-i$oWskSdF=g5enZC7(9E;3 zb}+U71mnOvAj>9=gf9A^?p?@+-5PpY>lAKle9e2aqIN2VdOqn>PuL0u#;%VO;VLQ% z9qF2eYi)|QO2Iqva}? zc=$sj+xT106HbgO+mDdMi5Z{&YOZuwqvFP)A!igXQcwD3MaYLlZ2lhZ=l;mzw9-@N zW6eV!0>SI(K-g3A+u${w!Q@NsM{Tt{SCwxi#feMy+Bz#5xPvPNu5C1pt zLJ%wcIS2=*+9v7_H*lES0@AmIrg)bML&NNr#vfRDD+NN+e5@p92v3*Fhw8bX>T=_wU*b1ExcUx007YdKII$YTRP zbUS1Rw>MoppX3fOA$>=dKIqEAj7X&B1=;pvZg5z~nF!pvh%XbnBKSYA9^mNf5{GH( zGb9&(5^*8(H6Yo3ya{`0<$Ctw@$Q>xSShYFoI1R}ZJ0l#nB|)J9r3S1=-=WalW{PP zD;z`&p`vV5VaE+*>z-0djAku)P zXtB>o+~m@9&_IQVeZP)B(}>1<3jd-!05`jLl-TdhMS1Fd$EvoPE%zhZ8Nc7?a=Z+y zu9rV7=#1aQ&K~Om^z|f|-N@dVf3re<{3Z_I7;=rRx0# zKT0gibHM&=Kf%=@K;OR!-T4<~6vZzGIJp6O6&_Fq0q1j15MwP6Itu;J2HysF-Q}Vg z740{g&ruSV^nwO{Xb{RcT3kTM6~(s7mP6XlL_tFjfXswfZ!@?mv=;{b9N13^eqdAD z&-fk|Eh0AytisA_=;j}N?4-)nQLVIHcl`l(7 zBPW;`5@WnSfdwo6OUse0ei;MnoJ(7_Wz-T&`KP`Isy?o#&16u<|J&dY{zj{!H>2EK z*e_sdQ6TDC^#YCFh1qML@?ii6eeYK_Wq7kCf_!TIGJsLhNe$F6%~TniHPrtKIC4}h z(?Ku+5SRRSC|GoiACPN(our{`S_ic`_ImV9Km>qGOsnKtjeeI1a7l@wQ``!1 zkLw?rFHbzK%cJkS4!dmsYXO#64zQDj^$K|6xCvLsxY-Ib7)v5Cz_))ILwS^gk28(X zZvp-=7;#!v0QmFl4P-UmLwVvL!<2=-5r8b*uqfYOE~Ut_(Ixz20ohJvX$E05(*?Ne0G&yiW~TcR*wL+!La%JQ2-6(?wFdYf21PD~ z*mPV0hl$b}^dpiX(_wM{A@%d)EnAU0A>bxUtiC%etDL^Ao}yjvr8k=K6@IS+hm#H{ z>e;jba?_ipp5r|%oMI{v=g2*iRl5NStsWqNL1kUk^Jl53Ne7eyN^<18cAyJmccMM$ zLW4^gHc6M(MUU0(;2CMy-l6}*j-fCtndd3M9PPAZP*RYj*pA3A^m_}?KFos=59BEb zE?oi(U|4anoT4mu+Ai&s1X6sW)3;heRa-&$h1r1V4nC2x3nquE#{pTg2GmnssMOE{?=^s7S5H_$5v8puBRZ7(e+0C`NjOoX`NdGG!ohl#!TeA z?!uS*x&Q9V9tI;EwS}4vsG9-@FtQqHqjIJEa;dn)0XI{T^B_#T?*-KZ8T~?r`(X(f z>~J5tTn7FgQ%(5$A@~s&_pX2SdPx0!h26RHge3c^|Nr}W z;|DUZ^r@gOz+-aL@;S*E0z(|Ii|#uchFtvuVD8AkdOtvt7I64}G^Py$CjjaBGEwcj zX1H#L9!7wy77(Nd-`HPRUtG5)<(!jpE#w1xPApS^16~OM>Uoy>}%Vf7g z%`%FU_~VpLx25M1NH)U}%fid_++>I(w^q}JMw}W&{PdST!Vb=Z>8D_1_gHCS%J$25 zjT#|e1i~?s96-XEmm1mwuDt^XL~r?bKcvLPCl9LDK2`HM*Hrysay{FOh4Rd&6W5f6 zWxW}kRv?7xj_m6%zWM$RxSt_Dyrsu21o{YkBrbgY^S^zB$xD>|^9ZpC|5c@bk8HwR=|HA+WHy`%9&`LRW&a;) zdjT5~=JFoGe~|(}?Xig9g@56IZ~vI#0d>b%5G|sA{vC35z>dWk=YN&T*uiClfLXXu z;28Bk(|;5&rG0_^+dN?7!yLf-O|ca7kp7hl167^|dXL^Jo&Dt@{a+S51Dlm2a1_6L znURCv676QX%R6{qM6`RIwo24Uf**OrL+Z zX7<}*uEYm+Y6O@AilSe%(iPo2Um<$werIj$>4*`nx8En7&9H4al7~ok@_C+%xSmFF z(XRC)b$IS3p1lyd3{);VZDci#kUre6oPz5oDWdiG@IKQ&UCcxmj6dc5`{6wm$q{2B z%8TH%aD80f+B#y}_|s0I6jM8q@8tAr+j{ z4R0}5vxUw8w#qim%j=nijey3=R^B$(hg5TR;?=LG;?pG0>ZrG^jjMPzI+ld}TirU& zhs5c?ww6V(;7?cW3|+ToXE0Vg8rNB?j3BnMuY~U0u6x3J7=-2#da<>b z+Uy>1AF?_yzfU_q$@D-C&j%0b0z<1_v<(!vDDqj7haa9r?uOy7rqk|QQVzQ5qYWzZva1OvTCIi zY55|Agp?P_+<>s19bmie#TNNHc!CdEHyS6FcSS~HRqtXy%LDp?d25uJX6I~jyj602 zV!F-y=4wX&Ap9c?G2dMblR2|hoxVB%O6rXdCL~&K`f~vqtl$bJ=6$61yqwpbp&DCbu25_(|$86KXm`4`?bLOO$`un zN#Caz^!(vE#d#R}tk$YDL3D5w6b54{Jc2eK|$6gDs59+^{~;vLYtzag-FTDs;9Y8* zgp|#Fqdx39+WwnJKR4BM-uCiOXEc)(h-eZa-3E;kCEAZ-7Rr!JtKopY%t;c9teD@gbmFNTN&y=vwzq3C*-Hj~_3zrP0`54=i zp{ALSF!W$Zef<7CcA)IHF6ilQPVIsF+5ITU9$Fd`s)B=@yJlfsKk2wZ;R&juL(}*B zP+m8_Ee>Ux6V@|JB7Lu?-5cOLWu=CF5Wow5EnLvvtBr*B`IpqPZvp9zLGzfd_665Q z!%19Sfb!K>-C}=g$0*#;du9=KWTeF5 z_PV>+Rl8bC>D&&qL5$01^zKJ!i-W0TdDo0=HAoxvCdgAu|zuCCR})z2LOnh=paq5Vn@GKY>dr*j6htuNnH&YoiO% znF59`fsYGpz&h775NL!cVnFso6=Q&b!572OhLMnn2=l*3#l*z8wiS>^DG&!1O6wko z6wNEIk7JCw9u;%G)xA)|Yja*!hdt6_+Y&Y7Ln(ZH03dYhG40S=eHd!1yNC9o# zD`#1EXgDav?;Pj-$aPM*9WSqNZ!V1FhhjRD^e!h4u8SD@WXD5R9_U=owoa@sMRP2R zMzCE*M;8$4GI16V@}mjR!3FtYVEi^=Ff3M*f|rA#lNZHGA(21!%ZpnDt9kCrnSb5g z*8djeXf&UF2nr&b-W!(*Hhucu!9_-DM%<}O>eAlQA&cCEEKsa@W8WrL!BtJ{p8Yba z)A@0$Dai?9odVL$9o|4JCmie2xymhnJgt9+2Zy6nwSajy(_~P)Pm`!8YbY??>mnartMG9Q?#jLh^`Hnn zJf7r1ZFufpDnk|;1VNiLlcX?NHaqYlW)7crmoLI+=19iYEg=+J>4V`hzkdcNgwhdX;z~~UR+(hJh9X3oRniJMLeFzqt0!$#V&S7 zxQCiWr^VNtF%zR2ZE{TO+ZcqBIU|=C{Fl+dMFhg=@3$U4P%W%<nS6R9~OMZtv}% zc^E5j7mQ<`0(?~-7{aw($r4);ndCvZ z=_Sd6(Ds)>L1@$azJL&YOpjdx?*j=WaE=gSa9E-pRKETg?ZCG)z6}yEIuw-NUbuR4 zPB^gt{Ysn?vhPfs5|gI?-(P&tdk=2ls{TDmSnPklKmi{L@Wmk-$|o(r`R5$K;c|X{ z1Z29|xP9ukD*=B=k_w!dELAxlL+Gu0Nr1zcFd#fhX9-Pwu4*6BH7Gbl`_?P9vfb}>q8Yz`)x>(vy01aanJ%XC9wn< z(58QyT7puQzZI*zDG+^s`CF;cX6>6|iB79?ox`r=aPlWz`2&jBzs>n23N+`JYMvs| z-{wf9_!=Wd$HbsK0NBqGjan1sdJC1qnIdH13}X=28601WfqPJHaWuD>%mIreomwRJ*9bS(uBO#|e9yj?HyCXBj z3V8_%jQTy0c+4gdTw`gUE%yO3Ptk0N(hNXpIRHp0YJ`_S6HjFg*B6`Y^M-4I<@|68 zwR#mvfkeD0g`d4rotZ+t*UOWeW}R8=;iTn!dC67nk`-;S<5G?B3H|BygU8LE50J}P zw8|lG6=5ybT0VOLnY=52C*4~4olUR!E%`I7zTEt^XgN}@%5DF9Ff|KHLXGK!EJ%3N z;pxsEJUWg-s&t3C=!H%pH-M=E1t@R*cOX!Mi-M2Hy@%Vl#3Xjz1oP)|+yUBk(pD&& zX@T+S%j#yAOg-|(Qi>h%Ae0Ar#Nk|7>+M{b+Qb`4W^JST93VsEe72Yc*=%%JSApqc zP|J7e8Fnu=+GZI?l_$`yl)Nja#FA0TDcj9&H?)7UT zv(x@)p1~z+()47t`Q&sRzun`ORkOjWguVK^K~-{ZrqM_egQP8M)#@XFKw<7rL4Se z|5h*-gXZMHOwn8wcpF+u^|ucYwO5C8;hTx#iL{9xY$g?5_y&zD2SDFDpGMn2^m4zD zf2^3u?4V^1a@~yVwi^coI#OflY_~2N?tn@JmMBa#5^t*7aL{bAO8=w|$L1TG;XnlL ziPxexVANJ#TH|tq5U9tQf3qObxSXu+3Dq$C`|!IyfsNo1t!EMj!I5xweBkER?$@qL z7DNnBpj8PA0&-W=Rg9$uEN6l3;v2bok7{S|NrGgEnDiS|LKCT@T} z%Y43EV>o1~!;9;9tu-0Ys?&T$bNZMT6UlDCsxf?? zuam8nS*#j><3KL&1P4lzZ8GACg(3T!MC96}isvZ-{11J_TFbj;B$fI#zWB3t);#DYvQP>1bq zWi}me8(HbLXLdYU<=9qFX${gHz5m(p?}rdf7c%b0mfwen_wZPgKs9Jsxq}qA;qDY0 zsE~#I_4Zc0w5~cW$DWjzu#)c}c{^<>U=+-m3`P;o&Ai5Z5W4!X&9B^3g#_({7DV|i zv8jpoOMBEo8{gBJ|1@zgRp-k?S(+a>5Ab9Pg9NcYY8THgx4G3a<%&iTl$aF1GG@E^U&)M$zcV0ZB+=PobTTe&m z==I&7Es2NA6<&oZ>>!1iv0~ACU|8=4m}j=dQCvW2=V765x0-iozx*%Hp%h(}Q8s+d z3t{$!V@xWvn`gase?Kg{R4#~B(XWsB)mVH&yz*lN6IjyYCfS1+z@FGts3w6K4LmEy z+ocd_gPI8VUR4FEC;mbTW5BhEIsJ`E2t~{Q%T)qpmG-~y4ktM4=tJm71#P0&W<6B* zho9X|qtmuusPVE!8Lbra#Zj*-;B-S7mA{clx=M`JYIqi0HzI#Q4r$K2NuKw3ZT~_H zR>{4l_P*A=Gm6mds7veg=;0Ab=smLu%8tSh&CfnVMxFobxO{o=+v#K~t!U_F@a<1w zm~>dywfut-Y(DGZeFK}53#|)BI}|1TX#Tx;?psi#P&Fd*Hw4O;2120x zQTJp;c(DJSS{&moD1vitF8+Ie2@*iekf3p@Xz};rp>IKvaQ8<_@4B?VEC6iGf4?y? zOt9olTc~lAh$7mpSxn|qC4Vobp7HL%?rOI>5t5A?5QFju`@HfrJPf=2Z9xD(DH=a< zR0nqh8r}-Jp~sgc-pa|gq#tt!fy)gA%DB^mtaKc5f5SNxaT4$|$F6<#*AtIf$D49> z-8qx0zK1{RS+4p=s>_ToN}TmZG#obT5yl@K(*C~pA7bPoL2cl2&;&3`z$AQajNX41 zQs3YJJehy*U(ft4Ow~8n%x(Mcn4KK({F|se9cunNgz^?V_5~#6|7|x3wq_-upQqpfm`1W3z|FLo_%+rQSJWjt(%xMV$oBS?A=SdL{h z(g!=9v&LUqNo3)?uF}mN?e8TMlWja;hwk>y(Y3S5PMhh+R~lj6Vh>b=t7*jg0>kSb zj|Bt{$d37_r6oSbHjhzp>?-C6CVl3{`b8%T51({%$Mw1q=c^L3v*3ITn?lKml(mD@ zZ_o3xP|3mko7h2gwWEmii)L*UVxZD(Lhz%Jx06m^pp=oYaFfgZvYn`~LrXXjVML|l zkp4#K!E4@6IyIiK?IwGFB)NyMn)%YLYQDu!>&Lto7nlyKcI{1ajqL$O1oj6^nXk6? zRfiji;~|dJLi+ZprFC1Ore^jBrH(hJJ}NDX3B9O9vZk-8J_}Bs$Kn#luMb)6j^10O zx;XTW6RUd+MV?H`?A^MlM9B#Frz?UtvnBrH7gwX5)KX)I3Ev%uawcK}&c(X0@C1zq zeQ=K7Ph-*u8xM+Pe_W2BkJ;R8f=#Hmv4$HfZL1i6Lq4Sn3r`!5bCr7JUZfR|PJ!?d z<-A11w0kFG+mls)*{3TyhRU^+c^2E9b4N$74e#YEZMN&#`f4HUmKLv~;m7#{=DO=Z zHM7@{XfyjI3tGhK3a?+VnyT$!gpW7SiL$S)O%8}ZymKfR$~2>IeArb_3n2`76^zyA ze(5itKWJI-absJi)fe^`luq6x>lXbiTUb39!>96j_E%kdMPaC%lGm9a!ZSAgveBN* z+HfizE~%V<9o;~-zb92;wJv!?>=TrfP$t{Dj<+8RDYuQ&p`lof^~3y}Iy39@iWk9X zl+PM(qyATUYO}7M7!&X^ff6UouGw^gE{`(Cc0t+x);`x;nd47urN_j^XD&XM z3ooO)qOD5DM%@N;Py}tF(1&L|)0ihl#XHPC&p%EG)47~oP6r3F1bP?Cb}#se9~|Q> zn45fvaCpYa2s`+RT`S~WG-aPzaEr(wHoYl;}P6Ggt~bA0YB?Rd{Sd%{^Zk4 zB$?Qpn$PcGVs_ys?9Hs!p=L&vm&*7Afpxc28A=Vy%+b!N}(?|%^+0ttA570vHg)Vx{5Gwh)C*Pu1 ztfzBSRD8E$D_>wsIn}X695+)ZI~Mz?qY%v>O8$OgaEjwZJz6faVz$Zc7Y^Yzv0lk{ zh!XK^?1SYfojTJ^dD@rt73G~%+~Iv+k9DmIt7XAQ-n$sR1GNVmrp(O8PcBsz#JK~ z542?^E-sQIe^)D2wxBrXlM3&Vsz+_Sjg-5`$2{lVRPMwXF?VFGn_*9IFQB)0?EaNx z*QbF{CHtPwY3AGc76a~Z0x5H{67x&`RexA%dRN8Esp2`Tl*EG&5}sc~6Z~d$HQNVFKVuy{lLqdN2{mgqDt|mZ z^0=AWt;Y|sVx^sb{Vb`q$!m-gaB=;q!eJM6nC=v7e>t@0;+HC4oYnOqH5(^FqN7N7 zlTUHerdMXRN+jZdRQH#)gIQvq=IfuY+8)EhzXe^I#=bV1i=@)3$cxJO*<`Nmtel{` z?p$U2C{+ZfmDJ%5Clwk%JT$i>OmeBrmnS?+>SZn#!~zc z>$4IX^uYd~_RcaWuBLtS!68^6A-IJQToY_?cZc8}2<|et3=D2TgS!VwAh-^a;O_43 zu6y!4Z{B~^e%`9Bt=joGHFKopFO zm@Wy&DbdDv^fFq-d{a&>#zj6(Fw^+k^iE)bqCuK`@D7Hjy5k2Mk(*h5;hiwNY!#~D z;d-Q}1w8!N#tl(K6SW@Mw8u5Y-n&;7&@`U+6Q3YVvfp+~1khXO;}o7adc4qT4k}2I zh6V*qeBD1Y8hor_^2*7@{y5bb&vkHYdsQIn!=<|QOX2v;&wwdKF3E#3g7><$8d4>IZ<&zl^~DsCU~@;+w$DB@Rk|A z*b(sOdX>cUp4Q-wW@orCb4=wDH>KHTv)Y4q+GA|z#A4%;eEV^;;^Au_7J_CC>7$sA zpTn}oHCf2g(+=+yBe?SW3GDeHDb3?mYRR4T#a_{pZtRqSk%>dMp4JLk_E7K^0yd%+ z@%V)l%G$|%Q;?eDwx`zC?c*mn&q{&mZ`sr+Ia(Vp)*4akkKW#uXP5W@&K z=GQFyZ^akZCZvV$(Vcy6Lf49flD5=ZgYL%iYxX8YnZI-FpqcnXXC#*0cZSZ8X^*b=m2ypR ztPJ>Vlp=A>p8@*F*2a%np}a zp`H7UZ!TQE$hoCF-nzC&K6c6M@h6|q*hpfleaAIHt>&S(QJ0^vz?gjrss}x-YFa;H z;(V!IU^umh=O7*2y>*j{G2Bzl1Y#a5eo2_VAvb>LbGlEU^hXRe^5Kaj&H4wFhSqEt z)+X6bcxbElag??7)Yq`qxlGIu!3oH#QGJc8U!cRW?~@J-mD5h!T!udxG6yCalDWop4i z+y-}r@ot3OA6WxDb6U?TPDBrUE;RnMm%E?@G@ZkQwee9UKN|`Y&v2Zh zJl`Dh5GahrJs(a4UW^(uh@*-IG%xUvTwl;Kor*TX$elZmnF^XiJ*4jsC04o?(&dclNjE2Ouf@4ovg;ficcaSgb-@^TrQEk_E>fX0HY=_)Nkwbkx zBiaVk?WEs!ZCpAnHi+-dxn|96u@qIe--|v@x$Zmna2Pfb;aqANZ$H9njuAtiG1tK> z+7GKt0@3D@m~TG(po=@kDWDM47G>p-&ayC1p9Ib#HvG`@Zta>+E2-xj7sT;N&+dll ztUZ2~3hY0M-IUwT>|)t=$cv*$_?zCYiu1hQki780L=0Ko;nRV59GhODEq-Zs5Y4|MB*X1}DC%p3SoBGSufX$F?KxN+IX%?m8qOfeY_ZsF z`xPFg(&(B@w(q8t(;91(7ZFpOw!KK!>OWX)T3X_?&1>X|D!R`*IV9#AHQpx^rTc{q z3jwvj3BLRomXbgT7(pLfn~8&?Z!xr8 z4BB#t6EDGx^dH+{juJ0SFW+IR8*ZMaM54ke11pL`k^wTMiMXv3Np)6QAJ&P_k8*ge z8AYIZQIc1|G+XzibEPK@hI_cL*#h=o7!vg|KZS(j7oY#iwzO7TdIcFkw-pfc7PWU` z;j)dNy?hMLg7pz|j)sBc~gLY!sHN>-gfU$4mb91W1Eu> znF-&c85_%BdJgfT<9$}LyuM32w77tXOGXN*GT{|^4c<45j8wF!vvGtpvSLHFfw05Z zxV4Y0V}_==oAe4uigyVGK09Z)s3Lt6-;owT-YKl(@a^_W^sW=DUY@(GWUb}vXS%)z zsO95^(@4hqEOxXiSyqx9)-kmUacThzlkMAKj<0>{QNFEx6{yoPD_PZgcjS8XqpcwQ zn08*kEozegG~Uy02M0oD5L^g;r-naKPT~a<=f#we!6M2sqcG&eKapKtmXHh-c&p^C zzp6<`AXKkidv4$Oxm-En)ZS}!Rx;ylM8cAQcOoQcNvZp-?RE?B%WIiv?~or=j(1nU z^f3O|&uF-A!ij3OVFYqJlq7rC %=TKxPtkY@T{k6ihs^Pd(~4aahAh<^OK%T z-`E3{`#Y^JI=7`@oKiRw47iE%;2NOu=a0P8qbWP#7eFH^1>fjgGIZ&GVzuskqS^0| zPINpQw?Ob+Ty^Hghzhxy9{5AERUgX~dkXKXReryHw1|SGSWcn17 zyT3VYd2gb5+mQ&aoF%){w8qmJg2+-i>ZsT=agXMr=4vs=b)3KF&&hUw_1#=bi0CoJ zWQ|aOugT4tMluBYsOOsw^vpF-r^e7F5(ArS+GI;$sA;8iAvL<^6Y)lryv}D6m|s*& zr-3)}z22&u+jWTlC1Dxj+~&ZIR{cXR$>X8j<7{UA{&Y8gCnLQe`4uQCmkr!d%~R}| z3W!x}S*~qUK{&H*-%}#*e;TD@W$q`aUhTu;3JDsKF*wN`6Q+WF$U?8f1(_Fjju#AO zLl`t7k41wqeM-MqjExIa^Q0Zg-lvnhA9yH{cx_k&d2`Z!-7lk~QwpQ;yC&m@hQt)x?o zjf~_S^;XUcK9S5)+RH0PScTfp{ggnY9Rx=W-aG~P@P+60ueqTpAcaZfmlBVem-fwWR zf=a^44~zzTd9w_fiCdgM2d~6}lO-YpKOCNr`+T(9?@T?Uxb7sTu0m{l4aS)~og+z# zuMpM*kycnu=IFnC)aBCFZ7A_5eWUMIzA>6|QGL1cvpP@LWtR8T+XIh1{u+{IfpWo$ zGa^LdIky6FYWfoKotVN}L*+c#J>3j6s?qGGS4bI0+ddb^K&Z|=GSS$wOWqf>!W6Az z01mpuB$p4DQFm=6(lJ1{JBH1vuE4c3EOEJc2=4^eI_)Mno@l!;Qnpm-(OkUiuxY*p zAGdi>192m%(iA?gsaa~x8#nRvy9u_kk0nS`U3)wDNyQQj#2={oyP_428`d^zh{je` z)Z>GnA3gK4UTtWznxX_qfp784S=0ebuR~7F(Fz1&T(2A;v(c_fzsX|Hr%|wG-9}B7 z(pqK4-P5dm*J??tEo-fOlTNTeE+bjxYw71*x`hoSgFDw%klypKJS=h^^E(_3Z4`2! zCrKK0Fwd8g^UyrI&BjqH(i8VvT;*sqtXo(AxRTb_(%3C~Sz4ufTWi-$5~D}NH0p<> z(gy<0!>z=*Lvxt|zmAejktcj$!ueVn>%>C}!n!JAf1b4EBtL3Q>@u9#Y&GdC%hCpC zR)KRqM*`f&MG~nS_u|9d_fLhB4E`r@{wo1dL=07vXA z1JRSAqQNkvCiWfMnxa>uusujuCj5!pF?}T1!0$CisRch?E5$C={p*o4YoY2g+uZzI zk>ZbZ#F%$8rX+I72YJ?n*3~|`w9T{K3P%sivrpY7uDyw|+ZU1tUK!~zl7&?Y^aj5q zp0F^pwW)2!P1CGsH(QyInP$v}1F%JQ3LhyyxE91QR|=cFcD{F-BCfXoAuQO0BhpOP zU6T`$6zY`L$-dQ}S{TtFHtQI6J&+ue4Np|M%pT>!>C<)n%sJE-IVEGeP zsIn4wxMig{xUUOVdDuVF9-T$zBu(0&hP49q!zX)Yn~_a75=!UBU1#Q5?0Xis52P9# zQt@%u#F?YhIN~LjM`k%KRT;$e3Uq~u^Ra4_>qW$_HYl|Fp-6d8Yvp{m)jvlJtVpXJ zlZ0nx;M~G7!x>hP6MF4(2QmY1y)1TZ6wdTLdGUs<)||x{TxS#50<2uD%xK8GbE=C& z$%;OyA`gb8BbypEdvB0RWlC(=yh;oMCx;Y?06^#w^m<$pPwEj34(Llf#mD2o5BsK@gqHz9WwXONefX*4oM1bTR)%GYRU9FuyHwjp{q z3TSqePs}+iSonSi5r%+{G^6T(ZT#hj)7FWxeDU<&Xn!-8Zy}a5grB9)@&iShM)i`_ z;RFTSel8M2wXuKQF)Wzw!28BM^sK6vwZnlCIVqu8D8`D{E$)Vo0OJLi=-6!7CAvm+ z>7sQ{*QXVV!eXvr){m+$Wl3;yOBG-7po$1VL$9!?cUV?Zx_9w-Ahh;g4)r}kgQQ?a zoc4c`GRb}5a~>@YO^1HJ$~9Y(qStAYc$l3n7UoH93A}shKF+dN-)c*kO4PBVH=&?7 zQCm!zCbwffo*NVia%@@r0>OMmK&rj$u2na)VN~B=)psQ4H2f2WOc`Cuh4DxgfV08? z46Y9qmbuXl(Bb7B1(4I%;AEoNVnr)nQ@PR##(zKw|3GR(X&6GOaSlXOPRNoI#I9am z^jLnhP?*u_|AKUngY&K9(n=`J-7zGXHsY$#=mj8Cm>y$JLonl9Crk649WxhZtD1| z%{0Qme9z11TTSmbHkyk~foJE>Ls6kMKc?VIy=TV)mDBUj4%tJ_IlR0#tw-XIgY&1{ zE_^lQ(Yi|$YYgi>eDAApzu~l(hw=uj;4!sNN@kRCmgvtHK)KKBH;1A#YR5tpTyH(o zg;~5dvj#Gu-)muM0kj6L!~T*=%-N(H)}_L<`KTfsyJVpvI;ViP8fJFx z7RK%n8(9dGd;Y{icg)`NQ-eQmIDiUZbiYEAPECB?Je~g2*)#TqA!_^9V2fR2W=56n zDPfen($V#D<7H^3FEv=gFoxpw>TFbcQ`7xB7v@#r%Jh6Qj$Ym7lCa<0K#~b>%HK2_ zCv}-g%TjI4a1irwhK`;!KFR8m`k26w#{#gy8^Sz7hG$~iL&BA!F>p5~=OfZA%rbA) z;7K$olKJV`W*7y#7Is&6kO` zSmmz0v&Z5S)_g}Q%D`>+zNaJY>q9iVSlj71%ljC)fkCaMpOELa;%O*#I}OTc*W?kY z6WG;i?)j#4MgOI>0S|E?ml(L2HPYSD^8F&ioKtWGET-c~7EY;^QBuC5m6 z?nMU-jTKr=;nR`9898^1nm0CJ(sN-UAb57tAp`zOfDzzzkeSCcbhYX?ojD#p_@XqR ziSlcy#!6IcLJAxrRZed-kZj@hHMwJUwwTaf-8e|V$-z2q#f2<>OiP?FFM=Ar*o!SS zb#fs{vH1JupbEK zXnT|P+6(nds&X1PA$d?N=5ZD_Ixl2>CYnQoy@|osndPAvm(G0L0HF()#k|9_S!b}r zNWC6I*=o;f$4GrsZ{x+3Q{maz+vvMa(7UulNZ;l^{^k!d;UD+{aI+(YttsvZqPvq8lSzI1OkgM4Re=xaXAb?G z?Js1dZk;z5EQ$50G2CZFrq$cNZ#5gm|6KM~%hLILv2aITz#*wy*Jkm&j$a5Q&w7v3 zwzp2md^`-6t-OF!gcXPLS$81&X%VD9XB|i!an&H{w826RLV+j4K^-OIwNvsT^Emk~ zn}CmC;rO}TSCPjx3ZfG%UNQq@v0j==iN-VczmJ4SIu2ISAR>p=wu!=@4D!YZgy7V- zb*r_fF)LyXO4|P@fA59=5AF9B5w6dJ?*obRm&XXKJYk^%pVg_YI>CB;|Gp(g=$LRS zs3j`{o^9Z=Q?XSExl^HXsxzr*uP0%|AN_jx_mm65p(vS;em7EuKT9sc4HA2Xm&>U( zid_pKxOi80-vJ0^yyHNLPZ>jkk&D_~pHa6@qF^A|0Y7c8^xNu40{3`OFhNX{=O+C7dhS;fR+4bGfEo zW(5K)|2w`=5kMhKwQ&OmN_tLQRa=ayZ1#Vh_<8>l{z`^|k1q`%{uKc}I2*YCBmEz; zF=t%X(?US840`X22@SO}O|}#^6XZxD4w(eFR_q`9f)+}RBUqMdiwezT-<7MHI6-bf z=988*k@pkQCXGQ#eMIF7b%se&Dg3m7^sg=#=*U+U8nHYvuzc`jEL2h}L=e}I-JE5Hm+opL?Nl6w{JCuzh)G$2s9zYl`dRt($E~6a-;C-QXjivI_-Qn${J_cy$sJ$&XHT*9Fkgdza+T=<73C-=P<77fPA7Y~13 z90<2;M+hSuz@+Dp}0tQ0CF%6<{KvH22e{7yaRwad|BI=vc@8)kMm+Mqu6VbZM|ZpOcWQijISD3*BtLfG&C>L-u8 zj8Gm;SHaR3J=cy`VB?K$b_qZK2u57?K1RR&^#rUDK3-@5x{iSMaHAJYfL&umiQ+g; zT_iDA)L=J%IJAx&*m`j5|?9NG<&Zj$4G_ca#Aw ziRq_!MlBV0so{^q??xV*HqKfxOLS(t(*yMgNx3tqUXGl}AAI=kgo=6ddt&gyou;k` zaDB>RZ+^2g!-l2ZI5m-RJmVC=aG;t?a^C)=I~RNZzT?t_uYdTyS<2&pfkqE)svd`* ztwZ=2T1~i_B~u|*vX|aW;xgaF;X+9)@}B>~eUF#s;YWKu4A^x2S#^@VBvCuem-5(g zLa`CVomd=jH@aK4*xr{xfA~q#zZZrqbDyjx-y#e7iP zc_|HS20bvciyhe{(+mPI*}x@A(X3*`%?DXfJ03ND-Q^W3yLNj#XuM$)*3HPDnA?J6 zZYl4PmvdwB+|UHGS4}EXDyHR4i)a+3@~z_pNjqBu&z<^B`}J^o-^p6fPMbdhSz)#l$n&ynHW*;Rb5(;+ z;wVLtJpgM*v#7$TNEF{T`h*`<10f+Fkc1a^iw;aw6f^gK6wLN!q6A0Wr<) zcvYmA(R!BCcm~6E))}LAH7zE&K-y@YG-QDco=W7b9gZNtYO0(%o;-jLC^k%5qFI$= z41EB^mKmVU2W%1p@Cs4_IX8@8cd8;&l0BXj883pEfFEcSjROQW$rrlB$OwZFfAmd) zTL>i_)u)@&jWEhlk6P6wstSz%O>V-ZRkwedZz2Yhnc*Y65J~Y3cgNdgZNIlgCiQ)8?kML#M88T1j?{ePLHPYQX6p% zw_C3VLb*o5UWt=A#aWAIPmv~&S8QUeIW+cqj5D^wb_}|=dZt_4pvS2eXO*)OPNFX4 zi^Z2>3tyEx(+g0|9_kN-t^~g6flx-_kPkJUKo($0-iK+HK!uYZogoIgQ;-uh(L66o zV(%rcK$-O)bX4Qk_Ir-KpI;!dj(-^sDg624<0oGq}6xeOaX6<7Om2wd1c~#9M)^(LxDlXLu60I@hj=LcZBn3_0d&s zoy&v64|;Zng6C}))%ICgvpxD4HQ@^@$bzwZu-!O*%AVJzW{N|T>1C`j^Ra@+SuQ~RmJ6KgaBUt9 z2;s`+TviDeln)?h+zu|{=K^xK!}Dpw+>T`hjRR31>j>~REd6H{_{8{%XFo^D2Bzuqa#oDa^z=l%h=HHdIgjC9ct!$$U`JZHY5;SQiV9q#B(>OBIc z1E{Sm!^g7WV9agZCa?oggsdhSlO7VOeC4p+0}Z_6C4M6Th#|+_oOrvi(n|M;mj2Xy zM{p@e^2oJ8$_*9>=J!SREX3e+1dhCQfC~GyMAtFxI=!>F)vUa-fx6bpRKA7;k|e0` z**TUvZR3sY{$-$dhn3+<l)&ZuJI5Y^?n@7eG`dKBSE_4J8H4MM_`oJlIIk1yRPt?c9Os2 z83NNwGv4?X$-#zmn@*32235}Vg03tnlV8!y-VV)N1!6l`4>Fe_y-ovUh04`BfjI6o zXwD;LxnmP)oFM*c+uJb%{>baDd{pOQmoO)01FncSdQ=ezg}NJ1+w>j@2eA}iPVUHs zo}68Wk&lJS2NS3;!W#77^D6m@fmMc1j$IDW=58JfqJp;}J zz{|y3l0QrD(au8cHvHb{*;?0}?p>Sp>3mT`ghKGpqa#5yR(J#1?2mGt>e@{Cseq_x zjL;80ny(UCCv^mJX<~}n^T9-nN?CrVUWi6i^>J))s@% z@h5|eop(k%(*tg!&K&N68tu;HJuf-k#CCUxM6pm;Jppm!xcv+G>t+7q*I;IL)80I& z)Hz!x)~5j?-E%x+?Pbh%In*C_%r2lrAch`?s zCqXe=B#8F&U|KIjfDND)RPWd7ww%)?FZ#TVg^f{e`g$CviG;fxNz|NxEWpq6kNhhp zR3PezAOJy8&*y#Ze7#fYW!~6YGSFB?U|x;58uj6Q*?<9^$*x6>yCtqXI)Rhxl zENSp(_rKUieFS1Wn4WlprY3qez357BYZ;*jEFdfz5KL2S6XP9^l7Rf(GOYPXSPU@>{^y{T4b(yCj~V762}$TH%YdMxS6iIOZt z;Ny9@C8iSRMlv4IOlxB~_ex_uGu)SD;Oo@UJ|0i`Y(}ZgK2LcCb0!<5{npm2IMr2V zrkqp2k)DI2|3#cGPM^OKd?!yb5-A3V3&U>uAcG6v3FM5s?c6-%yB;g42CP01*G>U7 zV&iS#ivJ4Hw&m-(i4o=0&(zBe?L=hBL>Q1~>1jOR*B&RT4L2&5#2$du@}T^|10`zf zSFEV7dgjcJ&omfJJDShV$|!93lCRv;`VE>Yg724ir{0V7lY$13YLoOmq^po5J0r3L z`d7W9ZZs?BSeYR>knjk*)5H&(;^HYKlut_M^Eq2PAvT^!Nd^ zI21dI!^Mh^JLU5f6W%H&=CYP4N%L6*? zOLH6%B|0w4gRMY+CcT&kaaNs?7eBKgaH{xOHD+LyPV)3A_v=wkw7qE&#Cl*V=3p81 zx;%S%Fw%vd6fx9L&Oq^U#55x6m46VRfL8X;1m{SyQp58>aO#FuINFskp}dC9Sx(~1 z)QG~x!}3FFZ5YS|)QgJcs4-$a$o#Cb$iB(XtzY*yv@7*KKHN>%HkBgoRNLPN5k2=u zCnZBAz}l`e(sW11U;;~X{}l0lUmXk-*oo;l2_jr zDZQOQR2{YBk9PJUBP#nn!Sn4VoL6DXvIhR&ecmr47;<`ET63%+Z3wY`whl5;Q`5_} z%|?MLp3Bj%qd{=qCn*J+CncLgYzUH%v#8?{OHrVoUTBu^E3};NUBsk6KMi?lX4sa1 z1$*{`fAOwey3dX1LrY^JIvkuQE2sThw;a0Ik)ZB^i`xL~@b=uAgmHz&lCKzlB^#^m z2M@9sKho+01^J1bU&hOubxqVoxbFcjqi_X+jE>#6rUv$nFef&npQ@O_Z8e9arjIx`O(E|2r%iRmPLd6M@2 zl)eFjFUP{89kbXFVS>57kdaM;Foy+}H5%^&(lF_TE|SG`sp_p+c2O~IZ zH#x!oP-bm}&paOVqe9^i=RAzW*H8Y1A^YzXKK18+XQzPN;# z{mto_N95#%xsk>g!bx?oCUU?1uqa)~mS5wIct-bg#ovk#qT8tgl)Xj8GhAOfxV?Ao ztUvtp+|Mvt)^acLPfx*gR`v<{rju8ml;K~hov102Sm})^ zbh#tTQtaF%>kT;jJ0Ksm_kG*9+ze@T8dhj~y%Q~mrmkOQxQ9gw*8NGmoy>ut-1Uaj z<5(}4-pTdSTz=)}*8!_-r6d{1msz`YtF*F13CH{@L zhS{-@`@_I;2s&xNZz@fGR#6l5p|@enIwOnEE;`9D)>4k<0u)`G?}S>~QD@P1dl}ij zHP)GPB~PfNeP$I_(&zW=DbvV05CR>med3tw!H+}Nz+4;e65{ErGDLk_*Mp$=fLaj9 zKzc$-V9@iDY4OJjLpddgxR*DXz2SVZ$Hf|Y<>M7R)t8z0Twt(BXN`o?+n$aBW9*oa3)HtID@OdfIaU8XoIML7 zu4&PR{;Nc%zc3^!+#aB2hc&p+r2JK?SCah6u4tI%RQ~I&>0Gd7&P z@yvnG*QMk)p6BI)^4XPs^lBA3KUPaiNGkusLQ(+UVQ{JKU*f|a4?5nTUj+Q9w%$s} z%lr6!IN#^1-1vom+IYQm`6p#Ey1;**Tg_;pFKm211}^@{PhRmq$*^k4#KSFgvz0(Z z_s(#ZI=rb}AMjoN9SCi^h+hI%Mw~|BZdaGaK7O{~dGP$uCm-kWx+ZP$??BK@63QVW zqhX#eDD2r!FiH@!79{YwskcMxO=5C+V@a9x9}BT~5sDEEYywgy=wWAhHlKOX&ezVN?(6SE9ODd-P-s|T+lC|zqS_Wn;6 zQ^=7bCJTz9kM+)hRJw5{%STD^f6fLG3IM2Js$!{88j6ef^F65#|M+idCI|%(l4*KU zXT!@lnJS1Ugy$7js%3QT&G2#Akf_Ewn#thNT&S0RLZ0Pp!Cf#Aa7tTGQezk9&u$U> zo5}6ufE&u-DR<)92u503)p@>&n(LCwFuG$`!ho>0d!F*)v_9ZdZGE{ew+2DNuhc~L zyvS7JtzXG98%eyf^91Z&r+L}TO;Ix4)s!cZ^t1Obb6RrLMgEfo7Wz&VV^}(7oG^2p zsD&UC3zHt-h3GjyTE3lNO81v=qnD#$78|Ddp*X5D7B!re88z|^RpAv1yXS*=@3axe zLR3Vm%jIr-uav4jvxKaxZgwdbi9?pr{tqGV3tPgwvkkd_62QQt)PmYMklR|3)_iGX zad#d6!qqB%)pQ9vvss)K_2WUk4EYd9IzfLSRecQ{?;W{HI4^B~ zxN5Yq-7!w|;i?(%>+*Vc#g@i(|21IzsmjY4?5M8Imcv(5dekr}i@lL;QHK6$2W2B3 z*aKn27b?7*$~@6CaQIfS{vT(SNs1UlXb&*p))GQs7DaAKd><^?`P#+jUCy68)nGw;Ic|&Xq%Bn_-{UP)5=+JES`;yR zQueFVOMyBVx+%X-+Y9?>jW$9hX2<&_#`Kwldxn+@-~>ssm0BMAYh_fw-i?-=b62?a zHJyu$&3}L_CHZT{?NlUWHEF4iby+c!#vcEgnR7lh4g}FO@Tup3ukn{I@UZD+6aO6% zhH&s`oa2tve2>9c4T|%MpIIc8+zzKxKhncQ8EY-B?RqR$=T$#}BcbvANgoMm9$I+i z$OrhcODs1IOV1A&m@7oBcWuq@;6J2BCS#fCRggcqu4sWS)j2$x6kLfe``8jpOO%K? z$m-IgsvOu&+X-g@qm-Jm#GsZGU+BJdQQO{0e_eC+)3|(sKr)|6u9frFTQP6(LI?>y z{J(=)lA;|WI#3ATr%$>)|pb4FPEk)BRvXDv2FD)vqMP)WQlU z)6D<8js5eafYV`P$Zk_cUqAEDeu-g`rP?zFS_Kub@E5MqX82M}=|O=6M-x9~dGq7b z+(oFq^ts$CF#Y6yS zs7Ak9#4%GvgD@rG;{4OX?3z2>t(2E*+)&p|>pHQ`sVJ^3%{V;1z?TsOZe>~Hd?W~= z;e3$#@`?}t``M!%kw&}r_C}Ky-FMWNCU3Z>-^U-5J(pAT&Xf3fo3cjJWXk19xoOiP zmkWBWlJP|c2f1d8kj@Mn)vPB1{FB1_mqp9UREV4D5ZdV_&2eSZEIrG?W|E!JNBLl6 zo?^vPKDE7pZ+V!czFWqvm+?&#oPrPamv0^#PMc0==Vdee%kj4fc4hzb?gTT1El-pjIdpyobE8f=5g&npyb<>ZabH#{7 zd2$zeG3<~1B0V!YC*zWy+eiMU@r8)LD{X&&(yzME%7D&QIVfm1Jv?Wc_qZu&0F zL9~;9C~~5df!WFPJ08An?q;KDCm{W0a`Zcu{>9I;hx#IqDvaLax+%UITeb%=@6f+w zOo$acr|XgDz*WeeY~3l0p{}p#JDm^vRWIHNT96ZTL^tZ!aq9~PgKBGf6%A)A^AOp*H|25eXKz&=(gMdVE@9cj~D_M3X7Km=l*12s@ zDQ9`{axX05<-aQg3Ta#^dswc`0YD~e9lk}Q%4Z1j5Pk^xZ_Bg5qX~@Xpnr*nm#p_0$;m9dMk|2rm6n{-QEg1r$7}wF z&l1Y{^UcU`U(mmuB!rsB2XJ3`O`s&)zlWCk0DSY7$fN%6cE%sj3p~B*d$DN!62AQz O@R1f*5Gxlk4ESGZKoiXX literal 0 HcmV?d00001 diff --git a/SUMMARY.md b/SUMMARY.md index 4e1216884a..7c9e06495d 100644 --- a/SUMMARY.md +++ b/SUMMARY.md @@ -162,6 +162,7 @@ * [GCP - Cloud Run Unauthenticated Enum](pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-cloud-run-unauthenticated-enum.md) * [GCP - Cloud SQL Unauthenticated Enum](pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-cloud-sql-unauthenticated-enum.md) * [GCP - Compute Unauthenticated Enum](pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-compute-unauthenticated-enum.md) + * [GCP - IAM, Principals & Org Unauthenticated Enum](pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-iam-principals-and-org-unauthenticated-enum.md) * [GCP - Source Repositories Unauthenticated Enum](pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-source-repositories-unauthenticated-enum.md) * [GCP - Storage Unauthenticated Enum](pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-storage-unauthenticated-enum/README.md) * [GCP - Public Buckets Privilege Escalation](pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-storage-unauthenticated-enum/gcp-public-buckets-privilege-escalation.md) diff --git a/pentesting-cloud/gcp-security/gcp-services/gcp-iam-and-org-policies-enum.md b/pentesting-cloud/gcp-security/gcp-services/gcp-iam-and-org-policies-enum.md index 0cddab7e03..b8df617a4d 100644 --- a/pentesting-cloud/gcp-security/gcp-services/gcp-iam-and-org-policies-enum.md +++ b/pentesting-cloud/gcp-security/gcp-services/gcp-iam-and-org-policies-enum.md @@ -190,6 +190,12 @@ In the following page you can check how to **abuse IAM permissions to escalate p [gcp-iam-privesc.md](../gcp-privilege-escalation/gcp-iam-privesc.md) {% endcontent-ref %} +### Unauthenticated Enum + +{% content-ref url="../gcp-unaunthenticated-enum-and-access/gcp-iam-principals-and-org-unauthenticated-enum.md" %} +[gcp-iam-principals-and-org-unauthenticated-enum.md](../gcp-unaunthenticated-enum-and-access/gcp-iam-principals-and-org-unauthenticated-enum.md) +{% endcontent-ref %} + ### Post Exploitation {% content-ref url="../gcp-post-exploitation/gcp-iam-post-exploitation.md" %} diff --git a/pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-iam-principals-and-org-unauthenticated-enum.md b/pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-iam-principals-and-org-unauthenticated-enum.md new file mode 100644 index 0000000000..72846d3202 --- /dev/null +++ b/pentesting-cloud/gcp-security/gcp-unaunthenticated-enum-and-access/gcp-iam-principals-and-org-unauthenticated-enum.md @@ -0,0 +1,119 @@ +# GCP - IAM, Principals & Org Unauthenticated Enum + +
+ +Learn AWS hacking from zero to hero with htARTE (HackTricks AWS Red Team Expert)! + +Other ways to support HackTricks: + +* If you want to see your **company advertised in HackTricks** or **download HackTricks in PDF** Check the [**SUBSCRIPTION PLANS**](https://github.com/sponsors/carlospolop)! +* Get the [**official PEASS & HackTricks swag**](https://peass.creator-spring.com) +* Discover [**The PEASS Family**](https://opensea.io/collection/the-peass-family), our collection of exclusive [**NFTs**](https://opensea.io/collection/the-peass-family) +* **Join the** 💬 [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** me on **Twitter** 🐦 [**@carlospolopm**](https://twitter.com/carlospolopm)**.** +* **Share your hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) +* +* +* github repos. + +
+ +## Iam & GCP Principals + +For more information check: + +{% content-ref url="../gcp-services/gcp-iam-and-org-policies-enum.md" %} +[gcp-iam-and-org-policies-enum.md](../gcp-services/gcp-iam-and-org-policies-enum.md) +{% endcontent-ref %} + +### Is domain used in Workspace? + +1. **Check DNS records** + +If it has a **`google-site-verification`** record it's probable that it's (or it was) using Workspace: + +``` +dig txt hacktricks.xyz + +[...] +hacktricks.xyz. 3600 IN TXT "google-site-verification=2mWyPXMPXEEy6QqWbCfWkxFTcQhyYdwHrOxee1Yeo-0" +hacktricks.xyz. 3600 IN TXT "google-site-verification=C19PtLcZ1EGyzUYYJTX1Tp6bOGessxzN9gqE-SVKhRA" +hacktricks.xyz. 300 IN TXT "v=spf1 include:usb._netblocks.mimecast.com include:_spf.google.com include:_spf.psm.knowbe4.com include:_spf.salesforce.com include:spf.mandrillapp.com ~all" +``` + +If something like **`include:_spf.google.com`** also appears it confirms it (note that if it doesn't appear it doesn't denies it as a domain can be in Workspace without using gmail as mail provider). + +2. **Try to setup a Workspace with that domain** + +Another option is to try to setup a Workspace using the domain, if it **complains that the domain is already used** (like in the image), you know it's already used! + +To try to setup a Workspace domain follow: [https://workspace.google.com/business/signup/welcome](https://workspace.google.com/business/signup/welcome) + +
+ +3. **Try to recover the password of an email using that domain** + +If you know any valid email address being use din that domain (like: admin@email.com or info@email.com) you can try to **recover the account** in [https://accounts.google.com/signin/v2/recoveryidentifier](https://accounts.google.com/signin/v2/recoveryidentifier), and if try doesn't shows an error indicating that Google has no idea about that account, then it's using Workspace. + +### Enumerate emails and service accounts + +It's possible to **enumerate valid emails of a Workspace domain and SA emails** by trying to assign them permissions and checking the error messages. For this you just need to have permissions to assign permission to a project (which can be just owned by you). + +Note that to check them but even if they exist not grant them a permission you can use the type **`serviceAccount`** when it's an **`user`** and **`user`** when it's a **`SA`**: + +{% code overflow="wrap" %} +```bash +# Try to assign permissions to user 'unvalid-email-34r434f@hacktricks.xyz' +# but indicating it's a service account +gcloud projects add-iam-policy-binding \ + --member='serviceAccount:unvalid-email-34r434f@hacktricks.xyz' \ + --role='roles/viewer' +## Response: +ERROR: (gcloud.projects.add-iam-policy-binding) INVALID_ARGUMENT: User unvalid-email-34r434f@hacktricks.xyz does not exist. + +# Now try with a valid email +gcloud projects add-iam-policy-binding \ + --member='serviceAccount:support@hacktricks.xyz' \ + --role='roles/viewer' +# Response: +ERROR: (gcloud.projects.add-iam-policy-binding) INVALID_ARGUMENT: Principal support@hacktricks.xyz is of type "user". The principal should appear as "user:support@hacktricks.xyz". See https://cloud.google.com/iam/help/members/types for additional documentation. +``` +{% endcode %} + +Note how when the user email was valid the error message indicated that they type isn't, so we managed to discover that the email support@hacktricks.xyz exists without granting it any privileges. + +You can so the **same with Service Accounts** using the type **`user:`** instead of **`serviceAccount:`**: + +{% code overflow="wrap" %} +```bash +# Non existent +gcloud projects add-iam-policy-binding \ + --member='serviceAccount:@.iam.gserviceaccount.com' \ + --role='roles/viewer' +# Response +ERROR: (gcloud.projects.add-iam-policy-binding) INVALID_ARGUMENT: User @.iam.gserviceaccount.com does not exist. + +# Existent +gcloud projects add-iam-policy-binding \ + --member='serviceAccount:@.iam.gserviceaccount.com' \ + --role='roles/viewer' +# Response +ERROR: (gcloud.projects.add-iam-policy-binding) INVALID_ARGUMENT: Principal testing@digital-bonfire-410512.iam.gserviceaccount.com is of type "serviceAccount". The principal should appear as "serviceAccount:testing@digital-bonfire-410512.iam.gserviceaccount.com". See https://cloud.google.com/iam/help/members/types for additional documentation. +``` +{% endcode %} + +
+ +Learn AWS hacking from zero to hero with htARTE (HackTricks AWS Red Team Expert)! + +Other ways to support HackTricks: + +* If you want to see your **company advertised in HackTricks** or **download HackTricks in PDF** Check the [**SUBSCRIPTION PLANS**](https://github.com/sponsors/carlospolop)! +* Get the [**official PEASS & HackTricks swag**](https://peass.creator-spring.com) +* Discover [**The PEASS Family**](https://opensea.io/collection/the-peass-family), our collection of exclusive [**NFTs**](https://opensea.io/collection/the-peass-family) +* **Join the** 💬 [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** me on **Twitter** 🐦 [**@carlospolopm**](https://twitter.com/carlospolopm)**.** +* **Share your hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) +* +* +* github repos. + +