From 15a5ef9e5089c7135e39b55a2c204d4553c57c78 Mon Sep 17 00:00:00 2001 From: Marcus Bointon Date: Tue, 6 Dec 2016 15:43:08 +0100 Subject: [PATCH 01/63] Snippet & document cleanup --- xml/source/client_info.xml | 45 +- xml/source/contract_info.xml | 66 +-- xml/source/futurework.xml | 15 +- xml/source/quickscope.xml | 113 ++-- xml/source/snippets/company_info.xml | 29 +- xml/source/snippets/localisationstrings.xml | 458 +++++++++-------- xml/source/snippets/offerte/en/conditions.xml | 2 +- .../snippets/offerte/en/crystal-box.xml | 38 +- xml/source/snippets/offerte/en/disclaimer.xml | 38 +- .../offerte/en/disclaimer_code-audit.xml | 41 +- .../snippets/offerte/en/engagementtime.xml | 6 +- .../snippets/offerte/en/examplewaiver.xml | 188 ++++--- .../offerte/en/generaltermsandconditions.xml | 482 +++++++++++------- xml/source/snippets/offerte/en/grey-box.xml | 29 +- .../snippets/offerte/en/introandscope.xml | 23 +- .../offerte/en/introandscope_retest.xml | 26 +- .../snippets/offerte/en/methodology.xml | 133 +++-- .../offerte/en/methodology_code-audit.xml | 80 +-- .../offerte/en/methodology_load-test.xml | 15 +- xml/source/snippets/offerte/en/phishing.xml | 3 +- .../offerte/en/planningandpayment.xml | 9 +- .../snippets/offerte/en/projectoverview.xml | 77 +-- .../offerte/en/projectoverview_retest.xml | 61 ++- .../snippets/offerte/en/teamandreporting.xml | 106 ++-- xml/source/snippets/offerte/nl/conditions.xml | 2 +- .../snippets/offerte/nl/engagementtime.xml | 5 +- .../snippets/offerte/nl/projectoverview.xml | 123 +++-- 27 files changed, 1222 insertions(+), 991 deletions(-) diff --git a/xml/source/client_info.xml b/xml/source/client_info.xml index 8c0ebbc..cfadfff 100644 --- a/xml/source/client_info.xml +++ b/xml/source/client_info.xml @@ -1,25 +1,24 @@ - - - - - Sitting Duck B.V. - - Sitting Duck - - I.M. Portant - - B.I.G. Wig - - Sir Knowsalot - -
Reed Street 42
- 0000 - Pond City - Amazonia - 9999999 - - D. Ollars - freemoney@sittingduck.com - 0000000000B01 + + + Sitting Duck B.V. + + Sitting Duck + + I.M. Portant + + B.I.G. Wig + + Sir Knowsalot + +
Reed Street 42
+ 0000 + Pond City + Amazonia + 9999999 + + D. Ollars + freemoney@sittingduck.com + 0000000000B01
diff --git a/xml/source/contract_info.xml b/xml/source/contract_info.xml index 143c1ff..93c61af 100644 --- a/xml/source/contract_info.xml +++ b/xml/source/contract_info.xml @@ -1,32 +1,40 @@ - - - - fixed_term - battling the pirates - Contractor - - - Petra Pan - Lost Boys Inc. -
Cloud 9
- 1234 XX - Treehouse City - Neverland - peter@pan.tech - 0 -
- - - Taunting Captain Hook - Feeding crocodiles - Flying to and fro ('to' and 'fro' to be specified at takeoff) - - 2016-08-18 - 2016-09-15 - + xmlns:xi="http://www.w3.org/2001/XInclude" + xmlns:xlink="http://www.w3.org/1999/xlink" + xsi:noNamespaceSchemaLocation="../dtd/contract_info.xsd" + xml:lang="en"> + + + + fixed_term + + battling the pirates + Contractor + + + + + Petra Pan + Lost Boys Inc. + +
Cloud 9
+ 1234 XX + Treehouse City + Neverland + peter@pan.tech + 0 +
+ + + Taunting Captain Hook + Feeding crocodiles + Flying to and fro ('to' and 'fro' to be specified at takeoff) + + + 2016-08-18 + 2016-09-15 +
diff --git a/xml/source/futurework.xml b/xml/source/futurework.xml index c075ac2..3b4ef36 100644 --- a/xml/source/futurework.xml +++ b/xml/source/futurework.xml @@ -1,12 +1,11 @@
Future Work - -
    -
  • - Title
    - Description -
  • -
- +
    +
  • + Title +
    + Description +
  • +
diff --git a/xml/source/quickscope.xml b/xml/source/quickscope.xml index cbaf2f7..31a0cc9 100644 --- a/xml/source/quickscope.xml +++ b/xml/source/quickscope.xml @@ -1,64 +1,63 @@ - - - + xmlns:xml="http://www.w3.org/XML/1998/namespace" + xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance" + xsi:noNamespaceSchemaLocation="../dtd/quickscope.xsd"> + + + + + + + + en + + pentest + + + penetration testing services + + + + + + + + + + + + + 0 + + 0 + + time-boxed + + crystal-box + + + + TBD + + TBD + + + + - - - - en - - pentest - - - penetration testing services - - - - - - - - - - - - 0 - - 0 - - time-boxed - - crystal-box - - - - TBD - - TBD - - - - - - - - - 0 - + + 0 + diff --git a/xml/source/snippets/company_info.xml b/xml/source/snippets/company_info.xml index 868b930..0e7f2b7 100644 --- a/xml/source/snippets/company_info.xml +++ b/xml/source/snippets/company_info.xml @@ -1,17 +1,18 @@ - Radically Open Security B.V. - ROS - Melanie Rieback - Melanie Rieback -
Overdiemerweg 28
- 1111 PP - Diemen - The Netherlands - +31 6 10 21 32 40 - info@radicallyopensecurity.com - www.radicallyopensecurity.com - 60628081 - 853989655B01 - NL06 RABO 0188 2813 12 + Radically Open Security B.V. + ROS + Melanie Rieback + + Melanie Rieback +
Overdiemerweg 28
+ 1111 PP + Diemen + The Netherlands + +31 6 10 21 32 40 + info@radicallyopensecurity.com + www.radicallyopensecurity.com + 60628081 + 853989655B01 + NL06 RABO 0188 2813 12
diff --git a/xml/source/snippets/localisationstrings.xml b/xml/source/snippets/localisationstrings.xml index 39fcb87..d785016 100644 --- a/xml/source/snippets/localisationstrings.xml +++ b/xml/source/snippets/localisationstrings.xml @@ -1,223 +1,241 @@ - - - - [D1] [MNn] [Y] - [MNn] [D1], [Y] - - - - - OFFERTE - QUOTE - - - penetratietestdiensten - penetration testing services - - - penetratietest - penetration test - - - penetratietestdiensten - penetration retesting services - - - hertest - retest - - - basis-securityscandiensten - basic security scan services - - - basis-securityscan - basic scan - - - code-auditing-diensten - code auditing services - - - code audit - code audit - - - loadtest-diensten - load testing services - - - load test - load test - - - VOOR - FOR - - - Kamer van Koophandel - Chamber of Commerce - - - - Factuur nr. - Invoice no. - - - T.a.v. - F.a.o. - - - Geleverde diensten - Services delivered - - - daagse - day - - - BTW - VAT - - - BTW-nummer - VAT number - - - Extra gemaakte kosten - Additional expenses - - - Totaal te betalen - Total amount to be paid - - - doneert > 90% van haar totale winst aan goede doelen. - donates > 90% of its entire profits to - charity. - - - Maak binnen 30 dagen het totale bedrag over op de volgende rekening: - Please be so kind to pay within 30 days - by money transfer, to the following account: - - - IBAN - IBAN - - - Referentie - Reference - - - Met vriendelijke groet - Kind regards - - - uw team bij - your dedicated team at - - - Spaar papier — niet afdrukken tenzij absoluut noodzakelijk. Lees onze (unieke) voorwaarden op: https://radicallyopensecurity.com/TermsandConditions.pdf - Please keep digital unless absolutely required. Read the (unique) terms and conditions of Radically Open Security at: https://radicallyopensecurity.com/TermsandConditions.pdf - - - - Over - About - - - Infrastructuur - Infrastructure - - - Reikwijdte - Reach of - - - - en - and - - - - Getekend - Signed - - - op - on - - - in - in - - - door - by - - - namens - for - - - In duplicaat getekend - Signed in duplicate - - - - security consulting agreement - security consulting agreement - - - in aanmerking genomen dat - considering that - - - komen het volgende overeen - agree the following - - - hij - he - - - ze - she - - - hen - they - - - hem - him - - - haar - her - - - hen - them - - - zijn - his - - - haar - her - - - hun - their - - - TODOXXXXXXXXXX - As such drawn up in duplicate and signed - + + + [D1] [MNn] [Y] + [MNn] [D1], [Y] + + + + + OFFERTE + QUOTE + + + penetratietestdiensten + penetration testing services + + + penetratietest + penetration test + + + penetratietestdiensten + penetration retesting services + + + hertest + retest + + + basis-securityscandiensten + basic security scan services + + + basis-securityscan + basic scan + + + code-auditing-diensten + code auditing services + + + code audit + code audit + + + loadtest-diensten + load testing services + + + load test + load test + + + VOOR + FOR + + + Kamer van Koophandel + Chamber of Commerce + + + + Factuur nr. + Invoice no. + + + T.a.v. + F.a.o. + + + Geleverde diensten + Services delivered + + + daagse + day + + + BTW + VAT + + + BTW-nummer + VAT number + + + Extra gemaakte kosten + Additional expenses + + + Totaal te betalen + Total amount to be paid + + + doneert > 90% van haar totale winst aan goede + doelen. + + donates > 90% of its entire profits to charity. + + + + Maak binnen 30 dagen het totale bedrag over op de + volgende rekening: + + Please be so kind to pay within 30 days by money + transfer, to the following account: + + + + IBAN + IBAN + + + Referentie + Reference + + + Met vriendelijke groet + Kind regards + + + uw team bij + your dedicated team at + + + Spaar papier — niet afdrukken tenzij absoluut + noodzakelijk. Lees onze (unieke) voorwaarden op: + https://radicallyopensecurity.com/TermsandConditions.pdf + + Please keep digital unless absolutely required. + Read the (unique) terms and conditions of Radically Open Security at: + https://radicallyopensecurity.com/TermsandConditions.pdf + + + + + Over + + + About + + + + + Infrastructuur + Infrastructure + + + Reikwijdte + + + Reach of + + + + + + en + and + + + + Getekend + Signed + + + op + on + + + in + in + + + door + by + + + namens + for + + + In duplicaat getekend + Signed in duplicate + + + + security consulting agreement + security consulting agreement + + + in aanmerking genomen dat + considering that + + + komen het volgende overeen + agree the following + + + hij + he + + + ze + she + + + hen + they + + + hem + him + + + haar + her + + + hen + them + + + zijn + his + + + haar + her + + + hun + their + + + TODOXXXXXXXXXX + As such drawn up in duplicate and signed + + - diff --git a/xml/source/snippets/offerte/en/conditions.xml b/xml/source/snippets/offerte/en/conditions.xml index 1fabb71..f09b2dd 100644 --- a/xml/source/snippets/offerte/en/conditions.xml +++ b/xml/source/snippets/offerte/en/conditions.xml @@ -1,7 +1,7 @@
Terms and Conditions -

will only perform the +

will only perform the if it has obtained the permission from as set out in the penetration testing waiver, attached as Annex 2, or provided in a separate document.

diff --git a/xml/source/snippets/offerte/en/crystal-box.xml b/xml/source/snippets/offerte/en/crystal-box.xml index 8548fe1..b468c51 100644 --- a/xml/source/snippets/offerte/en/crystal-box.xml +++ b/xml/source/snippets/offerte/en/crystal-box.xml @@ -1,17 +1,23 @@ - - +
-The Crystal-Box Pentesting Method -

- Crystal-box vs. black-box pentesting refers to the amount of information about the target environment, architecture, and/or applications the customer initially shares with the pentesters. With black-box testing, pentesters are given no information whatsoever about the target(s). With crystal-box testing, pentesters are given all information requested about the target(s), including source-code (when relevant), access to developers or system management, etc. -

-

- will conduct crystal-box pentesting, which is the preferred - method. Unlike real-world attackers who have all of the time in the world, - penetration testing tends to happen within a limited time frame. Crystal-box - pentesting allows us to make the most efficient use of the time allotted, thus - maximizing the number of vulnerabilities that can be found. Additionally - crystal-box pentesting fits naturally hand-in-hand with the "Peek Over Our Shoulder" option that offers to . -

-
- + The Crystal-Box Pentesting Method +

+ Crystal-box vs. black-box pentesting refers to the amount of information + about the target environment, architecture, and/or applications the customer + initially shares with the pentesters. With black-box testing, pentesters are + given no information whatsoever about the target(s). With crystal-box + testing, pentesters are given all information requested about the target(s), + including source-code (when relevant), access to developers or system + management, etc. +

+

+ + will conduct crystal-box pentesting, which is the preferred method. Unlike + real-world attackers who have all of the time in the world, penetration + testing tends to happen within a limited time frame. Crystal-box pentesting + allows us to make the most efficient use of the time allotted, thus + maximizing the number of vulnerabilities that can be found. Additionally + crystal-box pentesting fits naturally hand-in-hand with the "Peek Over Our + Shoulder" option that offers to . +

+
diff --git a/xml/source/snippets/offerte/en/disclaimer.xml b/xml/source/snippets/offerte/en/disclaimer.xml index 2c4fc64..0215784 100644 --- a/xml/source/snippets/offerte/en/disclaimer.xml +++ b/xml/source/snippets/offerte/en/disclaimer.xml @@ -1,22 +1,22 @@
- Disclaimer -

- It is important to understand the limits of 's services. - does not (and cannot) give guarantees that something is - secure. , instead, has an obligation to make reasonable - efforts (in Dutch: “inspanningsverplichting”) to perform the - agreed services. -

- -

- and agree to take reasonable measures to - maintain the confidentiality of information and any personal data they gain - access to in the course of performing the . Both parties will use the - information and data they receive or access only for the purposes outlined - in this agreement. - warrants that all core-team members, external freelancers, - and volunteers it engages to perform the have signed a - non-disclosure agreement (NDA). -

+ Disclaimer +

+ It is important to understand the limits of 's services. + does not (and cannot) give guarantees that something is secure. + , instead, has an obligation to make reasonable efforts (in + Dutch: “inspanningsverplichting”) to perform the agreed services. +

+ +

+ and + agree to take reasonable measures to maintain the confidentiality of + information and any personal data they gain access to in the course of + performing the . Both parties will use the information + and data they receive or access only for the purposes outlined in this + agreement. + warrants that all core-team members, external freelancers, + and volunteers it engages to perform the + have signed a non-disclosure agreement (NDA). +

diff --git a/xml/source/snippets/offerte/en/disclaimer_code-audit.xml b/xml/source/snippets/offerte/en/disclaimer_code-audit.xml index 707937a..8168427 100644 --- a/xml/source/snippets/offerte/en/disclaimer_code-audit.xml +++ b/xml/source/snippets/offerte/en/disclaimer_code-audit.xml @@ -1,22 +1,25 @@
- Disclaimer -

- It is important to understand the limits of 's services. - does not (and cannot) give guarantees that something is - secure. , instead, has an obligation to make reasonable - efforts (in Dutch: “inspanningsverplichting”) to perform the - agreed services. -

- -

- and agree to take reasonable measures to - maintain the confidentiality of information and any personal data they gain - access to in the course of performing the code audit. Both parties will use the - information and data they receive or access only for the purposes outlined - in this agreement. - warrants that all core-team members, external freelancers, - and volunteers it engages to perform the code audit have signed a - non-disclosure agreement (NDA). -

+ Disclaimer +

+ It is important to understand the limits of 's services. + + does not (and cannot) give guarantees that something is secure. + , instead, has an obligation to make reasonable efforts (in + Dutch: “inspanningsverplichting”) to perform the agreed services. +

+ +

+ + and + + agree to take reasonable measures to maintain the confidentiality of + information and any personal data they gain access to in the course of + performing the code audit. Both parties will use the information and data + they receive or access only for the purposes outlined in this agreement. + + warrants that all core-team members, external freelancers, and volunteers it + engages to perform the code audit have signed a non-disclosure agreement + (NDA). +

diff --git a/xml/source/snippets/offerte/en/engagementtime.xml b/xml/source/snippets/offerte/en/engagementtime.xml index 1aa21e3..34c625b 100644 --- a/xml/source/snippets/offerte/en/engagementtime.xml +++ b/xml/source/snippets/offerte/en/engagementtime.xml @@ -1,4 +1,4 @@ -

Based on the information provided, we expect -this to be an -day engagement. The planning of this engagement -is as follows:

\ No newline at end of file +

Based on the information provided, we expect this to be a -day + engagement. The planning of this engagement is as follows: +

\ No newline at end of file diff --git a/xml/source/snippets/offerte/en/examplewaiver.xml b/xml/source/snippets/offerte/en/examplewaiver.xml index 06f8f4e..f86b794 100644 --- a/xml/source/snippets/offerte/en/examplewaiver.xml +++ b/xml/source/snippets/offerte/en/examplewaiver.xml @@ -1,93 +1,117 @@ +
-ANNEX 2 Example Pentest Waiver + ANNEX 2 Example Pentest Waiver -

(Full Client Name) (“(Client)”), with its registered -office at Somestreet, Somecity, Earth, -Milkyway, and duly represented by (Client's CISO)

+

+ (Full Client Name) (“(Client)”), with its registered + office at Somestreet, Somecity, Earth, Milkyway, and duly represented by + (Client's CISO) +

-

WHEREAS:

+

+ WHEREAS: +

-

A. (Client) wants some of its systems tested, -(“”) has offered to perform such testing for (Client) -and (Client) has accepted this offer. The assignment will be performed -by 's core-team members, external freelancers, and/or volunteers -(the “Consultants”).

-

B. Some of the activities performed by and the Consultants -during the course of this assignment could be considered illegal, unless -(Client) has given permission for these activities. -and the Consultant will only perform such activities if they have received the -required permission.

-

C. (Client) is willing to give such permission to , -the Consultants, and any other person might employ -or engage for the assignment.

+

A. (Client) wants some of its systems tested, + (“”) has offered to perform such testing for + (Client) and (Client) has accepted this offer. The assignment + will be performed by 's core-team members, external freelancers, + and/or volunteers (the “Consultants”). +

+

B. Some of the activities performed by + and the Consultants during the course of this assignment could be considered + illegal, unless (Client) + has given permission for these activities. + and the Consultant will only perform such activities if they have received + the required permission. +

+

C. (Client) is willing to give such permission to , + the Consultants, and any other person might employ or engage + for the assignment. +

-

DECLARES AS FOLLOWS:

-

1. (Client) is aware that will perform penetration -testing services on the (Client)'s following systems, as -described below. The services are intended to gain insight in the security of -these systems. To do so, will access these systems, attempt to -find vulnerabilities, and gain further access and elevated privileges by -exploiting any vulnerabilities found. will test the following -targets (the “Targets”): -

    -
  • Target system
  • -
-

-

2. (Client) hereby grants and the Consultants on a -date to be confirmed by email the broadest permission -possible to perform the assignment, including the permission to:

+

+ DECLARES AS FOLLOWS: +

+

1. (Client) is aware that + will perform penetration testing services on the (Client)'s following + systems, as described below. The services are intended to gain insight in + the security of these systems. To do so, + will access these systems, attempt to find vulnerabilities, and gain further + access and elevated privileges by exploiting any vulnerabilities found. + will test the following targets (the “Targets”): +

    +
  • Target system
  • +
+

+

2. (Client) hereby grants + and the Consultants on a date to be confirmed by email the broadest + permission possible to perform the assignment, including the permission to: +

-

a. enter and use the Targets;

-

b. circumvent, breach, remove, and turn off any security measures protecting -the Targets;

-

c. copy, intercept, record, amend, delete, and render unusable or inaccessible -any data stored on, processed by, or transferred via the Targets; and

-

d. hinder the access or use of the Targets,

+

a. enter and use the Targets;

+

b. circumvent, breach, remove, and turn off any security measures + protecting the Targets; +

+

c. copy, intercept, record, amend, delete, and render unusable or + inaccessible any data stored on, processed by, or transferred via the + Targets; and +

+

d. hinder the access or use of the Targets,

-

but (Client) only grants the permission for these activities to the -extent that (i) such activities are necessary to perform the assignment and -(ii) such activities do not disrupt the normal business operations of (Client).

-

3. The permission under Article 1 extends to all systems on which the Targets -run, or which or the Consultant might encounter while performing -the assignment, regardless of whether these systems are owned by third parties.

-

4. (Client) warrants that it has the legal authority to give the -permission set out under Articles 1 and 2. It also warrants it has obtained the -necessary permissions from any third parties referred to under Article 3.

-

5. Should the public prosecutor initiate an investigation or criminal proceedings -against or any of the consultants it engaged or employed as a -result of the performance of the assignment for the customer, then -(Client) will co-operate fully with in defending against -this investigation or proceedings, including by providing any evidence it has -which relates to this investigation or these proceedings.

+

but (Client) only grants the permission for these activities to the + extent that (i) such activities are necessary to perform the assignment and + (ii) such activities do not disrupt the normal business operations of + (Client). +

+

3. The permission under Article 1 extends to all systems on which the + Targets run, or which + or the Consultant might encounter while performing the assignment, + regardless of whether these systems are owned by third parties. +

+

4. (Client) warrants that it has the legal authority to give the + permission set out under Articles 1 and 2. It also warrants it has obtained + the necessary permissions from any third parties referred to under Article + 3. +

+

5. Should the public prosecutor initiate an investigation or criminal + proceedings against + or any of the consultants it engaged or employed as a result of the + performance of the assignment for the customer, then + (Client) will co-operate fully with + in defending against this investigation or proceedings, including by + providing any evidence it has which relates to this investigation or these + proceedings. +

-
- - - - - - - - - - - - - - - - -
- Signed - - on __________________________________ -
- in __________________________________ -
- by __________________________________ -
- for (Full Client Name) -
+
+ + + + + + + + + + + + + + + + +
+ Signed + + on __________________________________ +
+ in __________________________________ +
+ by __________________________________ +
+ for (Full Client Name) +
diff --git a/xml/source/snippets/offerte/en/generaltermsandconditions.xml b/xml/source/snippets/offerte/en/generaltermsandconditions.xml index f2d95f2..7040d51 100644 --- a/xml/source/snippets/offerte/en/generaltermsandconditions.xml +++ b/xml/source/snippets/offerte/en/generaltermsandconditions.xml @@ -1,197 +1,289 @@ - Annex 1<br/>General Terms and Conditions - -

What is this document?

-

These are the general terms and conditions (in Dutch: “algemene voorwaarden”) -of (). This version of the general terms and conditions -is dated 15 July 2014.

-

In the spirit of 's philosophy, wants these -general terms and conditions to be as understandable as possible. If you have any -questions, feel free to ask for clarification.

-

What is ?

-

is a private limited liability company under Dutch law located -in Amsterdam, The Netherlands. It is registered at the Dutch Chamber of Commerce -under no. 60628081.

-

To what do these terms and conditions apply?

-

These general terms and conditions apply to all agreements between -and the customer. rejects any terms and conditions used by the -customer. The parties can only deviate from these general terms and conditions -in writing. These general terms and conditions are also intended to benefit any -person employed or engaged by during the performance of an assignment.

-

How does agree on an assignment?

-

wants both parties to have a clear picture of an assignment -before it starts. This means there only is an agreement between -and the customer after sends a written offer containing the key -terms of the agreement and the customer subsequently accepts the offer. -Communications other than the written offer do not form part of the agreement. - can rescind an offer until it is accepted by the customer.

-

What can the customer expect from ?

-

It is important to understand the limits of 's services. - does not (and cannot) give guarantees that something is secure. - instead has an obligation to make reasonable efforts -(in Dutch: “inspanningsverplichting”) to perform the agreed services.

-

will make reasonable efforts to perform the assignment in -accordance with the plan set out in the offer (if any). If -expects it will not fulfill the plan as documented, it will let the customer -know without delay. is not automatically deemed to be in default -if it doesn't meet the plan.

-

will make reasonable efforts to avoid disruption of the -customer's operations and damage to its owned or operated systems, but it -cannot guarantee that this will be avoided. The customer agrees -to this. is not obliged to restore the systems or recover any -data deleted or amended in the course of the assignment.

-

What can expect from the customer?

-

The customer will provide with all means necessary to allow - to perform the agreed services. If needs explicit -permission from the customer to perform its services (for example, when doing -penetration tests) the customer gives this permission. The customer also warrants -that it has the legal authority to give this permission.

-

How do the parties handle confidential information?

-

and the customer will not disclose to others confidential -information and personal data they receive from each other or gain access to in -the course of an assignment. has the right to disclose this -information and data to persons engaged by , but only if these -persons have a similar confidentiality obligation vis-á-vis . -Any person will only use the information and data it receives or gains access -to for the purposes following from the agreement. Both parties will take reasonable -measures to maintain the confidentiality of the information and data they received -or gained access to, and will ensure that persons engaged by them do the same.

-

What does do with vulnerabilities it finds in the course -of an assignment?

-

If in the course of an assignment finds a vulnerability which -might affect the customer, it will report this to the customer. If a vulnerability -might affect third parties as well, retains the right to disclose -this vulnerability also to others than the customer. It will only do so after -having given the customer a reasonable period to take measures minimising the -impact of the vulnerability, in line with responsible disclosure best practices.

-

What does do with indicators of compromise it finds?

-

If in the course of an assignment finds indicators of -compromise, such as malware signatures and IP-addresses, it will report this to -the customer. retains the right to also publish this information -in a publicly accessible database. It will only do so after it has given the -customer the opportunity to object to the publication of data which would -negatively impact the customer.

-

Who owns the products developed in the course of the assignment?

-

retains any intellectual property rights in products developed -for an assignment, such as software and reports. , however, wants -to teach as many customers as possible 'how to fish'.

-

For software it developed, this means that gives the customer -a permanent, non-exclusive, transferable, sub-licensable, worldwide license to -distribute and use the software in source and binary forms, with or without -modification (very similar to the BSD-license). If 's software -is based on other software which is provided under a license which restricts -'s ability to license its own software (such as the GPLv3 license), -the more restrictive license will apply.

-

For other products it developed, such as reports and analyses, -gives the customer the same license, but this license is exclusive to the customer -and does not contain the right to modification. The latter condition is intended -to ensure that the customer will not change 's products, such as -reports and analyses. retains the right to reuse these products, -for example for training and marketing purposes. will remove any -confidential information from these products before publication.

-

retains title to any property transferred to the customer -until all outstanding payments by the customer have been done in full (in Dutch: -“eigendomsvoorbehoud”). also only gives a license after -all outstanding payments have been done in full.

-

Who will perform the assignment?

-

has the right to appoint the persons who will perform the -assignment. It has the right to replace a person with someone with at least the -same expertise, but only after having consulted with the customer. This means -that section 7:404 Dutch Civil Code (in Dutch: “Burgerlijk Wetboek”) is -excluded.

-

Due to the nature of 's business, regularly -works with freelancers for the performance of its assignments. -has the right to engage third parties, including freelancers, in the course of -the performance of an assignment.

-

wants to be able to use the expertise of its entire team to -help with an assignment. This means that in the course of an assignment, it is -possible that the persons performing the assignment will consult with and be -advised by others in 's team. These others will of course be -bound by the same confidentiality obligations as the persons performing the assignment.

-

What happens when the scope of the assignment is bigger than agreed?

-

and the customer will attempt to precisely define the scope -of the assignment before starts. If during the course of the -assignment, the scope turns out to be bigger than expected, -will report this to the customer and make a written offer for the additional work.

-

How is payment arranged?

-

All amounts in 's offers are in Euros, excluding VAT and -other applicable taxes, unless agreed otherwise.

-

For assignments where the parties agreed to an hourly fee, -will send an invoice after each month. For other assignments, -will send an invoice after completion of the assignment, and at moments set out -in the offer (if any). The customer must pay an invoice within 30 days of the -invoice date.

-

may, prior to an assignment, agree on the payment of a -deposit by the customer. will settle deposits with interim -payments or the final invoice for the assignment.

-

If the payment is not received before the agreed term, the client will be -deemed to be in default without prior notice. will then have -the right to charge the statutory interest (in Dutch: “wettelijke rente”) -and any judicial and extrajudicial (collection) costs (in Dutch: -“gerechtelijke- en buitengerechtelijke (incasso)kosten”).

-

If the customer cancels or delays the assignment two weeks before it starts, - is entitled to charge the customer 50% of the agreed price. -If the customer cancels or delays the assignment after it already started, - is entitled to charge the customer 100% of the agreed price. - is entitled to charge a pro rata percentage in the case of -cancellation or delay shorter than two weeks before the start of the assignment -(i.e. a cancellation one week before the assignment would entitle -to charge 75% of the agreed price).

-

For what can be held liable?

-

Any liability of resulting from or related to the performance -of an assignment, shall be limited to the amount that is paid out in that -specific case under an applicable indemnity insurance of , -if any, increased by the amount of the applicable deductible (in Dutch: -“eigen risico”) which under that insurance shall be borne by . -If no amount is paid out under an insurance, these damages are limited to the -amount already paid for the assignment, with a maximum of EUR 10.000. -Each claim for damages shall expire after a period of one month from the day -following the day on which the customer became aware or could reasonably -be aware of the existence of the damages.

-

To make things clear, is not liable if a person associated -with acts contrary to any confidentiality or non-compete -obligation vis-á-vis the customer or a third party, this person might have -agreed to in another engagement.

-

What happens when third parties lodge a claim or initiate criminal proceedings -against ?

-

The customer shall indemnify and any person employed or -engaged by for any claims of third parties which are in any -way related to the activities of and any person employed or -engaged by for the customer.

-

Should a third party lodge a claim against or any of the -consultants it engaged or employed as a result of the performance of the assignment -for the customer, then the customer will co-operate fully with -in defending against this claim, including by providing to any -evidence it has which relates to this claim. -Should the public prosecutor initiate an investigation or criminal proceedings -against or any of the consultants it engaged or employed as a -result of the performance of the assignment for the customer, then the customer -will also co-operate fully with in defending against this -investigation or proceedings, including by providing any evidence it has which -relates to this investigation or these proceedings.

-

The customer shall reimburse and any person employed or -engaged by all costs of legal defence and all damages in -relation to these claims, investigations or proceedings. This provision does -not apply to the extent a claim, investigation, or proceeding is the result of -the intent or recklessness (in Dutch: “opzet of bewuste roekeloosheid”) -of or a person employed or engaged by .

-

When is this agreement terminated and what happens then?

-

Each of the parties may terminate the agreement wholly or partly without -prior notice if the other party is declared bankrupt or is being wound up or if -the other party's affairs are being administered by the court -(in Dutch: “surséance van betaling”).

-

When can not be expected to perform the assignment?

-

In the case of force majeure (in Dutch: “overmacht”) as a result of -which cannot reasonably be expected to perform the assignment, -the performance will be suspended. Situations of force majeure include cases -where means, such as soft- and hardware, which are prescribed by the customer -do not function well. The agreement may be terminated by either party if a -situation of force majeure has continued longer than 90 days. The customer will -then have to pay the amount for the work already performed pro rata.

-

Which law applies and which court is competent?

-

Dutch law applies to the legal relationship between and its -customers. Any dispute between and a customer will be resolved -in the first instance exclusively by the District Court (in Dutch: -“rechtbank”) of Amsterdam, the Netherlands.

-
+ Annex 1<br/>General Terms and Conditions +

+ What is this document? +

+

These are the general terms and conditions (in Dutch: “algemene + voorwaarden”) of (). This version of + the general terms and conditions is dated 15 July 2014. +

+

In the spirit of 's philosophy, + wants these general terms and conditions to be as understandable as + possible. If you have any questions, feel free to ask for clarification. +

+

+ What is ? +

+

+ is a private limited liability company under Dutch law + located in Amsterdam, The Netherlands. It is registered at the Dutch + Chamber of Commerce under no. 60628081. +

+

+ To what do these terms and conditions apply? +

+

These general terms and conditions apply to all agreements between + and the customer. + rejects any terms and conditions used by the customer. The parties can only + deviate from these general terms and conditions in writing. These general + terms and conditions are also intended to benefit any person employed or + engaged by during the performance of an assignment. +

+

+ How does agree on an assignment? + +

+

+ wants both parties to have a clear picture of an assignment + before it starts. This means there only is an agreement between + and the customer after + sends a written offer containing the key terms of the agreement and the + customer subsequently accepts the offer. Communications other than the + written offer do not form part of the agreement. + can rescind an offer until it is accepted by the customer. +

+

+ What can the customer expect from ? +

+

It is important to understand the limits of 's services. + does not (and cannot) give guarantees that something is secure. + instead has an obligation to make reasonable efforts (in + Dutch: “inspanningsverplichting”) to perform the agreed services. +

+

+ will make reasonable efforts to perform the assignment in + accordance with the plan set out in the offer (if any). If + expects it will not fulfill the plan as documented, it will let the customer + know without delay. is not automatically deemed to be in + default if it doesn't meet the plan. +

+

+ will make reasonable efforts to avoid disruption of the + customer's operations and damage to its owned or operated systems, but it cannot + guarantee that this will be avoided. The customer agrees to this. + is not obliged to restore the systems or recover any data deleted or amended + in the course of the assignment. +

+

+ What can expect from the customer? +

+

The customer will provide with all means necessary to allow + to perform the agreed services. If + needs explicit permission from the customer to perform its services (for + example, when doing penetration tests) the customer gives this permission. + The customer also warrants that it has the legal authority to give this + permission. +

+

+ How do the parties handle confidential information? +

+

+ and the customer will not disclose to others confidential + information and personal data they receive from each other or gain access + to in the course of an assignment. + has the right to disclose this information and data to persons engaged by + , but only if these persons have a similar confidentiality + obligation vis-á-vis . Any person will only use the + information and data it receives or gains access to for the purposes + following from the agreement. Both parties will take reasonable measures to + maintain the confidentiality of the information and data they received or + gained access to, and will ensure that persons engaged by them do the same. +

+

+ What does do with vulnerabilities it finds in the course + of an assignment? +

+

If in the course of an assignment finds a vulnerability + which might affect the customer, it will report this to the customer. If a + vulnerability might affect third parties as well, + retains the right to disclose this vulnerability also to others than the + customer. It will only do so after having given the customer a reasonable + period to take measures minimising the impact of the vulnerability, in line + with responsible disclosure best practices. +

+

+ What does do with indicators of compromise it finds? +

+

If in the course of an assignment finds indicators of + compromise, such as malware signatures and IP-addresses, it will report this + to the customer. retains the right to also publish this + information in a publicly accessible database. It will only do so after it + has given the customer the opportunity to object to the publication of data + which would negatively impact the customer. +

+

+ Who owns the products developed in the course of the assignment? +

+

+ retains any intellectual property rights in products + developed for an assignment, such as software and reports., + however, wants to teach as many customers as possible 'how to fish'. +

+

For software it developed, this means that + gives the customer a permanent, non-exclusive, transferable, sub-licensable, + worldwide license to distribute and use the software in source and binary + forms, with or without modification (very similar to the BSD-license). If + 's software is based on other software which is provided + under a license which restricts 's ability to license its + own software (such as the GPLv3 license), the more restrictive license will + apply. +

+

For other products it developed, such as reports and analyses, + gives the customer the same license, but this license is + exclusive to the customer and does not contain the right to modification. + The latter condition is intended to ensure that the customer will not change + 's products, such as reports and analyses. + retains the right to reuse these products, for example for + training and marketing purposes. will remove any confidential + information from these products before publication. +

+

+ retains title to any property transferred to the customer + until all outstanding payments by the customer have been done in full (in Dutch: + “eigendomsvoorbehoud”). also only gives a license after + all outstanding payments have been made in full. +

+

+ Who will perform the assignment? +

+

+ has the right to appoint the persons who will perform the + assignment. It has the right to replace a person with someone with at least + the same expertise, but only after having consulted with the customer. + This means that section 7:404 Dutch Civil Code (in Dutch: “Burgerlijk + Wetboek”) is excluded. +

+

Due to the nature of 's business, + regularly works with freelancers for the performance of its assignments. + has the right to engage third parties, including freelancers, + in the course of the performance of an assignment. +

+

+ + wants to be able to use the expertise of its entire team to help with an + assignment. This means that in the course of an assignment, it is possible + that the persons performing the assignment will consult with and be advised + by others in 's team. These others will of course be bound by + the same confidentiality obligations as the persons performing the + assignment. +

+

+ What happens when the scope of the assignment is bigger than agreed? +

+

+ and the customer will attempt to precisely define the scope + of the assignment before starts. If during the course of the + assignment, the scope turns out to be bigger than expected, + will report this to the customer and make a written offer for the additional + work. +

+

+ How is payment arranged? +

+

All amounts in 's offers are in Euros, excluding VAT and + other applicable taxes, unless agreed otherwise. +

+

For assignments where the parties agreed to an hourly fee, + will send an invoice after each month. For other assignments, + will send an invoice after completion of the assignment, and at moments set + out in the offer (if any). The customer must pay an invoice within 30 days + of the invoice date. +

+

+ may, prior to an assignment, agree on the payment of a + deposit by the customer. will settle deposits with interim + payments or the final invoice for the assignment. +

+

If the payment is not received before the agreed term, the client will be + deemed to be in default without prior notice. + will then have the right to charge the statutory interest (in Dutch: + “wettelijke rente”) and any judicial and extrajudicial (collection) + costs (in Dutch: “gerechtelijke- en buitengerechtelijke + (incasso)kosten”). +

+

If the customer cancels or delays the assignment two weeks before it + starts, is entitled to charge the customer 50% of the agreed + price. If the customer cancels or delays the assignment after it already started, + is entitled to charge the customer 100% of the agreed price. + is entitled to charge a pro rata percentage in the case of + cancellation or delay shorter than two weeks before the start of the assignment + (i.e. a cancellation one week before the assignment would entitle + to charge 75% of the agreed price). +

+

+ For what can be held liable? +

+

Any liability of resulting from or related to the performance + of an assignment, shall be limited to the amount that is paid out in that + specific case under an applicable indemnity insurance of , + if any, increased by the amount of the applicable deductible (in Dutch: + “eigen risico”) which under that insurance shall be borne by + . If no amount is paid out under an insurance, these damages + are limited to the amount already paid for the assignment, with a maximum of + EUR 10.000. Each claim for damages shall expire after a period of one month + from the day following the day on which the customer became aware or could + reasonably be aware of the existence of the damages. +

+

To make things clear, is not liable if a person associated with + acts contrary to any confidentiality or non-compete obligation + vis-á-vis the customer or a third party, this person might have agreed to in another + engagement. +

+

What happens when third parties lodge a claim or initiate criminal + proceedings against ? +

+

The customer shall indemnify and any person employed or engaged by + for any claims of third parties which are in any way related to the + activities of and any person employed or engaged by + for the customer. +

+

Should a third party lodge a claim against + or any of the consultants it engaged or employed as a result of the + performance of the assignment for the customer, then the customer will + co-operate fully with in defending against this claim, + including by providing to any evidence it has which + relates to this claim. Should the public prosecutor initiate an investigation + or criminal proceedings against + or any of the consultants it engaged or employed as a result of the + performance of the assignment for the customer, then the customer will also + co-operate fully with + in defending against this investigation or proceedings, including by + providing any evidence it has which relates to this investigation or these + proceedings. +

+

The customer shall reimburse and any person employed or engaged by + all costs of legal defence and all damages in relation to these claims, + investigations or proceedings. This provision does not apply to the extent a + claim, investigation, or proceeding is the result of the intent or + recklessness (in Dutch: “opzet of bewuste roekeloosheid”) of + or a person employed or engaged by . +

+

+ When is this agreement terminated and what happens then? +

+

Each of the parties may terminate the agreement wholly or partly without + prior notice if the other party is declared bankrupt or is being wound up or + if the other party's affairs are being administered by the court (in Dutch: + “surséance van betaling”). +

+

+ When can not be expected to perform the assignment? +

+

In the case of force majeure (in Dutch: “overmacht”) as a result of + which cannot reasonably be expected to perform the assignment, + the performance will be suspended. Situations of force majeure include cases + where means, such as soft- and hardware, which are prescribed by the customer + do not function well. The agreement may be terminated by either party if a + situation of force majeure has continued longer than 90 days. The customer + will then have to pay the amount for the work already performed pro rata. +

+

+ Which law applies and which court is competent? +

+

Dutch law applies to the legal relationship between + and its customers. Any dispute between + and a customer will be resolved in the first instance exclusively by the + District Court (in Dutch: “rechtbank”) of Amsterdam, the Netherlands. +

+ diff --git a/xml/source/snippets/offerte/en/grey-box.xml b/xml/source/snippets/offerte/en/grey-box.xml index 85e0bd4..a73f17f 100644 --- a/xml/source/snippets/offerte/en/grey-box.xml +++ b/xml/source/snippets/offerte/en/grey-box.xml @@ -1,17 +1,18 @@ -
-The Grey-Box Pentesting Method -

- Crystal-Box vs. Black-Box pentesting refers to the amount of information - regarding the target environment, architecture, and/or applications that is - initially shared by the customer with the pentesters. With Black-Box testing, - pentesters are given no information whatsoever about the target(s). With - Crystal-Box testing, pentesters are given all information requested about the target(s), - including source-code (when relevant), access to developers or system management, etc.. -
-
- will conduct Gray-Box testing, which means that partial information is - given on the target. -

+ The Grey-Box Pentesting Method +

+ Crystal-Box vs. Black-Box pentesting refers to the amount of + information regarding the target environment, architecture, and/or + applications that is initially shared by the customer with the pentesters. + With Black-Box testing, pentesters are given no information whatsoever about + the target(s). With Crystal-Box testing, pentesters are given all + information requested about the target(s), including source-code (when + relevant), access to developers or system management, etc.. +

+

+ + will conduct Gray-Box testing, which means that partial information is given + on the target. +

\ No newline at end of file diff --git a/xml/source/snippets/offerte/en/introandscope.xml b/xml/source/snippets/offerte/en/introandscope.xml index a5a64d2..bb8c684 100644 --- a/xml/source/snippets/offerte/en/introandscope.xml +++ b/xml/source/snippets/offerte/en/introandscope.xml @@ -1,11 +1,12 @@ -
- Introduction -

(hereafter “”), with its registered office - at , , , has requested - (hereafter “”) to perform . - Motivation for this request is that wishes to get a better - insight in ...

- -

This offer sets out the scope of the work and the terms and conditions under -which will perform these services.

-
\ No newline at end of file + +
+ Introduction +

(hereafter “”), with its registered office + at , , , has requested + (hereafter “”) to perform . + The motivation for this request is that wishes to get a better + insight into ...

+ +

This offer sets out the scope of the work and the terms and conditions under + which will perform these services.

+
\ No newline at end of file diff --git a/xml/source/snippets/offerte/en/introandscope_retest.xml b/xml/source/snippets/offerte/en/introandscope_retest.xml index 67e76ea..ccc5971 100644 --- a/xml/source/snippets/offerte/en/introandscope_retest.xml +++ b/xml/source/snippets/offerte/en/introandscope_retest.xml @@ -1,10 +1,16 @@ -
- Introduction -

(hereafter “”), with its registered office - at , , , has requested - (hereafter “”) to perform . - Motivation for this request is that recently had penetration test done by and wishes to test if the vulnerabilities have been mitigated.

- -

This offer sets out the scope of the work and the terms and conditions under -which will perform these services.

-
\ No newline at end of file + +
+ Introduction +

+ (hereafter “”), with its registered office at + , , , has requested + (hereafter “”) to perform .

+

The motivation for this request is that has had a recent penetration + test done by and wishes to check that the vulnerabilities found + have been mitigated. +

+ +

This offer sets out the scope of the work and the terms and conditions + under which will perform these services. +

+
diff --git a/xml/source/snippets/offerte/en/methodology.xml b/xml/source/snippets/offerte/en/methodology.xml index eacdfb1..a3c2722 100644 --- a/xml/source/snippets/offerte/en/methodology.xml +++ b/xml/source/snippets/offerte/en/methodology.xml @@ -1,67 +1,90 @@ +
+ Pentest Methodology +

During the execution of penetration tests, + broadly follows the following steps: +

-
- Pentest Methodology -

During the execution of penetration tests, broadly follows - the following steps:

+
    +
  1. Requirements Gathering and Scoping;
  2. +
  3. Discovery;
  4. +
  5. Validation;
  6. +
  7. Information Collection;
  8. +
  9. Threat and Vulnerability Analysis;
  10. +
  11. Exploitation;
  12. +
  13. Reporting;
  14. +
-
    -
  1. Requirements Gathering and Scoping;
  2. -
  3. Discovery;
  4. -
  5. Validation;
  6. -
  7. Information Collection;
  8. -
  9. Threat and Vulnerability Analysis;
  10. -
  11. Exploitation;
  12. -
  13. Reporting;
  14. -
- +

+ Step 1: Requirements Gathering and Scoping +
+ The expectations of both parties are discussed and agreements are made + regarding how to conduct the test(s). For example, contact details and the + pentest's scope are documented. +

-

Step 1: Requirements Gathering and Scoping
-The expectations of both parties are discussed and agreements are made regarding -how to conduct the test(s). For example, contact details and the pentest's scope -are documented.

+

+ Step 2: Discovery +
+ As much information as possible about the target organization and target + objects is collected. This information is passively gathered, primarily from + public sources. +

-

Step 2: Discovery
-As much information as possible about the target organization and target objects -is collected. This information is passively gathered, primarily from public sources.

+

+ Step 3: Validation +
+ All customer-specified systems are cross-referenced with findings from the + Discovery step. We do this to ensure that discovered systems are legal + property of the customer and to verify the scope with the customer. +

-

Step 3: Validation
-All customer-specified systems are cross-referenced with findings from the -Discovery step. We do this to ensure that discovered systems are legal property -of the customer and to verify the scope with the customer.

+

+ Step 4: Information Collection +
+ Information from Step 2 is now used to actively collect information about + the system. Activities conducted during this phase may include: Determining + which parts of the various components will be investigated; Testing for the + presence of known vulnerabilities, using automated tests; Identifying the + offered services and fingerprinting the software used for them. +

-

Step 4: Information Collection
-Information from Step 2 is now used to actively collect information about the -system. Activities conducted during this phase may include: -Determining which parts of the various components will be investigated; -Testing for the presence of known vulnerabilities, using automated tests; -Identifying the offered services and fingerprinting the software used for them.

+

+ Step 5: Threat and Vulnerability Analysis +
+ Potential threats and vulnerabilities are indexed, based upon the collected + information. +

-

Step 5: Threat and Vulnerability Analysis
-Potential threats and vulnerabilities are indexed, based upon the collected information.

+

+ Step 6: Exploitation +
+ Attempt to use vulnerabilities of the various components. The diverse + applications and components of the client's infrastructure are rigorously + probed for frequently occurring design, configuration, and programming + errors. +

-

Step 6: Exploitation
-Attempt to use vulnerabilities of the various components. -The diverse applications and components of the client's infrastructure are -rigorously probed for frequently occurring design, configuration, and -programming errors.

+

Note: uses open-source scanning tools to get its bearings, + but generally performs most of the exploitation by hand. +

-

Note: uses open-source scanning tools to get its bearings, -but generally performs most of the exploitation by hand.

- -

Step 7: Reporting
-After finishing the audit, a report will be delivered where the step-by-step -approach, results, and discovered vulnerabilities are described. The report and -results will be presented to the responsible project leader or manager at the -client's office.

- -

Steps 4-6 may be repeated multiple times per test. For example, access may be -acquired in an external system, which serves as a stepping-stone to the internal network. -The internal network will then be explored in Steps 4 and 5, and exploited in Step 6.

- - - - - +

+ Step 7: Reporting +
+ After finishing the audit, a report will be delivered where the step-by-step + approach, results, and discovered vulnerabilities are described. The report + and results will be presented to the responsible project leader or manager + at the client's office. +

+

Steps 4-6 may be repeated multiple times per test. For example, access may + be acquired in an external system, which serves as a stepping-stone to the + internal network. The internal network will then be explored in Steps 4 and + 5, and exploited in Step 6. +

+ + + +
diff --git a/xml/source/snippets/offerte/en/methodology_code-audit.xml b/xml/source/snippets/offerte/en/methodology_code-audit.xml index 1761516..02b24cf 100644 --- a/xml/source/snippets/offerte/en/methodology_code-audit.xml +++ b/xml/source/snippets/offerte/en/methodology_code-audit.xml @@ -2,44 +2,56 @@
Code Audit

- will perform a code audit. During this process we will verify if the proper - security controls are present, work as intended and are implemented correctly. - If vulnerabilities are found, we determine the threat level by assessing the - likelihood of exploitation of this vulnerability and the impact on the - Confidentiality, Integrity and Availability (CIA) of the system. We will describe how an - attacker would exploit the vulnerability and suggest ways of fixing it.
- This requires an extensive knowledge of the platform the application is running on, as well - as the extensive knowledge of the language the application in written - in and patterns that have been used. Therefore a code audit done by highly-trained - specialists with a strong background in programming. + + will perform a code audit. During this process we will verify if the proper + security controls are present, work as intended and are implemented + correctly. If vulnerabilities are found, we determine the threat level by + assessing the likelihood of exploitation of this vulnerability and the + impact on the Confidentiality, Integrity and Availability (CIA) of the + system. We will describe how an attacker would exploit the vulnerability and + suggest ways of fixing it. +
+ This requires an extensive knowledge of the platform the application is + running on, as well as the extensive knowledge of the language the + application in written in and patterns that have been used. Therefore a code + audit done by highly-trained specialists with a strong background in + programming.

- During the code audit, we take the following approach: + During the code audit, we take the following approach:

    -
  1. Thorough comprehension of functionality
    - We try to get a thorough comprehension of how the application works and how - it interacts with the user and other systems. Having detailed documentation - (manuals, flow charts, system sequence diagrams, design documentation) at - this stage is very helpful, as they aid the understanding of the application -
  2. -
  3. Static analysis
    - Using the understanding we gained in the previous step, we will use static code - analysis to uncover any vulnerabilities. Static analysis means the specialist will - analyze the code and implementation of security controls to get an understanding of - the security of the application, rather than running the application to reach the same - goal. This is primarily a manual process, where the specialist relies on his knowledge and expertise - to find the flaws in the application. The specialist may be aided in this process by - automatic analysis tools, but his or her skills are the driving force.
    - Depending on the type of application, we will identify the endpoints. In this case, it means - where data enters and leaves the application. The data is then followed through the application - and is leading in determining if assessing the quality of the security measures. -
  4. +
  5. Thorough comprehension of functionality +
    + We try to get a thorough comprehension of how the application works and + how it interacts with the user and other systems. Having detailed + documentation (manuals, flow charts, system sequence diagrams, design + documentation) at this stage is very helpful, as they aid the + understanding of the application +
  6. +
  7. Static analysis +
    + Using the understanding we gained in the previous step, we will use static + code analysis to uncover any vulnerabilities. Static analysis means the + specialist will analyze the code and implementation of security controls + to get an understanding of the security of the application, rather than + running the application to reach the same goal. This is primarily a manual + process, where the specialist relies on his knowledge and expertise to + find the flaws in the application. The specialist may be aided in this + process by automatic analysis tools, but his or her skills are the driving + force. +
    + Depending on the type of application, we will identify the endpoints. In + this case, it means where data enters and leaves the application. The data + is then followed through the application and is leading in determining if + assessing the quality of the security measures. +
  8. -
  9. Dynamic analysis
    - Dynamic analysis can also be performed. In this case, the program - is run and actively exploited by the specialist. This is usually done to confirm - a vulnerability and as such follows the result of the static analysis. -
  10. +
  11. Dynamic analysis +
    + Dynamic analysis can also be performed. In this case, the program is run + and actively exploited by the specialist. This is usually done to confirm + a vulnerability and as such follows the result of the static analysis. +
diff --git a/xml/source/snippets/offerte/en/methodology_load-test.xml b/xml/source/snippets/offerte/en/methodology_load-test.xml index a0de315..a4e325f 100644 --- a/xml/source/snippets/offerte/en/methodology_load-test.xml +++ b/xml/source/snippets/offerte/en/methodology_load-test.xml @@ -7,7 +7,7 @@ performance requirement, in a consistent and repeatable way. For web sites and applications it usually involves simulating multiple visitors using the site's features in various ways. This sets it apart from DDoS testing, which - is much more indiscriminate. For load testing, + is much more indiscriminate. For load testing, generally executes the following steps:

@@ -30,8 +30,8 @@ to see whether it brings performance improvements. These reasons boil down to running some specific tests, usually one or more of:
    -
  • How much activity a system can cope with before it starts to fail (maximum - simultaneous users, maximum request rate) +
  • How much activity a system can cope with before it starts to fail + (maximum simultaneous users, maximum request rate)
  • What level of performance can be sustained for a given load (average response time for a fixed number of users) @@ -116,13 +116,12 @@ 100, 500, 1000, 2000 users, or a maximum load test using a slow increase from 100 to 10000 users to see how far it gets before problems appear.

    - +

    There are many load testing tools of varying levels of sophistication, including Apache's simple "ab" and more complex "JMeter" projects, the - Selenium project for fine-detail browser simulation. - + Selenium project for fine-detail browser simulation. prefers to use open-source tools such as these. There are also online - commercial services that are useful for testing very large loads that - would otherwise be difficult and expensive to configure from scratch. + commercial services that are useful for testing very large loads that would + otherwise be difficult and expensive to configure from scratch.

diff --git a/xml/source/snippets/offerte/en/phishing.xml b/xml/source/snippets/offerte/en/phishing.xml index 9d6e156..8f084da 100644 --- a/xml/source/snippets/offerte/en/phishing.xml +++ b/xml/source/snippets/offerte/en/phishing.xml @@ -1,5 +1,4 @@ -
Social Engineering: Phishing

@@ -48,4 +47,4 @@ (hopefully) been received, the logged results are analyzed and presented in the final report.

-
\ No newline at end of file + diff --git a/xml/source/snippets/offerte/en/planningandpayment.xml b/xml/source/snippets/offerte/en/planningandpayment.xml index 7670b56..19b2d1b 100644 --- a/xml/source/snippets/offerte/en/planningandpayment.xml +++ b/xml/source/snippets/offerte/en/planningandpayment.xml @@ -6,15 +6,14 @@
  • performs a on .
  • delivers the final report .
  • - -

    - Our fixed-fee price quote for the above described is .- excl. VAT and out-of-pocket expenses. +

    + Our fixed-fee price quote for the above described is .- + excl. VAT and out-of-pocket expenses. will send an invoice after the completion of this assignment. will pay the agreed amount within 30 days of the invoice date.

    -

    +

    Any additional work will be charged separately. An hourly rate for additional work will be agreed upon before starting this work.

    - diff --git a/xml/source/snippets/offerte/en/projectoverview.xml b/xml/source/snippets/offerte/en/projectoverview.xml index 62f9300..4aa5cab 100644 --- a/xml/source/snippets/offerte/en/projectoverview.xml +++ b/xml/source/snippets/offerte/en/projectoverview.xml @@ -1,38 +1,43 @@
    - Project Overview -

    will perform - for of the systems described below. The services are intended - to gain insight into the security of these systems. To do so, - will access these systems, attempt to find vulnerabilities, and gain - further access and elevated privileges by exploiting any vulnerabilities - found.

    - -

    will test the following targets - (the “Targets”):

    - - - -

    will test for the presence of the - most common vulnerabilities, using both publicly available vulnerability - scanning tools and manual testing. shall perform a - -day (-manday), , intrusive test via the internet.

    - - - - - - - - - -
    \ No newline at end of file + + Project Overview +

    + will perform for + of the systems described below. The services are intended to gain insight + into the security of these systems. To do so, + will access these systems, attempt to find vulnerabilities, and gain further + access and elevated privileges by exploiting any vulnerabilities found. +

    + +

    + will test the following targets (the “Targets”): +

    + + + +

    + will test for the presence of the most common + vulnerabilities, using both publicly available vulnerability scanning + tools and manual testing. shall perform a + -day (-manday), , intrusive test via the + internet. +

    + + + + + + + + + diff --git a/xml/source/snippets/offerte/en/projectoverview_retest.xml b/xml/source/snippets/offerte/en/projectoverview_retest.xml index 1d0da8d..948b027 100644 --- a/xml/source/snippets/offerte/en/projectoverview_retest.xml +++ b/xml/source/snippets/offerte/en/projectoverview_retest.xml @@ -1,27 +1,38 @@
    - Project Overview -

    will perform - for as a follow-up on the previous test in XXXXXXXXXX TODO XXXXXXXXXX (timeframe of previous pentest). The services are intended to see if the previously discovered exploits are patched correctly. To do so, will access the systems again and test the findings from the previous penetration test (the “Targets”):

    - - -

    will test using both publicly available vulnerability scanning tools and manual testing. shall perform a -day, follow-up penetration test via the internet.

    - - - - - - - - - -
    \ No newline at end of file + + Project Overview +

    + will perform for + as a follow-up on the previous test in XXXXXXXXXX TODO XXXXXXXXXX + (timeframe of previous pentest). The services are intended to see if the + previously discovered exploits are patched correctly. To do so, + will access the systems again and test the findings + from the previous penetration test (the “Targets”): +

    + + + +

    + will test using both publicly available vulnerability + scanning tools and manual testing. shall perform a + -day, follow-up penetration test via the internet. +

    + + + + + + + + + diff --git a/xml/source/snippets/offerte/en/teamandreporting.xml b/xml/source/snippets/offerte/en/teamandreporting.xml index 57387fc..17dad5b 100644 --- a/xml/source/snippets/offerte/en/teamandreporting.xml +++ b/xml/source/snippets/offerte/en/teamandreporting.xml @@ -1,51 +1,65 @@
    - Team and Reporting + Team and Reporting -
    - Team -

    may perform the activities with its core-team - members, external freelancers, and/or volunteers.

    -

    First point of contact for this assignment shall be:

    -
      -
    • ()
    • -
    • ()
    • -
    - -

    The workflow of our penetration testing team is modeled on that of a Capture The Flag (CTF) team: - - - has a geographically distributed team - and we use online infrastructure (RocketChat, GitLabs, etc.) - to coordinate our work. This enables us to invite the - customer to send several technical people from their - organization to join our team on a volunteer basis. - Naturally, we extend this invitation to as well.

    - -

    Throughout the course of the audit, we intend to actively - brainstorm with about both the and the process. - This is a continuous learning experience for both us and you. - Also, in our experience, a tight feedback loop with the customer - greatly improves both the quality and focus of the engagement.

    +
    + Team +

    + may perform the activities with its core-team members, + external freelancers, and/or volunteers. +

    +

    First point of contact for this assignment shall be:

    +
      +
    • + () +
    • +
    • + () +
    • +
    + +

    The workflow of our penetration testing team is modeled on that of a + Capture The Flag (CTF) team: + -

    -
    - Reporting -

    will report to on the . - This report will include the steps it has taken during the - test and the vulnerabilities it has found. It will include - recommendations but not comprehensive solutions on how to address - these vulnerabilities.

    - -

    A sample Pentest report can be found here

    - - -

    One of 's Core Principles is the Teach - To Fish principle – otherwise known as the 'Peek over our - Shoulder' (PooS) principle. We strive to structure our - services so they can also serve as a teaching or training - opportunity for our customers.

    -
    + has a geographically distributed team and we use online + infrastructure (RocketChat, GitLabs, etc.) to coordinate our work. This + enables us to invite the customer to send several technical people from + their organization to join our team on a volunteer + basis. Naturally, we extend this invitation to as well. +

    + +

    Throughout the course of the audit, we intend to actively brainstorm with + about both the + and the process. This is a continuous learning experience for both us and + you. Also, in our experience, a tight feedback loop with the customer + greatly improves both the quality and focus of the engagement. +

    +
    + +
    + Reporting +

    + will report to + on the . This report will include the steps it has + taken during the test and the vulnerabilities it has found. It will + include recommendations but not comprehensive solutions on how to address + these vulnerabilities. +

    + +

    A sample Pentest report can be found here

    + + +

    One of 's core principles is “Teach To Fish”, otherwise + known as “Peek over our Shoulder” (PooS); We strive to structure our + services so they can also serve as teaching or training opportunities for + our customers. +

    +
    diff --git a/xml/source/snippets/offerte/nl/conditions.xml b/xml/source/snippets/offerte/nl/conditions.xml index 8ab5737..31ac007 100644 --- a/xml/source/snippets/offerte/nl/conditions.xml +++ b/xml/source/snippets/offerte/nl/conditions.xml @@ -1,7 +1,7 @@
    Algemene voorwaarden -

    zal alleen de +

    zal alleen de uitvoeren als het de toestemming heeft gekregen van zoals uiteengezet in de penetratietestvrijwaring, bijgevoegd als Annex 2 of verschaft als los document.

    diff --git a/xml/source/snippets/offerte/nl/engagementtime.xml b/xml/source/snippets/offerte/nl/engagementtime.xml index 25bfbb3..5cac4af 100644 --- a/xml/source/snippets/offerte/nl/engagementtime.xml +++ b/xml/source/snippets/offerte/nl/engagementtime.xml @@ -1,3 +1,4 @@ -

    Op basis van de verstrekte informatie verwachten wij dat het uitvoeren van de opdracht dagen zal duren. -De planning van de opdracht is als volgt:

    \ No newline at end of file +

    Op basis van de verstrekte informatie verwachten wij dat het uitvoeren van de + opdracht dagen zal duren. De planning van de opdracht is als volgt: +

    \ No newline at end of file diff --git a/xml/source/snippets/offerte/nl/projectoverview.xml b/xml/source/snippets/offerte/nl/projectoverview.xml index efd9776..ff1a933 100644 --- a/xml/source/snippets/offerte/nl/projectoverview.xml +++ b/xml/source/snippets/offerte/nl/projectoverview.xml @@ -1,58 +1,69 @@
    - Projectoverzicht -

    zal uitvoeren voor - op de hieronder beschreven systemen. De diensten zijn bedoeld om inzicht te bieden - in de veiligheid van deze systemen. Om dit te kunnen bewerkstelligen zal - toegang krijgen tot deze systemen, proberen kwetsbaarheden op te sporen en trachten - verdere toegang te krijgen door de gevonden kwetsbaarheden uit te buiten.

    - -

    zal de volgende doelwitten testen - (de “Doelwitten”):

    - - - -

    zal testen op de aanwezigheid van de - meest voorkomende kwetsbaarheden, gebruik makend van zowel publiek beschikbare - scanning tools, als door handmatig testen. zal een grondige - -daagse ( mandagen), test uitvoeren via internet.

    - -
    - Scope -

    schat de uitvoering van de penetratietest op ... dagen in totaal:

    -
      -
    • ... dagen voor het testen van ...;
    • -
    • ... dagen voor het testen van ...;
    • -
    • ... dagen voor de verificatie van potentiële risico's, opstellen van een Proof of Concept - en het vastleggen van onze bevindingen en aanbevelingen in het rapport.
    • -
    -
    - Out of scope
    -

    De onderliggende netwerkinfrastructuur, ..., ... en eventuele loadbalancing-infrastructuur maken geen deel uit van de scope. - Uitgesloten zijn ook:

    -
      -
    • elke vorm van social engineering;
    • -
    • (D)DoS aanvallen;
    • -
    • ...
    • -
    -
    - - - - - - - - - - -
    \ No newline at end of file + Projectoverzicht +

    + zal uitvoeren voor + op de hieronder beschreven systemen. De diensten zijn bedoeld om inzicht te + bieden in de veiligheid van deze systemen. Om dit te kunnen bewerkstelligen + zal toegang krijgen tot deze systemen, proberen kwetsbaarheden + op te sporen en trachten verdere toegang te krijgen door de gevonden + kwetsbaarheden uit te buiten. +

    + +

    + zal de volgende doelwitten testen (de “Doelwitten”): +

    + + + +

    + zal testen op de aanwezigheid van de meest voorkomende + kwetsbaarheden, gebruik makend van zowel publiek beschikbare scanning tools, + als door handmatig testen. zal een grondige -daagse + ( mandagen), test uitvoeren via internet. +

    + +
    + Scope +

    + schat de uitvoering van de penetratietest op ... dagen in totaal: +

    +
      +
    • ... dagen voor het testen van ...;
    • +
    • ... dagen voor het testen van ...;
    • +
    • ... dagen voor de verificatie van potentiële risico's, opstellen van + een Proof of Concept en het vastleggen van onze bevindingen en + aanbevelingen in het rapport. +
    • +
    +

    + Out of scope +

    +

    De onderliggende netwerkinfrastructuur, ..., ... en eventuele + loadbalancing-infrastructuur maken geen deel uit van de scope. Uitgesloten + zijn ook: +

    +
      +
    • elke vorm van social engineering;
    • +
    • (D)DoS aanvallen;
    • +
    • ...
    • +
    +
    + + + + + + + + +
    From eab0771cd9be08cac3a3d08151efdcc24d0f92b0 Mon Sep 17 00:00:00 2001 From: Marcus Bointon Date: Tue, 6 Dec 2016 15:43:34 +0100 Subject: [PATCH 02/63] Add training offerte subtype --- .../offerte/en/prerequisites_training.xml | 15 + .../offerte/en/projectoverview_training.xml | 23 + xml/source/snippets/snippetselection.xml | 854 +++++++++--------- 3 files changed, 473 insertions(+), 419 deletions(-) create mode 100644 xml/source/snippets/offerte/en/prerequisites_training.xml create mode 100644 xml/source/snippets/offerte/en/projectoverview_training.xml diff --git a/xml/source/snippets/offerte/en/prerequisites_training.xml b/xml/source/snippets/offerte/en/prerequisites_training.xml new file mode 100644 index 0000000..4d13029 --- /dev/null +++ b/xml/source/snippets/offerte/en/prerequisites_training.xml @@ -0,0 +1,15 @@ + +
    + Prerequisites +

    In order to provide training, will need to:

    + +
      +
    • Develop training materials
    • +
    • Book an appropriate venue
    • +
    +

    will need to provide:

    +
      +
    • Training objectives
    • +
    • An appropriate venue
    • +
    +
    diff --git a/xml/source/snippets/offerte/en/projectoverview_training.xml b/xml/source/snippets/offerte/en/projectoverview_training.xml new file mode 100644 index 0000000..7d26efc --- /dev/null +++ b/xml/source/snippets/offerte/en/projectoverview_training.xml @@ -0,0 +1,23 @@ + +
    + Project Overview + +

    + + will provide xxx training sessions, for xxx different groups, + on-site/off-site at xxx venue, with a maximum of xxx participants per event. + The training will focus on the top 5 vulnerabilities from the OWASP Top 10. +

    +

    As part of this training, + will also guide the participants through performing security tests on the + targets described below. This is intended to gain insight into the security + of these systems. This is done by means of accessing the underlying systems, + attempting to find vulnerabilities, and gaining further access and elevated + privileges by exploiting any vulnerabilities found. +

    +

    Afterwards, will coach the participants in writing a pentest + report; will start writing the report and + will complete it. +

    + +
    \ No newline at end of file diff --git a/xml/source/snippets/snippetselection.xml b/xml/source/snippets/snippetselection.xml index b068586..809dcb6 100644 --- a/xml/source/snippets/snippetselection.xml +++ b/xml/source/snippets/snippetselection.xml @@ -1,427 +1,443 @@ - - - - - - introandscope - projectoverview - prerequisites - disclaimer - methodology - - - - additional-code-audit_methodology - - - teamandreporting - planningandpayment - aboutus - conditions - generaltermsandconditions - waiver - - - - - - introandscope_retest - projectoverview_retest - prerequisites - disclaimer - methodology - teamandreporting - planningandpayment - aboutus - conditions - generaltermsandconditions - waiver - - + + + + + + introandscope + projectoverview + prerequisites + disclaimer + methodology + + + + additional-code-audit_methodology + + + teamandreporting + planningandpayment + aboutus + conditions + generaltermsandconditions + waiver + + - - - introandscope - projectoverview - prerequisites - disclaimer - methodology - - - - additional-code-audit_methodology - - - teamandreporting - planningandpayment - aboutus - conditions - generaltermsandconditions - waiver - - + + + introandscope_retest + projectoverview_retest + prerequisites + disclaimer + methodology + teamandreporting + planningandpayment + aboutus + conditions + generaltermsandconditions + waiver + + - - - introandscope - projectoverview - prerequisites - disclaimer - methodology_load-test - - - - additional-code-audit_methodology - - - teamandreporting - planningandpayment - aboutus - conditions - generaltermsandconditions - waiver - - + + + introandscope + projectoverview + prerequisites + disclaimer + methodology + + + + additional-code-audit_methodology + + + teamandreporting + planningandpayment + aboutus + conditions + generaltermsandconditions + waiver + + - - - - introandscope - projectoverview - prerequisites - disclaimer_code-audit - methodology_code-audit - teamandreporting - planningandpayment - aboutus - conditions_code-audit - generaltermsandconditions - waiver - - - - - - introandscope - projectoverview - prerequisites - disclaimer - methodology - - - - additional-code-audit_methodology - - - teamandreporting - planningandpayment - aboutus - conditions - generaltermsandconditions - waiver - - - + + + introandscope + projectoverview + prerequisites + disclaimer + methodology_load-test + + + + additional-code-audit_methodology + + + teamandreporting + planningandpayment + aboutus + conditions + generaltermsandconditions + waiver + + + + + + + introandscope + projectoverview + prerequisites + disclaimer_code-audit + methodology_code-audit + teamandreporting + planningandpayment + aboutus + conditions_code-audit + generaltermsandconditions + waiver + + + + + + introandscope + projectoverview_training + prerequisites_training + disclaimer + + + planningandpayment + aboutus + conditions + generaltermsandconditions + waiver + + + + + + introandscope + projectoverview + prerequisites + disclaimer + methodology + + + + additional-code-audit_methodology + + + teamandreporting + planningandpayment + aboutus + conditions + generaltermsandconditions + waiver + + + - - - - - - - - parties - - - - wa_companywants - wa_companyasks - wa_contractorcan - wa_d - wa_e - wa_f - wa_g - - - c1_title - - - c1_performswork - c1_tacitrenewal - c1_termination - c1_prematuretermination - c1_otheremployment - - - c2_title - - - c2_planning - c2_assignmentaccept - c2_organisingwork - c2_authority - c2_independent - c2_ownresources - c2_notification - - - c3_title - - - c3_payment - c3_travelexpenses - - - c4_title - - - c4_thirdparty - c4_thirdpartycompetence - - - c5_title - - - c5_retainrights - c5_transferrights - - - c6_title - - - c6_confidentiality - - - c7_title - - - c7_limitedlibility - c7_thirdpartyclaims - - - c8_title - - - c8_responsibilities - c8_taxes - - - c9_title - - - c9_provisions - c9_generaltermsandconditions - c9_dutchlaw - - - - - - - parties - - - - wa_companywants - wa_companyasks - wa_contractorcan - wa_d - wa_e - wa_f - wa_g - - - c1_title - - - c1_period - c1_tacitrenewal - c1_termination - c1_prematuretermination - c1_otheremployment - - - c2_title - - - c1_performswork - c2_assignmentaccept - c2_organisingwork - c2_authority - c2_independent - c2_ownresources - c2_notification - - - c3_title - - - c3_payment - c3_travelexpenses - - - c4_title - - - c4_thirdparty - c4_thirdpartycompetence - - - c5_title - - - c5_retainrights - c5_transferrights - - - c6_title - - - c6_confidentiality - - - c7_title - - - c7_limitedlibility - c7_thirdpartyclaims - - - c8_title - - - c8_responsibilities - c8_taxes - - - c9_title - - - c9_provisions - c9_generaltermsandconditions - c9_dutchlaw - - - - - - - - parties_nonzzp - - - - wa_companywants - wa_companyasks - wa_contractorcan - wa_g - - - c1_title - - - c1_performswork - c1_termination - c1_prematuretermination - - - c2_title - - - c2_planning - c2_assignmentaccept - c2_organisingwork - c2_authority - c2_independent - c2_ownresources - c2_notification - - - c3_title - - - c3_payment - - - c4_title - - - c4_thirdparty_nonzzp - c4_thirdpartycompetence - - - c5_title - - - c5_transferrights - - - c6_title - - - c6_confidentiality - - - c7_title - - - c7_limitedlibility - c7_thirdpartyclaims - - - c8_title - - - c8_responsibilities - - - c9_title - - - c9_provisions - c9_generaltermsandconditions - c9_dutchlaw - - - - - - + + + + + + + + parties + + + + wa_companywants + wa_companyasks + wa_contractorcan + wa_d + wa_e + wa_f + wa_g + + + c1_title + + + c1_performswork + c1_tacitrenewal + c1_termination + c1_prematuretermination + c1_otheremployment + + + c2_title + + + c2_planning + c2_assignmentaccept + c2_organisingwork + c2_authority + c2_independent + c2_ownresources + c2_notification + + + c3_title + + + c3_payment + c3_travelexpenses + + + c4_title + + + c4_thirdparty + c4_thirdpartycompetence + + + c5_title + + + c5_retainrights + c5_transferrights + + + c6_title + + + c6_confidentiality + + + c7_title + + + c7_limitedlibility + c7_thirdpartyclaims + + + c8_title + + + c8_responsibilities + c8_taxes + + + c9_title + + + c9_provisions + c9_generaltermsandconditions + c9_dutchlaw + + + + + + + parties + + + + wa_companywants + wa_companyasks + wa_contractorcan + wa_d + wa_e + wa_f + wa_g + + + c1_title + + + c1_period + c1_tacitrenewal + c1_termination + c1_prematuretermination + c1_otheremployment + + + c2_title + + + c1_performswork + c2_assignmentaccept + c2_organisingwork + c2_authority + c2_independent + c2_ownresources + c2_notification + + + c3_title + + + c3_payment + c3_travelexpenses + + + c4_title + + + c4_thirdparty + c4_thirdpartycompetence + + + c5_title + + + c5_retainrights + c5_transferrights + + + c6_title + + + c6_confidentiality + + + c7_title + + + c7_limitedlibility + c7_thirdpartyclaims + + + c8_title + + + c8_responsibilities + c8_taxes + + + c9_title + + + c9_provisions + c9_generaltermsandconditions + c9_dutchlaw + + + + + + + + parties_nonzzp + + + + wa_companywants + wa_companyasks + wa_contractorcan + wa_g + + + c1_title + + + c1_performswork + c1_termination + c1_prematuretermination + + + c2_title + + + c2_planning + c2_assignmentaccept + c2_organisingwork + c2_authority + c2_independent + c2_ownresources + c2_notification + + + c3_title + + + c3_payment + + + c4_title + + + c4_thirdparty_nonzzp + c4_thirdpartycompetence + + + c5_title + + + c5_transferrights + + + c6_title + + + c6_confidentiality + + + c7_title + + + c7_limitedlibility + c7_thirdpartyclaims + + + c8_title + + + c8_responsibilities + + + c9_title + + + c9_provisions + c9_generaltermsandconditions + c9_dutchlaw + + + + + + From d7036b5d86b1028b92817a2f59e96007992dadad Mon Sep 17 00:00:00 2001 From: skyanth Date: Tue, 6 Dec 2016 16:04:12 +0100 Subject: [PATCH 03/63] Added training quote title to strings --- xml/source/snippets/localisationstrings.xml | 8 ++++++++ xml/source/snippets/snippetselection.xml | 3 --- 2 files changed, 8 insertions(+), 3 deletions(-) diff --git a/xml/source/snippets/localisationstrings.xml b/xml/source/snippets/localisationstrings.xml index d785016..7855b60 100644 --- a/xml/source/snippets/localisationstrings.xml +++ b/xml/source/snippets/localisationstrings.xml @@ -51,6 +51,14 @@ load test load test + + training + training + + + training + training + VOOR FOR diff --git a/xml/source/snippets/snippetselection.xml b/xml/source/snippets/snippetselection.xml index 809dcb6..0d145df 100644 --- a/xml/source/snippets/snippetselection.xml +++ b/xml/source/snippets/snippetselection.xml @@ -102,14 +102,11 @@ - introandscope projectoverview_training prerequisites_training disclaimer - - planningandpayment aboutus conditions From bd45a3c4c87985f81237b6eed5b60a090c6a0278 Mon Sep 17 00:00:00 2001 From: skyanth Date: Thu, 12 Jan 2017 11:58:28 +0100 Subject: [PATCH 04/63] Implemented pie charts --- xml/RELEASE_NOTES.md | 7 + xml/doc/examples/examplereport.xml | 29 ++- xml/dtd/pentestreport.xsd | 13 ++ xml/target/report.fo | 313 +++++++++++++++++++++++++++++ xml/target/report.pdf | Bin 0 -> 188486 bytes xml/xslt/auto.xslt | 310 +++++++++++++++++++++++++++- 6 files changed, 663 insertions(+), 9 deletions(-) create mode 100644 xml/target/report.fo create mode 100644 xml/target/report.pdf diff --git a/xml/RELEASE_NOTES.md b/xml/RELEASE_NOTES.md index 4e7c204..9e6b20e 100644 --- a/xml/RELEASE_NOTES.md +++ b/xml/RELEASE_NOTES.md @@ -1,6 +1,13 @@ RELEASE NOTES ============= +January 12th, 2017 +------------------ + +###Pie charts + +You can now generate pie charts for any countable data that might be in the report. You can do so using the element ``, where `x` is the attribute value of any element `y` in the document (useful charts would be `threatLevel` for `x` and `finding` for `y` to show a pie chart of the share of findings by threat level, or `type` for `x` and `finding` for `y` to show a pie chart of the share of findings by type). The height (and width) of the pie is set in the pieHeight attribute, where `z` is the height of the pie chart in px. + August 25th, 2016 ----------------- diff --git a/xml/doc/examples/examplereport.xml b/xml/doc/examples/examplereport.xml index 50cebdf..b2a5cd2 100644 --- a/xml/doc/examples/examplereport.xml +++ b/xml/doc/examples/examplereport.xml @@ -121,6 +121,19 @@ who is also the co-founder/CEO of Radically Open Security. +
    + Charts +
    + Findings by Threat Level + +
    +
    + Findings by Type + +
    + + +
    @@ -232,7 +245,21 @@ Raw packets sent: 1681 (73.962KB) | Rcvd: 1681 (77.322KB) - + + A not quite so terrible XSS issue + +

    A description of the problem.

    +
    + +

    Vulnerability described in detail.

    +
    + +

    Impact on security.

    +
    + +

    A ready solution.

    +
    +
    diff --git a/xml/dtd/pentestreport.xsd b/xml/dtd/pentestreport.xsd index 487b680..eb90fdc 100644 --- a/xml/dtd/pentestreport.xsd +++ b/xml/dtd/pentestreport.xsd @@ -158,6 +158,7 @@ + @@ -173,6 +174,18 @@ + + + + + + + + + + + + diff --git a/xml/target/report.fo b/xml/target/report.fo new file mode 100644 index 0000000..3e3b109 --- /dev/null +++ b/xml/target/report.fo @@ -0,0 +1,313 @@ +ConfidentialConfidential/Radically Open Security B.V. -  60628081/Radically Open Security B.V. -  60628081 + PENETRATION TEST REPORTforSitting Duck B.V. V1.0AmsterdamJanuary 26th, 2015Document PropertiesClientTitlePENETRATION TEST REPORTTargetfishinabarrel.sittingduck.comVersion1.0PentestersMelanie Rieback, Aristotle, George Boole, William of Ockham, Ludwig Josef Johann WittgensteinAuthorsPatricia Piolon, Ernest Hemingway, JRR Tolkien, Arthur Conan DoyleReviewed byMelanie RiebackApproved byMelanie RiebackVersion controlVersionDateAuthorDescription 0.1January 19th, 2015Patricia PiolonInitial draft 0.2January 20th, 2015Ernest HemingwayStructure & contents revision 0.3January 21st, 2015Patricia PiolonAdded threat levels and recommendations 0.4January 22nd, 2015Patricia Piolon, JRR TolkienRevision 0.5January 23rd, 2015Patricia PiolonRevision1.0January 26th, 2015Arthur Conan DoyleFinalizingContactFor more information about this Document and its + contents please contact Radically Open Security B.V.NameMelanie RiebackAddressOverdiemerweg 281111 PP DiemenThe NetherlandsPhone+31 6 10 21 32 40Emailinfo@radicallyopensecurity.com + + Table of Contents + + + + + 1  Executive Summary  1.1  Introduction  1.2  Scope of work  1.3  Project objectives  1.4  Timeline  1.5  Results in a Nutshell  1.6  Summary of Findings  1.7  Summary of Recommendations  1.8  Charts  1.8.1  Findings by Threat Level  1.8.2  Findings by Type   + + 2  Methodology  2.1  Planning  2.2  Risk Classification   + + 3  Reconnaissance and Fingerprinting  3.1  Automated Scans  3.2  nmap   + 4  Pentest Technical Summary  4.1  Findings  4.1.1  SID-001 — PHPInfo Disclosure  4.1.2  SID-002 — A terrible XSS issue  4.1.3  SID-003 — A not quite so terrible XSS issue  4.2  Non-Findings  4.2.1  FTP  4.2.2  Mail Server  4.2.3  SQL Code Injection  4.2.4  Heartbleed  4.2.5  Windows XP   + 5  Conclusion   + Appendix 1  Testing team   + + + + 1   Executive Summary + + 1.1   Introduction + Sitting Duck B.V. (“Sitting Duck”) has assigned + the task of performing a Penetration Test of the FishInABarrel Web + Application to Radically Open Security BV (hereafter “ROS”). + Sitting Duck has made this request to better evaluate the security of the application and + to identify application level vulnerabilities in order to see whether the FishInABarrel + Web Application is ready, security-wise, for production deployment. + This report contains our findings as well as detailed explanations of exactly how ROS performed + the penetration test. + + + 1.2   Scope of work + The scope of the Sitting Duck penetration test was limited to the following + target: + fishinabarrel.sittingduck.com + The penetration test was carried out from a black box perspective: no information + regarding the system(s) tested was provided by Sitting Duck or FishInABarrel, although FishInABarrel + did provide ROS with two test user accounts. + + + 1.3   Project objectives + The objective of the security assessment is to gain insight into the security of + the host and the FishInABarrel Web Application. + + + 1.4   Timeline + The FishInABarrel Security Audit took place between January 14 and January 16, + 2015. + + + 1.5   Results in a Nutshell + During this pentest, we found quite a number of different security problems – + Cross-site Scripting (XSS) vulnerabilities, both stored and reflected, Cross-site + Request Forgery (CSRF) vulnerabilities, + information disclosures (multiple instances), and lack of + brute force protection. + + + 1.6   Summary of Findings + IDTypeDescriptionThreat levelSID-001Information Leak + The phpinfo() function of the PHP language is readable, + resulting in a listing of all the runtime information of the environment, + thus disclosing potentially valuable information to attackers. + ModerateSID-002XSS + A general description of the problem. + HighSID-003XSS + A description of the problem. + Low + + + + 1.7   Summary of Recommendations + IDTypeRecommendationSID-001Information Leak + Here is where we write some tips to solve the problem. + SID-002XSS + This is where we solve everything and the sun starts shining again. + SID-003XSS + A ready solution. + + + + + 1.8   Charts + + 1.8.1   Findings by Threat Level + 33.3%33.3%33.3%HighModerateLow + + + 1.8.2   Findings by Type + 33.3%66.7%XSSInformation Leak + + + + + + + + 2   Methodology + + 2.1   Planning + Our general approach during this penetration test was as follows: + 1. ReconnaissanceWe attempted to gather as much information as possible about the + target. Reconnaissance can take two forms: active and passive. A + passive attack is always the best starting point as this would normally defeat + intrusion detection systems and other forms of protection, etc., afforded to the + network. This would usually involve trying to discover publicly available + information by utilizing a web browser and visiting newsgroups etc. An active form + would be more intrusive and may show up in audit logs and may take the form of a + social engineering type of attack.2. EnumerationWe used varied operating system fingerprinting tools to determine + what hosts are alive on the network and more importantly what services and operating + systems they are running. Research into these services would be carried out to + tailor the test to the discovered services.3. ScanningThrough the use of vulnerability scanners, all discovered hosts would be tested + for vulnerabilities. The result would be analyzed to determine if there any + vulnerabilities that could be exploited to gain access to a target host on a + network.4. Obtaining AccessThrough the use of published exploits or weaknesses found in + applications, operating system and services access would then be attempted. This may + be done surreptitiously or by more brute force methods. + + + 2.2   Risk Classification + Throughout the document, each vulnerability or risk identified has been labeled and + categorized as: + ExtremeExtreme risk of security controls being compromised with the possibility + of catastrophic financial/reputational losses occurring as a result.HighHigh risk of security controls being compromised with the potential for + significant financial/reputational losses occurring as a result.ElevatedElevated risk of security controls being compromised with the potential + for material financial/reputational losses occurring as a result.ModerateModerate risk of security controls being compromised with the potential + for limited financial/reputational losses occurring as a result.LowLow risk of security controls being compromised with measurable negative + impacts as a result. + Please note that this risk rating system was taken from the Penetration Testing Execution + Standard (PTES). For more information, see: + http://www.pentest-standard.org/index.php/Reporting. + + + + + 3   Reconnaissance and Fingerprinting + Through automated scans we were able to gain the following information about the + software and infrastructure. Detailed scan output can be found in the sections + below. + + Fingerprinted InformationWindows XPMicrosoft IIS 6.0PHP 5.4.29jQuery 1.7.2Mailserver XYZFTPserver ABC + + + 3.1   Automated Scans + As part of our active reconnaissance we used the following automated scans: + nmap – http://nmap.orgskipfish - https://code.google.com/p/skipfish/sqlmap – http://sqlmap.orgWapiti – http://wapiti.sourceforge.net + Of these, only the output of nmap turned out to be + useful; consequently only nmap and output will be discussed in + this section. + + + 3.2   nmap + Command: + $ nmap -vvvv -oA fishinabarrel.sittingduck.com_complete -sV -sC -A -p1-65535 -T5 +fishinabarrel.sittingduck.com + + Outcome: + Nmap scan report for fishinabarrel.sittingduck.com (10.10.10.1) +Starting Nmap 4.11 ( http://www.insecure.org/nmap/ ) at 2013-11-11 15:43 EST +Initiating ARP Ping Scan against 10.10.10.1 [1 port] at 15:43 +The ARP Ping Scan took 0.01s to scan 1 total hosts. +Initiating SYN Stealth Scan against fishinabarrel.sittingduck.com (10.10.10.1) [1680 ports] at 15:43 +Discovered open port 22/tcp on 10.10.10.1 +Discovered open port 80/tcp on 10.10.10.1 +Discovered open port 8888/tcp on 10.10.10.1 +Discovered open port 111/tcp on 10.10.10.1 +Discovered open port 3306/tcp on 10.10.10.1 +Discovered open port 957/tcp on 10.10.10.1 +The SYN Stealth Scan took 0.30s to scan 1680 total ports. +Host fishinabarrel.sittingduck.com (10.10.10.1) appears to be up ... good. +Interesting ports on fishinabarrel.sittingduck.com (10.10.10.1): +Not shown: 1674 closed ports +PORT STATE SERVICE +22/tcp open ssh +25/tcp open smtp +80/tcp open http +110/tcp open pop3 +111/tcp open rpcbind +957/tcp open unknown +3306/tcp open mysql +4000/tcp open dangerous service + +Nmap finished: 1 IP address (1 host up) scanned in 0.485 seconds +Raw packets sent: 1681 (73.962KB) | Rcvd: 1681 (77.322KB) + + The scan revealed a very large number of open services on this machine, which + greatly increases the attack surface; see SID-002 (page ) for more information on the + security risk. + + + + + + 4   Pentest Technical Summary + + 4.1   Findings + + We have identified the following issues: + + + 4.1.1   SID-001 — PHPInfo DisclosureVulnerability ID: SID-001Vulnerability type: Information LeakThreat level: Moderate + Description: + The phpinfo() function of the PHP language is readable, + resulting in a listing of all the runtime information of the environment, + thus disclosing potentially valuable information to attackers. + + Technical description: + This is where the good stuff goes. We give a detailed technical description of the problem. + Illustrative picture of an evil hacker pondering dark deeds: + + + Impact: + This is where we explain how the sh*t is hitting the fan, exactly. + + Recommendation: + Here is where we write some tips to solve the problem. + + + + + 4.1.2   SID-002 — A terrible XSS issueVulnerability ID: SID-002Vulnerability type: XSSThreat level: High + Description: + A general description of the problem. + + Technical description: + This is we go into great detail about the vulnerability. + + Impact: + This is where we explain why this vulnerability is a problem. + + Recommendation: + This is where we solve everything and the sun starts shining again. + + + + + 4.1.3   SID-003 — A not quite so terrible XSS issueVulnerability ID: SID-003Vulnerability type: XSSThreat level: Low + Description: + A description of the problem. + + Technical description: + Vulnerability described in detail. + + Impact: + Impact on security. + + Recommendation: + A ready solution. + + + + + + 4.2   Non-Findings + In this section we list some of the things that were tried but turned out to be + dead ends. + + + 4.2.1   FTP + The server was running FTPserver ABC, the most recent + version of this particular piece of software. Anonymous login was turned off and no + relevant vulnerabilities or exploits were found. + + + 4.2.2   Mail Server + The server was running Mailserver XYZ, the most recent + version of this particular piece of software. No relevant vulnerabilities or + exploits were found. + + + 4.2.3   SQL Code Injection + The following parameters are not vulnerable to SQL injection. + All parameters have been checked manually. + -file1.php +-file2.php +-file3.php + + + 4.2.4   Heartbleed + System was not vulnerable to heartbleed. + + 4.2.5   Windows XP + The host is running Windows XP. As we all know, Windows XP is bulletproof. + + + + + 5   Conclusion + In the course of this penetration test, we have demonstrated that the FishInABarrel + Web Application faces a range of security issues which makes it vulnerable to a number + of different attacks. Vulnerabilities found included: cross-site scripting (both stored + and reflected), cross-site request forgery, information disclosure + and lack of brute force protection. + Our conclusion is that there are a number of things that FishInABarrel BV has to fix before + Sitting Duck should use their software. A number of the security issues highlighted in this + report have fairly simple solutions, but these should nevertheless be fixed before use + of the FishInABarrel Web App continues. + We finally want to emphasize that security is a process – and this penetration test is + just a one-time snapshot. Security posture must be continuously evaluated and improved. + Regular audits and ongoing improvements are essential in order to maintain control of + your corporate information security. We hope that this pentest report (and the detailed + explanations of our findings) will contribute meaningfully towards that end. Don't + hesitate to let us know if you have any further questions or need further clarification + of anything in this report. + + + Appendix 1   Testing team + Melanie RiebackMelanie Rieback is a former Asst. Prof. of Computer Science from the VU, +who is also the co-founder/CEO of Radically Open Security.AristotleGreek philosopher and scientist born in the Macedonian city of Stagira, Chalkidice, on the northern periphery of Classical Greece.George BooleEnglish mathematician, philosopher and logician. Works in the fields of differential equations and algebraic logic, and is now best known as the author of The Laws of Thought.William of OckhamEnglish Franciscan friar and scholastic philosopher and theologian. Considered to be one of the major figures of medieval thought. At the centre of some major intellectual and political controversies.Ludwig Josef Johann WittgensteinAustrian-British philosopher who works primarily in logic, the philosophy of mathematics, the philosophy of mind, and the philosophy of language. + + \ No newline at end of file diff --git a/xml/target/report.pdf b/xml/target/report.pdf new file mode 100644 index 0000000000000000000000000000000000000000..fece72ae957adb22ad476af5274504c68822c4e2 GIT binary patch literal 188486 zcmb@sbyQu=(mr_5gS!QH3GNODcXxLS?(QxjxH|;51a~L66D(-Z;O;Q+e(#m_yWiZI zS!>QeXLs$VtEzif5%1__{+ov8D8(yh*l-p)#A99CbX+L4u+ zP-KcxuGRDdaa&V!xrS8pq7k#V*cZFo%MrSI5w!8&Nu37(tfloc>HQZIDggVsz<|M3L7PEufMUvR z)$a@J`zg%J1j=~Rw&msBy}cEfJ6$|6A^(L}mpiP&udMFK5UA=+Hszz(_3EY_SfA*M=`$W z3jNvRauX#Frp4SFucWD_06~B&LbK(;UIm~s0cAG;S%G+Gke!BvFi`QtNOaJ;anKx3I5ajnDd}1s%?2FK#d>CpZ=^$kiRPxXiA?tkQQvC9;Kl$eSI{VZvxUB$0VfQ=| zOZ*2+FCZBcY;jL(EsYI)ogpI^Ol$~tPniQ!J0wF8XJ4`dgb&I|fI?sD23{?KADjXS zfP~bgA7DgE7xFoT^js2-R9u~yLK12wpq_M9lE?`$o&_XZpxqY`Qtt-SUmv zB5Ot`g*^zF50Mt8-K5(T*o2CgWFv1y>5By4`e;mXj&jcD7;%>(N}`ppSOl4nRG(h| z#U;um{3=M6GBbgH_}moMleHz?C+sQiNj$RLv=F1TUq!o2wQw%qMeQJ+MSn?jNyhWr z1=p$+*ddADdK*Rm;k6%Ja*G=jF(;m zhgnS`l$wy zQ@ISpk{(s2)ulDCZu+TJ1#6qpn8~5hCi+-=qer0mLzzn0qHIDx+b^3&k6+J!)n@hM zDr+mcmkYl_hfBw?7uD6^b=iaSHPpk(wZb1kqf+K}ob(uJaYmCF&=2Bn&?iNECPOA$ zOLH8v=E2(Wvq03I2(u*P`qk1OmNS~`T>T#Dj?w3O=LR4bedQnu-fRVHG5NHQ>;?hQ&Ou8X{l%f=NT%5 ztm_-18-`kY9 z(KXn)@}dEh0alBA?z`67*7B=UpZJq;?bA4K^K!IWXV0rlAcDWZd&A}D;N*tJ+raag z7mt^Udx2-&cv{n_Qm*on!4lg(HJRau?piBPi?l9s+soFV%cukI1_#Fv8zg`E-&scP zBJQ!?9c?xYCU!Hw_?^uNp$YN7K!1_Q5zpb9q?}Y@gs*X_3D%!%KW-mbJ6@|4B`YK|QEH*)gZ2)< z4qOjvScO?{%zQ>-hHcQdLZo^NNu#Jm<}$ygs>QLV*(U2{(T_TgFU7OcAfa*Y2)9H# zwUM*kPpWp!>9)%AByn=qP@c;9xxB=K&x0!o`RAK$4)#t{_{ntYM`@4fE!T}1F8whR z8SO|}s0mOfui4kKs{d}eGxYIQ?NI|=-J-mNgsBO<-%bjmz|`#10 zS|VL`a<2IC^LeLyM`k3vDb(h0abi*b`}0n0KLPefbB(!U@}s1aBsFLaH?LqR_$A^0DdK&KDCw5h{RkT&!O%k?e0SG07tYpu&hS!dP0IVI?wNmE0UMA*TwB=`5}>{ zkooU94puV5gOP6WjR>rsC$`&`-9C9s0q2w!nU~Uk(i}z|;_~sFS}HW@xIf-8rQH#71NVp@xFNWsBR1 z*T%IB=k7XA`v=#{o2n3(L;i1{1l3DZt!HO5% z$FZj+_b!i@8Nm;{+!wk}PqQ_d`j(xGw@x>sIc2qF;WZ&O#RjSE(>`^t^oO?VZE5a> zv-hXpPH6=-efD2)uFhYmHcJ$`z=pT3w%)1c-&FB$()ms-|0194+${efqHKT5bQq;X zM1+l;%}j~kxv8?=KLG511Kzmu8zoisbTA`klrwWNGBt8BdY7oU8oT@@)RdF`HxkS7 zuH@g?DxaXo8^5+Tb0Ic1v#_$`Cp~TJA|^g*z|2TW{BGUI*xuEJpY&aosR@s{ zy_2nxi-3`XgN>Dm(Yr!M2UBxC#(&-V3ua?vXW?pOVJ6@~?`mglXYX$J7v!Jfzd&#E zY$ouYPtY?l(=)TEGBfkAv-A9wRPZn{{ng&=&cj?2!O z;jj5*FtN9Nck*patp7Qtw;MeFNP`6a_e6>Bz4yOBaD0C?MaBQlr3BuxufHMxlKp@1 z`E3>a?>>7NIlTGI^q)Sz_2BtCxl^^bxB0(y`~Sqft+}_J|5)Ph8Qp)I{{O)KPxrqJ zoBhA({BOwrbvpifs&9+??P)UpGZ@|)|BR=%;N~ZF`YT%gGvwdH@IBll1l;Xv@8EIGsGQb;n@0gnQAcVscN9{@kf-&bjK!|{Sx zPW630K&F}HNZe;=IdtX1_ldMhFQATkidXKm%~RSurS#*1uX66Z_vpG0bFpmgJnks| zawf@cz~LS~&gi|5H#NR_+28x88p>gf+YC>!N-6lZGkn)!z1_bM17Xuix=ioxYSS4{ zz`oBl)#{U|cKcuxQAVGA=Bm-99ewPfwwZ1Un?SRDC48^qZ4}-24^; z$Fs?$g6aB=Tg0i~YXVmkLg(v}57O3{>eQqv3J=qwIa}X=%8b^2+Cnd}&p~w-sqh+5DD&k38v9Cb{E@S~N z`gCLQEV?7@b)Af;_#z{0frm1%z^67jqGiEQDDio}(b@*zUXb%L^9~exXrg}V>x_On z(^bouCU|)t2iCfTSIZY$ zulBBJ5{5X03&W>|iHrELfLpel{))^y^5wK1c`NjX1DK}}@51wz9TR;3VBT^e=!;x^ zcDS!1&3D%-0!_m)X0@h`V$0ag#m1aaOWO9&V46+AT4HzHsL%)3dh`l0BbaDbA&{*W zznK%#W)2O>3sQKNHIPfuMT2yN$o1kd@rrLE7n=zBShbBtI}azv!b&NWND8)^f+Pzl zBH;p+m>8{C4nM0#nJsM8VDqMD^H$?>`J9$(?C`_*HsYJ@7#Ap8w8|Cw;R>Y!D?{K?v^{8M z6jAjQwTQ%ltTr9A9*4;Jpfq6*o`yS+IPI8oF=*iiI6h3&do!b(xv5an@y=&C4k ziM2Sr^j;Wmft4iod#*B)G*FTwfww_NQ+T=-T~C$G0kCo-r~=s#3zt%c!BY>hHb2U2 z;iwujh2Z&m2E&8CBMX@=-bAXaWPGjVt-r(it%z5CxWr2$%mx0TYb%w=GwwP zkUBQh=BqQN0Top^5ySPR$Xevzh$*m`KUJt+qs=eaZyQTB@a+7FAF9(Py72O(d{msj zF=A0z4|1}g)KqRy`52f$5ix=R)Y6;vj2bD{j7lWP(BwlK7pbq-rqI)5uB?H;%F#QW za8d1IIIM8HKDiRLy>LOo=t)Ba(b=IE;Rk=`8*yDsfto~-nFtAxzdVX|qEe)Ioa3{1 zl<>HqM;j|a*paXI?WvnwZPy#dpYOLwE}>Ct6d6&6vTZqQw@&M_I9ny3^pfd=Mvu%0 zHTp;>^~>gj-^!#rK5J;o>)Cmp%Yd~$mqCQJ-tgALNb2j+y(6o7`H_|KCV5_;ik40` zRF}DJjn+ybz2@W5L!!#6f)P3Q;(lvc)R)a-46L#tDWiyEuT(XMYLK*icIy71Cro=Y z&ZtP5+F_jZ@j(dSg^m{6Gv)in7-o7u^G`sCGIa?luh)ih zCxKd^S+@~(9im*FP=-+>r}r0|@GleQ^jK|%RGKr?Um(yC6`e^BcL0g04fo}Djxzq^ z5NU}cPhTIu3vL%J2gku@+bokkN!TYGWvkQAXO3s-H~K0sEB=OurJ`x4KBtjFtJ-qh zqBbcQ8Mp*zp1#cD^t~E98#68mG}uGfH?4n-&i;)9H@ihLYnBH*Q|vM~j5vKktM#I; z)gnY@vzb(_o5~Hsz4qn=`<75#`#Y3kPf*E1GwcDkWzYMYnqegQPKP6|Q13B2g$W>} z{+osbE#1POFGN8U0Ex%53O$QWcZNR0-mS~a^;OBRil1S4qAY&QBq+ZLhBD0CsM61{O|sVlFmj1}-jcy?2C&lfA=#1qj=inVJ4qgsPL3?SBO* z8acg@Z(`>6BK}`airCw^ywh>wcV_cf&hdA?!~B0#*^O-9au+FE=6{V$Q^EL?nTgB0 z;P2u)^M9?rzv2Fw??~DHJuMnmrf*eyc4m%uHIiml7M3o=tpC#zwsLV+G;M40H&@MY;hkg5VvfIB!#JgK7hzb-e(0<#!I)%_%3d5ZF`Y5cbd=nQ7<; z^85}$woYp!2r-+y2`BRq*o&kKRZmbV*;G4r{0@PLPS0Tp2jIw+r4U{gJwGawucp0U zJ)C+X=q$a(J}4^RrG1NYymJPlCgn4Poq;@bHCg(>Z>T6T0r&B%$cUM*C&bxraMEvN z$VrjKe6@SN(19F1A3wXuS3`~QD^g{gcR#p)2t20T-#v^7bpLVXd@)B@DhrT^VyOb! z22o6^xqS2@T2i|O~vP)O8a!_Uy9fhzgmO{?E=k(LXVGdkmW*y0^6ookfcm%yhbV z64LUV)$3xxE`G2Od;=A8u+sjhgCrtH$2^E-60(08aYaDEzTBh@Wta}Jnt>3_&O#gS z{-kjlXGbFP_SGaXvvFj4IKBQ9qRi6>p$H`2^gxe^R9T}ucI)1Xq3fW2w4|P#nOdkB zg#6Q0XfLdD2^Vr&>n7q+ahBQ~Vprv&(ds1HNiRuc3oPwY_$eQ$wTY0AY4m0c=-CD~ z%#aS1hmVF#Y+aZAyI?^V69OT%KALVPk$C0L9;8z@Y6Ohvg2!*seK&WfD-jcj z3#{nhJIT|c0~*R=a>Gm5|aH^!p4w+VMcFr&#_g`^F?ug`xh;{xJBOoPC? z>EX}J#neX!Dj8rgS@B6|k&WM~CR4-_KrPfJTZDF`+3O3YDw%GmY~U73bywPxNFg5( zcW(Zya%hDE(k`4AVizQa_l2HUoE?K?B+-Efd^eylU_MMx$R%atHkH*JZG=>6&?eK8 zx;LI`pB-{MP+5eH>zD(XI5M1a5;wi`CuzBt5=w$+^Os#vtP=7zEVd^AuX6uPAKfJ_ z@P6CJ6!!!t0H2yYsY+h{P$j&w>i6a8L{tqXY7mfrnw}_OhZR2O4+jt*swxFG%IA{6 zM3|%Y{5&xjO_E~1oB6uJ4SDF|sjdQd2n;Ax0pFOVQ{k-gKu4UlH1Vq(8uE84zA%Ix*)6>#d9Ys!_$2rMTm8vbl;^31$Df~wGOBRlTPDjY3 zaD}@=rctAjh@q^#@k<@%H?BW6o}x`ZUk@YDLPP|G2335KU)xKe*q3$u1#ZnZB|Wxq=*%UUhENGPL~;fAm3yBem&Yk_ zO4uzxJ$HURq;d?K(ALc07WnApU7HMd+`Ur;a!=*rUx(P9tz<{HYA4 zKxX-U*|csf2{uYT!zflBHy@qyj|V*!qAI~r2wVnDl1lCV z;D=X&3@EN~h)c@aRH#Z5AqGB&#UE+bYmh$+Ht5Me@-ab&6A~}+@?v>~oaGBcx)bil zn`AD&<~XqXl%n*e!#>O{HWp+>ZpB`8C&3@pyG*)_OrbF2@FsfUJ$VF3AP^~`bBZ~X z1E10YhF5Z=HvB_f<@?+{4SzwZ^Jwl}$TWvABeEhx?s*w5LaKk%1YXh>1<_Ch2NrTS z^##L1)-RQHrJC(CAn$iErfg9o^HJWlTNV^w`IZ3(bq$kpJh{BPnuN%}1^2psLXc5T zO}-!q=V3kxJ;4-(?0VDi)hDj)j!?N)@}zt_>5R7lbCBgyj4z+_WC;nU29VHAWo4!1kl7{?HUsqt;~dm}^epbt zPn-jK7*Hv`I7Oabf_%yO&XNi97AXq0l^94a1ElBG3GeWa&5@9kxVj;(9jR|_A;+HR zLV=*Ht-y=c_m4s#*Fr*^N@L zv-85gNI4thyUM$fi`5`b>@<8_R~^s4CtVS;iiQaMk<(0w{r%uY1DMScJ_l z9W}qa0DgM~RF>LlHnpYho*QVZa2T`S6n;kU2cC69{>%s%hs>3^4m=Bh{^=E94c-r4 z_N%575^d&l$`ud1q->2q1C*-LQ({U4ZkUiLh`$iqWsUp+vPy}>JGa5?+Kbl65ypb{PO1_FSP?#@a+~M3; zR$~DagFk^3W8omfz}3%i$Z4RhfYr}Yj{#7oNFK+N;BCAy{*v^yZAzP9wh;ui9ZD-u z?TC9?-Dj`PtsV9JT$2#zg`f`*SRRKzg6yAv2cg1;0M|m#y3ux#I|@10aK3{)Kof`6 z(a1>k-AaUK%Y6tUSc_GH>ApcKmE(@DA47oByZ6iZw}^vjP;LvxyMblPzZxroMff-V zd_i1ojEp3s-`J@^ZnpgbV}iA4uf8G7E7r1xYv_h>Feg+a-p{ceE24yewy$D&p)ZPpB!82awa&!n0|V}4z#y4|um+^W+EH6-OoGxX!>Ywsmrny&0v zRfOgqnXMFd>e=uv`F$L4kz!FiABdawB#Y?<4v-6JB65CAC@%a&I9xFjH0UkF-1mI5PhHT6d(Eo zvAs9%3`psXtAIKLs~S2Ro_Q8pHaZQ(x&@oK1i2P?NJ)-ZlWczy;v;VPcnPUMxUbcb zGNUGa)MI8;lJUGpszi7PInE{mejd>Oz4HFt=FE;UWzh!vPsARs^0{tt4p5rKddPwt z-CTN23TOugw!|?2Pp3NSj~^27h&lKe009|en$ILeSQ2@-Wwj(IMClb8N_Cm# zkAS+cBq)>i6+WgL(<$^aG3paw|6(@sIz;a1x<9MV#S!Hk#E0N!bAlm>pVMUnl&3&Z zskp0;G)9X@|FvL=`qzGgu8n)&p!*uVq@}yvYIyOTiHzn4==OqeSMd87vPV+Yj`1N=G8} znQx7Q_yDe7=Lp|p{+w;8wXpE^qfBJ7LZq*h?bp! zf`UDr5J6)i0xC2pVsKEaj8M!&;f-#}-6SFOi3z8@L^6v`uG1ePhBt;|7V3c`3OhE{ z(kdh3^I6ucBsOWljRy*+>u#LLlQ~aV_NbA8QPNXRCY)?W#cegdZ7}K(S~d99eCn8V z@N%ibN;|NlYPQFL>73ZB`-An$V6aNKc~Fx$%czp!ch!%DqZ^#zGYckOk|V*AI1*`; zS5zONi)BhUYL!V~uV{&ceG`5OhbC&Wo1@jTRQhj zm`3;Z89}50XOuthN0Hgv?wsvF51*$ChZXT7(7FMbbkGa&QF9;6chD2QpKP;X3WBoe zBi7xCAX96KuY{>6ul1WTGM=xmzn|> zJOB=0g3@G{>x-7G!kN$8 zK1(T4>Oi&>`x`zjBnmh;chqx_DQj#OX5Wk$0xS-@gL{Mc*+ZJh#reTGMqwv0Mfww@ z-46g=#VXFja4F+Y{9%5tnFL-&D+V^B+J6IiY=pVw)x7@)e`8EHm~LyDV@6(*H86b} z58|-mfIr&~?rE7RTEe%^QSi+`;H|D!SK38EXGd9zRuNiwKC`=FqM~> zFMtf}(%+(HO*<7!-#&nr4+RDpvKJ!o3`G3brT+PfQy_N;@Xb8PgBWEpq1t8IIk&yxAKiTZItE;W3BJl^Gmz0a7VHGmP= z*w=g*K!E7gr`M$=tyJ0oCk6(Fi+a#VFc6uk3c_&I(t7I64V0=OiqKu`v|nJga`goJ zu272LuweG*rEhZw*$s`FYts1c(NGxOjc$#jSAOJLoyBD9t2m$=JYpq&Fr}j!@SWxs z1E0Q#{fa(~62Qb^VPO%P(*6WToOyY9`BR%Xv>5j6P5u!LBg1z1&9Uz-EiGEI@Xb?f zfpbKUsbDzBo`bylV5TB{*P%NB@KUb>15l(&U^vj0JQuG|_T*VnJ0xV-+ihp{uY;WMI`o0ZjHb@eu;Pqxa$W`UeWdhOni+BO1+ z%a@frkzzRxPoDP#2lBV#fN=Zp=_JjI3)+B>kco3&_n_nBYA>9;yrMc_&4*bZ{hu!Q z{h92UUSGy9BgB1t?u)$Z0G2(HQ)#-}0WZw%6uAf<1LM|;kYsV!lz8%keBR9AV;;#F zPi~hcXAcI9rzK-Z{d3)7^95D?foacQcQgQ)OQ*Lkw~_6L##d!g=#bRH*rrQVW|87Q z-L{OCMmO=Y2;#7ceAI7gxk}2LlADq0y6T_cx^Z2pU=%~lJYIJ_NA7az1revSza$3r zFGPG&W1*I!$#wNoy@hU)71xm>3_fC{?*eC%yoLq8mGVf@Ioq6{pH}i6$>3YsE~A}` zx`$;zr-1uBo6W(?9(SE932$1Tta)){q;rpnv`&e=*lzRr4|)hetV}6zX?{p}YGL&8 zYC%hhrwCg`qww4(nFq*D>j*YNr0voL1^-(jK!IQSgDr&=`FHxa$K?Y04SibUs4a`) z<_;z=>6r>doF-EO9f5n?-nb4XOK}x5=zQH3+97q7tgKp(Ze5Qa$RlxgP~~9vo3Nz) zw!Kt+-%HEo2CV{-S)WFHhSYE(XiGnp$NwFrzb=3e7Ddvmm_c9vb>oj>K}o=QTUn{`>47%Z^d<*CSP0e2l)^dwUI-U3IBgTnVYRSdu|I%0In^ zBq81Fld)w{e1_x)`FpPx{$#oZ8>oKo3UK*IZAxzBY{C3X&E=Mr-Q`LllfF{lbYDy( zHglx?&7Tx}eFG;by_JL_arw4nNxTSWXJ?gLL%D;BGh$0pVUYhtuy6&+Q)@dhDa&Gk()gm{Nn0&b>=6s0M0jO@aUWe5k%G!sLWCt)I@YX6rVbTE@x7cw`)H4UK8N zPSI#_Tcghu4L{>#C#H(ADApp8(yT+Px}-u}9@ZH9YWotsM_B^DweeK_JUeFM?$utq zT5Or(XRYAlHxHY%rh<-IBGL#4&PRt~QUVra+Uu*%oeXYS#3h)>~`FLQj! zo}fi-{;s(qtR`AdWiSnVsJV0@k>3I&|KT=xv?kKc&u7=V+ z$?v6KFO{kGeIVODYTN=A6-midgA^<`fA7-G5?q%DwC;y^V9F!|0J!rCQ07!ARoo4G zpM=NA8yJ!-M!v5^N9AIXJurG} z!qvdeSdjx=&}C9A;nV_Tu(8D@p4bcWutd>_rVn%V`KtAqIV_D$O(8X#agXRQv8omR zyrlS*ZD?CZ3QgEmoM<~VXA)qnh0fZWar(w!TLM2Ei}#3q5D9Ii)yVuKFLcS^{~6z> z`!Rb(E#^3r@b@s{NM~^uoeG+~=Uv-(Qy)=jBmYr5T6pca&*;)4iQp}G5vNKz0_B6tV1q_*KvP!N^u(NELF4p%Z2CVQhC5_{1a`LfL?uo zg5h2QCu16mKwK~b+p6$#1VmNcwm6#_OGtp$nW}rzHcr z9`-ARx?W5BMo%jmIEE=3lNBWBQDkzO+E49IroKv71huef({0IbefhM1s4Xi_YNpD4 zceUmCv>_vKm#1;Pm|Yck#v!_WSBn<{g|qoj%zOV z(RbmNB4)GiyUobz{7yOv{nuGXl86arvuA_U9d3a_l+cQ?xvFZ&^EL;t1Qv_Ehrh-IgstnvdD&#OUDTEQC!y$MoEJ_V@*fv4MXwT5sB5But}gt84upbG}1< z$95p4-L%l|2GdlOM+3gTUA_Z}Ua}{*eo#ir{6Ks-ng>foe*20dZ(|AUN_xt%U3O>b zT;uknzbZ<NMWZnBU89!#J5a9sq}or9?@QB zD!x=-#q%k!dhu7yZ#1j33x-zI3m)Z2{3(mc$w{Chq{^r$k-px5Lf;tiv*81pxfn4o z*{2UAlX^N+B8Nxpko+x%zsWRmyjH4hc-~ZbSqbGFN+>iuDG0%{3}xD<5Q%VvkuJ*0 z_OycfeSaK8fl@y;jS@FoC9%qWS3`x^$4l?mQ$4rKJ?@*g#<)F+daA*BYAsXDY{XpX zA}1Dng!^z@Sk+Op`|y&&c2_)<1WV^p_OT7u zS>ZG`#*^8FTAFv;h0=yMT^)w4VE97tX+fQK2Hf{CXr`D-F%+?r0B)8`l{sv#L!%Yl zD5mJ=={g^>9e?x>vgd1h&Q)-{#FmC&g^pj*TG(UG>hgM~?iPUS*C?$0weK;(G;LLj zNJ)1Mbv4A8GA#t13v0m3AU-&WT{TLW@c9!_95M^Nsp)P!l$jD_J~PWrgI1zP`0f#(HX?1^ro9K`+>nyi15R-s2_J#{Jdv}V~O?p zpOZ28PCnoLv@7JA>VCxdgsy_>R3Y4@*I6rVH2Lrg^hDovGl%uW6Y^2W*1d-0N@6pA z`(ezP+YBo*qV#}n_bfSjcv<)I+CEMmpi#QA2adGF)lEph;!KjStv2@eJ$Pf+;2Sx* zvr5b~C;BPz;ijjHDD?Z;)^O9NWS`on3RZ#4QYdZP-=`s1rYf9u)T=P9)=PonpJ%cd zR2rROGQvs_Xj(z`nVF{ycI!x1Qd|VFl<_i^XxOjcTgxYK=>!Qr+ljjAI3_7crMV1a zD%W>M=1aGC6@zza2vzaZwL0`J#@MYFutX=b?+zso5Zy}{6)8%8Qs2!i?N!QXzW&XsXFmd~`fcO7Q0PvV8ODrly&yQ}Z@mN1Q|IfA5X;NtoXDkR ze(00eveJz2vTZT;nkihtkBth#S)}20zCw&&6VQOiCvmVzeX%~Pdr?t$&xl)9?@>WE zS8@uy6W}TtSILlJfT14>R>>aP71As3_o0mHm2L>g3F>`z?>PH$M&G&fdz9*Y7+gwR zF_`qRB&`_=iF6^W0%|!Ov!0d4QSKt?Kt|1x!n8?^Y1UPIbX!jdW5ixr0tT%CT6+qE z#U%^=+m!jq$(*2*rFL?2aVWfNOEO#!NfDHsio%&+Q$*o?Qzp^%qY9ebkS2v=481kY zLF4H9C7w^_90x^25K#LeqXbq;{WtcQHErWI1#40Q?fz!230A#ju>wyX)F_CvLj3^- z3u-;8QK$BkYRZ!M9E=2fij=~`JJBZf>1bz!m!OFqXc?yNzaz)hx2VogPSm1YofPo$ za-TT*r9N&)>-TkZ7yS7=o8@kT8?{cGj8_SBsL*&uX-%<4EO3w5I+9VZ0gLM;D0H&< zOVQkK!@2%F?Gv%B+v0UDs#^M&_@jE9nDt`|f@Rv=j1~2#E(&YWP>rdIsh5H)U9B+z z6tE;kCDfpN3Ct3b3($C9ez96DG6?$!$xzt9b_{nTB09wYs!RIKn--j1P4{K{pq zukKOw?I4Wp=gd8?oD2Wg$=6-+lrhO7>>k+ON=c=Iiugmx^tP*S)?EXd5~U-GqUOv8 zKQsNbA50GMgMM?G-(Y5~t8q04VQJ=xMRBL&0xz5JXsmx})xufwfSk?_uN8P?^rw30 zSINXOC}Nem_A9zu&3$YnRZJzD)HYG7`F7jA$VA{{rl<$-foGZ7xRs7S&b2qv!R3Ja zMCa}k8MtS>o-oH20$QnXrg(=%!3bn~eB2k#&NeJuo{ zV{l!7QCKH2c)cMe0-unjyFO+_pOw!O$lcE|Gko0kgJn+?4og1_hlNy7pI^*V514i> z$IWAhGsY1hR3abGT>^Xxdm0=8LA`%`e7saf{HkqYaxxztK!;Fo*a3+QBr1k8stYf*;`ZyFZm;BROk6k+NOc_ERh@e6;oxqm4ZT-Ct|xCWYhq@Z~|_S=6GlI;tM(u6237obM#QZ8EJ3kXKOJfc>Ah>>HTyy3mnvkWaU76_?A4 zwyu|FnB%)kmlrDCl>eQw(c- zc|i15b(oI!%9s*HotT(tZ9!X6ULqGF4zyW5@P>6+u91E2(ZJd??&P+$riWqYa4q9U4cxsq2Id9?yQFt3R!NfyP<-u}S+8@i`tR)hLuSJELY zJplEmtLQFAc!o-a2ssLUr;Ins#Z9rEuI|}$fq&dmdo%5k(1!5qE_Pd!?Qo5b(&VN#g7&r7U;>3TLMb4g7VP18{9 zak{bbF-_Ld)&E@SZE8vBQ4poG2>85jVov1;ZNHva2-0)IgCR=p6HS~AH>c}~Q3Rs? zBn8sqil~z$NE960e#akL81My}4lc9oCMs+1N7vHCA1a(2c}aTGypn zU-nW-1+~mlXWw+7(dGU4aJciFRFjy-)|hz2HNileaa&cY^A5+rxBH}vTAHwm_X#YE zOL+#|HtY3n=kX`z-Q7jxi@2cqa5{MHhlR}%wpk2?Z-Toe8v6?J7CP}Vl9Pq>nOf<+ zn$_gBk>`jogBoa`Hv8jw2)BP)i^lu}7q+*(=_q|_MIx1c!lGjN;TKW74xVyI*K&{t zMU4DMn1c#NXMg66?cN89c;$7D1)9nKgvTPbD9ehD*)zjnK8((y2`kI0KccxYSolpb zI{U#AjQU5h$kK(g2K*1+Jcw{hhtBQc#W8qJk7=K$(C^@&Noi$V;eml$E?24$F-dW-vBu zy*isEIDFV3tZ<#>Uf#$D5%q+%iqv5@rIZJihXwsRI&898vd>WL{5 zT8x=uIx9`6R4AdsyP{K<2+pU#6|)VQjA~eJSWtoR!*{uqFz@xm>8<*Q!dk5Nx6u9T zL$2xb7Q{wx8<`B}5%$LE46f3-`@y%*Dn=X^60SgP07rBgzomJHD@CofX08FF#jJm) zUw>4sPnC!I#r4I@v=;1o2HMw~n!INiO#dWwbc&kMv^`6pPAXOmzYjQk-TLWqKSsLm z100F>s2^Bk2Pxc9-}B`KuTuDcVJ`dpUg=7Py&M^Rsol7Xdjj_CEsJG5OPl3eaDS$j z64h!#;NJV{8CW+hYtLZFY1h^VUrfx87B2S7dAzAO9!s_BcPsC3G~cq+w_|Piu|aMT zco1)SzqcyQ@13&QC90rc2lc2>_uT1);o`bxtY44n-@BquEA=Z<>4)d*s4Y{$YG8)l zzgB{T;kyUF)hU~D#4+MkK^+ljas{#JQ;@!xH-24$@L00LnhW}K$mFHkhX>hgLiN*N zZ@e29b&*oM5icgyE*haGF~7bIi_407%bt>UgaqWdPBEy(8_eRAJMqkOB7=q-&owxu zZTQn0iXI@xjAp>2e|w|QYOtnql-IDa|AD9dPeK*ccgw=2^O4TlV(mPctsmE6?3Q4Q zlx}=O=C?0fz z_~Y!-6J;-*LzYaLnFXVia+oc`w!iMone5=!R#u52L@!y>{?>7oVG4XI>DkYoJj1ef zXy(>FCvyh81C*5T5@avE2FNkfBZ| z>?WBKD9EVEMOzkZ<0ctnX?&Pn0(GT@n`rIGI2TlSP#LTpr@yIY8L0ZUdT}?i4(Gn5 z>6MRnb6<4Iu<(55f=8?9aVHmnU!>z@mUL`N@{jA8b{@f3mN$*a`&#~+U%G{i_sv*j zydJc9)BU!Q1pF=o3W3ue)c?iZTSryZ?O~&vMjC}p!zK*6HrvQ%t7`N`#aSECQ$)zihaiWaUid;nN&Z%9GHdErWG7QLU&^b~H*irtcAZh_WX{Q1h>T#*%p;ZP**wbi z?6m?RlzEz0B}vmQ(3!`zK&c>F#sub6O#p&T(FtKXxYBJ+(v-dEA6 zl@450StC~u zpHZ9_c4yXvtAayIvEyPpp|=Qy7`LM6=OL0jbD3 zUe_%%%{y%_{ZRcQn_2*-br)u5venU0muHfH->ZFM&SvjC@h5Y~}` zg)`_M7e`WOn>Jaj2i~CLmi;tF@k#*-FP(*EAh!}+3V85S-(>4=)9 zhLMD*iU-t5d9}!y^zZb0mcFXIY3^y%6T<`DU8{Ox^kR$?L8zkSjMJ$2XE)+Y6O^$K zB?s!o_gS80Yp&UmVD5kq7$J;F37XYW5^0e^k3eYy_OY!FX1e6w!b&OMOjZ}tXuF^L zUX_cR#k-wn*|2c!l(@NV6aR7!3}#<% z@Epp!`zSs~Q-xe2FBymRtLwd|Ezb`Fch)37p{LSjI-du<6`6THEY{r;5F&v^Lu9n_ z3=#~anfkBUx=&|f4UEJ?EyT|hw%Z52Xjx~SJ@B5{RwkIn~>DZ)!S zgvIV5`lvo6i2_w>zK5vx!zY-HyW%`0Y97F+5_K%uwGu60Yr6|p6-@0(+jNhx-I;y? zS{0okGi_>7I#9+Az0Md8yEvjKzJSWj{%kB55mGIY|4^xVc@7TfM zCteBic16NoAQtJF)QHEgE6eMndPfrn{ebi;tCq(ZN?mdNG*rY&FuXhq`z^1Cp*Z@N zFZ{jmpfi)A=}+KMziqzo(Uy?qeSJphN&TssGLTb>Z4j@S2(w#yu)x&n^5BK)NamcYzQ9;YIylQ#FE(rr>-8|I zXwTYOxx-*$r+^76gV>Dcpj3x<-OjXlTwsab`s_JoBiY?6cWKQdVCMFJ}fzJ@J$R zJz!ejg@OvYQp&->j%v&B8qFxBg*yzwIFY!?NGM0u(ET*N4nY+JkFZVnWU9b8Dexl} zktxcKfU5ezA^6wp@%v+aNqWZ(Y@@EE)X_zJqfB(IqqGHDi3thmh%N?QC=3c7S~{A^ zNK<1C0oS45G$ShfVrGKc2v(&XRdk*M#~U8EG_EDVQ>qp zY!cJOFuOPK6Bv2n^lBLNI?>UAgK{Z28Tgf%g4tq zA_Ia|dWK(+P9s9LhceGYsB%&xH6X_YBIxxI8uAL|`KUGF%t@#_)3smJVZ)P3^;{gm z&KwU83sz?n6aiEz1>09(U%w*Hmwv`EOXplYW8K$4=toiKd3`hMEtX9180(O}6PQ}t zw>`sa$krzs_SZlD^qRo8BiC6PE32{pKH=T3Ob7wwylhuS2W`HVaXT6w-hozENij1& zH6e76>o4do*Vl*204|jA6 zeAcH?=HuhzS21UcC6s2UYp{eY=)84wd9#tKx6#VsHOP=%jExrcNhR#O#vKT$0+#k_pE__k? z*!hdHRu5mp-)Vp)9qKryUZ)i~SGR?MbDj7*`Esd+fZ!+^_48M&5C~Ht=u143+$&)y z!EOeEf0kb2_PJI@f2qBAy3nL^3B=2g*w$#Fe`;X8Co+L<&+E0ua;vH79GAz;2e>9f zYe$i)AfnC4sBh*P0PE zBF*-~J=V&-NX6PcweOMCzU8pLk4u*|=cUynC^QP)(gZENaUM&pGnQ|Nttcj!s5K}fODll zs?>Kpg@tr{?-{o@kse}{Z|cfSo;22>a$aEncFdK_LF(v57E~l&(4g(OU_MLVP(v{N zlO}--RQzmVZ2&x@PO^#Yw1*ex^GWTZP@x7V<9ZQ&K#7ril7|d!2PwSwRBN@a)m>`Zeg}Y)zUgs38`$ zZkuH5P2OU8_29Ff=u3O;_S%J}sduW}4+d4pvz1-B+L2S3L_Q>KQwxyACvg^Wt&1jY zU5SMmbXiW8^sTm#cab%`p#1*6)1zy;#%t;j1Yg9@e{6{GnQ;hSfU-iKd*pOAB+ZA; z-t$M;-B=q$A&!w_-te;L&+7zL=Un75S2Fg}lB=+d-C8$QuIB<bAI-=rI^b|zdt+zcRy=VjGCT$mmuKiBu{X*H=SqGj zcX+iYf1=!@e57jM&il4HEXKhQ6vpH*@na#|`XrrA56mYoLS1Fk86bw;Qaz_RVi(9# z=vX?5{X)!j)N^LM&v3Lxc%yoE5XQVwzKOagWHjs1q6=Q3m<|n}jGqh9j1up0P-Ur3 zx9jwJ6z?Li@zb1D!xNdWSN?G0FD$KTt|^Z42FB(GN7ThzG&mQZk7;+q0b0#)6zO|62d#(Coj60(G8rqfROH~oY5#nb@7!p5s4U; zm-$DrC3lf>LqFR3r$zi6ETtoErh2a;h5M7qx{B|KRNwI?yjyd%_G96VGfub#-|It) zH&I#<6|USxBk6n0DkPU-V)AwOQ&O&$lH$?2s0kseIDBJw%->Tw zEkt;%g?C3`$hJdxSXt94G3zw;?%}+`=eGW+?@E*Vb+kHnO)cIjv(nnEK3+if zGxvA3!u?d1Uw6OTz8<33rD0l-V)Ed2nJ#)X_?+?MctVP1u!3N8}c4n;82lXDLq~oKA%6%&kV4tj7mNYt@s7&f4lTeq1lv z-}+htG1z4n2a9umlCx=R%#v`IK#!9V{+_Ppgh(>IX&g&ux7r5`0uf`vfdw7tNh?>y zG554|T{WU=s zyNyHGQbeuFJyoT+-jgLg@WAX#x7;~BCA-UH+=B7s+bxeb&&$rhWf+XfbbWD0$$&1$ zXG8nhN}JX9CY|;;KEDMI4+~b5GWI`6MwI8Zw(g2Q`B;+3@R7GHNcO#_)1XZnd>WG1 zL!?i^q`epS6YCo96lN(W&91vkm?ZQw(NY9R-EoX`{nEL*Arm(Y?{fhRvkOr0czA#d_Atg*isiMj|G$-|b&38h_b0R0&)-Ah3yl^FY4*MMzDj z!(Qr@Sxv;ehNd9W1B2@qtxmg=9L_$GAJUS+q}x_*)nv-s3HKi2cw#Rjp*PKS4U=}o zuNSHvMwS{{y1XZ!>lq10L*R~^w^fkOVk}pnW;EMlUz(Si!Z9#USQ1%J+RISDCW-Hg zaz4pe4M8b|I1~djIZM-PNh}-}0br+>&5Xm#=z|6A>Jd*ashF0wWr;lw(vl5NdzIq( zM@5Y+>bC}@(X)GaUntS1m#Oe&V;N8Ate-Vdzvm}CAV@oxJ3JulV>=BCtzQ|pt1k!SU-bJ(w|^1ny3!KKMc;?7S_yA45?G0!?`f$ zrB0#=mZcrio^x1|)QqTYBi7WrCwN-#|EN%lQX4OqOzSIq?59*(DEjUagqtH`sJgOa zw!0FIC|0w{Ji8F%1C{N72_tt~sMR-v#k7xE@;~@C+p9i29jZgx^J<~hoZZ}eoZFUN zZiI#5QQ?rM*A-Qv)!^^FX22O>sRG2QGO@(LcIvMC%5_K7tL=3XNphqw!aWzF^M(&X zPDMWq#K=FCm+YRlgjBA@Ih8G{%qdHqkn!16rEWO)`l|{LZ?0yMhTw-apbih{!GA8L zNzDoS{;62uC!n0y0&JaTgE9>@n)e3~zl}%F$vwY2mqGi(eIthlfl{z|I40Fu=huye)`OQK0#5l`MQ7Vuv+*5UhSHT zr_1Xsbzsi9>9Wvh&i{mCr1-=Az7AsH86x&kx=YRLg1a34-OpB(WRcEg!!&(?=nd$R5Q=hJ6U}DR{0p-Ze(VWyyf2>jbX~ zv7{hsra00etEp&sLI9R|pPN?Q*+lHy zd?Il#fy8isco0cfqtHV5mM2ZIE5Q)_<=}Z@$T$3MV6vO$F8@I{^U|1u*|ffXm|jM- z0@~=M#S6zVrT8h++8wcSLgv{+87mLPl`RJ^w<2w3U+#?v_iBNY3nZQE*AoJHNTr{C zP<)d>UaZOlix+zvKO(S%cG++aru)ad8X8~FoBVe$WhbxfEO&DKD=HY z7dZj?nlCmmJ`$ApK5;sZ-66H-S`wedr{tS>XZ?ZB1I;aFFFVk;PjmO@S>!cxncG-i z*Rs2x>H{HB)j>*XX^#5|NIhgO)=`^e4_x$HdvH-)4Lb1D?rJK=yt#T#9ue-<2OJH8@6!zEPhybVVu5Mn~taQ1u%xqAC-%MFhr7B!LH# z^ZZ;o*-y~!hQEG}#G7#BzF?TsRP$q>atGbgkHMJXI5eQ)9rxSOt!O$!b#&7YL!uNe z2#h#sO-==Ec)3U+*6|}h&nmBv@%^Ob@^*NFus@R$=1blqe ziWkb{rzgOp643z*>WG)5W`5y;HTd=#=-_i80mKU>VEGt9Bq8&y8wUMy1 zBw#*z-&l3*!_m@O({@chRj)s!IB?8L?EuBqxTqii{GF20H(=B|YoEJgY%jpvPyX@Z z4j;0wA6VQMC-?KyXJq}~h>_9n_n)I9pPMHG#ZhtmRio)dT-n^ndt7rJ6`cw&SVGJi zqR>@xAbcq}?NRB&1_h*WoYQaIX-qjl@FkF7M`_YGUCQ+BqDgqVwUb6~fMMvHcw+=# z5F@I8r)bWj?mq7^>9j7l;kzQ@5L`1qg_y^1ruUZ|1eNTh{g{^cIuQ5r!%P`dkba%q z==$MFhvL=IBXmvQv(q*fAx+G=F_llUj>B_oxwQ(RLX7rD?S)U0)O!1~I$X1Z*nhRr zWf|R3f&DG@ntPB_-Wvr{pdG9dNbBSREp?y*=vg!MV{p`>$*Fd~v%*s%=MbU*2vr1X zNqvf1^Bv-<#H1uwe#!WrVItdNMK9{NZ{u6EAfh<9(kPnADQm*t_R{DXIB}&fl$zYY z*;cGBv#bXZO(sS;$ZNvr(5QU631w9bn=GsXNS-EMcGAWkFa_@Ss*5)mb?l)q(C=c2 zp$7Pc>;%DImCHp#JfmpfNX^;Pz|uH<5nss_34kQ>bA(bRe7jk~G}T~uIa5vOK9Dmg zD!sT|f3;nn$~%unv_IlkDU43qe~Gk7u&OghM@WEVvA$kZ(OKWIHg10bM9IKw49$LE z?ldbVNSyg`^`@va9`M#dt^@@KZ=hlZC9wiJjT#tT9D)R}Z#2VNs@%fTcRwXe-{?~> zQyg#T2bAe|^yuPZm7>DV$w-0@$R*LLd`L30=AtdVsbG;bf2^-WPtZ#`L%EjV7=6K~ z5qpsmcc(cfYhkZO%v)4k*^wTmr5I5 z#HsnX<^`+|VEqi&8srM)x*LdurTsqC1Q1NYP4DXO#L2k8l$`vL+u#=)coEA6=>=0O zdJvH?x-cU!xow$%QvRfMJ3=#=pq7Oe1kf+6-HxBqXX6i9F!yr{#g#!bfnx+QLL^$X zI5aCLus-xZ^9YsN_w_{ra+NNf0+cpCk;tyz7z$So+GKeV|6;*{+U^ z?A~im8R1W@z|#yzcJ4KPTp#g#9gM7oYaW0Y!n?(blo;MgkCPh>;O+NP1Zbse+hz$It+-QgX|)l z36&AiwW7Qz3#%iLhLK7@z7TnLw9f@%&vsr9*w}!wA)0m$4*fN3ppX8G!e5Xt!gVAeBw$@o+PmNx7>JT?aPw`f)UiG=MnxV0+6_K;(4)kP>rb3I7b`4&r4@t`q(WoA%3m z$?KuV2ZW|5h#-7FFet*GU1XNWU&yAX+g+|X=>hRRJ`KuY=%^G3jGze;rh+Q2xRDo+ z@*_bUB2G%^P(eZArWUz*KK;}0OUt4&jhJR&k>T*fhh!wh759PFkcwD!Hm79vaszrz{D|@Zy3;!84B~gNF0_;bevTM zqiaSZVI+We;NQPKW-l&CVLwP-(fm3{VtSGXlmqF-1%Lf@AP#so=l>{>?AgNIfeZqs zvdtQRmzGZ2fwQaro6Hq8HCsAFzz=P10fGCJ6%`e$I`?2j|M$NSi`NK`8Ijm>SGz-+L3iwfGob zkGw46gkNj*U;C_f%DB+HAbxfCyQGxk#8*?3OMX4jrH84kETPuB-7Ri@1@55d2DrS8 zXLlMG>|6ofy=+yKNYmpcZHhSoX&jk@3I|l3YDSz>d!~XL zTpBmWroAy=g*R=pcvdoGETK+*kx7^6!l+jvd&z1z+zIC_^`6KVUhVarcgUOtaoAF5 z6Egx(#B5SZE@$qb!DvJ{-1r6sbd5*K;Et2DpTh<089hzR^!y*5=3NPehdlop@hH-1 zLvtdDVooIIle8dvNS640d74t<%(0Md8EA$wAGt(PD$7CBiO4tPTFh5TVgr{k1S~J~ zwv+qc6+HWZ>j{^=GX7wMrr?_libh+kUmRAp6YBVT_`ZX>)_I$SZ8;Cedle)u?)%F7c;rKQk7CUclpk&nial^-BITimFgpu25s0oxvYK9U zxf&PfuIPMm3g&qCvc>qz$kSRyHKIn5-GiJ@2@LZjmdCzlDSS9wPB)XfNgl}n2e$_Q#3U}<3%cTl_ zSV_a6?2$tTBn8fuq)sP(gACT?oePP^Ka2c$;1M8+;8JSR#+S<}S~J1t!O%Ia~g ztg7or?#mU=V!7gwOr|eZc`=8L9MvA;8V9*;4Q|+U$Tyv5snTh;dJNHdD7-Mtm{U%z zYTMV8p7fYz`p6_EFDGVk3g7=x3Mr#br8}8#$5lsS@mb~TRj6Tm=|^(1&80RK^4ulo zpgBZNnd=5zk94kwi%u#Hqf^reporYS@3TO!x1l_x@!v*nX|L_kTAT zTiPA@3!HbS≷ky5>}9{6s+K#cK`C?wVgv*yJH%gM|Oe_n@ND#t_8oenx$w&P;nNtR>|K|N!I=9V|McWcilVoNYn zy3TEjQ00-R#Ld%LY*8gKWb>S5Kb?dxXVe)!N&ETe?OvOw<-w&%?a8v^s?q7H@v-B@ z+{*H0Qq{ouc1sbj45V}LEid69oGUMmh2XM(Jo3>5Vy9<9l@p$;Px(lV_wuJGojO~- zx8h>Z{w^u8O)f6gcKLk|I(;-H>uYv{I8(PR#|w{>SJp@t-%9dM4=i)*!OdQKXnV^& z*U&m+GI48}KxEgw5c~;I@1J&2;maX44%dX3v{->*_qlCFPh2-c&TD=a41l?=M=uY* zK0eRM+AK(*|1r$=XhkVyH%B5#XR2X?z zCXy*Ye};RQcpvvmE9d({dH<>VSa;0-|*>h z^(T%UR*hr@3`=q_}g#ZW^WPj&@rUrKb;9EY zPv3`kI>x4)QFp6^YXYowE1}OfhT~|FHk54K%_F2JKU)XB4d^zSiIpa_;!qI#9jy*nasQgB-gxBe+mA@s%9ywr#T1G~<|;1m#>sFr9koJEuwk%Yernw$79W?Bxu$TpJy3%qJ*(_EbP^A zH5r<6`+aAUB9lB3nJ?K zjnwQ2Q^&u$koP10ogPGyj>E&Jyx$PJ)PJ_66SC*oDcDq(m$Wg3m5PRNxkUq zkvYQb^v+m&sKN7q*3h`);{E%TXG9q!$460Gr-mo1e5mJhd>I8~txEk~&pn&?(CVVf zWDCE^kL#SS`DvN)A&K|b8kb$1;QW+-A)w2Xacs|I;jf?aQkU0ON_GWNllS4PwLVO- zH#COS@QlTEB3h6kyVS)jvlW`ar?Jc%sJRCLjD+tc&MtKl;?n#fHc4tE6>Z{)MLBEs zDk5&5E$!Yf`)M0TrM0Rmv(K`wZ7k>{*}wgIv7j@+P;!>Q!HU=RB+B8f6+N`4i~jwI z{ET0Gg{GURl>Cc1Vp~MVFk>U0G^H27VvIlkOEP@$_raW zbIRo1V&i(+6#+uiVD+ZVprXV5=O&OgvHDm)JBdjX+;j)GjQweFzo_t>F@m2;H!-TE zT!nkwhTE}|a8@Ayp82{3Ka$RUhUG|==T1&4G%ZFck^U-FP@=iPu}W)StNWIZMwuQ? z49UDOFV6F~)S7i~_)hfrK_}sMQerXsz;@$H#9TRW`THcrd*lIXU-Vrz{0Gn)&>BK; zs$ECAK`xYw6U5tz#lp`UxKWzLirwtqLTJ4GIvAbqU_arq`V_VqE$JkSnj3y%wY`^! zgM8PX6(d*rf>hd*XL`Buhaf{W&+}ZxJVkB9Y+0*{L{!G|puQLZyk~tL?CwnmmGCDI z-*GEr#&ujagC7VqB-+*WRr?GwTzJ#Js9=m9-)YCxGGXe`WoyToj$(bzI?{ z+zu1x4N&CsV;1sg?mnPO>CB;?LmNUHQWbCXTEphP2zV*gYhpT|>&dZV@&p5`%%s@au8_x& zoD5fqn<$Ufq8zbn$J3{$opV55oQ^U(e|8+NVz@kZSn|h{pKY(=J}>>nv1hO6?y#LY z*FZkpTP{ia_*v^b!D=jxBT(x33rDOuyYnDZ3x&C=t1sH>E%E&IK}G z*mB&}bj|%KkKp6y54d^Jdhap>i!OJ$In2h%1^4doe#dlOX&Vdlk84NliGx=N2>_$k zQ!lav95SfivB14JR@x1m9!d05?RUv^aerAHfM2A%G^d5ZsUnK+XN`h|hOnVe%3DTe zg;U~-$azm0RO%r17N3I{vq>G%)D7HvPd!fif}uTPzKxn=BL;0~ig^)mMz zBsFW<^$A6eqN(qBiouVP;IQeB2X10NC94!FjEI>Bc~bDZshRVzHM~i7ZEP|I58y7^ zws%!mhZCk%`a=fXIVSAeuRcB%32rm;k7$@6zxx8bdnX82|I%aWAP0)=`NSeBZByXj zK|a^o%KRDr%YqGxn0$lXpQDD#9WnIB+_gMdjw8EEM-8qh%e)5nLp$cqF)h097?)AI@^eMWJ)9!5S37q+9A9T@&BZ0# z?ND>Fb2O=%g)=sl$e-mn2<%fm7-DJj9Ah@!0zBq=*k2wqE@=%_fwpcg*7Xvf$}x~R z(5;&cgwN2h`R-8-=qt0-m#*=;TpFvoJ5ZnC{ay0xD~Y0G=c>=1BTQITF2=;0y7UZ0 zz@sD=aOf}A#1(%c&*ePy>L=0&AljP#OtKTUX`+7~L%d@jANqc8J57GvzH?&qjw~6! z`Sz<+e%Bx4zLAd^o3!?u0UQ33E9`N5kV-<;Oc-;1YP!VdBR)gba{G>?z9}+G$G*G| zepZ1tN0D)5>%L|-SzBGU%9sy3N~X%IhWqG)>e!bGwrtN`1(uES;M14mNta@c%Y(?~ zoz%SFFU9IDd`x>AO17ZRnSb8(Vaj${9>RATytMjYiMh|22yNu?$kC8n&+>u!s-MSQ z@}iQSN;Wx*%@EDOPu0rfq53vb zgf_K0vkLr)pUA?hw13!~qCA+vj+(fGP+q4j(l*t0>>lx>A9INKp6D3My8$iCPP$2* z$3r-uI$z#b3hwdko#FJaAUvx6*1#^|u7~XqAS%dIoTNHSg=Stz=l{<1^_{`Qduh0V z%KrFDGxoU&^!L`WkcX)KFjr1aOijqUiu3f08!VY{(=i)_e8lnsxN7KAsY9w zP#>c^M+H?9$~;Ddq($H`+>@tO$v+huwl$0R?=j)8kq~UDA$B(Ie{EF6_8*&e0xS6Z z|6ouE8w395a^-CQUatJ_jg~}gY;2v-{=Me-6LT9&G~nJ1ogi8e4o)Uc9ySOU8$C2Sgj#+Z4D8HmYQS{SdWvFamZH{f{Fe5VpToJ7<;#)il!$`~ z%EbymV`pOfOX=F z0Jgy3>7U*BwdHk2OKyT|50cqg?G?McM%P(30PxMEy+*YA)XklajWpdeA0msY+ z^cc)p{w^&rz5O4y1t@-N+X6GOoHtlFpe#(B+xAHi~4g}$K$aL|86xj>}J!VTd79Q5y+T#kQ;ashvT zYumyNRK{_G1x5=na{Dt_ZmZBYv~U2??XS26pofJGfCiZ0-<6hsh;lh^>l9(Og$ z!oq!%SOAoWofUuvnBd=~}!$REMNbz6o0ixw#06n~jq z7B(h!9-xN+2mQMy7Z_RoPY2C)Tc-%*cwoW)-&kO@KzRVq^e3>~R-tcb;o|wrz>_FQ$Sbj+h3yh{efaSIdeM1W{H2llt0?NeA2|xo(@Nd$> z{SQ$t_iddbKnpA2zMwZ)ewkc$fR;aj<+ciaLklc-`^yt?0s0JuK%syM{#{!BAM({sj$?n%|}6AEI3D+d4&n7MS8f zZ?M2Pw{?jCD=e&lu-ssQSr#4+o$jOFydfKw82)9tfZK%vrVAkbcMUo# z%Rjh()?eGI-v$gDFopoeZ@{$nFEkv$ybBvE(Di=?&3_tzN2S*8{s5nvw2?N&*xMobg7D}$K70xo6H!@2v_k6B?##}Fl>-wa5F1qyiY^twNT=(c+ofXtw zC|pCLHD{t_i7KQv0%qXUao~`{Z#fSMCdx0gS<2$&wS~+ z>e{Vzp=?Ef+2hpn=VRIH^12Hj_cQ7is^hwAp-Unm!3Lk}x~tQ=t)9JdJ&%oiyJ$jd zISk&>y=9{s9?kuN>wN;gGxqBh0Fv&tGM0zqvf;?gMN!q#O2hd!_HgO?&ZVE8&;0SM zu2AyIk-4##SM4xGu$1&kortVYAsOpZQqs;v%Lana^)7tUwcg9=1>3KVA`~ZQ{8txi zj??5=bJ8y0vT>nZU7zttg^Y%?%PZc!;DaZGx-SpUB)G3DCi*lB35vM}dak~{Wj}lN zK1}2A5ZOn=yXE?##fNUiei-NK^zf^fU!%}PN7{AcDZKWvuJl!4rOwBRkxS=omsGrY(_#TRuNv!$%GSZd%Hu`P|wm)-bMZ+n? zekcit34c^58^=hOG*iSiTjqM&FESENag9=6`{^-?Ha+4#ZZ=k>1Zv4b<(w&aQzvrE zZ3lIxPtR0>UMO*!!q?%YUW>=W(}xm#lwWP=x%j8uC|oj%)mwMTLf52~bU%T5sx-o@ zMqhb05lD}))+Xa7x;*A0KYzP}Jfm9W*PPuU7Bo|8G*UkyxN6tv%Axzpi`ls*z*I7< zGGn3=-P_rL=QER!X`pG4cJ`*K)fDE;umeS&E*Y>!t_*K6lRjl*dFdcE-gz2xMXgRt zI=zPUu6EvBrqakUNg@#k#bfoth`B1w3EZ;}O!e%kQ!QEa8jp522IiGE^DR#vx|x(X zq-jw=&*QgT+$P5aP5C+~^&SRI-P7bBt8!0TdnA(Ns84a|HB4=Cp1km5dg#2;>fLAT z%3}6~vaamQ%d%yYoprCVFIB4nHk+Ll)-!lpHvI;Ax=H7?;q>Du)>7DT6JbM{jL4o^ zI}VHI{ovp{Y;Y}&SFc@*-9-0(Nyy?0lryxo%yPk1_?aQa@aT6ow!58$ZcJv>VEXgg zv3pt?#uSGMv$41bN+q}fQaEv27)Pv4+CvH33&WfY4RTEh^L^QZ%V<3zPs0odiZ))p zickm%JY?l^(^=Fb5j+1lfUULW3Nhc9vY_3SYd>mr!To9ts(syEu|Mj1g{Xx1K?iX}xV)bT&f z#zTyOli*E!>+f`v9Ej-0pS6E5P5cmnki{Gu>=|SPdD&Wdn9Z!kk7nW8Ea7kRSp#o^ z`v0&wPN*g3xzn0h7R>4RtA3AT9E zNG3T)nU)I~lgJP}!<9?7QoK?JkQ6Y`Pm7NYkhY2akv#jD3}xhmlSyL&qg^H8yT$dpnp4;D{|kramH!?kNlS(iTK$gFd@SkJ(gY z2B)iR(8=@xC$lB*yGB6Fwi(<^Ru19hNDE<@0d6`OD?cm4^uU8l1{V2pfgaZ^uaFff zi);UwGc#P>qL2HhN8aI8m%`@8VHKlE!NGLIpLpl>h6|8;EnoYciV&c5Vv3MHUnXUGy;pf3ZY(Uw@Hzed@PcJfic$&C4 zY=GnaZz#sxrwq3Y<#7`U9`B_JE;r}1s87#JAp@ll@PyU_n07l`-%#MIJ>S)4)VgT( zW%M@kotN_J#q_q5*h}^5(%z%is{0X+p?Hy5I3F}q{^eAO!YOFSV&Y%*02b_= z3vn`Iz9p$#aA%`@Hxf?kG}u>`&%moY(5u%)sdQIK{|C%0j{j8#-sVU6SuzP9`?eNb zT6-EiVD=b&jq1U|RFFr$B?`ngRy#QA=7b0^lI%k$h>}nH1Xu6Q#o`XoVH(zhg{UB* zr;&M>IncLoF3O{vxsqp>x{N&PIy-&Kj5eH~~ff`*(LgxaW9wI&MP z8v~g1hk{rkdE+d|gH58we8_GIb&Ty*rMLl<_1aB9-NHKQ`WR+q9Jwy2b~Q-uF~|Cc zHXh{_bWMbcYQ}_coA=5xugb)HV}9zTOs9KkFm8TFHPr-)WadCI;J_PWQYL&DZn4IxeSP|@O@og0F~6`hYO9$O!ZQqd$TSh+U`_lS zWv%b|9#9LLdXm{tL9#O+bJmSdoga;MagWNyO~$wEEb4?!tM;0*zw zap_kH_+=zPF=r8PtTE4xkrRo)o3P`ku(p44Z?UP(z2{qW$D0V!eh668kfTK4{=ch| zH2Yem#CfI4e)duJuxRRaNB?yq4R)f~0%*EuS_SyC(4vVjLfx7WVLcm@TDU}GCkvqI zd8t0eqa4n+aMnXXl=c2K8Ni?B0JX{a<1C1iE7`y$8o(v3uuG1ra=lCR{?B4tfV!8M z{W_)zT$h={i2=8E!BlRmUIS~s8fddu&6*H?|47?rCh-(#a-$;~Q_L4SV5@vyG&z%g zoIcsC=8Zw-jZZN%n;3A;>U#EhvYDWbv(~H>Y)@iaFjhLQ>+?qFaoL_n9_N^#7_nn1 z^P#8i^PHOgIA~GHIQFEQ2gAoRiJU2KwUadHn48O%le0!Xhjtz2PWY<{pA5NiA)TxI z?9a|M6W}Fp-bCHRjrVyLIhHl}`}fY>!%Aec-bHSUZltn3%;OUMd{lNWI3VqkawNy- zoL4RqbySw}blPaKk}x8gtB+C~Rpa@G(f$r9Hgt!r>(M?P7qsbeu1mIhs^YYF$NsM@ z&wX(b7Ykj%SOZ=Vt%EI#cO z;&SUP!_IWMw{9JQ8Vrsa@&H=H8IrQLTHV%V`rrjL9VIZu;H`VIQS}$7cy^y!tX;$v= zAQdwTu54%6_{ldW(z{`c)VliAnn^foNUQ+Libl6XGN|a>=7agbhM#-aq@oUhAVJK}h7fsBod1 zm09wx9A?>oz=2tSk+53(cOAHGVjFbF9%ZR~bT~GGeohz$4gL>jHpI1gMURXP3UKDi zTN)>8v()oL;L5WhQot8l>*hPGUAbb3ay+>7N}PzERCDGp0Nag9-Ii%USH5Q@$^vR3 zH76)a1e*O8HY~@%#?LNOlF1qhT=s_T0rgOzuX}r|1#q<;g{lW@I#9~WV^lIb1WuLc z9e~wW!aYO#hdc1w#lq}Y<@=E(L@K~(h2 zE38q$`%^At8vuYwa6P2fi@(uB)3kO3rx7dbNfDV(| zPDf*rE)NzziU5FtLQa{g!j1se#V06+r;*!+W2k}qV^c#ECz>u*YHs&UcB$+`Zu2$T zn-BmxRxuoSSJOYzz0h}O*d(_;oG~ypl!^z4fvVLvzYI-4h|j*fN1`z)r!*CHbC50!jp2(^D$8Q zpvjX!4vg0IFC>6mn3W0TrefZO1Mg0azl9ZjycCfNd`Vn70n!9IZqc}K2?uTgaRM@| z)Y9&o=FkfJ%Jv43zXtB`b6_+9Mhio-5YzqUr@$@c0_TCRFD{kS$ghXBstF`%arsy) zd$RTokeb&lB=g!sI0!Rxh)Oe#n1S#Iyf?;Z1Cua{l}A4U9!h4;7#|OXj;ovldLYbi z6GH0&2xq%J9jjXMX^P9!3f*AvhJ<##jobTh!1{x2pBAwtza8}U6R9Lts*~B0LO(Vr zxbEKNFV)*AmX$3qFcv1uxnovFSr)6c@>x;+j zljI*-BFV9|2QH2>$bQl|<h<94^E`iRY$WMRQ0N-A1Hp@tu2L%qw2Ae57gXol*?%9Yq3*Z77yow?K+}V zBA9guTtEa=zzm$3YBV+HL3rv8T#Q<1Y5fT(qqvq3^Q)cI64Jc#5Up6)v89BnFgA$R z$Jz8H*pHYG)XCZVuzK`d%h!0@L8{X)fOh!S$_65%Apf9Yi?R9;-n6kEG&(Lzx+pJ{aFZ;ZFKY0A&4qK;5t=7l4M#1jnv=fp!$bq4XWN zdbl$Jutvi;0a_!%=krsoyuNOwR5e3{;b)yf^@U4LyMQx_Vf;YW1bSy=xRg0|NkNVE#*?1A=u_ZPQ`13*Mo-!>j;6;J_<84L4tn*)$k zUssu9z}o;{8;=m4-UnL4P<&qj++{sgEk6tyP#(BgFdv2tXvPu)esR;K3HuqN=>Px* zb}xj;C6N=%EHW{O{|{Sl9uL*~{*T+z5HX63-HghXeaX(4#z@&BWXVp1vSy1IjEqp0 zB0CXTlI%;i$da|}DNA-DyYRh_Ua!~t^Y}e}|D1E~>$;xL>v>)GVP@`g&diR!^KAz6 z=Y^s)xlA>n7i8-)uKSGqTu({r+m|)SYI2~8kSm3vu;~1x>W{^ncMutVBvLaAk)=wP zDvw%Du3tGcX84w>H19XsL|r(bceCpI_M(>Dy85AU{n5?Ce5N;Zyh5imW?7|X>bG7Q z3hu6k^iy*dAZCZO_PbU&+1@GZ2ba-`uusYEoBi?r#r90Gx@ebE_?hBftz%0NQe;wpyLtWm zkwV;+c*lp2kRRw3Id@0*N(C8ue5$qQtE}KBZWYa+s9G}g`|vevCF)+I(nQ(gC^@oQ z6Y=AsMnw%L`d63>qB_7v7}~gWFh6>e0KRtM$?#q&O%y^qVM>%t;=Q?T5i@=Kj41iK zm3QaYavN_V3GJolp9CnIZM-`JO9Z3fY3V1#y<14+L~Yj}ld4}i+@d~_f=Ik2atXLz zpAh$L2`u)5Ge_slh#G$bL}U`B<`)2G0^n>fk;evxGF|Jiq8#g3e@;68R^E1T5i;5y z8}U$%8o?+;4+LDO1xNqkl;t3X6)0lEkmKE^hY`ma<(2v6#CSZ5|3 zJce<0Se4ZYc36S;xscZocyUll07G$^Ku7nDIK;Vxfs|5EWZ(nnsJV6hIp_``nKuCd z7!-B~gryb6$iRwsR)AdPrTEsnPX8rK+!T9e@R!*JFsG$J5Q~4A2cY(y+Ti$?x*PI3 zLBgqbOF`-VkTj$CR#>t2D#UGwP^6rODy)L~oH%Ec&>mO;nxK8tg^YXz>QjqPKai*e z@j&^w{(tg)!E{&Y{Wo2ITe*G!wd}YQA<&apH%KAq&fjcXh8&rj{NX8}WWqnp;%S#a zoZ%bkOHttTfFywKlP(SZS6)Cud&2&z6{s%`qXpFm$zC^Ay#04dj_2tZSFf?qaj<<{ z9pG>KrvoT1Gw`CF{Y(kic%g>pJx&REO;b^?v8-`1;GcYCf+N1rDNxt(kMa1lXg@G@ zzKz~pbq-hMJyJQ;%U@DRc2oQyd~3I_8oVr@oyc~IkV!Erm|cvL+fcuB8~m+aDi{B$ zJs7Juuv>WD?fb;*8P1BspPN)=qFJ+~%x2 zvXbxjV@htXt-qORakRUa;P}+g!)dpl+ePajw0&G-b>(0!cf##GLsvr$r;FXVPG5wX9OH0^vMC?zZx}f9A+fEX1 zpUPG-@}-aQ<5mdL>#xlA(gfti6MYoMtX`0Q%D`?L+6G>$1p^Y@j+M*u@xwkZd_sCR zx=3F5B%>-n2HNUm`U;|yEsflwY$$Vwn-t;^+5>Nto;t#!Z*8@hUbP%%gqYShT>tgM z&DU-apv*6P=7S5tO6bmOv%fk%@JPwB%cm4jY5sKkMufMTp)khY*d zNACy9*jaZeo5%aR09-{apUKrVJp;0ny} zJO;@s{slb-90X&1uX;0{+jj(|{?-nj}&}g@YL7x0$kG4}}&SU!MfwdpNLkJtE zRdbCbo%zMiD?c~zgb5;g+IdXGzQ%T;%?b3Gn>e8{i*Bt}-a_$!c(qm<{}G*HOP^q~^i1ShMV zrHyPq6nGx=ZgvH_`#lqhv1AGY9Z`O4bRV!&cq~R0x_~!NeD2ym1j$E4`-s05)4X3$ zXZQ|ElV?DO*-z_9+Hb?HIX~>ikJsl~ANDUNe!blqV7jTRp29#oSht?Q zo!FiELrLmjDRnVmLU-6q!4}*i#@i?`J6rD_up)hv)0uhPn{(KUYT;JD2^W0-@;S*l zl{6eJ2fI(Sy<^HL)Y-$%M?%rXJr%}X3ndMNJm;cs*{viely5u_#Tbg4a#?Uke{SNv z{us{BdN=b%6g-dhrIjfce9+_^&JZuCabI##CFAw7qo5_8EL~>w1j8L#uSfV6bO~e5 zY5|)2`pAt|4xUDqRkHA!pVi8Z8Qip^H~KkHdg$Eyz6&G47!#Bkmre>on7&xMGD$(r z=P@r&U(5Am-)Nj;=P4d*VG&h&beqZhJ4-2v+g$0ojZ#(HTrq>W=Wute$`R=f=*Vw3 z$T@j3ZZ%*}a`Lo`uY{21U3~f5jLV`oW{bjMG8m&PJv0Y)rl{M@y^hp&mm6WHQY3@4 zBK@M<7GR6Xe)RT^3#U+eH!ru=0eL)5p9VTlhG!HO_ja|y^qD^Q3P)EAE`eIJvef+? z<^a*uZRT|IJD&p{VGPO5xhyVzdPzbaUWWZ3f@TbLqom=PWFaFDFL?#VU-R8)Xm}bE z$;rdBicc37I5Nw0MhVk3x&p zXqdw}R?~;kIJGZdBeC@3K^{+h?eHzc?iw!~#)G)2sRXl*AlW?Sb0gkz>zd!OtIZ2H zBx7k%_HFrOxa-;Fv4NFV*eRCOw}8xXMULmGY%8{vlV>63z1xirPL!a%AGTffRMjC@?~^yl#+keDaJ%juFI<-75j(>bcI(XFQE;)y{?7%yxwolD#L2)HS#$-4 z;XiKUdk;JpBn+~grVFol1%_|dAgrQ1s;`!^ zSru78wH6J2;zu5}UTF)4etZHr8{b#Wsu=~MYsBb)MT4p!e3_kP<3-DJkG~C7eYxjv zemlEt->-M5Dzr?A-g^9X(6{u0+CM`H0Ruxz(zhcVtHe4f2K;#`O4-I{>7PJH(Dn!<)ypM0rDH0B`%1g zG_uKeQJi~(hq{a-Grz;QbT%LDg|Ne~yi)l#PaB@gKUsJ}m1{9i#FkzK{Y~ZDVi&<- zbagbTmYaKTW0|c5H4?0^5eg)qc1ruaPA%z3`-vSYgdG?LQHXd&+7mY>Uy+f4kU1sIa*pVPeW{ zzQ4LuFcBS{6utdWHDe;yL>P;y$daxy>x3bwz4xVg9&cdlyTs7(Xy=u7!UGK#_uA)h z&)-_ktJGA()RpxDsJ_=^Q_sH14Y;0pCszZ0VTEdZ(-N!qDYEb!3e7a#a`CJRGVkM1 zgg%1Xg}dB41oLd{@`fcvTg0DrzAMquwLLQ@@`=UF1yx@JP}8`F)q?^&cej)Mbm2TD zk0WdC~8!@#+4@TsnI9mqLzFG#v&MxLdplzIA9MyXams64&O~ zrp6?SzA%$83T!xMNbh3{KL;3b%o?qxL@;Lwemu8^jfr*h$a47 z$FnGrAdI}L8>=C%&9}|p9Kk)YzI21g#l6k#6%>Mb+C=DRA?B7aKZ=-XzE_D5IodukcthN$|+&N4Bm`(!Qx z9wzeB#)cG_7h(^VPn>V;&0uXpBQ>1ad_>7dEE*=fCzD)bMO9s03~|kwH>JZuFfn6u zKBCC!uIMoiCI*$SsKRsNNF&%B<=g07=v=_!X;?JN2_cx+0|KCLQ{!vmVIsTk0CEwc z)l}V+3~?Bv=n5dpa$jBgu?_w%%g=ivID7na;}$gXQ)n}o=>e3Tbc79_*p*ZbY#avn zsts}0-Z3<_&%uS>*`+8I{2!JKxsPb%fgRdM#x36oc18>E;bZ?e5J`xdTm?9g?l>qLhG|Ki%?6bFV&%2rihVjMN$DKi=w} zaNqr1>soe$LzrI4t>~gkd#3ZBy&oRmz8dqMUtZ|bj3C)sc5n!PJvb{p&rUGzx=eOA z>P=&2o;ww3d!;@R^`Vh>vq{g%jy}4~=RU>Iq2U!Z$;RNq!J9%)NJf$Q=RzMkOS-(D zgcXxq?X%R6$CH#5{5g<0q#Rl?bP{>rXyt74CH&duR-C*uBkLDRx?66OHe2qqM^K?<=uHm@y#gyLs_5A+Ix%RS$_YW4SnaI*v$y?5;&;>>NjLUVK7u7r5hg zI`b+P6M5!-&Q)w|fhHS#cWj{<0go;1)eNdDVp!Gk%C}Y?Z*PWkFCX%qvBQ`8Iys6R ztgF{V^}l@zcgjDbhHu`_0ov5VSr0-}coLg1_&Mt9Pd*+4AKp@tx5 zz+h>=ozr^oS4Rnhw6obK!Yepx#Vj0lXIl%>oOi}fS!ePitstCx{xIcq{NGa6K`9_2 zC&>_r9`R2RivP>d4psQ7Ig-@~m=9!<1rafzgXF;c1g5?{DDlo3)6)s}rS-Anm^_&G zm?Y+c`jLBo?tu;{Lv`wu$==77LS({0JT9)8-e;IdULFU z3IQ(%AkeFqQ27@z=T=j}I13tkfOdefR?$Uk%n+cDfg+FT{W~9Q_@J@PP?QZ6l`5gQ z*o?UE0{C%BM>HsjyMBqL$P6vkRObXDEQypBwQj521dC)#4NV}-tsl78SYyU$?3s0> z$XPHOZ>OAnK9NMSrxqssg)jV63MMG}__5p;L%(Ys-+fBzEuLn98KtqO@6CzQ`mKSr z|Fh#>Z;crS7E#LRs30_@J;|=b2W!lNY$GqPHD;W~9>#ql0MR3Yq`8!S?yMM^`p~_> z`j|qLGA4lgqB~XnHPkh%J=3mxBL- z&Ynf4o!aRS2!-GOooazO)HNXZqjxt_RWO`7iU)Sg-1VdTv;KW3x%x*8izD3)4HAVf z$qseDAN|qEo!~S;`##B%n|L_(I*RP@*01-0sT*a!ijH+IQGrT_3LVA{&a5*VKd7+2 z*(bJ)f{(rh9M-=3IdArY^=Nziy_;{%PL}LJ`jO%F;G#vnUxgE4l`BperrJ-Ouj-|K zdwM%%?K(lHdeoh1A5*U(-Tqwb{d2gDexwMJ&q`5viKzY2Pc}jnz3g1bEUt|B?QN=t z$2Q3idSG)$ua~d8>Yx$7Uo(rN$DMySJ|Sd)Uk)f1Z!8p#ddG~46-#|AipVjv4&@rcb!PA)= zBG~3^#d1Di__PkT$f8j`o>;-uAW@`*z)v_pX-c0XBGRmPU7R0t!X&G%H!#ChlAUwZ z_=wsi$K*MH91f4W1Td(9d8rdtSYBhrf43NWhfWkAA9g)vsbqg3eAW)nGOl@!2#<+_ z@<5o#7Up#8T?r;tjLu)ql0Ol?!xciFHuM1$+noK^G<-}2nQZYTGeXQL<+4wI^Cd$w|35bt zqg^(3!iq9$$`90Zc2rLjsAiIV1$DYu`5riR+R9$P1c?`PK@Tdf{V z%jz%FS8D!L+~90UdH>zZ*&IVjiamfhOEJKx(zoWLS4;g#PkWZe{;xr)Z1Dr0v3Fsj|*w}s4d)K>H>Y;>6bMES`4%0AkW;THqT-8QQV%IpAe5kczY=yO52raZ+C=$t{2dMrM;pe$?9Bz}vt z?4cb6`2Iu?!ul9!FL+^S?>}}c8LnNXX-8(rvq#g6UR-tJU?S`LIztSsl9V}df+O*u4dl#)C_>P>S!CN1cz^vp|B0j@yHfL&*=Q9Us6=G0{E&lCEbZcuTt z4mgfk^O^V7TMw-ywG-Um+~*_aTA5tkzJ3MIK$6MLk`mymQs6qiQumtJHd=EQTPiA? zz5fb{Ru8<0Xd>9_e4Ga!-q8wd z$I>u6uq(jhXdghHNN+y-x2~k!fN^NN(=9QUxBW^rJ`k2op5o0%gh82jPD%TWsZAJW zQ@G!$p4Z?#|BI+$ftM0;GoePU>u_`>!LQ5QaS2w%_mM#~%}!?2sJr#kdn7!uh@R|A zJqjUu-z7yt;CEP`H^LYhLwYIINajDNB$PpgR&;4tV7@_0UfXy0-+-r6JQ8vmmyUzq zNlIuWl>E%*QsyHYruLf9!%}4DGAi^)Z)-xL20#{M?1dh-ZomT5XC7Aj=6?gcKLn!f zfgjVxj(%?_Jx)+(uPgP4aChTo9k4T_CX2lURgL7;^Zh;j?I;XNf*VpLP=94kGy8-dBx$sAApL^FYvS?7suLV2My*N2Rj zj62$<_slWH%hnz(kKjfx923}>-(FOpx8R;)Y5Gj4h_tZ7=xmMHoWz!9j=Yw0KZ(YP zo4E}kV#;Keh`H_N)f<5@BaHl49B4M1CwAKDv>Yn2WJpMfYqIW%3&|xK4y4JrM^11^@sUEY4MMtBRmcs3$DagA;_y6I<#;FNf^QjxE!G6A5bk zpWef;v5-m7(%A- zL4$0~PY6Cv00J*pSpsJmmnWvwjkWnR!I#$3PI-j#t$2oW@DLTZsWF}l>pOR3u3tZ`S@_=X2C;n?kIvC2x^ofB*S+#OjVG- zSwO}I5Xaw)xA{-$CJus%@REdN(mPP9DdiNk_>w1*syMv#`aYkD{E|~@a zVlv}7aSzE_s|PyP6Fz~T6KC%$aV-*)UOrO5<_HVNPjhC5c)A^KSgP8lXdRL{a`}I; zvor{g`n8AvcTK_Or7848^K`B;F(Q>8Zgr_?iz+i_`n1mZFcSB?+emg}7oT6^!YJ#v z!xXUvqHTW>O2r)=|_VdK-I%(d1#Y5GG&S|-*vM2bv^ zHp4)5*S|5dE_T0u3YUgPzY@q9dHrMF{nN*~NPZ_u6Moh&2D_mb(^xW%w;FClYyZeS zE#E_4Z=?P22?aloo@^d@PHL*|(E&^R+@py+c70l5lOn#2FOKiI(?@iKzlP!;t9cB? zrG%^(yW~yQ&Kr+9rPrFXGSt2enAYOf8Qa~@S}nYru39ok*vNW%$$c%u36~o>kYC1~ zj_lK^{TS$cYCNaM60M(QR!&P57vu9oibqe)fs^nO!JOWCR1j6uD{b)eLhTum{%4r7 zp00>;1h=uh={P$5qI!AAO&#I7ApXq&p96r>S~xLAoU7}}TU3}g${46GJpaO3FjTm7 z@SZCAO14Fo7QEL#{k>I$w7dqeD!S3cW=aZA*< zpFIs4l?ZOPxykoq(b2%TPNwyA??(u5|x}vpm+P6<%qoq_K%s#2ibMt5lv;OcZjFxG?vvr#DAaC4(cqBH!vZ+gleO1dXxr_U- zxcdw5sdWyg7jaa06IDx2qh*iS?uoAVMf=KzFs$P}Z=b`posk{h{F4z7C!hZQPX0xO z^%bh+Z$i<$d2{TN!^F9io|P4{@Ov+vhN_jhjCN)Zg`%U+m$KG~G?HPfUEIUY!J0Fr zpZ#EU^}-9StdWJkdi+f%CX(<2wk#wZO;E)|cb(#CPvCF7hxg0`$rcBa&A4JhqkHU| zC)m^LpE87=-(kUp~R$O`wY87ixmP)r#Q#hKJe}4Hq_$~4$J#94u)tebUF37D^C5Q3-sqqFa zzVY-&_2BJ%YSu5OhQY@bA=EDKt_73?9bSPSk$k?n>A7sBG}t{j5lU7FPc2V;Ta>Wr z&G$1Wifnl?SYURP(0%w|>1MZZz_fRP)S6bnOi|GuHb-B5H|C+n&jqR6TWc9K=a7ZY zhl`cU*tP=$#t_*Fux`V5p2tBrd#SFASW!)0Y)6hrr(|cBQ6S0{>0ZT2oOe?|5C}cj z0~HW$gwm^g+&U?`S1B>WBso7OXu?;>$EqHQ^Q`k{<1wb$u|(WL_noFD1j9JZgXfpQ z8b4qt)xY|QAgJ_R#P20{OuP&^Py3Clp8{PAfvfF|p@)ZbtzldZ4GWi!0pEGl!h4Vb z9@nK%ohr`LKGjR|sEnTv(YvCrPDSNSzIaA>1Lfl3Ey2~eg3pg-V6ceOMWYX7_S#tG z)dw8+A4rHyR^7aGo@X)-=<$|k;p&N3BS)?HdP^uHFGW$}24;Fc5bgR|$^Ne>EzwaK&&$QNoU4eh|!k)V%wo7`m=uum0KQ83RdqEa1c>EP| zo~q#DS#kvTsUP2WmC?CfTW{?HF@C_=a~-b$@ESsmEdW-L07CmpfX|Cz3*em@LvN?h zSz`>DXrtRYG61_KU?;%xPHRDCh(H^#qb$A7f^bwLguDe}b2~B~!RLK|n;v3ZhwR2o zw8XY;=;%LKd*#3Kj&quVh}=Oa!sOq4PDT}CLK59Qyk1?(}9y}iWV9CH~`a;y-FI99j@X(d4HGa44$AGZv__i6r@EW_`$ zK(n7v1emzi3{tXM+*kw=p;JG=C@2PmM&pdHbe^0v@Lq~Mln(fjKV2cwq!bX#wB4F* z(JA_Fb~H+EQ^(chR9!q<)25V;bWNRi(wE;kn+F9NVmt3h7Mi+sS!}iiTkhrJ4<{7J@zz1b^Vf9mM%_HWsu$Ti8sx@r zyzhv#wJlccUH!CcPrA`*E}CITq9ATa$aT$pfe^%w@rSb@1S#)cT8hqPQtqZed~e`; zIs#sji4e-9$K?@NgffrG&N3mLhkHBEGNFP_^Z+ud;ogc4UY^7gJ>nrDgnRj|K3T=g zT+%FFh!Bj9%D_E@4Mx7agcUos@OBG;o?iJM2-Rl;|4&E@;muQCEep{MBMOBZhJ?0~ z%(b&j;1c^Ag^(6lC6o}^e&<*>64ZLbkQmM01&YYHMY7B%NTGKeftpM&-NIRjBJ)3u z{2RfYG0vpqOC3Sl+c^88(GsKc?0rr#EPbB1mcl29#ZR@11AaNR5r``ff)Of&PNmvW zN5KCA@J>=wknik6pSJkP98+4e}FQ2V|j|^E!`N#g4<;L6{|;|FiGLZV%qyLw{I_CSoY$1eK?ed_J%EulUUue86tme;tq?W50O6lVXA! zLA!W(-e;f!cQ%3|tb>>Q@#EjNcLY&=iJZHuXZkr^_n4@T{EX}Si)0SsVvl~ejvX9U zlo{qQ#G}HG)~7W6JLii|+@9UA@?lp*@X-A+zTM^JEMfV{!c$|}MJe@aby&>J)yVPy z)9WebL8MAU%$EVB(Uri9I34OCk5?A(JUDeO==_Hb}{h6j)MLQSV4%9 zBkQ|4^(3$=uHwuG%ch)0fHZz2N49=*0wCkc&nQprr!07aWsC}TQk#6Ii-ES=j5~vd z5*7TTV9lb@6RcSjCX+Bx7nVRldF-U#0uE}*#*)j{wI4SX&M$+7j4N_v?JTkclCFg$ z@skMpG9OQ{lJSzA)Pt6dC$O~XycUYfxn&8~W_(GGY()GneZe5HPR22s^iIB&n(}b_ z5LFtLzgrI%d1In@TVTzXVpLiogJ+3Z^`MM(H0k{=W^3hd3xi$k&3Uli<}FJqIAr`~ z9#&C4=?*#}1v(*c{i3pbdAmCWzCZ-DFkeGWd9=NcD(#W4mcA_6;RhVkVU^aQS@FT6sv`i9T9NgOy@Hl8v5}XR=4>>nMHhv&@(A%Ry>`9EipH2PB?wXcO)|V!<2}Tc=ASUSdSkUBf^Xk_9t6$5qu4@{3$d?ubI#NqtSx13{H))vifWty*H3=sbe11% z9!RYQ9O@lDT;<#$U2;i0QC080c~{A6{_{-TzK@*arK*>x1x0!9!CxsCeM4*--~1pM zLHGsTRtmU7@6V4u@Z((#6nq{WNJd&6jf*UJ98Z-dDK=Oz!osC|*x?g?hNBcuuuEYi zv#w`5@j*!)jZspWOXcB4H<>k_P&!Ek?-mrG7>dK#xmEm7(FlM3>`jjkLU{3c+>EmF z+tKNlR#!-<;I0F-YhgtnS|C%i$Qr7Dkl1LHF2=8_)Q{;uNa@O_h5 zY>6MYNrB%a_JoKN(u%kxk)2==JzGL4W1$@1;TFV*%u<_kh(Dw7%Q(KHq3Hp3dTOBM z!qikWkLX21Zmzcb-kQah82J^uAV!pRC7VCkEwOoDFyuy8HH$YqhL@P6oOuIQT(+(i zqw!hcP*@{8h3Y1;t#$JnKq};E6{8oO@)IE&LG8f>L(vSjSqQnz+f5;W!KFhcB>OgG z+PpkVAwYr4D)w@C{#6XgrgN^``Bn$PZwy3Yhn)9cn1>KNhq01XcP^psz8mv$bT>|a z{b&$^c9s1E#c)sSrM$OTeD$8FZFpv^G#tmaDzsw`;{|L_<-PZ+83=)Z*>k`c2t z1D}@LTcDgwCW@f;n5bOpKC{oQ1Y6^FnH_Stt}xVZ0@HRE*zu}8z#4KlG9`Dz1h8XF zd&y>BT4A&%&rzUfQTqss5Lh@furJEpV31pu^iuT=EIk}Fq4_bq!Sh*vNf?|Tzr}r%Mw=T1 zhQK}{y6FY5xo1bh3`Lc*d-hJ$UUW47egJ6kkJD#?i)U2xGsG)X%8rvRxPr$-+7TF0 zdT<2*K%eggVo)RSRBq6yk~Ih=R(pG_LqbGEN%ajqx6>5DvV~w?{YeI-&wH{Z#e&m2 z<|9Pc9Y<4VK{=)~p=#0@=4C(~3^K=c#Ff&$wG7OI{20R?W{`oXo$S7`r-aSb-rFEk z#^&n!oPLYOR9A&+uX&7Heq02pU|+7P36oi4SozTjuVLw*9zBI)5nL!eVgD#uWy)A# z4+`4T*QhnlTo-Y?XTG|_yP?U&s-;eq$rKIW)VQP)O#W=L50hzg{dDPaRsy*g(o4Z& zfLtuYpO4qx)m+bHM1Twt^Q1$_C6gx_p6y7Td4V3D_+le2FYVJKl}C4qsIBqsV72L# zHAZ2HVcFvm0hgEd#EiL(u#=s~#i{k0I#VJV&Yw|ND+S@s=ASz$1}^mqw6*4o1U-Q}FWqpZk&AARuq zz%UWY9=hd9s5YAI@G00C4A_mRS3lY-3YgcQKl<4)!nyRyt2=mBX)pL7JLP22epB%5 z#C~x3vg-Qk+HaQwmC?yRa(jClcJXu@t@Z1itEY<4bhC*8J^E9tsq23*;PHin-Fqu^ zt9y)!wN3%cbo@C90Y~3kmFBMx-7Zs-fp;3gb}4j!~ah>}ZuKK6W+>7;r=wATeHc8z%i0o?DWd?TjS&FLxwUi)g%WHQ+L&_Qj^X5lW3y00ADwam!Q3s@@iHGR3_MB!bxb8{IS;HpRde;5X+ye%8=HZc=&QfiXa_Q;{FyQ z<`dyTR_iT1yaoMX{t_e>ik^%&S#m(3o-SX^sfD2y?rR0WDGWOwD5As=aGrCJ7Qg0J zOFX=5>sh}Q1)N1@pV(%Ni9H6j!#R`S82g_~Q{s&ST?1&)idhr8ifZ z+I#?RJ7C)sWwpS7M7ze=Qk1+W3Lib^srV2@EWXlz4^Mi<;cb2-p{H%Q)fEpfzcp+E z2ukShB|Z^Bb0n_F29ZP{R$D#s@P@Ky{a$$ZZd=qE4CT}M0)Sw(Go4?s*xcE>K2aj* z>vsKq#}X@|L^8^gD@WR3o5|OY;Mm-?yDZUMXp|l2Nd|20=G|M-BIsJX{$M=ZK{4q9 z522@XxHSY1@7;>+4+S>mBt>BB8Ez%u;dkEY?kE#~cq>gGeKAiOb&-0@eUw*uiE6o< zGp_95enf5iuV+h7M?0X8%mm|8bzi3(e3K}ctI{WSU0!-B1!k%nk#)E(7mRXi(L z5$<0xyX5}9!B@lF-1*R)joaYWI;4|#L#U={xdqz#B9&Jg;Q}; zI_(b4#61_DMW?Vqy><8bB=B%eY);x4(lT$&clTeCc&_%r6w6(#@lHg&HFpcHJ7lRR z!ROK5h$nIl{Y6QbMY-NfYzXfBbLdn@h2K40Cyx;+$u3c~&xP7J(_ z>R|3M%j}Uhct~qSdw~8_{NwekHU7g!hl%+8q5+*C~)ypEgQ?>uE$< zHE=nQOvo&8!nx_fS}z2_f8hEr1d+NXI-h>G6AeZvm5Rqt%%P0>7GyR}cm-&$hHD^@a-pe^S&ZJnnuR@a%P3wF+{w zPU2DbGVnxg3}HmjAN%_+kilJ3zRncLp~WV@QYe<=tueBbQ-CY4LB*^pgs`GGKF0VI zu7cVLy~IPl4*plbuoAR%>+P2?S&Q~nHN9zRtlCinvi-ZliDk-#p`iY1os0YEh3tT|+cq27!AHB9CUpuNnxm}StNMdo zw;%oq+2hSDIx*2cS39?3v$OKFcedW;PNj$2?goX`)~asbLBLh?PJYQ-pG9}kjiWtG ztDRBJ!(E-*OY|S>GpZ>jI${EhUR{ji4>;^PId<5e@TV(m+QICH(l@a`W#e~Org!I+ zQ_elmc%5G{+Wji(yDx)T%lIsAR26-uL&1rTiqXq=Bn7Vj?;xsFfkL8qtbZ%Ir`c6& zR2)5fG=IkzXKz`Vv&@}7>8v%1YE&dxUEAyY#Z#$uU2wZpfk$tA8H5adSzIqwKndvs zLJo#R!^KbK;I` z;a`Px2$IMvI7PwE?-k8K)uxm`0MW-Tlu(>kDoFY0-peolRj4EB?+7YP=Lq}>!VO6t zKwa789sV}}0T(2pNhu4%=N*f7C2rlRYSPY7`WRCd7Wgv)BL5^62Ldn(u0S~@&voWC zs2le|bHeZ!h){s%6A921q+=ri>JSwQn$`@q%?(h%W9)H+%9%>2C>GI4Xf~Q*CXOmr zZ&E75@UJ2s`~-UJKZ$Qg_qfBm+eI2PK3bSY&l@@FOvNd<(NSGLx7MkET!P(|+fABo zZ#4P{4Z&^&VWDCr1O-O277q@PN*5C1T(6SI~l#*%5=@ifS z#&5ED_5$kevoqsj3=CI7@=+n-fwp#AGx0Ie#R{6P9XQ+&M@5wl4^JMofkKEnEN(q# z3GzM5ssu)W8w0rOA^9ndm}Z;mm;IMe;0hBLHI=a*02v3Q<{7j9rP|QEgR>rP@S%JL zFKewF7kdi-p*y}%OvGbi`R5VWutOZP9Pu&qAgN~u4%=)joo|7lq8go|C@13a%l97} zW5tm3KFfd%_LnpI^x`q|XP}kX)@R{Qp}@0LciW#*frqF0bO#QG3){qcVq=YM@>3eD z@$QDHs&wHFq7{HBBZVor8pzLT+T-=X4Ph&G1buM0Fpq8=xP>J8$~MU8Zpf)dM>St; z#i2lE?PfQj*ljL`7JFliMI&E3dsvHrr|&7ffKU@%3#fA{pXZ|}fus>=3EPm~<)kq1<-MmA`nHU8`|LD_N^NQ7np>BNxg zK_CE!iKvJ2JT-6Xj+qLR*y9tY0n>d z;j=U7B407&$%B*pJD{TKBDn|Bf=}8R|7Jp?#Yv#ad}6u3;K36S zu_=Wcitkp6x_8Un^e0xMo(Uct-YW9mJ8=2q^};9ar&fQD@~iL+pjD()W9R@XRZW72`oun20Jup{rUbQykMiP?rFHEO5H4o z9{TDG*_@7`fu4T0H*m46p0(9|0xvt-mJy;aE*N)D!2bifa-$FO{6lvb@cF(4M*q~e zYwe=Qw$BaET#3a8M{Lt%R4?#dS!_s&3BFE9L-4G+3}qYY?u8j<3+X+X))VlnQ{#%Q zC&<*DPp8CM{Y{QFDLY7YGvTr@t_Bed>&J@Q@Lm^Y=+oCU-JYD{nTAV&3~eRHg&hwF zJsD^v=Sa^)fYZ^7`>8I2!Hn*8%Ygd@6o!DP#;rpLn77a;&ld*kI*zmOJv!z;33Wu` z%W=WGW{lD_#pYH}Cqg&?1oe2SL7uNQkW1~P7O0JL@Z}U4Rb}vTQ6qPtu(1ZH5i^&e zwv}dnmJuS_m$!p7tppwo2!q}-7w1!heVJ!Uog#a5FAK_P6c3e)Q5bnS)d-99f>c}d zt^?|D-X7pF#(Z;0JNHg7(O6lTWb4|)=hufRr{#k=Ihu^$X~Fy9>J zq$fB6>h;6}((p3d01@;-{?uul7Q<%I=V8uhUf@Gc`%J%6`o32TB`N~OTwp{E)XCa` zap6Bf;K9;^2H0N^4kBFmJKkHOgW)Cj$-y(6hk+Q=cS_9ZTVG_r_&zi?0t$P-F419g z13W&1@v&kc4~!+Roe{<2QNuF@bOv~gVvy;#!u*~o?W2X4|K%ZsX=2`cX=ku`hLla& zZwS7vSVJ5(5PXV$a7N?8#zmJe&z)9v$Xhj@k12PfJpxzwo0Pa>qU_IAJYK!SB&+yN zi5~vh5z=7-bqdm9ICmLT_1z4NW5D=to0w!kC>I+W@Y{hqcg@ya9>-YdK*N>LDD`Vc#nOx569)(~p50 znROk<(xFNFn=j#M5L;BrFekA%8lnw9KA8ge_}kX!AgQMiP*pfk1uRxr@&w=O<9eVT z{5@Z$$LT&4S$-D~9NftXUheOR%U09m_L$EIIOI)Ti5fjPdLeYL?f~4||K$s~w?9U| z@MBl~y@$#g*6c@z54S!*@6U3|u5xE zXD$5-a6#zy^)C+`0x!p%RaP$Rsy~!(sf5{=Z4V|ke$8jla@l*GL{IkA=?`Ndzs93L z+Ip=_K&`ylxhLoAKfO1z%@1p<1?QwLn>iIJH9281h*!D#lqrEAT#sQQ$&uNjT+m4AE9=8m zA^i!3lyM?X?3yUD2W7CCY+E>hi!%A*)&DMuv}*kGy(IXs)c)hzU&h%B)dLs#d(ZT4 z5xf048P;%7cG9TFPFwF*gf@6|cE^X`4VQ~Bi0@oZiy6uzTo7!|6FHRk_>HDAa z4b+?%d*fP!a27|7z6uB(C4w(}8dUo>r>+^YZ=lfzfx}C9lfb||Ld|B3~+97;{=Z?xNJ}XYzaKEh9cS-Q&v{5D*#xm%T z>Ezfud=&i3L%uDR@I(EF4;L)4l96M>Gpk~cqlFL4foTym& z!$~t+(%L26n(|Qi0&NP^e{iKo-;bEvflh?$S5D0jcM%@Egc`j5^L{6+GO&|h5hEda zQVWtIx3lq$1sj`*DVjtDzM-~C20+-l#u_l@%3Stwp+ya_`GG`8L3`r%n@KAmqNvxn zi9}9qX+g@zkvaX__cE;`$JE{bq*TdJ&uC+dOm}8-rjr4=!1s!;VdeKVaAVkOuVQ8F8Pj~zqe@L znlDiH45=I{|C6B;(6&IYSWAq88%ZsheQbq!z(&h!`q)GNP`_)jAH0%zs6D{V2Klcj zLVkkhfN%U7cSfG-gZMSk#?McWsks3)eXr)I-e)mIEM5pj1iR^U6sAgFH^v-9OAZx~smf z>Kc<#)m=SGo?%0z%gdXZs;`1kph^%oI+D@Ums#+2#~3gKY8itV)GcQIpM&aWZQKrl z8+SdVl@Yad`~<#=@*M-+Br)6prnrQp9SMzo2=E&$@Uft^bdAiQ3bCUkr~zQ#s0@W| z{2>V{1Sa$~gKW^<9{Mj;A@3ajw4ZAnYp2kkyrm95J{ESJL?+ZyK&06S98XGo@}~Q# znN^o~V+AuFD*XGtL5MJ2PmMR#NqrZ{Q+(fqe*eKE-evWwQWyG!-`|VO;`a)}M^UpB z+4(?$^%+Vp-x8}m8+8?dZ{-CFaciT^KZyms1(X%Z1*?uc6GLdgH?LVRRUv2Dt)>}r zuI2~i`Ql#eM?@I!7ll>G&a+*qi1!_s>fWH(%_Zc?@x`G&QJ^y4C%My*TGIZGWgr#q z$-kLY#?{xlU%*iY5Ze3dRA8 z-uamWFbe~e*ebY0RT_R^%cPl1|zUoVQ^iNSJ*h;h+csCeUg|N8VVJd*3j$BglQT7YhnVK#*1jnyO)bT&cV?T95(V2S<{C z{3J$&Q^4p!j;W*X(8V#}Ux3Etk`(}i0B|UuaNH5crO?Ti%^Q{b7l4*7zqzcMHtknBYTj@YeAp^ zD#iRj%J9usiwXHO>JVrFr({TZ0c5IP5NG!5E0CZvHTiUK5aXzz?nwr6C@0AT&=~FD z?I7ze4p-~{6MEvSKe{b?4p|4XvCvP`5sKv`hV zZVl)T(9GQ!t*d^I*`cnR9aT}& zf;i%#s`pXA>9`a9@@9fvj^Vd*9iNrhHa^$KcM`=u=7byDZFdKZ`ACl?Z`&T5Wr);B7W@fOTbW)cEA znI{I6#S2v6kbQ_4E^4iTqBvC>2qEiN$EByJXalIFtMpwgsx;$=9FOs;T&i}x47Z5O zrP3RV{0FW^3OC5F__jp!voXaFbBFmcWFiEXaD$;%1v>@1YvVED!*@bvKPlu_b zdUG-0gpsBqusK*VM~UScQ^;cHCeKJ>)twzi1rp493%hzM@1S#=zdfjVDug-Px+Xga zW`G_TdSU~{t}0VcbPm86Q!Awc&yImFKz212o#&;(QLNQe6wP%g!88ttfggizW+t%# zq$mWWAUUrAa7X~0Fa>A*9`>*ggZ|)P$!Qm^3XH;YpUiIiV2rWzw@69$8{8BaNh}F4 zKy;e?%uk&`LC#hb7-2yvuuy=TL{qRuN*b$cJ17AziKPWlN~S#oD~o_{e93eW8Z4iiXKsty8*m~Il$SXh- z2FMsz_(b#JUo_|EnRIMPm!AO$}xMJ4L){p4@9~C;{W3P51LuRgBc>@_vf88WF5!RH~tZE&-wc0HI zVz^RWejQJ$H9u28nW$;tzQ>;`0ByYa$i$7(bbRij#lnO7d+qnb#g-VGx9Nz)!)12W z0;AUi} zCEIAdDT@3nM!@*>-AmHTmPxXsu*gn7a~|lXRxq$R<^AvQvIiNEcxcR|>lU1*oz`h4UpzZ=_NzBOResB;GM-K2_B8tD$v&y&wU49vuze0rR z%V9(EFR_sT$wP|q?qEMZ-B$A5P_8r{01Gq|05ruW zF=_K<%)$nTRy@7S=t!_hD*0tLf03+%%DTj!x z=mmgV94$OJ6!vv`O-xPhXA*N2Zwu&SuQI0~Ob`c}o{I0>pB+FG z`z&##NeoC=<|0c#4AF*2ggd#wVYb*K~`2Q0{>TYbk0!rtt5Ap2$w zb3r1B_l=3;)!ixg{gUe&r}%|G_mRj*K_l=x7;M9Q7qKl7iKBW-2|PYZl)x4WJTutPzKstKO|~hg@r)S&nuc`t zkhi2Q@RH%-&Ta>wUNZ*}<`J;{s>8aEyfgvqy+D&0$v=tgHlGXd0C3tmt3E#CEp8w+ z^Zt~@AN9O??CL0A|Kn~t`wj{xX#7Peq?e9wQy4+=raj5K7X&9mZYwA}0wO`lI_~0H zLjh;5h0U=7N3$>Z3i@EK4bGuXMO~WRekBVSj>j0+3Oy>SYM5`H0*BZXuc_Gy7aGlF z2HjnmlWaV}&u?-z^Sg={df4s=`!!wprCR2-s2N-fH9p$yTUBCb(-enGSw>(yXRiYg zT$L;i@Ih5uV3}j%hgw;CE3Fo^G~d&@9k&dZ+iTJ!d6RD|**8xS)(R`$H@{7*L+osk z!kOGbOl*^4!TL$0!+M)M5@}7otNhhEZRz`;s|%3~>T1v#p_ORrzdhA;ZlGCt^&^b= zR=jyXp8HMNw8ra~-?6(~4?|wpF&_f!3^p2dXtWoHC+4cxpzeMAedNgI zRQj6FgW;p#)EqZD3gM&A`;1LYYYXiMiJwS8o7LDC4}Lj;-(b+nj!b%aPe zbhjSq7AkyX$4teoX{UvGAGi0eU|^fb`dA8=u*u3ShKmD5ajN!H)-l9)V^&{kL@5Xq zNAQl5stfF2x(A5jckXLtOO$y}nq33gFgbEn62KzSS74tIt6`3mY%-FYuLLy<)C&Xq zQ})QKaAF@7ZTNVlY7Gyy1$nBJfEabA!d)_!?Q8lU*Rh!UYLO_CZEf=CCKZ`pp^PmkECKp5H`oLE8o@scoK|S%?ZUiedy~DFN;np5hWB6k1(~EMG}43|n^N6kyRH05VL02Q;Ap^NLGI zP-wS7AVW;hgi%PkKedahG!!Mkvj`s*cJ4=m6(^?wLexisrY%~T9mzVz07H|VM}xj67t6M2LVX%oF``_FsRhqTE($n~IkN6d6{WyY zypScBO<*P$WgvPY{vfV|1AqsD2V44P0v&+x)`1-`s>9yov|-LFbt1liwt=tVAXHd+ zC?$nRJd0=~9}kPc!{OXH%pG|EE8saH0pP!sRQ?Mm|7=#^1m$DgvF_ga$$B~R`Hm6` z;I3aT63(~@Q0k>WMeMSUK*atEam{LVCj}#!ooTi6?(BMQi|<5w_qyu7e4n1eUzIJ} zd7-}Tq346@){GsT1EH>CVaA1+?wXNrNNwPNhL_)adDOXO`3X+Q*oltVAJCSSS8Fg6 zOc7vn1{j1D{V#Y}3f|*`8@YbG^^tuk3a{Yl5iq@zb8^b6_XTV?8~r9kyooYHwod?w3w2>1-$J=u+5V=530*Rm9~_DPNDRFnVD$ zmS*~<1G-${N)@f!eTv2FU6~9-2_4YeaEOJ~Zi+Jn@QQH0wOv#_#(&rk2<0FZ59@6S zU&kRX@tFIS9OOIn$2y5L!Lk~l|boVZ2-4E=UVm>jxejOY&B_w|4DtViQB-|_*pjC`F z$l;XiQ*Xz_4w6iHwRXvHN)c^c8h=}|?uY6`?HuCY^^J_Dn~7vlotTCmr-Fg53Fs)+ z(9Hp`?iSJzt=z~A{qaPe*^uydOCAQ22KjX)~B15^szeOsf5 zPui2p6sU*~xmmIr0xv$9$K(AH?Hn{~Bt5Bii=p4vdxI*!Mr8N~cs@zUWV&b-2p#-Y zyuPqrPgDbGXH+noVfdCMY}WWI2;dN~1qf%$_7Q0<`LTTgZ?3y-KWn03_2!INGn-)jFjmss#^^4fk@H#TW^9v zkJY1)hESuE%L~LmG~#+vrDxKvg^N=ri15=iM>Q{;v3G-sD6^@@3)-82)Ohs+sk##!1(_Z$CxzUDmwe@TjZ%sQj)fT)}n}&9&E`a#( z#pYv6m+J59(a;Xxc^>~G{K;Qu?6s}wh6TCagui&_P9q)O&{+*R^47cA9^88|$~q_U zk499VQl=%kxDO9t&| zs7;&c7@(fG+VBh<;s(=<$FvdO3kHu+sJG&M(oN!_IHb9^vp<7TE5~ck&`F9}GtlS^ z!lJgT{_Gj|wEPtSW9C;$#;?_dLp)|0iNz!?c?r8g3F+u&wgB*sdm2H+o-u9aE#-)X z0apNhkfDbw@NyB>jI+1`VVf9{zdaK`wP(l}&w;oEL|7^QgSdp@AhQ169(h12ka~SG_na4%#6vp0*&U|>II52IJl`}eF7Z@B z7todqwE3YbdEry}28k5QHv&CGEJvgug0WsVw16n)`jvAs9AXwLEiV8~zV(T~3R;@T z;LG-gAgs9Lg@$2E3@Y=4^*7yq7&CsPSiu0eqt{gJFQoWAzN#||$Bbef#0B-mc;ZvF z2L&e5N%ko;^@60i6@7_A>MR9t=mAPXOEU_`$cJ1>i}xwq2VF^vVo33$0w~l^{RlM{ zU)4#nrO*07qi~t?fP{WRBq;H|lp@lph>+NsBJKffA_u_X*Q8Ok1K&LygNU==Ud)vt zF};*Lx66bCMg`45AVSSOKn;MCa|3roH=t=))aC{+tgs}O<(=EY?iazzRsQ?}Q$2Pv z5QiVgK084{vY+Swlos?|P&8%}qRm>$?+ObTFv$!gSBwW}GT*QOlf)=&9|=JY+_t^G zXhE}E`A5Kn<>oDc15F%H-PTVS8ogwUK-+1d3R5=yJsp5yKM^4a3psfdgLx{V0lsoq z;;||5u$QDJu~z!Z)4ADs6wd46`uu8Z#ivf5rtI~K=@*Ai*S?3_2jhp!o6(voSuD|8 zP6t@So!i?^-fB-d_7!iBdCx^seI53NUuTnq%la>kTn;IBc~8nFrhAC_HApRrKDsOA zRw9&G`yV9q>rt7W_jyE3=o${*I5&7DjZL&a9MOw7Du`seRGXB{Ns#^_e)`DXO)#O!zV+OSVAJ3)XnV*X{0|lu;jVz#|yhUR=`;CzPWd}iQ$h6ZYwgHX7hp}C$JxSpZ8o*B5Fp}C$Jfb!KKhUfC_ zpwDM;CdOx;=W^ko_Gd08#^(W^Ye@s`Pi35y;B@{pAV?mN0eN}hh=>@Jj2>qPjX_tk#ztoP!Zxl%S|Fj>xY&R)&um1TKrL-fPA(k~1@MMn z+y6))Y-wz4^dBiy?9HtHBY}dxy|J|;P*D77I)FiitgUSv0jZguXALBVjkO~{18RGo zB!2!sv}Oj)*0a)os3-I{wYr&@o@VhMRqJL3k^T=M8M)|zU)8@A0A~i-`hNz=22_9N z0&02x_nP7?pqcoeL9%c#(Q^U+1^x~4&l~9fb}pIOf!g#;9RCIhYWq{nf0g%sx|RRW z<-LzI`$Nb$P+DfxH<91P3-jQJIMG3`ynN-!$Um13w!!53_*+k^NP#AxQRX=CA-Ak8SqKgIL+>`q?(w7c7arjC+ICJM6N=3pV1;&z%x}wazFytkp5QvcX4*+WSNT8o4`8l%bm`Z2Di1aQ6~W} zD!PuB{0~em^7~(jY-wSXpfz0$mF#ld7ISyLRV(Q#I2PurEHQYIu;k>#fJ@WCM3)vC z&vpKi)!ApragjCF7Gd-^YOd(nQvCW|vy1jeDr$1Kz3V}V(P{2!{Q9N-lvHE}`W%vh z(Jzz3j@%)iwD1mhOha2l6g~)I379y{u`La${FlX7oD^S;=##(7n;ZYNeE`{><=E+Zfp`H>*CB0iZ>!xk$>p`A6$C~M}}jreQX zcEndk@4X;7K`P7-$|)q5!aZ{Gh{YvuQD2Q=k`ehYMZL7`^ASHbUpY3BnvDJ?RtVJq zMY`d0dXPrEfhrCLlO;Tm(@Oqo)U3emupH3{#W9E>71m9t<6wEO-PwnzI;A5M32lgp-FS;mE?5Ch{>!d77&HQ;TPn5u<=4{g1}qovT)a+kgHJS?(Ao#Tk;^1M4+K@T&iW79hLSDXTj zt}S3~9y;com-+(b-exj;bI4q4v7uvbE7z&?{m_<6&W$D*J3Eziu`V13k2(~xM-Qw5 z30_UjQ*j3w7F?tY{CaaQA+D-|CV$a-rCVs#tc7 zfQtA+1vh;p$dEDGNPrg;;9~?%_YW=d$i9qPJy%Q)j z+M`kH*_|@wYn)UzZ<(WMI=73JZB<#IwPS$splCm?Ci+ERBZJ)Kd`h3$jKMQL#on8@ z^}6Qs#pdyX4)j2-lqfdym#pFF^B|p%xd^n^fdexka$iZ}dn11B-|`W1Q{K>}Ira9o zB78+dni`L;Fb7Wst#qkC8t0eM-~wzERdI7Xe#SFFS+R&o+GF6`?GQ6 z^Or^KTe6jxEwe;?YT-VR9=iTA)TJL!J>-I$dx0*N6mM4qZAuDZ6CnbH{^{*-*9XL} z-|dQrqTaJwSR@t49nJ`5#eXz+c75n$L64u4SNwSCR+^hQJls`)uq#V(T}hDsiZWj0 zt|3KcurumykQycpQbUW7TFWJ4#P~=N9(LfuMdc#vw`-wL-4WY%*sUxLC-89n7O$J`*W$v8j#&b(^@u~=|>21{g?e_GYld45u z^HNKES~a8o&_(kDL>Q` zGw&;jeocfO(%a61;%Qf)!hrM2C*`Dg60XcHYr>42$-XKzb-BP0`)cqstS!8WS>mtI zQD%@7Van{Wsh@)Hq7NyQrtaJ=@I-D3$K0h4d#`PCt9ydi%_#y3NVZy}QeC-zYddmH z+bk)z)7&Lpb>#0Pgkw99>_C3pBPl7q%@!x0+FNjxG#npd3EZtIupTiD$1p}Ph)amu za7b8fnIW02Z;eGZq1FhBLNb^NhWqpc^>CJJE5qYzHNLjilema=#5-m%Mo|cQCK;p;oq5RPT_4ETUW5 z8CxCm)hLviXd&5Q5RL8pk~w;NmZCs>mH$d^7#n`fCtvmi4`;pH=zTC&>f7_rZ5n7! zDs`(f5FIqQL@G$W7^q!^xs`&Fk}wNh{Nmt^SZwJ2j=sM&M|yV3!gv8A3uAlYP}Ig~i@vX)Tz1MY4GJKSG6XU>IH&4sHw>A1 zp3a+LC*CaH&z{q^V)BJrx)Of(w8u_)yg$A7WwFRbCJiO3JjwXI=Z%;;Io2e%JGKj9 z-Cuv$iBlgy?11Ubjj)p%$Wo2<`F4^uBxILzU%n@_FMC}`g(PGk-b1l#I-&N5#CGiu zxne)kkVm%;_!9)v@pH}}tQz{R`7+j)=jVgO6}gwlOM}0W;?EetUSQCGAx_kSH%JL~ z8vK5Ls;TVrqC_bvO7FpVkTc=Cw&Ii2d6ZeNG`y7h2 zNqW2dSu)C?@!4(l0{+_hsKX*`)e9=A2&%+fMl?j5Gx6vo*U>PInL6jG>^T3)I=rvn zlh>7%bI1baz@2m#qCCberX_B=uKoRUWmpFad+iXqKeEmd#uRYQo*%}(&UN&nf6Swm z8>i+m-D{v5nN+qbbnHpEOTDPt)arK^;AQY6Ys30AJ8qLXm2lnoBS=8wCs!6f$$i_I zP3bv~@5v+uuX+aU$8*?lot>R|Blj`buzCXzouBoe7nSh(p?BEB4-)MVyd1|%i*n5P zHu}d9kSOXK1&@mA3wCJoSl#`}6vPt>eJA0&ckephgw?-^@t=FkqH-!$gpiXwWE}%O zdSu+5^ixUFBZT$rP`?PF`a2smB4>C_p7a~-C6wE)Rq?LOffOA7uxxxt!ayG4kPD{j zD6ZwC#dX~;eb9Vb@V@b#gvLoSzJZC|0!roG0xA+1FY<7?;&JI%hC9DXDW~6)a8|2` zu~Cj8j(74&GDEQmcQQ6FGrX{qd8FnK?(_COvcJ5iUe5bX{uzEA*C(>)OUAk1fyK?r zSCl0IB!NeaO`wb) z$wJ$MYECG5N%LK7mv`D6p?5#>#~Ys+D}PI>`p*g2RwR6pEt;jda^M_3E=X%zYWH>f zeUSa{q#)ICwwA&m$CfI9w^d}eE0nSP(nBBoEND_kmc&LvQeC5sLPqP)Jz_=qby+CQ zSi6vd{nOg4D`PtO&qmcTy1a9JC*Vv!xMbdsdznXb$Dg6@GU+mtPUJ5i|RqJme;#;Q8m>e?b|C-ZC1QP4GPuzMHgJ{ zeyGr5d@GzuC$i22vZ}Wh(r2NiV~kz%_+l+^>1q8fEL;I^QZ(HR0~?rhe;6~Ak6UDG zH_}BTfPK5|`37E5fl3?TJK45O9V|5SQ)R}$Td)_qkkC<9I9I`5rS;dFBK6gPx}s@s z-Xn`*?CgfD_b%s^GpdIpcaE0B*zx#zg(sZ1GW(0GS+&$l-itphXkG(EjxP2>E_sd> zdfAs2%?YC5Jo&N2LL+a-y(BTw;X)?9cW#6IfOU->m{EMCv2EnlF|4?*J9){mtRmTC zCm!rJt7p6697WMvbSh&J@0ma&N$u?5PSwvfrAQv~oynH9gOkwf)m(!DWiA-(xhMpg z+vWwC*G7rH?70+orKMe}d8JODw8Ls=xLq#Uqqf0-QH#AUo0Yl@8M*JqL;$y?1V(>* zPdGCSlDpsbBS~<(NqnKz=OdKad8##yWIKsg+rWzaqfZ`&*ey)14Z)ORcHhqKS|q+# z7P#2Z>`u(7oxU`z_3vI4m40}Dq$C*)*j=Ge6p|&H@2gnh4!Ok8EA5);X0O{Gh($dx@lzvhU>> zc$^a7e0W?ly?;=%2mJfIYBihdJ$8g&{N7UUX2spi!(mfRro--K#??4G)mdWjdY;Xk z`SYjqdwZzRh~hJzFD@a_h!-)T)+!0Q?Kzc>k$BF`fNQqYIQM^gV=}3SxC#LZzp%cRvG3|or z0;krse(TR6Ln+KNLyE}@6JU?5S`(Cq$kG(!DlXaTKcM+@o*l}f5mLQgds7Be{mr&$ zm4;>U9`r~sKl?X^uN77*rLP+hB4rPG_9l*KEb-!wuR|pc=G`~=M4Hpf4%S+xCtmMm z`AyJdaylt37L!TaX0uDnJ$^=$^DOH?*USL>{Dnat^CeW|4@wHTxTH&u_t|WvSG6C% zUPabCR@Qj8=#?tg5Li3}Y8~KlFyUeDezO*sw&M4E<3F=sSGEvpL3hXO#F@9RvbTmz zVM1vsD{$r$sY8~n!EYkzxrS_(-or|zS=1Vw6G@{s?OqNb6)*9cr&+5UOcuHmE@8V) za_g*9RPRmGFF`uzXhu7$gSDys*e$DCVQjW+Wq5Bu6_D)RC*8Ga>%87^8~DBlUXlNP zNwYgu>XnwfVS&O5?6rx9m}B3|hn`-ekb)ac!tFTK#A*AGMV{csXECb(+foJLwSH3HEJX zB{P7f8Y&}Ag9mq%r8_!TGbX?YHFdwvR%u-U<23~I_WT@mqoJMc3+^I@sOao>E|Aj8 z*s;!4K63pc%v|W#`$>psw#47A+dpqb{iD!??XN!n|0N_72R#c1 z>%WC2Z2xd~;cuj5WoD;m19qSOd$hy!zwKE3D>Ql9>-YzuiAH#Xk&D&~;NBbTWAzr>Cyc$!D}SvyG_pm0zA@>D?6ZzV#(SYFY_5zsST&Azcwak>^b`lIVOq+ z9O+nbox1Xvq#J7uHp7~Ku}ki;M$%i}B5Kn1l(kFnZab9li8VE+ovTH?jUl@F&CgFd_I&UR)PIK%0>ze<5sN%8V(;_0y}3^Q=ic!a8(;`qT^L% z6CTl7?TXUSyGRqpGaG_?R+dCg;`_k(;mlHm^|;-exDy&KZJd z+Lj!?zD;Q5Gn zg6Ca}y3!1#cXIl{?E-a1K*X_)PsD?%x~|%fspAkH6j&K3bmY?adKFu?jjn>is;4Al8z0`*RQs+Q z3JpuX($O#Xo1!gzS6i`9t3Sq40q=JN7XZGj-8Y4;vaEu+x^swX4&$qjREv9N&}Rv6 z?vB-Ns$Y&#o=dHI=ru{4Q4y7F>ne3!tZJ^%jz8(G52qc?vYwM?*yEQ)6(K3U9Xj#2 zm+7FfjRl1iT&)tIxVs)!V}zOKmo-sD({C!r$^7M*qe{Q5+f;~JvImj|zvC>~?)0T= z0fs?OnbWtaf+$?EUM$kPLQagDLfTn|7%nU<4kW7hm#b`s=CgZ7Z_LALJ%^LwLPT3Q z>%3QO>E9R@){^{0@c*2*O@ssUbI4zVDV?M-VPTF)0`}Zp$e^7b3&Vf{%Q0OUe@Aly z{<;nI8_V0d-E)+V`Vg!60$*ni^jAK#fs~_iL^FvtJ?Y&vn|#_mr-CK3eV)fLZapJ6 zc=S(lE%P1mvtIx(*$47hEI4EBPugA58Yj|Tzng|faq3Z{Tx_;x( zg!U(e+KH$U8N@P)XK=@{rH zYQaV1z+AWSs8@*B{0EdUy=S1&6qWoHXZqGgcXnHiUc`qP% z)VjxRIdv#?FA|Fj{+)-;BWm6b&g&br#`Q1#y^E=o4dw*eatA$t}pJF5vr37(5-Bd{O4e>**$vuZeF0bW*&An=K^1s{MjL{xnnf zcTe#@Rc!_@BPde_XTtJIMc! z-FNnXxK;i)kSt7`^qj!%{l7oO|El@Fp5jjnu>asGuBBB@R)FfA@qX+hQNX=e<(sqy zzRltB=yR0Y{%`6bmC=X4f1_klQ|%@bn0So#)Mif|rsn%LDtW3hwxxG2Z-CDftr*_|L?aB;s^?xK%PoN)7g9z*jLMF8@$Lkr9Zh6^zyZT!vX zpg`+}cKy$@)C;X&NN4wGZ7b_L&9!G1W^XeNZUpF0KJqLr%L`b}oqe|3QkR)P)v_`WKhgB8tBLv)%PRIRcQS!Ut{ zxAP3#X8ew7{QMvj?whGE07^o3QXwX;+OV-z-igK7CSPlnsR=XAqj&sHq7~_H-d-btT~_b+F$g1bGyCFF3ZK@(r4MB|X1!E}?evqK zkE9nv5V=DO&fpA}8Ljm!JE(I!sE&Tk;!gM8&yfEV+T<&^FnxsZNC&!1M(aZ-6 z!9)W8Q3Drz3(g3JsjMU-2yKWOFGB`NuM&fEK`?;1is|?TF zD>3U>vypi!&Z!IO%UnDu;hn|ZB$(0yjER6gu9GUXF^B!RwR7Ri)R`Dt6?r9+FL;<= z)IJ7>tMRkJk6sFCh)_unEI3PR62!b!2t1V~ATC-npBK)Jko4WA6FrksDoFZ$hn1c1 zvIyB+Iy*d8QI{I`B$hqm6LJhnsr~@s9u#lO%H^!W-K7n!~d1GmqbDNISQA4e;Ub7^?zrIL_`J$x0jRdz5LA71VOO4_5Q~hYZ-aYT%8|X?mAUu zj^EF3j(V@~hiwoTa$z=;AJuFhNmoxi*#*amxsn5m$xs&A$YZ-4cFvz$sxQr3NR%z&1*wnvKwM(Y{S+GjAXL2guPF<|`X6jVw zarbipnk>{-jYnj+xf_B$k+yCL=lSwa)V#xYJHGbs*C_Rw6z_JF2(|;uH<-(RMAk9= zn!ey$pOG+b<|X(*6>tSdxZfPd;QkZIk}m6I5GJ$V2jeKT z@>Iy&RU*ds*3cV8;P2W6Uo1nTAW6?b{7mW6>+Pqh$I4>}!wZKRft0%?D|+GYw|0&L zeYeOIu~|&3yd4KM(2fA6_=y(>#hZG00RDs}g6}1vkv1oK7Df}+9$t8I+HR#V5juEd z-8P0QR_1LXN}1MKO0JZ#ws(OZUEX|dYRBoG9~&D#OI!fD*r|g?c2q67uLH5i=-mL5 z#d;ULwJ@P-Zo1e5GzX0_MJR-$wJ=GvzZPZ9+i@bxSFr?d;$j#>=sg~m?IX-sy;V-l zw1zhJ{O2wM6YU9RqFqzp@X1p$Lkn#|Z=N%#eA*7@dQCRP-OK>; zn#j}(&6C~{#$9uKV|Mci*R}dJJ*b_MO>t&^TXg*|SMD?%?mi<_RLS#MWm*TVj9B)5 ze!KQobHo9VeP4;_d=9~X%#h{=jm_9DWr~<%FYnL3C>c%tYO#?DI|zfqld(PMD=r1G z+C^yO%Qans>9IPXng2zk7KhESygAfpFVFZ$?dtEGw%|mzK)#*5+gGsuXQ>>muC`XLP z?RB|1vK~@#n*Kt2z1kpAupdUr>M-WYBx4yK*a0u22GuwMuZj2~WZL3358aiDZYo7H z(@~{tPq>K$KctXx^3+>2ItXc*;JcJ_cp44omgZ~GOij<(U47tnekK+DdL)VF74UF2 zB1Hx845F{g)d+tyP-#z;fJf*et*Ko*9L_Mi2&asv<6?_^Ia8&={OR~1r>CGXApnse z;G{zfwX5!wXv9{`n)y-#Gph_y_Z}J6O9iZEx~l@gW7$dQLYR~Kv){NX+hQRlM#u}j z$sZh?S}mGE@GbbIB(^vh?#TYRNUlevuXYlV6fK1A_KB(rkK1Y7G48m#J{ONoT0x_T zu0O1fxX}JKM685o(euQhAhv|CU9S@_hj)09N#88eHEU<9nkKxU@SN?#^>HY@ ztwks9%-E!6;xOj1qR3A;4laf2$N;Cy&x@PkGoecj52cr2`0vZ0cWC?exVqmrxvXh< zj2cBLD(&TG6Z-y;Ak%?gEuL%6H$!22F}b9v@?a1Z!~*8{YC=b#5!n-Ck;#Mz6Z^X= ziEAV{82|FX(TzS5zo-U=*hNQ6<|oIcb*juZkBddy1n=Lde&#_sZG6k-PI~MkICbi> z5ySf07x8a1;5T-9k0*wy$-j)bgWoE?b7AEaDn=zNX!b8X9nqN3J|*9cw0v)e$6e${ zIyUw>MVaeeK1#E!M_K!;IWZ~G-(YBkwqsen3o71B*0?p zsf>$3Vqicr_zGzwDZmW(1->Ki-j}BP%z0Y->y&=Kzy-~VWU76G0$kpP`8qD6)1w=?kFGnB9ZYe&!)|BA7s`eQvh$ln!FKh&9@Yb1wK!i-hf?Zs z@bC0BR-Fz47D!W6?tX{n&_!Hil8QufRTF(xk`cGWumAEf9TSxW9j`?mC+oc~YS%lB z@%KNw>01w9xCTGglsV9p`TzLsp6IhhVnRi{rBrJ@;O_8^I&IJhPkD($ErRpouq59U zpD}`YSIR){CXp?1?ki~HR188|+rkjt1^TfhM+=7x?$T0}t9OV0@`m9j9h(lY}2^URE#^o+of02U^8dPX1* zUk8ps1Rw(~&oY88gl+7NjP3v0B1H5osuCQ7BoTuY++P-onVyaq{2|T1bZ`KaFtjl; zrZ=^*F|{(J9QdF0;-Ckz;fa_zS?Sq9dT{~4AdolB z%mv&W|5UI4IwA2ldi`~6`CobgYB|_h{zvQlvDomJq@Mq*1t&cha9{%1VF2>`0WFxB z>6t-Vad6Nx|6?tlBmckA;;+B0ziQ#4Z)@ggM*n;U!34O~jOne79sk}ge~qR8(f!6s z&kQ7%GqbYMbAmJiG-Cvgb}+L6_WH*ffdv2C`|Yng6MsbZPnlFo|L4el32!ihtnO&} zy`lgk^A(Mhpk8JH;Y&{~*B68c8SAe8-|_Uk`cDE?f@z9EmU7b1W`&#;7IfYO=Ta$o zV%#4H$@_eizeG(_W6B58*^u7DYs-79IWYh7jnupIboJ%}-q&-HJA8S55YmBLUL8R# zZu{k>F>!9J315q6lJ^~+50b0ci~3d5j!|@Pf-`qrJzILl#*vjr-WJb~_09PFM{~it zzTtd4-o0{4ES#I)O|6A1yJQO&QB(tGY7}l@{5znQ4!~)(aX*jYYqe$!nD15&yEa#A z_55H-&XH|D8hof3>SfCRk=wvJl6u$R)BLJsB+p};_QGAKM{D8-@+XN$-JcxIFY`5i z4pe8I<_*5m$tuEj?RjV(|6n%Zx-GE5Bu0;@>!t0ix=1>nE(#gG!8cIN06(hHy5khd zj9ixGqH{asnepm2b-HCDQ4UP?nNw%HX0=7Mc zs}W4xAgswCkwo)|P_U%8Vs`2WUcw%tr4oZC7`2kVtXsduI|pyuo78RtK9!lk&wT0~ z6mFX$J4j*LiOcw^F+6u^ee{C6nfFLqT4NOU@qEy?mcyH;<<|it?TIYZzQxN|c{wG5 z^+uWM^sJ;pFFL3p(xkT^Eq{EHtGEammn2Ptd`JrziCHDL3vu*( zscCF-!zu0HhMlC38jKK}VlCIHMg3KRN1rc-s<&pB3xc#UOx<~reh?OJT+7l}JD4nX zT|A_RRx??0F=F4>var(+k0Z{G2RpJJ8j=JJEp8hEK_qtPXHOENJ4U2tk3?d*R0qHsv^y{h4>R+T(kdwzztxs4V zcVc-gM#Yc5RzzEGAWc`;;Oxyw(Z7fuU9^kO#e6UejE?ARAG58X0@HbwN6LeGhLhkU z9;r0btC)#Hz6gi96bz$fH4J-48zNzpu&8x(k=`RSW?d-ip_3%G%Fvr*qUYvn{j_=Q zc|999l~E?$>bP&+!tJWm^9xMomEeG^Vaz1slaYPecMUaQ2?&9K3!mF$l4 zU5VX}Fy8gSkZU6;tPLRyps)s zIETQ_8VTcUt$&R3r!)Y=h#rk%m_T3J`b|Z_G(bN=oBI+&!FteViwncCP4@Q?Z~Nua zT0w^0A%os#_;-wHgrvG2luFN+&2_&IsJ4w zSOm6mn6KnugC)IZPjDTgac8AozEaF}34(e@QFLy%(Zcq>xO=B4Tf%KyGi}?(N@uRL zZQHhOuC#62w!PA}ZQH2ad!Mt z6U{=l)0As^!m=ms&5Ve;ZKq9w_-pkW+N&<{do&Biv|6amg{{H#u>3Ru0=WTsef$Pc zkF~*;^;;g_eRsS@)>m#RHTlQSCT6daZy&nCfR1KNlRQH(9a;3=UwUuEQ zgYE!P>V;y8E@X5qL6So2vge2XUO&=o>Xz|E+-S*1Fak=59`~ zM*6w|(`XLs?sx}xb0iSBj^(-hvCqG{(-Ot&&?3vrvQOugTK`I`>WGFjei~J0E*!j6 zY#JZG#A%dAU2GOXJjtGHDfvqv3V9+d%)7g;m%R)DCrivQVk73byP$m3MLBS7+wh78 z=QFtY=LwDU=W;Ja+Y+P~R!oa5T$pjg;qbToeWkTp{_847bPZjg^i4Cpp#qkB3?Yn! zVrs1F@TDmHDSS4U3E9Li4#<0M(w_+}h{ksaNyCa_*aaa=Jy|nKCApopl4L5m8##n% z>VtvqTuo@(2Rz%f01!iw(POdr&nk)IU6VUldAl+!(RZuIEW^&+I@TTXQT6w6o@gxa z1&HS}_G}Nh-Dl#}kqxG1vPRYX!$X#-4ji2NUgzpl-q0sYz~Uvwnp>6Qtyi~KWBt@H>(`?4pPJU!5n ze}ET5tbaxo?&wUKyUGn-}PJc0NzVD+qWxOm319dfZEZ-SVQDWQ~K8 zGlqAFJ?!yUZeUw3OigqmM3P9M5C3mT8Gti&B!ze(>Zk=B04&H~dx@f8J`|6T z-(S!~$-R)*EW8nR#gYzHze`-H|_W$D6|1$Lc zll1;YKL4La^ZzvT{)ZF%e=_v`he`au=<`Q~^IyvS|AmU@Uw-ocnXG@f^B@1}{~3c> z|Hq2{|J{81L)PJ^aQ^E#_>Ork+9?xMOe-Y0eE6OdT;hvcEgORGVegNf1ZgR5 zO>Y=VIVAM*>R9aki|$k%HV54L_K89q&Q0<4dpr0W=PM-q^Jhg_u{UG60$JbU-ET2r z?mK)7tsEZM@1c}-hoh8xMUU42YV7(vdi>PQG$%CF4Cj}@3{v)8_qn^ND~ZX}D~WGF zu`}u$?S!=yh*zlu+O6Z60hO%~IIbbH+5MT2(fvg6Y#|-yq-m@h0VJ(4ZT9wf)vX)6 z&~E`ecl9;EIn=w81-iR|pCQZBV|&h&I+_OoB0RwRD6nI!{HO@;6IqA+M>65`EK`KF z>CiCqgGD=*&)8%l#0@BEU;=1ce!gJ~ZLiw)^XorDsqjTJ2_Fh<86=kH#%JHQOuDhF z;N+H2T$iSI!*3ymkpS6+obwLtI+J6tLPZEO+^M;BPqOrxK1t{JFqezJ?6^>Wf^eo; z63tA}?$BrgAtyaEs1r|QdvFw%{H{Yvw&87r=9Saijj$r!eW0Z)q#6ngy`o>}A+4Kf zm;yndbAr2h*`N(iezx%w>=vQdiRL~qCWAxo-;VP@a^Wv&y5bnke|s*u+t;z-?EA%XBAeqTrRE;ph&CA>7|W}sLrxF9|z)$3j` zHYfhg8yQCXGg^c82L?;F(d*V&98yw=2v3q5^iT5g%ss%vxTOx(v=H%EBhHlM#gsA4 zEk~D^O^W64(7t!c+su&BgVlkHIZR&5m=fBvmUy?oJ#`Qb`a*ZPNE{P8Yv(iH*uu@M zl(Ao)xXw7W=hSJ%A{x8yA&9uNCz+M-w0kQR^0B~P=K^6jWMq?z*kzrrD3`w@*{aS- zu7)71@z8JNIIQ3a`N{kd#`4gibYX`l9OZ4HnfeXZT(@~)9?ZSn5m?S>TN1GQ zl6Cs}9+u26k1A&?wF;(XFp-z?S%FI+Mr674kj$9N4dMh=bZQ-!TCJe+gY|suiG^1>_hA?p?x?FN7UPEF6|Ul_WQkO!+}|!` z2L8|T!}IZ_TQW&{oXQ$A&#nYnGyrO*7wiDF!kEv!xq&<+^cX=+l{RkP1%8z_Pm|dy z#>f*eDaP#y)D0n^F6Qwm#SET~wi0rA&%gQ?7cGzc*r1PESuLvue2Eq1d+c|}{CRMX zcIqeQ#i}wzb3@H48WaIYTm+f4l`HYa@1$*~bVz_*XW&8d@>LqC3|D~M$$m8D$N6LH z)^zs1jMj$Gz0oe_9wZ7UD`@UTG{KvOP}Zcx6m*T;kcLV;V1ni_JaNskCmD}0nv!eG zWpDbof45AvRz)D?PZ#B$Euy&vvm`hNRW|K-oCd6u+2Di6XPw)4wd5*xlS5a!RLORV zp8Ya(Ax?Y1J|(>xVMj_x`tM5)Dt@M9=TjiMo)m35@^41;Ha}ZNXmVzVtkP!V6Kz$w zu{6f2zI8gd)LA>_v^_1s85~Kx1f%I>47NTB3gmR%txZ;&!n!Lm{t9m2>gdmb=T#aR z+$!=AS{6iH))4~t_D||&XMwS108#lFY)OIXlbH;=A30{@WRD`YH+51@b^_+7YNx?( zqls^X%y7bZU4G|5JSU={M1`zenDVOljz@;M{a#rNt2IE`MlAyxcY(5G!3H!)Qx0t6 zZxkJQ2N7`ma$}t4Jc<%*-HVjGY!t8Mz4i2%GaV-fpww9V(Bu9^7AQZwfOq99zoZ(sh|Tk7vNH^2Y)LEJ6ZMRm3J&3!Kqj+P-!(5kX@IRE^Hf9I+sDw-g?Tu0< zb4Y4mQD*GVELXM0p<%%O0RbHTGVv|Kt>IWPL$x4DA#nF(9v`Y4J8Hl@v{_l$NMqTg zepjLZJh!mL2$khcV|C%X{cGm(w_!^++qq~6gh&Mixdhm+l@x1ZONwX>=da``IY?0_ zm1=s(OeZ^2>C7I-h|Lsp&!IBVd^jt~Q!?h1w*>-w9T#{b7sqg{Fb4^XF(Pr6En5zG zH)B$&O^_&|{FRM`kAfAH2o^A&7<#k_X|oD8){ z!h1^2b>PiV(;4eA^P-6&ssg3h#4tkM5`QlOF><|TQPPi#21G+Qeghm&%Uf zh+vi2T%L)qNs9mF2{Q|AeKYjV%AkRN5!+(^EznOot{~LM!ZR`C(o`2T1|6^9sKkMTE zAEC`Zf9yXamj26*{U1?R|AjUTKXv(kvduq$PDbDQCyhzmn(-eW{>3F~vIZ7EO|^fV z_;=m?FD(2yBVuml^pCz7orsmbld+KTKl)z;bV7nk|2q6rZ=c4$M~qZy+9JE zsH!M}<>mqbxWwT14)FL1%?>Y-0{8*(fdc>t#KbH?F5vX(!HfI&xZ3hqa>hn+=g^Eq zZEvpy=*G(W;SLpgQcw_*P!NsY zSPhc@8pl7?JH{?3Dt)m!#t>s3`D&)*hXA@sx|To-`UxcYIf ztmQ0kW*pLm`s)2!^IZ2}clXQUyOQ#as%2~nV(W&+&USGXi z?^x?t?Fi_?|0EmvuDOdDUvTu;hj{ubS^HjE)bSnvAeV+0MZh??gt&Xzw){%?Z29V; zEO+;_7RI~$I-K!6HGG0E zs9Ms4MtEv*`6Uv(nzKB$)wec`Ix+EWi}mqcPBi(Q1NhzF@>t&j7SQ?i*RQ+l*q7xd zr}iuBopq^)@*5P)1*l`~TQ~FEcSrnZ&MRzJ)%FVZif7xW?){i=7|mymeTve{umvh# z%yBPT<NkFG zpUyXG>z}R)hLQ2Zo*l|Ibpn}4} zq5`Ah!UDq{%Y%WU!t(ilC87u-lv++o1)ox&JoyK4iNjaqZi%GkFGo07aBK1V1~WG? zwB2OIz2F-Kgl;x;o3AJ4%j(5{gMR5F`o#p_v9U5C`QhwvnZeTH<+S5n5K9t@d7m_c zg51y*mpY}M7fTlF(PPNXNL*4(@KehP3u@U6TJ)8n_v-n@J)K z-t;G)`7|p&&nDcAn}e;4Be_%1ga)=`x3#sd^fs!!5FWrM5DNX6g+otYt%hA zCO@f5L&el3e2A~x;WB@kt1!x~>=6J12HF+!H`Pz_LVB3?JkPIyHdJS%KwRk*3&C4- zL1l|Y?oCM+|!rm5)HB&=;c`w{LOpAQ!Ms5J1Wp4rA8$7WQaH-A!CHMP{6 z!MrAz29r{O-O*@7C*z33dZJo~^fNz)>ewE7VV#kbs&6uWflFF_q+qt6|J;NO!WvhN z_@a8a#mzNxn_Uy4D0d>ofkWV^BnqEf^?RP_MhoWKg5mmB~%5 zfL@d(nv>-6Nhy4dI|rQA)1!?fX&;zvskg2~L;_Tz!DDnFPfVRKH_46mx0J`O5B5!j z-pUf4+)s(Ai>2jN^ilQkcLY@;o?C~jJVY^8a09O|a-SLJ;sOR$Y&n#D zhaKuruX~BPWe@IZ0Y(6{jxSIl1&%#*Fc^g`Aj<@HjtOAq-DrQhrWixZl&4{ZlL-!t zC8kf=c`GhYvRZ-*N})-@MsR=GRoU=v1l=<H_gl&A4=g3eaWz)LiP zQUB8cZYw?Q1f?z+*=6)}ikt5g{v&lK0b$MZE%Hj8pZ2X7O52&Yi>4WEyM1Dxa|~JX^>Od0YpAMJvhfMxsT_TR=sJs=LTX4l~F5NQaC4}PG+LEmE#|8rh|iP6?NzI(`CkpwHEh!yF* z_O#R7RGE{~M-!V?FKL1ZVhH`RDCUo`XtjjhtpreX?Po;3&@HcV%%2kma@RYaJ)MMJPc%au*Mr9C|4cZ&5m1d zCaKwzjT$H^OQwX9c2LFu;hEin66g&wJq_HOaaPA;dCWmuYT zj(EuidmDHN$PsT(1TQ8mJc*g^#(e%PxGKcHBc!Bjt2|AzYUxVk1Mp0z6u(_HXsWlV zU}J1H9C@V&;$EeRV$!l?&s8)oCD?Vb%j%6@$6>Go#B07{eKUYfsuu$_q|mp;^5N;e zH7aDPO0=B^nBOYB!NoG`##c=pG%&)sYlvwS_+f@T5Y5mieRcF18f5V)LaziN8F^@p zr7@(aEjfaM5UH{C(2JW++D@B=40_!HWZ;$D!8xhm0*XzYLEOn@$N$c$ZL}1?ZO8(O zzk{@w$s1TL8s4V{Y%iiMJwVKuM~<7qX7!$k^Nau!r)Q%NHSs%Mfzcm>K_!p9C^D5W zRzLFvffU1(UrD8nEoG`ts>`IUJ?*`CB;>Z%wX7S|zV^kON|(HAwdnX8aFQvym~ozn zha#0^rjXPtv&q>e?trYcC@ug@u%6rF~KkuTEeiGq=|G-l6=SN%X7wx za;q}WGS?=~CKj$J*O?|zrJj9V98i@sMTiO;y~*E)FKItlD2_IbIHu1px5#(tf}!G^ z=HAo3jx3;9aFe+PeH)fALI_^@xc|qwCir=zGU`j)_a};&XJ3jy&g949jcMRLs~_9rjvI+rm{nRMt_? z5ilYyg6}li@uSC-DA}aZezsMd#VEtb=dnxCaCNqF6Uh+35F#ztAZO+pi8N(jTn{~K z2F=*08LmRU=|mipG1_DQYTt3iy|qW{h<6!Kx2jGAlBGeAlYU)8csTm;l4+-&b}|4) zU5P&YfR)RHFJGj8k3VxYqK)z0so)D5Y*Xm4I!=W_ZJP~q8k}rBz@|sghC=-8+A%Se zDas|<6r?6mojE}>_r@fq^4q)jqVR7o8pNTMCEjj`h`K=bibRyfNtcYOr z<0E=^j=KoKmxI+NGs1s08cnev!>v1A4F~YVW_}Y_z~7z+FrbeUYP!SY(Gp8;0}wVC zytBcAS#M*ZK$F8_x)yHs50bs97k$6Wdo9WGJQ#>agmG2cGyrp0apEy|25{K~TZvTr z&!Q)}WEKi4AmRl{M%B_$oHAg^leA^D(RdI*&|3Ct+-5Dc$Ww?E);$cfR&I@*OS@F^ z!|@7gg&QKmRwH0b3(hpS5P=|gY&Y!+YukM7TVG{E$FZ^5s-)~}R_rxjInRgla@q!8 zqhOV8fFY=>WtBa z)Cm{Ui~IzukSv}y@9u+5zX8_=t1PKXtEF)GsKNte8=bjZZh|Io1IM&9tKSM<0Cw9L zOwZCz@@!Wgq(w)PvK(O{6x-L6-M;OIWiL%{d?YiJtS{k;;NB5AXIkUqnk7Ga%vbt~2$1ZfUtUP?|N0UEFo{BB8WE+h~DF)*QvQQ49_ZX;@x0fHQMuAflv)ajUKXJB)*uwj={a} zfS=xO;hF}zFQp;~-<`>VZ9@s!CEFBp;@zi7Jhw$pKWTmTS=i5}jI$$r4z{D;-$Xzn zR_9(&P&Ka3qd7CtrnE>41V!Y5NbnhX>zmDFbJ^mx170N&Hd>&u7H*P&xi)&A{Z+^q zDQ@e=OXom4G{VT-fFd)`-7gG@SOsF_pde2{t+5k0sb|eY7AX=>^Bb=s>yL^%G$^B? z#cEJmhyca4{;lBANqWK#6J_+_s661ky^3^81al8#452uyFyRWLs_?qj5Cob^)r7X` zWR1w@NXw}QF!WBd;L*IW`v*jh`0`)`=mJ^WRmFJ;h~b5r?hGX=GO}f9Ej0D6%pX*6 zKH`{p+0+gens@36+g-fhai!#>{kViZ*%ACt52#`%J!zO-$h!c$aia#kCKv2YXg83q zCKJu}*qGn@k4CO`tO{cz3lC zgFW3WcWwgiQL>7SEvWQLB4Czm$$)gsw&yL6)mDpT&*ZJXJmw zS=E3WbkW=wV_|eNI?LNATfquF!!cb%+YL9&K%Ql^l|F=qtU6Al>CibdW{isk^(PzG z{vm0T%Iilk>t#eup;RfSY*FW5PFOZjjg$FxhG4PrCEQ(YJyMWAl&5&@Dc49$qc+?@&?P2{_vy<4Nn%!GBIrSX@zuwDmw2rPuPcAdUtCv+?2Ou z(U?cr5?$ajejRyTVneUWhztd6(sw;(OQYR-{>3%ely%yyBP$)S%1&CbZ0KU*$wziZ zd2ciI7L}5DVH(3?23>0~ckWROj2?Sp-$obqQ`}5H0h9Mv_w&ElOHXzvXhu+>sQp478OEBu_82L{G5coDoCY6&wLb6M`pf}V zsFE>Ujn~zuy$2y-*m$5b+1_Xb)s|^-Y0Na!zi;k_On~xUi<*W+fNdFxIr2~~Wlv9$ zAQ;f&$Vyj~u}dWi#+v@Lu68*;ul;@qKvUea6J$p2oLsY^sr~@}%$E+EEItz`)XwNG zEB3-D-cl(lw@$VPoJA6O9q-2J7t61OUbdZl0PHL(AA{*$zHt=VqrR#4KCi{O?dSyrI_cf>9O|b7YaOzus4w?i<~E?)m#rgWsnH>W#`B!Rra>)|#;etO z>jm!otTn@R`jJ?l*Y1<+&Ad-B-n$yxn-Rm6iut+q> z9*24=F|!A_u3ak$H^6=|ar5<)6swXg`;|MuXQLHfrDe&iOMioaO}q9q7FSfZ-w0C$ zZO@La(F4ABx0M_LLanBSdGkwtxe)(!B~14mVv#|hiQ5GQE#LuodphVH*P#_|5vWOu z!0XlIWri6SF1^#zjy;tBE>p|@_RwfV2|+&v;!t>txk`a4($n-x$}BsRvI0@v-Hml) z&^%3{?3 z6H4{`L4ZQ@fSFs}7gMQ)HSA7;2c?QxfG`NlF>TxPcgD=aD@z~YY`gmTf%lQ2G$(q1 z9ZY%_@s*N|P=r41r+?tSVB_S7woTJxlpM0~2*VN@BR)W*O*O{iRL!Ko>kIj$z#kaq z$@!aN!rWc>Nlh50hRgf@mm5X^-j7JFY`yJUb@R9EJF3b`pqA#TZDHxdR%xxgEO3u3 zxtGI2sl$e6x<2D+ftc}87PeAHA1aFKYAlDGNpEskL|Yq@t7s6iR8od-3m}1Mmji}V z=EplDk2~65Kt$vU42!o^TqzSfEU;){8*pGJgZWvu-El2+B#A;m@%ggzssdVVEJfjJ z-612iOGx!-f@~EKNZCaS%|ZiMJYDy23is6CikPv=xJ|X&1Y(*5ONC`2HcGbm=u~s; z4%R{^!?+A=;W#gP8d0n!^}vl1Yn=!7e3%ij3+078rP-LxO*Jube201)92-HEXq}MR z;$qkbZHolTX-EPE+ns9+mFFH5SLk_VxB(B`soJb>c$-iR=C)!2SL_P!i~Q@vGa{E18dJ{DvzT>sNEx9lMKx{W!%0r$S>d&?vLF1fC58`aY@v z@72ScoIyy;G7g*d){MLraa#9}dml)&x+$SmM|HZDubW~!U5lYj>`yt(;0 z4NW!Dflmq%#&%&#DPnt|lsN&xS%+&WY~z z12(7$s5bo#gzvTj*K?XY{PpBxlS?4J#5Ym2H)!789EVaW8tYB@GRju1AbmJbJAbZv-@@v zSWpjDa>8t#zpM`J+rR+e{feG!;qWSFL&M#?S+FGbXc-{O>bvX!**&Dj9E-tKrMmRS z-LfPb+M_rwky)XYI?267B$6`icm+ME#+oeHX3}DhKAn2TYEQyQgq5<0asoWJcVG41 zRK-jdwP$DNLswd`-)jJM4aHxbvW1Bjf3RSynPHF0ORi&@)|G_@$kPE8m)lwBzG z=AJsxpR#Wm3~+^$ThpcU;XpG$f5YJ;Q;?jolnvUpUP7YS^S_S1pPAaG%H3}s#s|2y(3wFN$UnSC5U@OifzIK&$%tHMn`wWL>E<4wcTx(G=68+S39 zM%D470Z9cAZfwel0hYwGv__$g{NdOZ)wz1=Ts(MEoBdY}lNf)DtIj5up%^YXUDgsn z2dOFyL&}Np4Ys1QEB%=%)_N0NkXjd;rdbbkXQpP-6>5)Tllj>hdet=?9RyhLD(6p{ zHP-V1F3lMSv2ELs!Gx;&qCX;XUX;ChHq}<6XnC!rDz3Q_J6B?`5QD}#z(D zKA=j+fPq6<3QoMD%f~kDY0md8 z{#Ccdi4WZ&3;P9Q0Dgo}tcz*iMu-}|=!hX?f~|U$E0p(^s?(9Y-SlRQp8+)CSYKaq z>QDN~(481~j$hfG*y?fE@Ogn0r2*mNy?lsUp|Ry_=iB9dN+~h;;45ee*x{%^BwXx22lmct(L@AglpA$>%E4>see()fj2={j`Jk`_$ z6hdUbveF683B_Is`jDalv@_(a(E0|7;;|wC{Y?d+$+=|YyxLtCWnQa(OD8(f%wh+IT!u2k`QmZ&&=^{sHpW)%{D-Ke)-^ zBcnLBvi0!|vjk1*r@SMJqi)8NZ?mPg6pX!VuxdXK%a8ay9@TlyHV3tFJ=n2?!GmtIBCZD$VO4$NlzYf=sK+s}H zOC!x8rzMb(>i7F~eI)K05hYKy8H z$1#VaVwg9GlMPfEwatu1Z)Gn~YZnKx?yWWCmkHJ7WKZiVcXq%)zQnOCUD_oHzTp?s zp9M5DT(p?03WOV0_7-`+2!cHma#}6uDqNHgoC58*Vk{jI5GFJjVrmhRb<- zu%GA-*4jQ@x|bSET*B|2<~hvCbaF#)L0j(4cK)1%vOdzWIEF-l_fB#i604^vjWDTP za>#LdcpBPC**Ea?A0ZDxg*{?Ft=8D~On2WN2-#=FA}iiw5Sn#PC36Tasl^q7_rxF& z0BxdEp7rQ>0-S(NVH4deEvnH4wJQA%{kvc!suqpaAF$cAt>nJc(kPy{Sdrbd!F2mF z*bo|)RzXJ9uE4Z5T7|K8)W9cdFh8Y^G*yBLj9Mp^zdqq&^rzkdCtFok$G3j#x3|fF zVQgb9aSXzD>}tY>oXv_F4b7=em!tXvkGNFYG2qM=G=nEOCe&)B)LrHl+t6TzKxd~a z0hlW%fo+=%9Xy_7a&qI*F2p1n-`~eVA1)Jvjq*Z4r2M4OGU`e@?{N`hBflW#`{9q( zvpFhjM?uB(rK|wBS~;uAr2Zm(iH~7dGb49=U-s z(Z_|d%lZgcg~@m_V#UCBI?JK0ap|X40z~7`#ipYd@a*6_QEmJtVKh*0914)2^abs6 z+B((63?`os+$GT;O`Pl0U7XY=%w%fbDyf<-B9uu}Sb z&lgec@y!t{i5%VlT66z!0VEpx*Hj)5Le&Xfw;;bBm|VgWEZhGP@+ej#SK$;9<_~jo zI?95hv@-UoC6(UlMdOM{%1r65r9G={Qxwcb{Y8uWxAIEwX$@bE>CLtl;yJ$EZg0#+ zbkIxJ>|}1aZvIX-%x3agFRc$X#|Ct=VhxT;OKQ8>{n4mhEi^;F-RB%m2q}}BO_DSw zako^-q7o)0MR+2GK2$mc?fPUcJIPs=y#GMnZMx&YJ*G>in4}7F2VI z1S>~>pf@OO9XhHRLKZP>l?V_wWn6X<_v56ZS}->Gsl-7wTZC~6q2wzZ4sOg82@yS( z9WAAzS5c2_^w6b&3rC?jOo;Zp4==#g%XNbNvNq4QZ-2lE=)&kH z_t$HN|9I|4&m$BEM-tQGwpm4PUZRgG4k@I#MD1YhhmU9n#qpeJ$sj44lk42j-w;u4 zK5)pOEXAOXq4FN!<^3dd3huIl(>g3o>Ig`80JZR^p1aAS=1NG1+kWEg45pBR$5Q!G zyULyx>a&2q0I@;WCx^D|VyXQb<2!T*fSzv=eK+*|m(mA?EH@bT^2x(_;a zQ#d%xcgM+AnRDPe57^9AcdM#uw)6aEVD5wS5aX!F)MQpdAx2!=>1AG)5>T-%w>dw0OCihq zQMQvyE~on!ril?^O%c(uJd5f=v+sqb!tLAqTE_c5_X05X2_O|rW9I#En*U0&ld$C* zKZpUrq5XLrMBsIPcU7!hNM`Yzc^X`F$RSlO*oXn7;K|Zj%*vghB|={j2?CiZj($Wa;H&q$%{B%@Xep zX^-*!ERJhqmtdmONor9AE;fQAQW#J@rOCzxInVFt#^sX3cnU_ls^MsCt?U?67U&y% zTO@Q+h$2*!oI6ByZ3DAH%)-L_&BGb8p}H!zKLJ`*UUo}SM`)1P=4zXS7QgITM0^7i zZ5@>`*Byx&#;$%ebr%#TtfmWn23+GGMa{)or<@o4BX2TJf&f^V5<2bqBI13%$x=GA z#CDWcrcM3+4NYP}0W@Aa3@FuVCabQQVdKev zH^(o*dy5t~k;8TN{W@6pV)T9P0b2bt$*>GZRZo&WT6C15QWHlDC3Z!nC`wRXO~&7V z>`{+Ex0>4GPW}o;w_WuHK8;ft5%fAh8*xH|Vlr~E{;hh)GgE=%{C4XVA`w@Dqky#8 zJj-`?byNJH9npT;>?AgGe|6viyW9J!D>dSuXeIO8&aQvZ^xe7J9*}_W6=0w5riehO7W*E8*NR$yNW!jM$b?qyER-%Ta2@Pkk5Gj5M!38}zfu92&xEx1MG!@441WWjdahAdjK1W2^W$w`Go$#+XUUT48p_GZ(D} zECp+s=ZJNMDXAzGuk%?}7q*=BBft58zo6W2$Ac8VtxqRyM3Pl|w&7dbZfYbU9SkR7 zrpq{CY2jUTa};lM-$jHNl6d7VP zm;8Hvc9cD{v}6SL<>%#H0zCM=9!;A}%69I-P8vCAT`MwW#Xh5NI?xL{W02aX78bFl z+)hu9Y?thEx`Z2Lgupw1+N>unpeA1_vT?+AaZ|Ok8(@6+8ioMrHPd7Wm>qwAqHV-O z7Nj)G#jMpV;}>-$?)k8|?=8|sqK9YUjuXqKzQ5O5fJ4Z-EJcal!_oQiSmB2e;+ zdw0?r<4W*xQ6;o(ddauL-THP_JOK!Y~Ct$siF%`A8k}K9g!y|`V!AH)mVnalcwI1({2LQF48O6_ z3J$HO+fJWPHJ9)B!>?LPt2&Ie97q0d7U}Yau-n5Tnc78QfX}COLsw)1*Nke17XP6y z43%cO8Xu7RuB3^GdV1+V9EL@f(Fo>ZUGg0R3+}iX^TIwE`EF$L*br?KZ5MM$Fo;CJ zYjz%i4`^#H9vP6lXCf>tY9B>~1~MLlbImR+K8sm-N=;{@78ara zIJ#dj%CU*HRM~oERdv8?yt47VtO-lV<;ycx0fF7LKhOFelp)QrVe=r6IxF!?wFLg# z>_t8mDhm{6U|kxfrg46WF=OMyn;LBoX) z0}ef#DwPvmq;_=J{v)Mb*>h2E95vtOO-gN^f-R3E5>+!v-0U8PpkGp8_PMW zYMbd*6z;F#pj{(tg*4JE4EFIjh=tHG1OlJ6Cn{Z9P0f3NJ6V(ysWYr*<+moF8o&oY zkGUeynsalXWesk2k1-sE_mbqYAdJf1YujdA{(570d65U@Bnk5ImE#4R78=pUzy8- z8NW|4{QD0?DOzw8LGD|k=Yp$li}^yb^|c}q|EK^M`4&G%uuhJ{wFkyk@{J$6#7NtF znwx&T+n&QBvB@qU(%ml@iUvmm!bT=~oM+|JI$%QDrxAOJO41~uJ;y7A+QiPPoYRCf z)}v|IIQ5|a?!8sjZ(ySC0hjT%>ORS;zv=-|7i6Sld7JVuZ;kEKZr~ z)iTNbkx^iE$Ap^4>pB2kFx$q$%sOjNH?GD!n@(1&#sm{&Q9%~TW`s)LctLLMs8(FH zqv=`UnxMGgno-1{%1+P=BccX*N%v8aE_H1^R>3!9itAC|13;(>SBYEvg99VRn%9d^ zapxu2oxq#MQ=VMU&2CVH$6*j@h`mAe&Ps1^iO1mpzWNE)RhuOSyy_#EjTVo1>(JoS zL;+qm2>;U)0*l@!FX~<3Pubs2fBT;NM1&7GZ1p{6HVOVNFJl9zDT=(al+;XM0y_n9 ztr^8U=GkAxZjtQd#Iwsa{sDE6#DIciB1~?O%d-6812Gi*M*(@uhsP?N9Rd*mSs!yW z;kXG2eO|>|(j6{EQo^=(pLz{XfljY1_1#jC?R)gO%$m3R?k;2kJrS?)mwNZ<(7xA+%+^V`3A-7`C6 z3|Ln|^Jd$IQ=?4LAD@SF&ARP9Gr`sy6;Q1C?62y70n`>;LIf1gVEEyt0Ii*;%ADr; zsId9xC|OhR!U64H2{XncwMOs%xbB&*g>EqRhwfIqbVatz`lU%rd4&}#R#{(>IIVn4 z$R265-gTfd686bZ!MccHHO{l6>ARb!^bB#{8>%i%Fy6Klht#$uT5O%BfkVl@ix^u$ z!qO&E_fDJXF3vFLAkEer=GHNM`VIbA?EHdkOKk)>=`ai1a>(w_Psfm$RzqlK5k7nQ zYa&~hj-6Ap#r~9-SfDeL!ppq4@o534>QtaAu&)Q|S^~-09#Z=k#q9h{V>!7m`rvP> zfhyH7-u;PI6AB;a^32yGXa@_r2QB_)_8ldBauNy4kp=BBqCq!u5onU6Jvut&;a&ccVw!fi;m)?|wHzqa z@L~bga$b7B#l@+cKVvbdMVhhEpOGvAcuDBh3JmCmvA7}>0%~sLMdZ;%R{?{WpLQEz zaEW~aXij*bcRs;6Xd}TP{(-aU^gP#x)-BPSmKO9@bd_Clbu81H;7L1?)T`TcNTW7m z3XjCgG3$04qks>6w0X$Dp_s+wUreCmgizX9w2rD>w^CbSSoW?)hfQ$Hq=?8i-nVj6epg_c@Q8-FQaq z%SpL=^Dy^Hoz&+kY>5x}jA`}N_cJR{F>_~~+uVtZQwU$`_ksKKxsAx-+AJ&v2LPiboNIIXfHZbb%?^D6~fqSEqE zRoI=U2=*b$T_yju7dhT_PCN3JUvaWBk&O?QG4#>&_mXD#mR+QTza*){tX|M0 z)%%+YF+VG~WyxXs25RcFfIvHvp`;t~{>0G}Dlb;(1iqA`4Ra9%Wu5y8>TP>WsNiZ9W<@Acx zZvDaqNv103epB8I&eDtXb?mS5W}9mN@(0GCP59#_&t6I$z_;quWj;4J^>z=@#^y-N z6HgPhPX4;H=@4T)P+=I3HqN@s1T}s6yzXSW?MK(EKZml!mjMK6nd8=RC|&p20Xm** z$T5lMwn@FCDO9OL?V8acku|(ik$V|~335r}ci$(JO*=l&Rq@ZB!HLp6r9rH}K9b1t ztPeZT)4exTac&y{Q`(IcZxf1 z{AV&JZoVsr+%(VgW9>w;Ze6M}bL=u}=~!6I56+CNnzGPF>#T{E1eZVERQlG*ymuzx z$xq&}JJu61(f=v^#n$>;Wd}sA7-g>3_BD_J|KwW&y50-)u4PSMm)-fqW1=Pfd(24 zcH~aF;Q3SMKWxwcoc)q>GEuUDaghS|VKBy5~X{oES8mfr1Y5A?iRXEPW$}fGeIU z0r~rZ)DaH~-YtcmZ$sm8_diodv{kLIhH{C{r@o|bV=hbw-wkl3pI8xdPvmgm zY=V6S$1g0%O7?6wNr%U#)Ui>w#anXs_%RTPuJ|EyzYEk_Phh9~JG0UP0p4v+RP-#A z&?YLX6S$>H4C2>V3V+;Jef(VCB)7nM6s~bfYUlzfWcL~`ge&`H8hugpD0_G=hZI$R z1pWT2R|b17duLUoy>WkVe&}n(y1C>b>{mA=yl{!OYzu0lFng&F%`|U`g)4bdiZ4N>wDy_SP+>ko<3;!xo!tnnOnJYmq^WBwtn1NK>i0%?OGq zDMf|1bd2>xSo1bMt}Z$ODOq#5Fo&AEL^j1i2c=x|^HyB=PfTSd((gqJ!`$Yra0d{l zvPtHuizqE-m>yUzlQf|+&R?UN#!)68U%ElzE92d`kzYs$5xq)cozk4`dqFzFbZ3*7 z2CA&#?MaLA(VnfbSF@vpi)8WyuydFy3|yszU7*@UPGLe)E@xJa6e$C)!7b0TPOEgR z!(1lO=t!5$;Z8gT1|K*m3uyuSh0HOE0kdHYBIt${i)R$FKHSNUjHBnsa+!ADij=?z zjDxxGw%J+LmRB6b<^=^w-tu2 zoU@t}qK%Kz&#R8&TpN7U>eKW_CDHA>ntHVdgC&?R$_7TZk_fh9-#b8zFPq(JRWEOl zWgo)dim?y&Me_+BE6+n!PS!e6*ocw-WCHw&Bp^cRF_WcUlX+o$nvcm}(UWDRX>dMs zb7rOVyC0Z#bKjREFG(el$eUP-K20}--^-lyTD~nvrSzOFCXEyNnAQ&R&=pHtz7BT5 zCxxql-3^j{R)EvwoqCjrD$?y~i1a6vn5tjpH1`&MyGiOt_uFqi!WN=?HRjaqa}S#l zZI-0(5j)(Hbb6&ib7!4FQcNQhG)%fjie}?hPR>v@i2NFsh_thpu6h9I`KCZFa+-Li z5*>a-<4t_vyzflHkkp!H+2sQGaG}UQ-sgi4;a|MYC{ACcGLkvX?Yh zCxnQz26+NWG2<9#mz!A$0u8I5vy#TgwY2|2QMjzJid~fHVi{a-+mS7sPE(1&r+a05KR&Ljh96}C5Q86c~`)etT z4(}MZ|5SG;Y#+ZTVVrj%Tp7zi0>n{0d;j-VrY!kc>mxV|UH{#h%gN<7C-f)kz;*t(=10rU;B(G^&Wcr065?LxbL`mXEIA*%7VI2 z;60u@*yshU+wdU0uXd9J`CGNS$y9x2B-xH)ZM(I789V%fKlZsiekInG7kpo3uGOhQ z==tZYH@`etvf7?4ULMm|kry4EhFN<~N8mkst);)9m>`fjXDR$l)&FB%oAN%lcKo+1 zk=FQI17e$F+;higfCR1dIEI$$v&-Tv?5Usj_hGiOLIA2CiMz%gyBrHosGbhTRmZtb z@w4Nu{V>ICXtY^MC88z#ga+OGBt*p`#T}2>N=;Z*5K)bvzzUj@uw+CNqS=fzEsAV@ z0Ia80y9Z~1YZM6DsxNc61)sTo1f3XeU~DQ)p4Frzd=>r^P)0C%KTAceF`(ulI=>@7 zg{0<2LmsPqN_6ZU^jh6syZB6C)JweSX-X~Bfq(0^@#5=2GS*$L9zx=y^zzeTS&dj} zjrk8HA6Pz#o8?Q5IyfNKk4>fr+t7{-bRD$eSb`Y|F_XO#eCs)`uzK4z&B)yc010cI z=auJ9Tnrx1!S1p&Cum^Pb9)F%M#mwLF6S9j)ncyW(SW}ow6XQ#i>-SSB$I$}jRfe- z5=p3`jXsgZ=l<1(s%%YJIfGBl+Dq|+A4^zJ0{yJW@E|yy9LO>#r+H8b?^?8=4743* z(=YHcw~kpfi{Rg!VlznEu710p8D`9E=wbrtSk2iamT#pt9j;&=E3n|pW;jPu@TVvX zcsY!R#ULEYiHLNl&nw}nWJCZVl!K<2?w3|@Och4*ggiw{SkWY51X8r=L(*p&EPYnx zUbP=@@0{a4_+K4o8OpP)#OMqz?tu>Agq#lm@4>nN-F%&WFna!$GyWwRpUGA}I`yis z9~63FvZlUQSC)`86mDwsBa!FX(ru?)LmNIi^+;+JPjnJZI}_a(BJO$3zQ$!(EE91X z2kr-~(tD~Vtm5^r5jSLETp&6bGNB*cUo7&UM6hIx^=^{eq|gv+hYSpKi$}UCkS9M@ zqzH13NQe##{iuq*!IdShgw5dA^NWjF$1ys?2S8v%eSwgaiR?7o7 zY+1^xB(X1U8E%B_1Wro{@0XVn*ydSg)6Wb)cr+BUxVn$37+K+BnIdD{Q!#YE-|`yQ z9oN}YMH!m=TItA{eRFW@wSPxvIjj`c4b@%=Q_8^ob@lWCkR8#u{>h|4Ee^dsv?rvn z(+`nV*NFYXbV#pgT01iMs?STXS0J8wDtA$7{r)Vldr;z_rd}PzMk(g5k)f9Sw@R^d z;M8o2X{NVGIW+*~$joUvTrt2vb?%~xH1lfG%i^t+a*NNx+E=rR_QhEJ0b+oKJ7~Me zm1<93P$#W}#7N96g3IE{f6`!?&!@zTp!RY$@9CufSp};~+4&@;RP%c?jyQ(JnIVQz z0hTXjfJ}Eu1AO`qRT1Bpv}uj#n_$(6D2wrx7&7}{kqEaPINIrNkmhH9eV<#W_|Qq2 zUGcUVb?D8k-=!1K-UQs$B-3|oXm5+qBc;n7+5y`9swlNB`E7n}_Axn-u`kR@J$lmW zrlJNkog@Z}&#l#-bo41tnI23VM-@i{>Q=XFkW2ffgmRH`}s=giPX0zLG#J z+l^oGScfslDCvxZ8PYJ*@rfc~Cr@UBHB1?K=MzMw!Y{FY8TTPppulKyOaP1?erWhqZj6T9fyCH)XpdYAWC^JHSm zcAxXi##xCIzK3J#l27?rgkCT00Jj71?pQBxQb`gHYuc>?a-XPBdEgnu$(2zYIdEo zF-)W&sX$sr^+mKHAe8~aBMt6UnDW(VFJ3D>(|-NJwC=hAaX!k)};jsy7M`fN%24;%8I{ ztEWk?w-%*&=5!AZS)gqUiTqU8CX%-N1aI9QM?l4Zpp(mTIc*mg97B$a^l?in*vrxGde|Dw%gf<8 zjCgPanVeiW$Mu#V2f2MLG`(0j>BwZq4*`jhiGzlqzGFJxJN5kZq>g{G0$+wj#*>V(l?<7Xk`3gn;{mTawLNsmW6 zJ5|^d5)9Csyzh?`i@V(>@V>uyr=XzkelN#zkn!_lW#vtUpCP))8+soCyUEbge#aA> z!sU1ldLMg{jn+aosA&Li(~%FEtsW!U{{TpgBMI@5PwaD`B$J`^%eu2y7bw#*2!kcZf+OQRQQs3DliQ*J%V;)!d#&epBOn=2*sVAs?&IwY=*-Ki^Bo zM=#|z)2dEeEtmzs?XNAY< zpj|9KH(IyPOt8$3&F#j@0~7gAU}$mT&zOO`pFRJVcaSvZ?x$lUwXgX$?^yXkrh21#*qq=rT! zM$q5$k1E*VG7K}uu8c@=wa}diH`cQAF`1_Y7)uBrrswZo^|Qmx3q|ba0!8k!#5!Nb z^d5nq3_OE=@7`#dMOBrTupV7Cpv99n4Ik|Cw=@#mE3a_hZdRdDe$D9~+elm>t&=W!(|DEgy(996u>0W`1)-sL@7;^tWgYHZ~SQDM;O#Q`X%D zX#2R4xQ0yBomWK%?;l#d8e+AY1~KXCZnvP$j}CT+W<#u-dJ+PW_==Q|CN4O+vRh9p z)}8qD_2o#h#5$JmYUcUhka6?7V)5u&G0}%g44y+iHPR;E{Qh1Q96Y%din1NHxYX4L zXx&NMVh^ZMu^vf-0;Nd%Jm@v!X;yU)0ciocO223EuR!?t<#H8TEJkS~U|v8vuWh2d z{{RThAV_iDu8b`i?0oCe{w>OKki2lujlG7R=SBPnThMxc47py)vxZ$Y57bvj43cfv zU#)YzY}u}a%r+8q9l))qOE28ly#|QAwWM_KP*=XEr6wTjL7fW%FVd`w5IfaKd@p*o zx>$4+2!I9XPp?tBigoB{WL)TVpb-G+)5@MOLwQual67zFqAFXp1Ce@gy{}FM`&x(> zu@|6?$QD|Q78-Z&Mhi^QfHdntUgQz4<4^>Wb-hYOJ?aWA-hiV@M*X_>sDe(N>BakX zpo(-*t*w~s0B%XBT_0p^A4~-!D_n@)A zz|$9R8V2iirZQ`98Ut?EQ%)N60Vq0m9clM>zh2Y^4dc?6S^}^JiMXE%2DYU4pgIO` zSN2hkz35Ki0c}Yh9cVFmK^&5iG<)D)kshYBIJAO6cp+G03#RP`m7B0MKB(n<0`x{{U#DSk^blc}`cH!J8kQ%9Ab;QXN-XnKkoIV#AC$ZPX;VA%%{|BN!Pd+t3!rNxWZZZ-X#;< znpX8l(XOKH=TvdBB7R67B14G_M#&3p)P>W0t>@Z;_B74=Eal~-GDcfuF~~P;zhxt( zP-$nA7-C@Jz~L6|tcQAw^$mK^ju{>J>}eRu`^gN952a)ZN|U>wt68$;<1R)Y9TZO{ zQwZaqXjTiS=K9bFj`=QT1aU zQV*}veL}qJFBg#ES$*htNaJHnnwz)N!u3WhOsomZBQE9_5~i1S@$>PZ?0L`WraQ+M zG4Oo31X8h7z{tMkxzwYPVO-xI&*pGB;|t{2`AN05xn=+oG`S^xOZ2NaA1vo^C65pN zNf<`zOme2}Pvz9tbe|#kugbT<%Ep;&ET#!p)fofS%Ez_nGO;tbzGX_JgAt-#)4aOJ zw4FAn)~${kj>a+OVXQfFOX&T~pU!m9lV$vBwJdrN zYmCl^<)0jO<9UopQa$0>m3P2z`I*<#e>x8Hm2~1Z;~0idDyl&YH>&Oy9<|cdhB9Ug z3TH+8Xp3G*u@2qNI}@*3r3|^4lQU(`a`EMfT^bj-LDcSX;o(}C*lWl^`;1;fIU#P5 zNguXFy6VTTodw=Mi{Rc_Va3Xm6PC;uTx_P?#YbTvvVd!$<1uk^xbwwlaW5WDJeJCe zPt_ZL?PDp`O>nCRH^t{lOb}!u0P|0j%I+iZL~U!e;<#Q4*?i`(^gaC_df+Yd99#hu}Ci;)SrnMHxOXHN7PIb5c6S@Ok| zhwrkF(#wqsM=GA7_jjyiPmXdNgkQGgCBu>1ZciIJuuGot5&*7`4+A5W#-AQs*%n{` zk(x_HeAILwO5u5K51l#j$H_cd4~R*IXb8DLeImoXs3>yyT(29-au}&1%>ea4jKgy$ zjr=^TDW(%)I^d&4GM`aq48D79(zp5OAla z=52L86=&R!GAuqsN*Z1vtkGJ|LUmrz$F9Sv}wp)kMV47 zRv32U0vFqT4UdIr^0IL=adZ5ilrFMm6-e<_t?mwiYXhCn&!35c4AeOI<$cJYz0S~V zt8W`nEG{$moJ{e_Foq{!Vjs$W?L6xKR!8i(cu6d7|71 zZoJY4Vd?6lwR3#dW(HBgz{GZV@uVdfi-v1|H3nX85fNn1%E--Y2*VvskAE7};;}Ph z<3}Nmn{iYd$gBVaeYZocRORAfB!9Z~%;9~w?{FKqYUp@h*-gP`W6BE88lA{G0%$o- zPd_Snwq%0AoDj-IRycm~iextgUB3#~F=FlZa&2Ink$|wc@vPOIA&PYou#kO>HDCRn z)Db9*aNSF-$od)%!zY;d4l<;exQ&rKn#+FXmPg89pBvfY;ENf6vhKCO`q!PP zcKd9keYVn>S%>A_>h)h+nhu9QHc3-_^Zu`WcMtvA%w~;`rTs^}3f|@26JsuxT?g=} zZjQh()O5C#2P#7tPnMT&@So~izi^xOn!;qk#$im;kwd35tlEHxR9yA9=Jugz+ zdQ=n8?Paa61|(78dD32c`c23LqoK^b)s?F||lj8_)&R8m!7gSXHw@lEc&ak9q-xK047X z2>Mh2QP;1PIZy_jXd7zY_o*ynv8PZ@q)|XV6a(3A;M7X^)qpM9py7?|C@M*9ZB-e- zJ!#nA#E5o0Qrx$)LhHlq~OO02XRsAVmexf22UxQ36G4#5k$84C!FkEqpqW=ptU^F zW8-`ISrJ7F*oe)EBfy%;oBseCo|%xv9zGl?tj62g{o}0OOEW0)>xYq*3>a{x>9PP< zE#BK$TGc}*pW!lATxdCu*hdw_+03AXPUTgG+t6fusvaLJG>rKrV~egR60}8_=u4>k ztC)|C;&`Ev%TI*zLFx+m4s6m})3P(6){mVY9A4ie@aW%>d1fB>EuKheZa^j|zS~}x z$T=PFg}+CRkMhGC-c7jc&wM z3`~ZX7;+1E@HqAfEFQ=PMer@&w|Rb5F(b}QWMQ3~8HQ;<3AQu@3vKZf4jTg#D<2Lx zB^ePVneqhV_{nhiSE^msVO+rjw^N~0cK$T58$+YxQS z*3I67H42%(zlgZ7C z#U@-+M!x=18*P@_n1CIPP|f(iA%xg3#^OsEAaBie^xW%bHPFkN69y5H664^_DwKE~ zz0J4ONV)*kd*=L}6jEX1;`3)0h|BiIWU!BNL{I|y(X?N}gOY!dO@_yc=Nl|EYzxe& zQtUbi>~$5|ao;(%8ONSA?rLzwbw& z6ikok&K7Ex-A^`dcHUKhnOrhzb| zp93aflfW3WM92QIJg;7I4<#hZoOXUqpH(X(I;j3%Q)yfH{Qm&TaphdW48VG0mm!og zs9R}bb-k!P(~sr9(zAckGaK}zQ6v^!RS44FG*K=dMq}jhc^LD%-Wl=MTR8*9KFwHo zs}IUC@V-mH@*6WTz+9YJR1|Y-6uH%Z3g>=Hjev6IgFhBdJCc$x!c1~iTn$y#mfGHf zp_hw`i_V>*l#Fb!1h`ozW1;?N@7Kz>+hP_3`FuWC_}4cseDd=jzmhd{044T~NENH{D6=5N#>s~%r=7@Kp}8n^*0B*I%9Zh* zRx294m&|c$4S0l(tC^2K=E!EM88;90`G7sN2J|ck`^bop&hq*O(j)qw9 z=EudizQ*nkt8KMCYR?-UEZHlz@wl*(LNvE}2IP(#V`J`*-Ap2<9uumW7yf#~hc;Z! zVKTWFQd88ixEobR;)yfOyIEwn1O(bCqi?OfQ+e0EG&Htr3$0y=#SA3GfjE0*@=Kjub0&^p!> zrdE*H`oXYoDh{7KB>Wp?OvWtKot+-{+y_tNM}wJ#Fj-gho_LSEw$z(-u69XenPJ6w zi^mnWub+AzLoBH)pewY55B?F_g6z3WF(dVs9Raq#jTb58_69;qtM4wh)Ld!m@T|m{ z{{U{d`1)=-mm1aR@hq#2Al|b5*EXQD?KBvWW=I5Vy4gKS{{ULu;yDM$S+kcX+AkAE zQC8sY1Xd%eV@3O5#3GF&ZGV9^L7gCl?S?GhEcH3se`JX65Y zG=U}m0IMgz(yn3t=Z}>eFCIytxD4^#h#nzpGY%=5Bo4tWY#*(we-y_9BssaI(X~Q6 zeCRst4ox>H!^t8tJu2(9f%;c%!u*Az2^LO6DH^dOsIN80ml7FK;v!VOw(DJ1HzUSR z7RjS1=S|x5p!E!XYaUhJju2X0Kb~*4t3)5PyU^~=Igll>W;l-(o1F6!g3D^o_lYI|b3mdhv>U`)0+z(2SG!Y07QA^uj z3MDE5dqB|I8}t^d9cfyEgTYkhj@|9$TFwTwLn1NO)D+Q3)Y^)JOZ30nP${PEyRF!D zsIF8(e`H)sw6&~k0HC;<>3jVsjGznZdA%t6 z9!cJGn;v^RM#jufp0&twIZ(kHo+~i%_;VeyBz6oy>JsGs#Jg5F$3trm3ZoA#FURqu z`8OvbWM*o4o<6w>qd`3I+RZ7|@5L^SVm1gm1yyr8Q%VlFk z{C6CNJQlI`$r>pl^c?)69Gtmlo>MMNtdh*fa>WP+;xT)5=~@|oB?*}h2OWzMSU@j1 zxGcn9XQrXcBwVBpB;_6<3+~8>q1%7Tu@E{fV>FS#nG$=R=tKe{g4;hrECYl6CNJB_uj^FITR<)p^_!Fe*VR8131LYV;U#Rwg%i{m7NkxWcH zm|Y=d-zOmf32-{B+y3wRG~Aabg&1{Asiei3tsfl;^#HnPe+mxOFjz{5P5PQS6_jyf`fk%GaB zn17Y*KJK;G@LX>d@!U*rl;CGggbdFRgff^NSb#$Vb3w>7(|m(Du=vE9W_fqI0k_o| z(T?j4Jgc$E_A$~teoGT?DI7$zg$)Csu=N9TaaaEUWezSrcgp#E#l+&EVUiF&cuw#gEVA_)qyLw zTWMWaFM-T_kK){hT95SnxLl(^z#nx;+vqEPwZPAa+%Gr8W9DR>d@e%hCqeoz8(f3C z$8qtl?}g3fI1U#h2j4l)vKV6og1+C}4Z8QB%iwr3i^F5_JfobPM<@2!*=KG}Jl(`j zntOg1HK3mu$jV0Ju%^RlNM(}`C-0F*{gZz;<4^JUTae>9W6Wa9kfvog*s>e6WHypV zw$@Wx9M&%x6nNv>WXg^)HZJIkQi}<;6b}&0?2)Szxy5R3Ejs z8(4W)O~(8&GC*AHriUb{jx3n<6Atm@DbOGHMO^rn zgW)CU{{S%k_B7bR;)9UlCs49P*Zs^*Z@x0UzO-!ozHj5>3n`f9VzY(IXh-QhEG!+A zg4emM@9GSg_%UJSaPpSQk%J^CZ)NLpx}9h_Xs~#xb0@_UY>k)n(-Vus~pkg;d_v+ zilhogo3-^*t{cQ#_a|yhZ|XYRuSyPwh{%VEz?w;2RkG}T?yNT+gRNG`=GPpoWL`A6 zGDmBX=X#-u$zjDC^T#WB>fUN^k2sG7o^OOl7Pj5f?>tn zT3KWpSlrx!x5l!0OxbesB80Jy2v=&xwzY*^%H*eq8y^*0XS_Aj?Y&}hFC4jQAzc8o zFe6er&^B&L*zP6RjiC3xja9>eu4ZAlcu?m3Hz#Qp?r8WjEJ)Hj5*xLs3UXcw z%VFcF>s7JW+Q@Zdquj0fQYO-wrPd+#j|vJfmVL)jd#Lgh7vXLBAjsvBH73JKw>;R{ zQeITt!~C)d7W&$%&$2kbPts)mGzhW|&vfV)zw=OOWVEs3v2qIA_*NoJLAgNI8%6vo z#QAbh3nBD}=sayy<5JDHb*(^WYk_fn03`T%RDH0Jyt)-9YJ>L+(DxPqG0|Jnd}-OC zXxWJ(TaQm`P!87Bg~9QudV1Q&wMTZNanhvPY1aCKK_R#c(f||b>N@yTtWiOJm2zA| z7COzLiTpaySB^HFio)Kd*K>6ID|Z_mIV={IAO!H}z;`0DW5xwQxkNu{9Zg!tX}I8J zjF3N+=nVv;hET3kAwxEv+g`x=Rrnubg=zPaJvv|bRXA~F$VSM3G=TQF(Dkj1MZiTK z=eV+4(g6Penu5Z{PfYqFC zMngG`U9qD*k%j)hN)JVYk;9YqvDACI28zc+SB^#*P~px#OB=GSad4pg#K^l{?*f)h~FHQxd4K zy#a`0dG|yXby~Z2Tt{Hkb3_B3T>mp)D-r=V^ApF`qi?4 z^{8wEr2vsg>-f=^O)YwDM?q?EZ`A8R%xp9kHC=;Vj(T`hc3-b*1s&FojNR(9Ty&|V zhfQcNDeXsIl}Slc>OFf6YRqn@Ku?tcsZ>EW=|LH|%;q$eUDWM$QVC!8yeJRb!m8!v zMFQBd-gHnrX|i+iabx%Am12Zm?&iZ!3iD5q{QKX`d`tw6C^fcoxVg9Tp`i2$xomu3 z(aJ;4stY3Z7wpwf{a+Q>r@Dquzh_}yJ15C=p=XvXgv!d5OR-yOw)>CLv2ea^7BWb3 zWL%e!{{WbV#CdHL9`t!EHZ3G9cYbrw3whOSjG2rrHY2HSq}ul$2E1WEsQJ)YQ`(ai zh#uPjt$!0+m_OBSIDU?FLLhx5&{;tIC^mUsONE9^zDZ_$OoBklha1uv^z|E5vA#?n zWMd%YF47Ch>b{yC)l-m*;#|iGk(I}1p~=ZY$6HwaJJ+3Ib8n9uVjYL}hib3^Lnt~1 z9q2n;ypfNH`|(S>t++D{z+dv#KkVhrEtQ{;xbeoffmm$<-T>AN{{S$|+bnRt@^Z6sc{h|34<6%g zI>tgS(0?-ZH>Jg5G+bijoUhp7O3d@Cwf)pnZHk_C82jjI}%}*ZfiFsOajKh78|82+*`E-vWjCITt<=3KtS-q zbwvbUe4ce#aU)bYnbET17A2B1w9LTtE8$xl+?bfZA`z@5lN)dEvnBK_k}u>{K6O!Y zWae|TIV_mOf48-x4YmY~bSv1KP+HE$hAtZqEc>y|lnILqf2K4B*Q#S18wx48nRSt4 zybwgd6?5skR@lcp_a%vijEwljLz%}#LDfO;ty1UVIxTHZE=I>@8hZLN6#dTpW0zF#F!-S05P*5wQmU0EK1YW8!>g z7Jd-IXU*i|ZRHN{Z_-FNthp8r2je(X46?kOnJlXIxm5&iR`Aok2B*$BZhMiHxcKq$ z<>B$>REq*74B(+4o2_(wU&pZWv8T-Ba+WL@;Z%+pdY~!`DD&N1&&Kd%gOAO%H17cmc^u@HZv~9Py8HHYL$^jWlkZtAXM;IeA_|ql#%6G960Y$^*8>z<23g z+;K^p%jd&3PWZ~EJn;EmRH z-xDuMwz--EyYp`8KpuCFJmW(j5uY|1dzXqfxZSYZYYzAEtbIKJPmOZ?ZWavh9%*U8Kf6a46AeIk*TREe zndNZ!EJz~CwZT3XUVw# z0QHVWMZ=pJLY#OsH(rjm@$XzFYkQ3s9Mc&=UvVP?Z=~yXZkMh6sc_o|_sD>*QUVcm z3LB}voni8WAAy-y5DC5bm6~~5b*?_p4@*!&WRn|-85nSF_3hr~?Wcuh`hvg+Y$n?AZE9zh}C@URI%eZ5(jbUKXv~AzJe

    _@_fR(V{$p$Y6cv5>RDpAKHygUI z(vHtG!9(-dv&g8%v!4p$R6w*|jQ0tws?8zqg*Az-0~YA?beh6>+%iMnMigAh{T_8#Bs%wjV|`8NSAT zBPuJ(u`vcY9_4?HZedRVk;f&I?6?DLsi8C(j%OW=c&YN@%ENKG0tjY8I(qxiKYs%{ zW9H#3%A(53*1zLH^y`&3xT?gp?1GLjB~Cbn`dWZ7q=f5Mk~@9fXsUrl8Bh_e09NbL zilluF7u(W?Qrh>RlH0#pnKl~GgL-{KT7Au?zl8&_G&a!On|W01qt1lQeL&KI7Z>YD zX{a}#7G=G(^Q0tWYn$mnU0d#@VmkDpnMT|6@$;a~n~RO4#O@;EHT$jfptaupszYtA zEq>?9v2uC*C{{mkG$KP~jlS#lV_4Z=FcYMYimUDevNXBY)E$#LfxLQS8nmaSX65{& zj)9jO75@Nxl`e^o7f?s@kD;ifZ71EkXuFV9o1S zADDV-&K@fyOw(e=lMp}U?jgwjZ4YXU?Zo}iM$iuN5>CI303gb2c?_s_gZC;i+x#ex znvEy8cM^30dVVxE_Sl6*B$06twV(V~s{WKs#Y#2o&)exhQ6!RXMD>2Eb1=#cU_a7N}p!y6mXjHpVP3Dk_C7oE$pK$y-wN^PfK*Jn~^7w%UteI{>K*y zHsawx2G(FSbqB_S2Q;@J{?p^MzS(EUX$cBsf6w&2H!VIP;;`X(S{z{|niT1f;Pl_t z)hwmUGNP{3T%gj-9FV&gTarIFl?#r=ljO1?C}QDw=DTG{>4{sxPjYB4`?>fz+;$-g z1ZG4MV@Bi^jEmT?)}``n*`GfmE*}+f(;fEYO5~E)QR-XL;yA|7E<=w>?ze3RN(}rCC--=;K{LF0Q@!3&$9au) zz50PmlZzi0k-^U29!?}OGzuEVG<_F)_}|W(ndNdbawN&0It)MD-Z+yQ_FQEh2H-tb zy=N~ag~ss@9~}?9hclFk=DCsO9Y`H0ET=1*KR*sbPMH{((*c+(rHv}+u*)c&$sXLqs9fa^EYz$)-Jg~A)J8D>tgfZw14;MRQiS)8U!ttM79t%(E- zB|$m7?lv#mOlC;% zayt8}-}O#UYJMMv$>F7&ibH;12#@sza2sMUzSIY{x2|vZiv(%Ma&eqqRV4SZc}1}< zm$>pDg=%pegXDasE<+-7H2i}55wItF5G|-ZPMzo$PDFfnKNdj)Cy$zA4oe0g#VHz+ zqw7-S)%ZzsAmhvDz~8Nz6R~sbx7)J)g;$G`icGFgh34?gqCCbXWzu-PIxz#&StFOq z!{&fYlrN8UizMsr!rBPr8jGz3{2b!A84QElNz-g_KU*KLi}+Pkm zulAwo{gqv&#)?dg%*k$1{n+u>?IQQmpB`+ir+m1W38x-|f3**428SCFvLltH{VZ#P zZkvaVR-Pe{&yZzChDNe|DA@}i?UxM7B8ax^i*+ZxP@LgHOJgs%P+9=wfIo!rS|J!ol^ zsVntm?3HZJ*RR80XkBg%sJW;g9m43a{{ zqc(1r@}RVC8SvG>K-U-Xs!kZS$+_|RRF18>{-dch`dPe11U#ww5lz=#;+$(h?{aqz zl*JmuPQB=YG81sr+|=1NL>apFpbCQCkyarrIxY3Lx!8GBOjbbWsjJu+GD<-jC^s|~ zaj~T&Fkd~(SCThr?7_Dm4wPIxU7<)~Q4P&+oIDR__dt+OQQ<*>??;OxN0AwoAFi5; z&X*1_%_%!kzR1s7-{i3j*y3ndNecbybYbDrx%{L?(8yJoSpe456z764zT{WfI?w_H zQ7|?_Y)|)ArZh3gcB^e3blDQTEwJrmUZTQ+F=xukeZ}`=TaCZr6i6+Sgjk3UrXnr; zDkcfCQ{IFCy~jgP_dTdeH{aUbs5S7R_TpoR=;GUUN_r0)nzegY;&M~-%6Yrb3)7epK?-8jU9yt*Dkg##p5HHufAAgFR2!~f^A+|jq~ihxo765b{R4Tju?O^+g^dR7Oqb> zp62=KwwAIMl`e72%iCrE z*eZDgZ&h@7GeysEPyYZ82&3gO0ePX9?_!3;>EBA>vth$r+&}b=NMmNkqG>T~V)u7? zif(NWTUCG9a(quTxtu2^u=02JQyO!!CkL!Mn1weq9R_DD2QboLW+}dGU#Mi$+m%n+ zEo0ias1cdw<8ovmtQ-O1*4}l!@_d!%V~>-D7UI4`gX#dBKx4nk#9v$zTdOIL z(rSQi6Xeljxu5+zng|HVLtySY2|P8Rrw1hS?VBKO$;91{n7RWjW6~IdRDCgoYz8S3 zyEJC{T$}ATrsnwGZ;Z}E$YDEWmE748dgGOC-)PdZWz3d9WK=PB_I8^o{%Q>zjPWd9 zQG}1_<#tx%t*ZxYZG7C8+hSNi3JG$S$;Xyy#xsj#ZLAKNWA^s|5 zk<@Hc?XOZtK~htw2$%D#(Y_)g`XY ze3{toF-8k&bhd!kS@7TK{{T7joU)vJAGG4`Mn@wepKJm7V;U2GD*8v_e+KyP!!bW^ z#$v1G01WxE09~5iC%2HG@ZX3307Sk)&njkfr~Mm@xMGd2L!tgb(0|geO~n3^{{T<$ z$c;GDm_Pu@lFW4-{UvMA<&)fPrLIR&+wh>W-3upu4!`W6<0SaE$D1qLz{7?FfLh9$ zY4xJcBE(0Hf`nB46h*Kt=W6Je85eS**^aK&SmOs`ilL-B1L644c_+;z{{U5r9zB#M zJOkX3HT5@LZCsBR#^uF@K5SBcx{~50)uN1gZ*iq{e?QBR=Klbu@!pwO{{Z505Lm5^ zy4Get{{XUZ;{hZwu0{UD*>3^7(hk%aE1F$J22=Op;a13~$}y z%g_9Vd73qUZ;QkqYaW-|*J!Lok{NQREf7dC-sVr`@E=;9SIF{OLUBmk%3>2Ry2Q4# zGB5L5gH{Yr-88uq=c?ky-lQEb`Qlsu0BuhY=ILuSEvLz!|VtSgw z&7M50JYGMHj?v?fc1fJs@?~olAax&&Y2d}ia9mt@Jf)_XN&AR!6z(OL{?Ue-UV~pN zCVZBfc;Q)aeYM71chcxUJ66{9X-k&OS=WvbQ`nf%Jp}y{j{o=l=kC$PP?O#x1_wF*i~Mmu2fgUnU+)o#onSy-_!*0{x2_ z(65oH^O=GPad_@M3PA!`soHGz)QePyDIO*^&N;+B?fu5uM3=UsUe!YyIHOP81!;z? zUQVpu0`wXj21Ix=CU&>#4K|+U{uCFusG-8+C6-v6$DVeHWIJp@zo({}Q6=YO z!XLWCRrhh(LPmAo2>_eWr!!58{{ZV5QOSphp|Rl|+rZkn%$)I&Ce&YJ9BC4$`#|kM z(DQtr6q!pr&hmT8C6ftkBMf@(pm6^HAj*X14`wlglNpKen&ArCzMV7un5gp3**MBYzSkhxKgB_}pPeMUha;4dzwR@MnULG= zBFA=}Em{0p!vc_fZlt`VbQkKn)qK3R652^_>?~f^sqwKtB$H!dN3r4z^GZ&PI#5rN zo=le_5>OC5xCsOi<6Z>FatFI2kVz-VP*co~Wt7dAv?29GvEOkZ=~d*%X|_o+-CJ2y=s+G7VI;|% zOUSqpK@kEV$X98%Pgh#aZ0XtAgr-^LxG2KP2bJg}pF7IiVtYn(3u-hm!xlPimeZb| zcdCl46z`VoJ5|9hCNwcm?Hq|szz6dA&=y>n`215GtX_F_u&g;Il2fjqN+j|$(wQ8P zTcPR}grzrkKkcA}i68B!uomx9Rv?fGTlb9}2LiQ990AI$46ovxcquQJyUr@2PYPIcd3p*XM z4%7n*!0jVWxA3Bf!>!opn&0VH{{U|Zg&9FIlXrgBrU`Z##Gz}&+X&LsSd1P$@DHgYKZ&)0LEJIaaubeK;em~R)0?RFhS=owh}*!fb#w<{;AC+feA2Nf)C0rgqGnQFSIaKc^gN7~AJ z`PW62feo5>D7gp7|-^Qio@<#>M< z!Aab2%ANK_A5f&5UAzT&FFW!cQ=80uzCv%;B<)zm)GhP^gF~J9Pa!i)kBg8VM<)9; zQa_Z}B;riR5xD`iX8O_bqmj0(aRpMuvnja--CM$`zL{G?ZH;tyzjHySi-#nM99Y>4 z47Vd?u3P>}==hE+=5S)k77rT?(MWw#w2O7O=IL0N@kF1fr`HX=Nv*~FYon8r&yR{L z7H_i)xMVp{j^xxazB$CWNOR+SsLOAK znSUf$^W(p2TgR)fA-v0KKJdN6$l=t%oELW8`DCz=lo0zkASC$>VWy z8eEJgXko`5*$xk@$yC-(Ps9E>nm=+~uyX=~wMk@hHMt{0TMx}cE;lEOJS;Ml1BEO@ za0cLdm!)NAz_fcD)FoNx|`m-tHz(yB|QL>U8N^^I#@K-q4S5u{*81r;TRGhFG+Cik|1%685B4jm1DN9o`a7fT=(G)g;E_v9dSv5lxo_Y#E`7<9G)^$6Jamq(F;ihGq1!vl#$B zd%IP6WSqH$kLi>8j}sdbJKS`=2eEPA*B_2zV@1cu!(`#&LV;tB0bl?c`bBEu{{UII z9EVdT4npGfSqUKD&1=Hro?J^4kS9=Vqiu*&+WqR{=A5);by62p+vy|l6dyw;^%I4c zi*82-H_0*o0GWoM`~Ltyy=oah)DAj67aN%W08hzCUpmK^GUdg{ zVNWD^7upJ4Y)5wkt#8fC^10bKvF7qdWs1%>`ao~vLG%;+hY~53XHu~+2i*hhzh)Jg zC(QT&(__UWEZ5kwGM%Kiab99F^3A4sw+S@4b7nv8))qj?%bO|{^vsLC;PzkTpw#Aa zzi|#-rHN(t7`&Goii6s@en*zco)hZ_V6bk4+PS=(jF)R8ZPf02?kvFcH>dsM%L?Mo zgWbNYG!~#@{@@7ZqmAy;3+T<_Xi%zxBwa$WHva%^6`(DMy z%|IaBYeA<59#q(G%Es{-BWN<3!%*G(Q$y5f!3os|g#)8i?@+`de5yp#;h_(kFFaTrXK&*$FLcz_q_J02W#-{P@ zjbvgK!PUBwK9yQa*a9pl4wDziR+)(-qxbx3&+nR9N4)li9ac5(S+^uubQIcs4F%W9 zlOuAxg(72cfaphSikQ#Ijw6kX+ZVYS5Bl$;L{b-m1NwO@l zyr?b$#yk0uR@07#IoRd8qaXUa-oxua1eRuzLdL?v@y4UvH~#<fOe=fmLmKgZ_Gn107naJgx*DLlCKbul$ zGR`^6nnrd27W5!Dx7M{W-)g1Fd|{;o`f4Z`}64O0F07sfDb2+npxee=z(-=*rm zB{VrXBt}Tbg-XT;<^#JL$y>94peSyF_6CDXkmYmvA?(d1(S1sT?X_2kd&{}s)Y@z1 zPXqy^FcK|))M5F2f$v6T!`=IE$J$Lpj}buX_}KVTw^>~JZ`4+K$e4gSSWz=(j%=H# zw0(tEYmEdD2)0ShY)~6X)1URwk4MxOJ zI=;|-Ad}pRO}k5tO)DKO)YFwLbvl7S$I?dKYFkQ>2(vd4 zajU7C1?h3p;)1+LvPhvW5x(R903~bB3aCKix1`m0@kw}<4$yjz!&GTk6V3cKGX|gq1K|rf$F5w08O=|?RC8X9zkxk z6_>cFI8t=bP!-i~H8<_s>p^Nc8M>QPnZVFBX3w1t1PwMzSbjrrFXcglk&1jz-*5dh zuD!gdH6)!PLhjZe=nryhllhm<@O~i-P{^WAODRc#0k{N>39f(Ve>7-u#5in)NBW@c7hR{3hrpUy|cZj_H!6YgH_Opo15#zt2;f3$% z*S&L6$k;*(Y}4++5nVGZ8&-nP3^&z+%W%Ytvw$yI%l00=GAX<5=?WK9&3#UYH!*2#^vWonc^wZqvD zG8$;ypKsd)g|~Z}0;eaD4Zmu^0nwcL(#Njt-70w*(&plcaiUW^4QB+E4!z3Ss|;}v ze9Ro1<4Q`Z8*Ta@rB!Kti5d48a}|HgU1D`Vm8dNyT0A$6J&dq@S0>i)RpnRx(R^eQ z6&~WU6Zdo`tH+-4?nfe6Wzs;ySg+l!+N~_J@$DK36vb=9zwOugEwAyQftcqp_pJks z9{&KEs?CT|?JQ0r{IVd^{5P$RHzVWOF}re*$%o1*zU@7i^F8Y;lrq7P*%8z(ZGP0-K(V5b8s$0k9OTl9X07%c)VBYVL02K4kd{lsb1?kpP@hZIQWh*DRpt%~gS#6RJCB_KoxSGQ z^rQTsR9Zy{iUszbv_1Q5+pc^nEX=_F04)WU$dQ=G9i!iCno=;wh~tM=EvaGJtAk() zYI~Z6&vQWcwT(G9H>mZcV?eHHz_Hel0Cg9q09#+ef<-~pbfvJ3O(ng6?S7PT6BQ?L zu>WljIcGu z^sCr7kp@>L9LFojE>vG| zVnG+_prOW0X4i8dcy`is^1VQA-d#&awL+jITn=}E92 z6={<4BM(;XE&M1c!ymhf#vFkVjP5Mr`u_keYh{dVtb9W{T42B#)9q%rU*TBT*<%;? z3g{(Sl%b7=mOaOvY;p49O^A5+N#aD+8_-or@b5wOXkxbqLsJs7E{95$l%UZAXz=j4x4KqGF6>cNKVLG z{G)waZ-pLM71b4DGMNRkzrZ_Gv#~G}j)Ae5zDy+gKf~IBnmv)72`&YQU{7APrw{%i zBn01ThJ}|yarLS&WVh^ti*J#(Y&12W_W2UWKj{#jmh5jqsg0W+Mr6{@31N`F(}AYz zch~7zc`~#)Oi<|)7z9VCu-!t3BPtB9TihYK5$99SXtHyllNG=5H~#>~D|8xlpsMKd zWLk6*M>-owPNPnh7+Yz_XpksP=&FA<-3=AwWy}h}eVxPEasAZNppJ4QA>9iyu;@2+ zpwhzK`-TQr5$*xizb@hVYeN?qak3>?-+W2bpdp3z+{EcX$7adMj7cBrdwZRN>9u>+ zuW(0=?_#)MK}SM0BL4u(K(Zg$-<=<*3$yp#r~rjBfR81gdP-&vZ$$AjPbdr&2Ck|7rm#0d8z zZ58~jL6nitizJHJ{@Ysa(t3oJ>KG3SO*=`C6EsYS?fQF%q#yA4R?qISG9=kDJ7h8v zSz5uZ&~2)Vn;N8MMR_7qVH6pqE{PU9385;d-t)EX0^IPF7T1 zyN0P@;wzx#IIb%?Masd*_KUCTW1sr3ALCs7{8n5#;|7v8()145JbboouMR_M)5btj z-%hn9%J*1q$Ym*^nRExqf!4FeE>ae>E(-NFH3E_;w8~ccjl$F#=_6y#$})^z=+&V% zRzKntfAt2H)E3y-%vi_>yo04+5*oy4Pxe!dpqrgXhk6b7xsKuoK`;6TW(x`&&>+O1rAGf_n_a|=B zFMSxDYhnlDaN&WrXVe}cvEG?CO$l1*++Q$&}Fc((B9o@XsF-@HXbyZ%6E0WLsb_Y=m{f$;Es#^ zwG!uP1m5SR4Em|T08mYv`8p9}P$Z6&t~B$eBF6Ltk&{5Ht+lB49zGP?k3&ukhn)q? zL}@1%U~ScHT9QiW;xs!{ixGOu$B;uAkp0J{N&@*Z4M}3!iUT}A-B5r*^)G#Doba@7 zwbX}5pz$pkT0i&IJ;De z{{S)iP(-O6XzS8;(FW)z61MUsMdnIV+D0G z3+d=jDzog_w!3W%2?N533aVarH*TA1(kVs`{-Ge#%7J2I#;JGI_N(}j2FTcu`kZ>C zxU~)}Z(0t_YknB9@FQm_eZy9u&dZD1kz-X1K-BiDe0&hV8!~n%w$OH}S+a-Jk`=z& z8z19V-ZqDfjH%ot9S^F2NG8pdon1^#_J9rTS5XEM`gK;($f$8r7;Gf zW>)o+sO)GBg*0)-RR-ey4@wUr!J`U}RP<|fy+9+y0TO6Q(2mptC?BNkNH#X?Xduav z6dR95`&+58`clUp)0N-usnp-7t2r}A3NN-wt@R7xRONm0hJm&%wGmZE4i5teV^Ku6zD4$9^g0-lF5uKQ+%y!h@~ldF)J% z6E5f5mEdJ#du?lLt$1tl^5vq*5Hc_x%GUTm7A^Bmom1`%f*a{V!J3(gOo+YLOBJw`soT?` z9uz6WY5L&ZrO=V$JWVunM!=zvnB?>uck`$-m63HBiCC!z#I(Gz7qssPiFjz98!WeHF9^Z8ah8fGk zOpI){X(ol5DGX-dDLNg)%BH{R(Z-LBJ1p#_WoA2;AZbt5M(&c z84DPW84krl+9C38)XM_2j$>WU{)dC@1cB6%LYEw@0SfMri+ezyxOK6hxtoU@rKDnV zH||zbyLQvk^^uT$kFx6;HusEbS-e2^{{ZfIP*zCiC1;r2 zNvEXS`zq#M9wu%)Q{l3t@wkdlbZ!KlbOxip6Jf@V`_aHgzxEm#21Sh@X!a!C=={V` zRGW!{cxHAh9>%a`L1q@#-V}e1@LV={n;$!TflZ>wi_&jC%xUjRLr}`_uNhrm^Y$ zl;-^i=|Ls-{{S$*g{pC&W;$pE3(^LaH4nFVHXSGlEAHBgI#!+&dn!F3IsDeFq(_m! zQFG;2rDuvSXlo%l+o<}`UsMe&lB=<|+@#ze!l+JV_es#Nfff~e0ta+wvkMJK7rhH2 zHc_|p-|c-323+bqf$$p83fr$rxjKuGRBjfzT}4!I!?D_EA#HTlp6BUPLwARWfP-#`V6WTrR#4L-mah6TJW+Kst%4lLd#rL`IM#^U|x08ro5 zY&yM#&{0UXrh>%y)ySc8gVm*65PC_Lz#fCnqZ%kS zQ*t{B04^ye`_9Yig?gW@XpBh$2XC}}tKP0-!H4X7va@d;7TxGzfg-G%h4l^PL2Hc0 zX=PR~vNijG6kbYUy3t9{>EK7wfj&q`7(h>j?N#HA&exLcQ=<3RS_wkGs3eo@Z53Ew z`zrL(yG0yv0u?#{w9kmntGRByR1VY#r2T!v>>66;g7V9^+gIv)k*!^Z%P395YjwS5 z%L{v|Ewp{WpE|I+)uNNCqKzGiW`D|i zP!|$OA&Jr09on_W_f<(Ih_P6}BfDQg_)zjPHUJjh;3C)QQp)xf6Cxm}_WeXBLqQoP zv|9^b!m3Ec(Ae!^)Q;oAr6eVQ2ycCEDHuvbdzICPdJN5_iTyKk=TZvH>RcNjwZ61K z=;TWU!!J<8IyEqlzmAV);Sl*wzZd^7bA!5Pmzfk z#F!PhJq^4n6AW%nNV9TcV>BmmnElOf8&Ek8K;`5~Er=ovNeW9M?1Z!K4b^}; zP)cSmna4_sk+eJ@LH4GIvZen3 z?C+>rhGc4zLz5GkA&6Lq?t9QuNm23I26aQb^wi%$;ZRjL;~)t}#0q`0a!GEbZ&A)- zl7kBdjoWbD)L-dJT;m=wia@dwZYKW#tY0D8)DX&%BxMom+gDDVs*I)9G75z%eM{w5 zBy%$(6t%$Ac~D)pm{~{v0L?&D3era^5$$+(y(TxFTi6?DMzkoUjTT%96?T(w z=JxB_j{6fKOj|;_THqhJP+7Y_9$g%6P}V)kw@MnSWpMHjaEapz&VUcM^HA_u$kN3r z+(MRH{$p>oYWETE7iJ2h9iw>i_i9uyvgtrF-oXK}KtON`;|tZ72bY6u8l{$gBdAsOe%^hjHav5oeh(eXMxQ9Gp$P(*FSF#x=dX zO;G;;Po6N+;m83DeYnN<52flYl_VuHX2)o9qS2*Zr_HD=u3jE|rQ9@96QcAg-gHFd zqQ!MmwlKArp7*Tmmzytsc0444KT=5g+ayUD+MP@_uJt?9!rUfCyjiFfjJR1ujO3Ck%e&^-CT9ALpk{Qc(cGDY-uBu1AAG3 zu2-1GgsV**x35z{hqTk>V^*u#MBHWN_C9T+0g8-*bRRHa+$AV^iAwDN_G+99zC!boOKWXMifw%C5)i;dyUrBa|anE$oAz^f9CwO36^Y$J-C3d7rho7 zCC0l-!*f-vxv_AU_V}>_Kjx5hw}n>5f_#~MT7#~%3OG#C?MsCn`%yv|*t5O18!0{> z6{aEfAs~=?eZ58Mgo!+os8wB;u_vvC1Y(EYebTV8`&Xr05X$qh7F9v0ruN=R05Pcv zpgPr<;V{NfYFu}q55DtDv^LdIts9NTj(KE|+uL97s*kl~5pB0-VMfHBI1)&dn;Hj$ zeED)PEXuk729^|g7<-BB7T%{&K&jzw60fss8bN2OoCZ zRW!*cp6Oey>~GeC9G>)y6V$8Upg+c^8>El16c8HBqsD-nR%^==kV&f<3Vnt5AJo0- zsg;#&9o4U52TM^ia*-ibLP>747_xSmK;TlO$7F z)LcFM4Oz*EJW?Y=wF%t>i}wZas&NI9HgsD!HwC-VmnfV?m78;Jvw_%oP z56NWYMZ@F5vImq6hBX$uHiE9?%QV=yu}%y|7}t8*-L<`CpjoCVCV><@H}P67UVOQb z{^CdVGVCkkw@M07JPVo{$J;_~qrFtiX$!FXV%$oo@TZph*^!F$xE>VJ%e(~w=G{#N zIj*tUwf<8;7Dz~Qsp;OHQ|eVWusYOa_C%yF-K7J=FR4Sh@)Su{Cydw^X6oH-RaI?} zhoC2|T8+#GNX3G)T$%t4_5h&$EmeHdOUBH4lUTN{2lO$bo@yXgAHvH*+q*Yu2@3@GfER`{>sB{%lzCebWJHOia?7+iYk_@iwOVIc zWrBEy$ys)}9sdB{s-@k(af~e!L+gqAU%*gV_ZjfzSZCcfBVELxo7m}U*5r9ppT)rJ z#JNQ?NIvA-u9brv(ajqbAzn4UMxSw}f^E_MoR$(PR$E%)gL5gk?5udCa8}%J>p|? zx{1efnRw11m6IwNN3!hX2JsEAS_9-_EK`XQ_br2O6?-?2T)b10jzW#LW+vgh&8oIG z7EXRXLF48}$i{m-Qm?iE{M$k6r57`hTucM|Bn&R8G+Su#jbB2WXM)AsBd9{ zkOtW*T&@mg6zM)b;R|}Nd+X*aQJFZ*y03`I)hkZUF0kD6|Dopn8dHAevJL}pq$y6c@u_d z&$iyC9W82T@_JKXy>V*%#{KHfqg*Qf>eQe zu`{WWq*826o6OKpO-Z+E2vmnqKA+mr4IHY zO+fA{xQ&S28|XT%N;u1tWj8%d=nFK8-{r4P;;V$bi|8Pe*7czr2$2xVLGdQ194ZKZ z^9T1(Osc5cA+?8kry?w^=mcB6Xv(qeAPhi55LGNqwCzR%aby=316qo+=r;AzjkTk1AFTt3 zq6}D#2UF)s*a38XswxsODj2CI_6oh|O&XzK%ETRZUV_v}Sv9yV+N|T_yhg`C{M0-F z?>4G*^Q{RYVzw6x-hfLCipwgWP&!_;qS=j%(@xu2zbK(4pj8sx!TUu;gHGF}LG6x| z30)X&wSyb$Mu~`!klR2S9@H(n#?1iiYEUGFj4U?+($pIm?FKX+{I`>ECf#+YVg-@f zW&|M@7Z$Y&G?5BN7pwWV9k%)o^`?-%QnVQQ>FXy>o>UYJhDUGP_C2c1JA%5){$;c@ zXM+Qe#Mukpey?hxxgWUP6}F|U81*z2n|HX#%XYt7VZ94oZoVRkEQ=I+T<$j{^*`>> zaV zU9JthEkGxUToNz0vo4hkSyvKIa>qlh`dX~bCdhz2YLiVK)9#W%IxPl*=3`Aeh`-9W zL)PYjksCAmmcR`yOsNm;x1xoc@{>}IY1SaqvhD**P*%o4BeLJIxH?*ZxX2Ke>Pe|! zKkhS5=D0V%;Y5?$SsFFe-%0>t!mjM#_0pJQIy)&kHC)2R_LR8*fvu@Z{{XmeLWKx! zNubPeBvK2F?5cKd@%(5IT3G;_^qTi!9-7vMd?_je86aL1 zP@t;mxwK>W)tGUkFv}EnyLyL(W^eWSqb#6k$6C3B72;-zm=J!`(t`B!&wqAjXACZp zgKJchR*M=k+B|~qaoUA0ILB*}&5%XCv)Y9`%wt%Z<%WiUGEUy;C9iAhG_XCW-s(zK zN`=~{);H_ksS>D!H(Hvo1#X00deB4MW`*1vJ?(!gc%AmzKpNw%4FFYPyV7r`<5S0s zGmx#i!=(jNqu2mJHy5DD2fBNcR^^V)qi?F(&^-(vPg;>haS5379vjU7SC*`1@xK-6mW7XGQltlWH#5vf-DuE-dm^ySl-$LukoqmMI2K5nC@967rPtnV@Gh3BO)^0I{iCPvF_vc zj8|iHZsLGZxPhGUJsd%(;Kvit)l0H2|Kv>q;aNNJ4EaD#Z4TD2NjO z0G#+xRhlFTwT;+yp}UW1RweZgg!HQ~405n&B;2Q|^Y2BE6rdKKgJTd1I>iMB!`zT_7-@u@syHm2<6#k@4DivU2=vAJVmK#;Oz zIuWJxKZOLa_aFcQS-cIv{A)rsHul}czcIbf@T%~_lBy~a%lygGuc%n#2&$pA0Jl>> zH-A87e@Oi7EpG~BoZC=Z{{WWOA6wL{WdY)_0Q%LsdT5^9uW@m^%ff*1G$JE(_X+8( zh%{K(qJt1V;p|6B3{VKv$WDX9#;!)*;sSt%Jq-clie~jlLpd6DBg(FfE^h7L@T)kus}L@>-PXf*EY0^fm05UMAyiT~ z56k6Hm4sGlMYPg@GL?`7E!$S0;G)Tu?XvDwH@|CA_TAOw0^szkSW(LaCPFYk zlb;{mSfX7NYS*{+RW}AeCFrB5r0_Xy(_| zt%Ej%w}qss8E#vP=nXiUA_3Wj^!)l!YTzzkjW1d#sX#KD7Yes$?LZ zCSY_2K|xa$ope8C>eL#jMp**2il0bTdBo0_Xj zW|qU!e0*vFm^eZ`XTZ|P+psp$9Z9~l0FpOHAr+C(LoT060p!QNU8GspOZe3* zNREBZy^Ux}H>x=Vl+c0JtK>iruJ^dndxJp2JIc27sT%pvJ(8rzx)4s4VOYr$?+1Ex zB8g(kUtuQTHK+s>3reT2-A(MegJKy^t6t6Cj}peEnTS;e)^43ITHFuDbNT#M5p-;*ZTn# z=<)nd;}}@@nH)wmbMV}v6wQtOWIGF3kb74>mGKT^;?qFz&eHLCQk?PD!L6-%Ps_Qfgr+FpVFW9I(64bp z#&g*ZHrQl)`y`Njb*xEWYMpKyQCBk^rDkL5J_4vuba5M=*R_bX0Arp@5HzZ@scAO> zc_{2q8+0e9odn-;BS#%IpsMQ2as`LxK6NAtR5kS-s#cJP+BE9dBU+N96<LDX7;xE&q6An1JRaUc(6HorwXnD z;|4VnDcySj+S-i{BRqAy@Z6^U!`iv9fJD3EG`$qgBP&^n*wjs%8(** zZftL%ptp+-hhln%MjdKT5Z{%WrzrWFXSeKkF*ykcpOskVjgK{OU5$ynSZ zXL4Ab%Wc2%(BOB-J5hqJwvpqf>_nOnHCs7Z;l9Sde1;;0=UU50GD#2 z#Qy+xdwxu3KzS&5lC55*hnhzV$7Bd>cY_?{ytNkiSWhfY_FtOXb+SmU2 zXrY*sHb>ZivMTf>^c6U7lx<*)KI<^Gs3y=DnNY-KR@6Bo{grws5=R?`&9>6wfVk^m zVm3?Jf$8<4KFH0+)Ghg&QT>zz&&d)G+roukQE~aS>s1URY;dLF)>y}MI^{JI}2?c`|DWd0g*GzV)qdZ z!(P^-qeB>Bk*kAqA=a5P5?e$ru#s}ZKxiQ?;v389Yk~gCtgyCi+Co6>YAlN8;^3|Q zBG)#p3~1a$y$~*^PShFE;~1DDNLUWdS8`-#i6D+Jt!}H~Mw(d7_n-g`3GY?oED@SM zjjp~F8I#6VP`0@8@uw@igl(%J>J7>M%Cq}sl0wRKJyg*o$6Q1#mJ&De^b{2{CA2E4 z>{)cy*8C_DA7#_uxmN!Gv)B9SBIHQY831JjT=bQl$rOTQh`V2*8c#)sN>uBai9TFwLW*!)DJAcP5O+>C>9|{<)tE^ z*|neb0UCj7(9Oe>7^}_-GyRS_5#dzimRC)aU(iTGEu{qs;0Yr^E`vghI^NaXy<>D` z(Y7_3q+(QTR&3i&c5K_WZKEo-Z5tI=Y*cL9&X+pp9(?bdciz44=iNW{UTf^p#-1~2 zZT7xKA9GB0U`pfF^=)$tb-%Wk-j}4GZmX`j1GN0|1fa2FwB$&*P0r}DOqH0^K`I3o>irNqkf zL_f=^-gmN{dniXanFv;ZZ_P9e0i_e*pQM~)N_K5wS+Tu9l+WK4MTSG~5snWz6pNZG z3%oDGh6=`TYo6mdYv+;g9|&o3aJ#P7jYb)**^PeBkz0u!kuE>q;_0bnDoVg)=qm*} zQXv#J`|Z7;P%H=Bs5P{`EQ)c%eF*>BQeDG-O>~ji{(RCwA(M2aaI!tdQJ?tMqgu}a< zj7-GlHF`o#s&11iXk3*CI+KG&BFILD32EY>!8yq*1}s=5HupIPIoq}DtK92&p!A}3 zIAJLuz5VMyU5+%(LEYJ58nkicBh!U@s&m#YgwZMfX4(;S0YSs&~P4rn<=-?y_o ztCIm4JcsE+G<5NgK6>-8;X@M?CBm zzNX}n*vQLr@&Uv;JQ4$raoG+cdP2dsro%>V@?)$3y!Eqt>VTEI4KwA}!eE8eG|e0u z!obFi03dvgrR+5}kS%^5POLGrVa?D6!xD(k6Q-a=P;mWh@Dq>e(DHg*UD?WO`w&IB z<}3@t3JJx|R~*z}bapggHw=0L6Tdv3hy~DZsYoxw(Jtb@Fw5guc+(b~%*7-)38O)d z=nifNL=Kfxn?Z8ca>D;qH2m4_N_e)G&#?HY5?BU7GLm#T`$B;fh0c$z4W57^XJrrt z-g!UEO0P`|@438YDafJ0zU$YI35k|)EH*Xu18v*^=#oqWnoC3bR>r; zu52_Cd#<9xR`{7mBhny^r>?8ZnFX+?n9VhOfyO(p6A+q6Yv+ZOgXcC zj*=)WEtH@hHgWR= zS9rNhQ-c=1Vx*PaM+DGJK*3;q=T7dj=DaLvymuC;+g zb((CtgK>fhdqM&wVeohOfs*BD7kQOE$n#?m3Op+3?s5$)2Zo7y?~GyvTIU|`a*8g4 z*bHw=#c-?C$2-WA$XUL{TAm0ow1S+2y&mFW6PSxbqrG6aG7lI7>!^)I9bA0w&g-|t zo2RZSRE?$^J1tleXLW-_vquptirJDL)kdt4J*4a~grusw}3V7C) ze&d6gSJlKWy=(;5OEX(P-ZAdMvMdf(OJ21c8P{xaT3=S>Yu_4-f16M@=^Uevjugj&QgLxgq`{$zQ~D$z zPK1c-#nAKd)9zSH4@s1QQzpuv1p!#Fv^L(BJ2Q#v(m5IZEuG~R2JsGs6B6{N+py)3 z2tb%E_4rp>BA@QcX7Y!fRpdlV)XWPJrNSl%TVw6f8wbwbZpr&j!9~xlX!vo4vt(`H zy&yOfC4d1qyhqffPnxY~GQ$|Z){rR@j=|IYuS+Fn>yhc@ErB3U_)SeBSblx~;f#&q zJmXjR%e)TRDKp>@BKXz9%4Mx!b=gCpvm06_pP=Z$j2{Rg%f{gCcxq6%~(}Vou+a=DgI$y zG|S1>o~pW`I8TKMNlNqtOY=4*V@)ikq4K&f)6>(GyfS^Ci!|`dag~sb_a-);-~5xI z=|Jsw$~Za?lwoL5R82cvD7H>;tB4ob78g28*L>07fDXSBeDhqXx$dc1&oFB4qI&qxF_ z`vFh|L`RdWBZWj{PZXPFm^su9M{r%~24XqikKe4nwP>M@ZHye99E|m?|6JJ`SU@u{ zvl7q~{JCOgV`5?ahnela%-q}rbW+APrcP!A49x7GMg;;oQFALNV~5XAD}5(pVPivE zBVz(yUg-ad?3Qt+K5nzaiqQ2!aSO6H0Sov68Ubb?3BJ4n(uK;?Xyy+h@Z+I7p+G#m zsHbOr=h8H2d@K(*Q9jZ;@4ns}HV?Z>A`T{4MG)7`rc0 zm@!&J#f8QSoqY6O1-x!;tLAzQ-+7h(cy? zho}?NEKTr~7YTO^F&PYV?WHJiR8c4rv zA{5J4(>>f2BIQ)7gGzsmMDE4$QZN-Fbz7z4;69hVG6&^=n6_6N^RFsE*Y#_qv|MMM zubJm*4br(m4Yolt8$Os=9$vd2KRym@DjXVPdkSc_*jU)*r`R?8^pI|~?Qp@676E54sgktpw$=JTzk$4HmLHu*2g znXSHji%;xUMVAGOMSC({M`AlUeAsU+5VT4bcr9OxwBU$gw{`s{;LLRkSA1dC^5vUG zP5zcna2gyRuKBlKG37vQbc=dRotg`Mp+~WMDxT`QGNL^NO{TWC`SVrEs^$>S(Y909 z04!9zhKI?_g~;j5JaA+Qb*mX*nmUGlFGJ=d6wV3UX%v*7Mqj^FhX#wWhCrJOE1*kp zJ@Z`ZXLSlmnsE@f^NnbIHvK}0|7hk0?Niev*w^Qk3e|?n{E8_6K_n`dt1!`K6dV;Z zw1v$jO*YfPMph+WgCZ1+05JPn@aGN=X9Yxt$H zI1XXSekse-xOHwEG?dfYG;*qq;JSVZ6uHzOV!9-xp2W$)SZ{w1?wi=sf3!2v-#63p-}j?18#!7-`H;YL&96%f zL?^Pul#MQ1?I}u6_o8B&^(fB1c(AjUixxmM26e;y@@c_ zpv}G$azY`r$zWXt0A?ZuOdm^!7A>UC3CF9irg-43J7^h(JpqHtd-rj8MZ<51VkA(=hnEP2yI3g(!Nm(Rd5d70wG5lD@Q2kbn& zgppH)h{E5N%e<;k_U+}0{tRlRNyBSO|b%& zLqM46Pm$Cdz1vvM#+0X<8bPC3fw$2WQ#*PFG z^naG^KQ<+IJ7WSmIek;(KX=l`M&|m0wr&KPe;imiSZEp9SP0me8EDzrIkf+H2szl= z{YM8uD`R7$|LCFQU~c^%9pv;KjBT6<7#RLGNFiGrr%%i0xS9WekOK54wEP!Zu`_)d z{!IK2D*bgb0)|fJwl>goiUf3Gwo10pbixFh3@m?{F#(;Lx&{FYD=jMrBLUmzCp!xR zfsM13mG(b}{2TuL&qFe?vC}fKv;9j*hR>h*$1wi}o-B-iCiC9_Pt4JXUDnHW-7Wku zLggdn8fvN7cKB8r=G~gzgi~-q(we6aAqj_8n)1<=^|2t>VS32s(X!&>!ZbPvHnsPc zD(*U0Qd2A+A5JgC7HmQ0A9_BQWL&Qv>^fgJvbAw=V3Q|dpx}GhlPOG3AWY$wg@vc# zl8d)?xGc4|6Du3Ze31C?pPqi6u=kvj*VGL@@WCbHe=Q!}>Z@euz=(8@Yw&Wz@-o>P zMoP@=Zmy%m zX|MC#e%8Slx4O6{0~l6(uvlqqvPlh_05OS4RwQsxY$R!vE_568>do%y3<0htUd!JG zgx0SXBn6L_-}BfNmx`c7H|j{$>w=45^Wf>#*mzBzIWx&k)sJvw-wY!E$)EuL_DdrrZPo#UYBPMZwJ^B`|@m zXp!dQY?RjGO_-Bzp4Jv_SLxc&_;RREFbeo$8`?xZb55jPCFSfTV$~Z6C06NU> z&14>W=-7CrkX2L~wDcBGIZ}{-ak=LD3&Aerx*QIUyXoJd-FQ`4G%T-oKNkpRc}~OG z>^zkf6%)$Fr3=adf^5QFrhEW|@!9~Qz~9JEo4aa#OCHCy^O~ z087#(L85Uk%d9-80fb+O6!T!gSfJ;yizK$?;TlZ*pjvwF=*jp&+gxqQ11G61qUN(` zvq`Mor*84oGIx*~a&v;!xvgly4ehgt?l<@PY>ndOOJ&(9a9;7$R{4XA3cm)$yknUY z5D%_+p?Ip3yn22j?Q3)H@*ozbhrrZ~g`j&&jaSIVDa)#zDX(T%{+8xQzARuk;e*+ihzV~)BR6dj*7 zB=+z040r)B*KmS{J5iJ^pTwJb5gm$asA+LoI>c+XkjuVqed zMexKIaf~g%0fbh9ywMDob3KI+kG*fEp%6bc&mI&2K$m3_5yQ6V*YitLzp(J?-%mLq z>sUH2VW#waz+vZ-dZ>s?2#Up@pU+{a%c0DOTtiQZjEfhfs;wLafPli4%*?qKk?4A{ zzk&rF!H51E9R16Z{8t=hqyHPm{1rU@3NrsoaP%*D^nc;#Kd8cg#?e1``-xfqgrlsC z%(V0@EdK&}pAh>G%==H!{I4Nd7};o9SvdYRB+LKrkjxC9XwS;@uOa`&oc_Pi{$EGQ zM9)e~&-(Asp821K`FFJcGxq-m+V81rmgBI&`fTVj_!3l6Z{&hb{FcnM&4uxXbeBj= zibI)6et(m|^Bl~YKIbHxLi0%CsV7>AqxNlEdUu#Yo;pC~%bTYhWbXX%dQ>>{aL{=Q zx)YG5fAetb!s}``<1^2w!dFE@%bejX!swB~O7Q=#aP86NleO*xpYz3=2q@zy_0YZG z0NFd+6e|Ndy1RJsqUaR!hm)yKAbRI-tMfbZhSeg9dyF6e(^q4!ec3?5pbHPv5v@G!D3-6u@K(Tx$2yD6c2TcPjqAuC0)mPE*5jiPfK-e-E>~| zTxUnMma%Zv!11uPEwC$I(VwagdM?zHZ=$-bhG!#MgR?2TYcJ9dT8>~ok2wF;cFR7= zHxay1c(`te#UQU{BzDTMHpL~CPtriYW`ba=yCRP*#bzDLaQ2WQDiQiC7ij!*tNEH1 z@K?TO^+3iPrd@|!$C<~k%e6lrZ4!FEC)|ZdVWG{1z*)plK}Tu&ss`=Omy$c&jO@#W zVHenc6sP*CoPX85=V7kr+qa|0Z3XvRAhIyxW)m+pvoXebSSNLtIjJle)ml5Qh4w2I1bz*h_Sbow>FH(N!=^FE3mc zGNB-~qb#Cu?oDSZ~*;a4?@a3Glp&v%0`6Ydv4ZJ95v z2`3K1IMx=Iyw<=+q#$m6`-=X9;8bz9bIDE^yLtL@Y`~8-2DG)gOej#KYw6?szZQ}0;# z+6S8J{U)Hr?(~T_#pN(!rm*hl%ynJ2@s^|2xUM{1Us-gS8(c|mLU(V!D*#jor~Rnst_D`Re&Ek}J_g`HHez;$WDLEF5yXqVG6>$*)fs*}lROq1NBq+NRZa!=}j6myE~Z1r|Fx zeaCk7NBTPW!03QU_7(r$f5r5g19)yUO;y|`1;tIgN9MwmY&U4rA}1sRV$5MltUBf6 zgB9ZWD70_Ib?&4ObmT@i<$Zev-S~PVM7_`_&1akGj5F_~L9SKNvwp6mR#{{6TQJ`V zF#(nBc4R_`=SXi#T$l2-GV=3gw~fVM@P+i)BFINk_yLIj43*VvIhaIs7UQ7@P&ysF zv?8pd1hnIHD9Ny*=u#o^Iwow*cG?aim2Ie6DtUdJt+Eh-Tg#koxr8c(k|RmqVp(px zf#XUfp4@N}jFP@oXSMnZ_MW=_$Xl~fN&}{$meQa(w4)c@Jp9P=(0i}Sq7k|s4=>f$ z_x_cAsWU=^(FI*a>sm>o1ZDgh>K-R14dP{Ptj^oO-mGwTr%mEwUVZNiLR))W&%%B6g-h(irqmK2qU z3op!Ch7wK)Bb045Eir$C^L_`Xt$B3+cbw>Npv%C@%KQ&b^p6Mc|1F&84{HB2Ct{%g z=co4n#9;np4E}FY^#7JzV4(kJZty>g$;wJk%lvPM76bi1r{@1>FMkYPHvqfL%#*glF6gd*Kwm^`aQS2PoG@h6k~*l`(CD~({yW3=t6zJ z8l+TQ``0glUc6l%TuJ8`4Ros8;}5C?${B77kbmyL#GeTXQG8w?tW`dTCahl$!DMdJ z{FKVk9pCoTh8(@)h@1*-tdsdG8rQylzxnfukrb8e^jOL&(+~WoCUg# zX{<=zXq+g(&#dI#-%UOjiGGY0YPwu@z(KNMkaTAE-&TBPdqk&J@jbcU>{G0_=C6*b zg?5F!h4b$n4b_qq)i?@Ih}u3F*<=d8r6|vCrhzBg*at3-vQthYf*z0IZcAa=Vo1*` zl0{H$rPaI+>G8(b%Cje?(m5z7ra6COWm)Qx!p2J<6i$aGY;$cFhz6vXlo-2%3vIiX z6ju}mhX}jEqz{yRZiguaPE@GHMii+j_SltRvhu5)4$VCLdSXXtzeg!lZl%z>F^xbt zTVmC=prX~r9gCJ2f}`5A4IDLG1bNffY~YXLCE_3!Z8z3&sM=syxh5xvAZA@_W$ptO zGN;z-+f7lzq`eZ!m=_Jvq5Rk876CQ zW+a>eObjg9#fqUI^MKg1-AZsY#%G_HNQB3OHN7A0eWCEXUACwFEC!f{KZU{SI@BQm z^f#|xn1~a6x4jukehyGf@h{myVnZ^M^nv1g9R@TJi*u}a)_XJJI|)4X;$oK}KFOK| z9+s>PvFkRg*#H@wva4VFlX#|X_tAbpj)q3soz(@>wva`23pk3g25KW~W@Q^i3O+(( z<3^i{xtbF4ioNc@^6`&~x!OhUatgF8OxNv;;SEKJDWSH!@>Qv{4Af0eef>V$=xnfJ zB!*`*KxFxy=_y4TYQ&M|m%bQBu4lk?kS5#*L6`^Dq>lP$F{ZyDsRsgdbeJCa2Fo=M zR9fgLD=}oK{gPx3Q>-CE<`SGh=2dK))$8cPyj5%uJkq7?S1u5EFV3yf$Y}4JZ}%b! zQ9>?b_i7uxF+Ufo{B;U0sQck1YBO<-%!W8H&%K#i-_Th4%&*ZQsZM!y^LevfiBtJK({X#it6Got&iB)STnEj{~2khn*D^Qc%ILB9O zC*5;gm<%W|I}a}!>d>MKj|VGSx5?r(&iN}Jbz;J}*B)>;O7~3)?S0$+V0yZGHe~7; z>vqIl>sx_7H9xeZ%9GQO+|6rcN4*>Hk)m z5Ic6v@X$(aK-O4J9rv5Ne8U**a}(|_Ez5cei?LUVycJp#Ab+_~t zS@RC%QiCL0b(u4ZLMhI9qY3XOO4j343}@T4Vmh($@!M1ONx`9?ViTu_AbgcjZxY!{ zuEI#Ihw<8V^+KJO1b(YsCSnP{(^dsM$=0`pKq0xhq9|i80PEEp!z=1D{a=kQAkpqK z$+cl>@5r;E^seWpTZi>|UnKN@m&#;l>}IP!AB#S!Q~H?0SE+2O_Sz9qJ#? zL3_q^RCfiWL#rKXT9Hd*l{P4Cq_8(cWjkOXp+(F$qAnPWvdA7zGMKPKN`f~RgnVL` zJeFIFq*1X$p8SeYqP9&!lA$`}B8=A@aVK{gOjtnT!o>HS`m%?SFmgo_F_nZ+^2 z(alAo%km7)S|+ZWdLfC|<6Pch-+J(XegDJl zQL;nBim(>@K%4g!8gKs=K4Vt`nKkc4?n&?j&Fgo|1J*=9nO+>COFR@y5V_^;f(aRg zp(`56sA`>?(bUjUlX!r(s(}6k8+`G@N)UOv6^3r-H<3iHPgs8KG%L1cpm36 z1EA?*Y)_}}EX6rQWj68s24ToHMSmLX8ZwsC(u&QRcJ|%amTmrf1a~0{cEj&WM*$Ry zIb@lFy3JcRTPfnN(fhT#Udy5{vBceTS|+OnStpag#90~*8dj5 z{{IvM89s^Z-%^f$=J;1CEc&S)3L85bI+)uz**g5O|FOvETYn0lA_9M2R8r;!#t!;_ zWJ5)L8%G&^2M1eM8bMntqrZ6z{zb5)`J>~}Fwrx83aIq-pKnY|e-TALt6oeU37DAv zcnj&e zGPYLv>!q~0qocWvsj9irXRQqj{a?QRGxpDF8)HTS2G+l;xIzG7MdMG!l=ZKY=|AMr zzxw^RGvEp1r8M7qq4B~nX=E}< z6%Sw>&PwedO9hxP0!X0%ut5)8P{e-xkWio?P~ZF@mE|>2MS$^@HBa(mXOGRbJ(0?j z4OdD!tz%spcqs4Jge(V|w&e@%2#nY_G(2S?lkVRqE><@>r#nq58y9tAZM|bZ9xB0l zA#-7!khkSe>SFAO^N+id5hK>X8q1&WV}?1}*YdxAFmQ80h&G+p$OL^reOnDeSnM`7 z`{3WH6N5%XiXl{Twzu@X*zfMTn-RNwTbb%|p;A&q3q$<1FVJdt5>tEP!?W^?m7tmX zdOl^RONX@X4*%_)O3uet?82GoQFA*Pv5YFXuA|;n?4z|2o)={A3G(RO+Q{u;snFpT zO>n${&)ulOHz)&+GZ*$oAa~9p1rX>a{>s4VXT$%H`w{IE+!eAe3~(ajjP?o85%uK< z^@e}Ldqefc?hKO2MW14uemQi$#qogV3GwmI5_8Q#K8!saHRF3m^nlM4!q52#LX6F& z%SCL!mOMmmKyuDwb%F_~qJ(syCfplsAMWks0R_{j3#VP;DG#0ZE)w$z)Dt6bkK2TP zLMJ9t1GGelP_?go;pvj-RfRPfEpT>kj%~PCLdp&BIfi+xx_EcCsUt&Qc9z}CIvR$1 z48u4jb$qz5LFeI_%2xZ)Y9mcDtxWFY#T7-n(Pg7eD=-z^B}ieUTsf;80^Keh6G|0c zEBFqJyZbT~E%lfO2Am2x00X75?%ncXS1rYK*UGCad#U*6ZOue(*;#;ISgf^z>MkdKJ*!_~lLDR!@1cs@Tn}^S+uK zF#kT_r^|pof1PLlXQ;PQVx%>2uCWzSbbh9LS(;7yH>g{i6?R9GTSYN2>g`MG1S=Re zh_5H%9Ubiyu1M?bRD<$VHrAGXky-I__y!c#tMk&ciEIAS^e_CHw6B}|*m7OY#;zd4 zW-hv#Afp&QVXI=?Z|+C6TBx8F{HOfrhe1MKs?{SLg#9c9|*Q{Pr*IiU2=!W0XNXOAqXR{zt9n)_}ND4 z%aG8AD!8eF8z%K+jPmOy2(=Sb6mGi&QR-KWxC(@N`LQc~wQLtS1&J;Q^#ajHAr_1~ z>;olZU;CoZmEXz}!IWC6Eb!TEiE z-igLZ=82w+DXm<7C`C#yOWs_NnE*B(NnZie%3d@_iCAB_Xw$8H+NywJQlXQf#Hfhk z;M#l=($}ag8$08f`=P__@N6!5T?W@(6Wb9n>WJU6k>PGSC_KhI(qLPP4u64GUjk4H8-%GD~R;^FYKPZTCmOcrF5-*b-=WE`s^EfB2(a5*L0ud9q@4kc_SD-45ILbeBB@Xa+RZAy^tSkq#>-#9yjwq- zO9f^hxAYG;LawKH6Oo{8BSq)+>*A2vvBUX&N3_=I5iuN%MIh-YTynxVN_WeHp0=hg z>M-=}!j{Ob{TyU+qNNqS-*Cr<^_LL+o|%)ctMmUcW-n35jNa;3cq^)<2vx<5A< z@Tkz#UM^n(hb)@JQADRR z!o_U5flJGdd2I0!R;-gmuV|^1G}q7dD3D1be^I5EXSeSUr;$0m0(GL#Uq%tD z6b+;xnw2nSN_g+9L>hw0ld0}>7*3WKDe8!Y*ULs!O+*Q`w;$_OXHeo{{hr2W zhvtjwd8Mk5F&#Sr%~5K)=kI@$gK;sF)v8Gkny{e+L4XBUaUl4zf;^U8KA3x zT{&7QBrt+$!$h^hfI9|77O0LC#dJBme$$UHs8ubx6H|=nX{o9j${x5IY>7HMQbGA{ z@Otv&HO8=;y-V-vjgQY^7yW_eiG9ggNNf?Vd?Zkt&EiLEmcnv~5GGbta}0#)?lJS%@~R-t_w zX^sgv^4t)BJIimsVY3M5N2X%-UR7lz+t_AUxsn2&TpnY*$aYP1q=J0S6fW5>nGyej zZ^I_OgF#~s9F_A8U3~qCb9*<_;?}U@8VbrtNCqt9{IgyYmGE24(Q8k6-|;s-=-4iN zoL9-pSr?(Nt<9s{Zcv-(R-w%&Z4_ z^pB2>8jG;vY~sby!J<=JS*fX!X!5AsgVWBJ1jk>JLp*)Ak{w=lZp~GHPy3w+7FU?l zVSeWdd;3@&SsPK;k~=m%I!!y>tkn(tsoLyiy?%nzR3X{TYY%a|8X| zvL(7(?p7~6xhxl5=j2|*9nj}_+n)N8q)tm9U1I~3_Qv(YIWKY6)^eWH1<@ZF^;e#4 zGL^we=@spu=fbVLoPrLGmaDq_J(CBPmQg3nob4)-x+H+g_6>CsI%%?Wf+w2e>qo>6 zXbe35@6W@|wzZNKm8z`iim8 zy#_b`CPI?Cdd}UEdvultU`ryB707ZV=bAEB&0d?*2%)N;_oz`#B^;Nsv1&%%q7fn$ z)bi5uXt0!|Ev5TO2eGYYS_|NGc!%wj1vd3tnAf56$;#OD^U^~--A1< zh*3`XyW3S|Lc0Jz-{Gsf75vr(^z@x-GkDL1%Dd*pX9dYX$)@J#D)kgL&x42-HZD3- zySE6#kG2n{Y8>4ro5*rnjWW89)|>6pPT5$N%WljT@51hmm-{2Q!a!)M2f;xMej%!CDQ`x5ztgf#_Ufmf&HnJsIv%mzs%AjES`kPxl&Lyn zk93GRTxp2LUWa_2|LcMjea@dTXo>LS7^J&}*h4Ld6u_B-p(uN15}5|nWu744d^{Yj z+)|ZRnFGHtOgai4+6?*&_RZ~>M&r$0(#2>T}UtSb_drFln49C^fMUG zNpLPCUv%v4Cbes}*nZZx$R{XyhtIjFDV(qCk%l`}gNa4>V4O(@7g(n;kV_?^N(3r1 z1mreBb8R@>s#_)-P#O!s+*#p|Yat>gpm2|J4j1AzCrSkr;)rJ-0EPVUyL<;SG>)?l zB(z@v>>ERff@N`f^U8dg)F5r41Vt6y*Z$~VF1>JQ@*i?pxWMQ-S)UvAPFFCkvD{q# z9ZZw?W3IfV)Iua4AAjRr&bH7E5_UH2r0dw3H+o~WhWl=Bp2F~L`#TfME+k#3H%9RI zZ@+T=LJ=%{V2?$g4?ICEp1^X&>e3er@MkArZ(=8)5}Ccw{Gi%io8?~ExIWUZ$C*^% zCS@F}M4h}%z)|$he=<6vrK399y2B^X&}eR7}(X+fcJ??@W?1-Wck94>r|_v zmn)lI0i#kdl1T-Y5qf49tR)>h@)0qG1f@Wkr;#v;2-)5)BY+|xGe^N5EGM6_uecW6 z^&n#$rmVpCrh@x&_Z-5hxGk2u=KQcTQzxwy6Ymg-bgl;2U=d< z86V6U7TEQA3ms!IO90l4|3twxFVyupkaXf;9+;m9$6&A&02pl?0HPpiC|{PF!7&%4 zR$9>xW1=UI%2a5Kn_*0OoYuQdcH-)7xHz>ay6xPzvE;nQ)+ENeT4%0DPS;dJ*jB+B zJIeQX{Dw<);d#dN5)bd>vYy@X9&G#L;%>c>6hq4qeFuupFAMUQ2dzf_Qy3{I zf-LhH?LLF6JbLa33s;;AmLqV48WGc*DBWkldpvHOKG8zUu?PqdV1*+&;<|(VxVO2> z@$h@G{Y`Hi$y;kqW~nCxEkTN&qhuj5zqq5dj$#*a})4iSm!b8arfrO z{8SaEP{QIJR)Qwt&JZc0oR=pRC* z#DiBu)kI7YMQjDDvrN2{&Dh4*RKW~R)c~B)gkwRl{)uxn&ui7r9LbaH6a=cF*Zv}GilPYLt6mjk0FL2Zv84D_f%#nzhSMW zB=wxi(g1Kx4oQV&bI5OkuK;5_E7JvPWkB;vLWhc4@6^HQabZ}<=bIM`Gc|<#c$NKz_fOUG#w$s1}&A1zBcx2 zA?f?Rll$eAmnzR0y`e=*ZJ)&?I2wwD^&V>+S%m3YyXtHD2ts1rP0b}VaT{vNwFGe| zur6BNPCGPI5jAp)E!5j}pjcEiH}@6LV$U%);%78Al#WMu%#ob>mcAd5rn~HpIW%2H z@@CUTX3L_MJ|hj;)UV!r?vv(ML)mj?YC5aHZtOBdtSF;YC4`*F#9#sU4){ zb8^SVH_`R9zE^EV^L&BOGH}senVAZBN4vnMc4+v8Pv`3ByFs?p?RlTpW;M?wrwNvP zmceu9v^=ym=tujcWXR;f2tgxB0!MBs1&v{T6W@;_Z&W70Z%FO|V_b*xi8k% zS{cJCBeGIl(Va8dI<^UvT5lZz!X22c0tj_@7-<(Vs0zzcbu8azOX`LZGZ3 z#~C}OYY{#YKQ{b);~MI_9*MO*<*w;?{Bj)F|Jt?udyHu76~gD5Ke^sPpi&LX^0vSu zn9q4ttAwty)YV#d(OviY`GW=Tu+4O+i73;5bGiMfi#ed`FxcB%xLP|V8f8W~R9`Z! zw_uZa%3qim%_vxTLP38lb));S@MuZ=z5r>IM|PW%%&!cg(fH($lRfNwuQSTMHhq9qOVThU-CzF34d>WK@e zKPd-%%aJBu^eb$QI&vSMYQJ&sVq>+t2$@)EZdlP_c*=JSAUXTdQFjkl`)X4I!` zdEjd@dpcGyfo*kJt#xF19>sjo-h{_S!_&fW3pHWeXY`=&Z;OiMFYQW2N7>3o<(2<&;rA;fw24E?5 z4r54NdY~l;=xH+PwR&JhP7joBM?YB^RD|J?TlGDa@)>T>)m#<7!c>1e!=opCC=Kkq z_H9n4O`9idQUoJH#Hb{cW(Aqi3ubX@n17VXyq+n5k3S(WgqUGuj&jLH#ToqK^4%7@ zcy&qWL=o!8A)@5#EI?;$js_-T{%# zAM;3?StvSM;3PjBBOsX)Ohlq2erCrS0=d}~Y+?DLPh-V>HmrR#nQH$tEWdRu+w-(B z`xUjhScl^y^TI3618lOdxwvYlH-qDjq{IA}uUN7>KQ%WA`BvPTeGkBnDf}oVenp?if?hIsyb4m^373pu9HF zJL{d%OyN;tg8uP9OMMFd>}TJWdQNB3&xEpW4c47XCplIH>rps-a7Za#^P_hqSk`Gk zQWKgDk)|T);kB5aG|3_OlzCVPZCp5#TGBRo5tj~D5qWebSwbd-J`7bz@b90tvXSr#6{qR8cT7| zk6y4;NERo0(&G**bzM!pB0dzYXLyivC79ZiD8 zABc3zqX&a!L3R?<7HM3Ix`wO=%wy)ZW8*)QflB-Ni=!CvZO}CQ&!=vm;*1DGO`p98 zc{Rs|3&_93Cyt4wWfR|!C0>Et~r65C)y@a2bf!L6XG_7rPZv@IE#lwJ#oJ)9d2BeGV*Eg zTn6W!>8>hhdyJQjlod9vi(gFNy*=1Kx?3izh^aQC74bHKV^IcN`F+;eVN}^r((g$W z-dL2cNSxi*-KVAfCPCt@yU*R)-`|2*r2gGZX@SC+&e=TYinoqZe!{gX-&|P#O^AM= z?cV-w?;d`fgFq~%{{r>bJa7Ry z2f?4zkc2=#q(9#kAn3jwmtZ0Pwl6Vbp7Bfd01}TC{PKNUdi9#ZA?X4I4?yGN37v7< z+^9C)r$+`oWsqQ3f3s*tn2rURWjKh1%ptW({S%CxQBpxFC2N|J7kYV((v0mlBz!xu zfV{wQQbAw0f2tXS#Fu=J)yiPsjno*}?0q1WtMrDJ3kjPyW^hpKq-9!NWO!qpqS11G zbo*!KOj!#tDNZ;}GPi`U^;FO1kY|q38G9k0Da7aXqBmxKKJTBSz_*T-__~Z+1;ni7 zcwLFXmozyU<`|5rml$TnSwL#AfuSaFa|S4-4tNUdW^&WebckyOgxHhF7X@W8&IEge z(&5z62ctUVXj3S+H8vqrkyoHfvs%14sJ6VyePGwd4cA9lAu6zF&>P-L!d`P91NH_@ zB-ARg&_;&i22sJ-MYx2;V4AgHC*D;danpf|4-*=7W?OMlu5iB_D$$@Pu9!q6+S z#~OeSd&ES+SAPPQi7NrNP8TuR2JfrTZME z7!@sxiW~KE`4F8`RV4j(INoWv z4_E@Hw?-IKg{L2(v&O3TKayj9?BH~1_HzjTCRmML!p7;v zia(3X>*1eAX3Xu0=IfQD$##c&H8p3c#exf`+XmE;0?*nS6tfLmA^l-LFRrDbZ;dX6zs?LF(cOc|11DJGgTKjv{W9U+ZT^o0nTQ zgZp;ydHq4d$ybSxuisHS;$b$m@#xQM>ziv`3%>>YAJYCYNV2C}|A*Vgv@vblwr$%s zrfu7rwr$%zZQHhO{CmFVcc1${5hvm~5zmVq89Q^uTDhw#ckQb9TvrMdC@GBAm5ihy z`=H{b3ga%&p#swlp3u>uO)2;l5=hSxruUlSvKq-y`cF|@|^YPWoab|W*XdXreHp2N;Chk_%T&hzJ z(!?RRt-})v)eS8z^#g5Eu`^I?2lLX>?$fso@o?jMZ>grE=fr29fR7`gOYEq`NFncS zfL;t{F99iqtMeuQ03EvCE@b^R=<_HssknVSa`6>HiC@5}kw8@unE0bFKhTppIgPxR z+6oK41WKb570+p$**-w(Nw3MbbiXoS%a>bTO94AZ_rr`g)UZtVjU2j<4uuze<8`{H ziuPXk-Urc9&^ihG%)dV6S(WM$xI(?jNT>O-!Thp`GZ_X;S2u3!m-SgkFFQk*^`4;M zO>27$?X40`*@MmIY+cLvtw*V+eE(@z)W&4j-p_t%;AUF$%}wSpir<*+A-ypVzM0;E zFODk!;R_I~4+kV5tfE&}=taQmIH=n!^#IM@96i=;yDG>Cgc8vdUk__CA7YJk24V#) zYt}&Qjk5lYHH@76b5v<0c$vNBG!!6a0wCUF3M3iTL8s@?YUqw>(2A~= zO#fW-KHj`n7ftTE&_CIo(iPnh<}`IfJQ+Q2s;^yXcfLOB8SXW`E&ak-Tl}@Ev#OxJpkh&<(hy9kIfk_kO~4ix2mq_kIJ;Ohht&J|vXssXALxs$Lr;&^ z>AukWR_J5NXQ`x%DG>R(C|5=)a{h_2HzldNUDGQ}04fCb)X(Da-tW|B2$yyDWUgtK4#noSkpK0N2ej+ zAH+4b+kJGk#NpgbY-!y%fT0`~73Jd0F=TCfkhv=DaDY%>pZ*&kfUBH)Z)dFjhi@2- zOY%y@&JA3rz1#5>RcI)P>fJ!6l9Qn&_s(xWO3W^VIvq@L zGHDpB5ZE(04oU0D9SQaO0v}{bz4x1EFcw#+A96oC(UG z6vl$*WW$Z*&aF<@D`lDzZc*A2?xDxGS~@daBUG zfN&)N2f0r2nf68;_fsR(WoF`wviXA^K`E#6$1HDJrXfS;)P2O}onJDZu${tA-ce-l zzIz3`hp{zJee0IN$*Oeh6@c6#d%p@x_8hd9%d@~`kxe3WoS~A3X$lmFC-a}mM%B!) zN{ioy0X3+)eJ_O`Va8O<2)oKP87=yO;Ov6k7MKs77GSwqmcPH(ZQMn#;8;|vFs}oT zK=vZIiX~c26qwRvp_f_r6{#>BsDO1IAV4kClyKXqDzp;uxK>&}ycY}K zfVsZwcU)VxWG`sp0^0=)EuG3!wE*-!%!D?(o)Z`lFC2$`;PK6h$?&p&jR&KvtsdvI zH^t!o2r*#h{!ry*o}0!eW!NWY7M-jUybr_7X2Z`<`vL}G~ zOHrPTJc`tptN~Sz0>(9nGeqN#kNhOc1Rz82mYdye^Bu@XU*253h9M(*_Jg}Y17ely zqc(~k?7?Ftvh20Gmip?emvbf{Mrb*4;f2_of2h;=l$_#Ns-d7$eYmHolqd= z^O3qy_f>7_Bk$xThE*;7(;o_^;#E`-sd%=#G^O~G8LuD9%o1Q^;N z!-55`^7B>~*c&^kKcI!q0*NIL;gJg-J_PIh$?efwXk7T>x(e#nBc~E+6TW}0s&Qk~ z2ez@dJ|sDJf~7*Xy1cQp$Sc$~PyZ6)%nYvgc;{|`%Kqql=d$XM96RgrbCnxAn@M=arncn^T5s3b425#bPG-&L@{UTL66)Tu zox4T-CFcq~A<}OKav_>;_QRTAa|Yec5kxuH!qun&=F|hw5jNMG>>)4Hj1j6IEnf~Z zu&G`B0^pq$!Ws;p7mV74kjcZ<=<9epxzf;~psY3mEN-zvg@bu7QDb0XYLjp3l6qE`M$_bw|)aWCcMol?gjQwtW9#4`^$A| z+6!!K?BG`xS8k9wLF<0O^e@_nm#q__F0O!b7t(Sh%|EYe+#8zAP=KYDJHlVbHm~AN zC1sDNg2muj>{bU0!G-x{0VDfElYs}8Xb++ZC-Zbi@<&NYh^Pt)EDE{P$pISt^aL+D@hld1e2 z{CY@kRt+wWU(uU07q{2G9d$nST-`1e0y;JIv_vtFwixT&i@Z=t0h|Z5l^+hOC4@q) zQaHi0CF`smrbo-icn7tV>~1W3I|#`-MG&*gzaFoThif=OzIsF6mVNLmOIP_rD_y}m z)|+XW#(AI~V6Ws@OW-l5FO)}GLgFNe71MsJZVk4ctD+3%QoiP{3HzKhD>V!q^A-xj z;`Qk-YjH$#v?2^jt>qNKua+oo0$D%u+pg_E>eBPJ^=dY>$xe}Qr%)~dr>`z`JF=e7 zWo4%8>mI92EFZP@bMh0ylv-2lZ+v{*F4oq@ZNTna^L?4%%?%%4H+^=|=PV~*clBNb z=r?xvW@`4OwC8r3?d5!Rmw#l-WNAP?x|D)+236fYVRhZB`^V%657cyM_C8H z_6eP;3uRE^J1WMc9Q&WOd4w{CPWu4rx(9FnFR1H3*y2BWeLBYf5U2gaLH-x@_;0VW zZ}Ip4Nr0W+W9I|)HSq=d{`K{xhX-5(08nENZuGxZ|C{k|83yM6#%x*st?&9vQ~n!4 z{fF&zGWhk6;m+UgfA~uQeMjTJNaz0zMHROBc2@f)Lcg(5qi=}R{FfWG*gsWlm2J%b zFuIT3Y&AE!(nAqa|72Ycto0@+Urfzs-{NE;Y z#^iXkvJOVZ4u3C|Oj%Iz`&`k<&d$o%`Y$?5_t#qPABgwgSnpq=_3zvJ?e?Sk4bRf5 z;%R=LYBDge;r(;4GTGx1+dpIf9s76uUoqb;6En*{ z$G_tLGY`Yx-2V~tHwP;NJ02tbch3LU|F8C6dH&V@Q{!)){};#d?Pv72#^3q;E9P&@ zM$eA-Po2Nl@E!Yi{BNDVW2~%vG6rI zVxCix8E&90^{M)LXCG1JVkuQL^_=YJ-(=eeh1%FWO-xD#55PLaealQu+fx_U+tpb+S)(QPU@~n zDhXHJdBRvu*Q{qR-TNT$UO6g})QbdU3v^6Y#*|`D**~dNP3d%c>12PXe01Ne#x6d5 zx}@Xme7v4Bo+ORVCdT>!88I#}s2G=7lmrvZ|4`?LW0;1H!*mbQ$wft^#&$!!O~nj@ zNzM2b8Y%vS2_F7QruJjJu+bJOlp8m4 zwWKg-a^g5=+rQl+z#|CT-RRaDOc3Fz14Gg%RJgXMMzx@Ka^twT)KunnbDiDx#^9Q- z-ahPkm=2k$Fjvr?r|aSdT)%Ai@Kf8ARwoyoMY-Urx(ge!Ry>9G``fVR^dn>1O|lND zDSbYH&@XYw{4C$z{T}HZ)N{pc7OZ-F6{rH=>`5*n*Lvb{|}^R zV8Ekh_%`_Z`?+RgW&J->^xv`nzO{Wr^xrxDp8x*?(f`+N<2%W}AbQsS!s`DMqW_<= zf`38u40PWzfWPJcwZd5c+p+BbCq(b*rl&ZR`aJI8&QWo8(nO6LZ>-s5ELmryo_qzY zi;n9H%K{b|Wo>mCNVpFoh=>S`{{wN7Xdlm7Vb)95IgM)KN;UqxNjjZHRkA((e)*!& z<~Yf@oxSGSi&2&VZ1&<(mp6gc)?~B8ZOij+Sg(=(v0{oPbyFIy4}G8oh-5D`GoNf3aU3e}sK_csZjlaaw+9XKx%Jv&mLZH`K@Q9G?Ze zvMo(@)Y(jo3>|t8RqR}g7cd& zcVY)ozZ3v;dXR~hg5wY?9KZbaxI$`f88%OVD;1x!chP}lqJ+k=nLjpz%;D+ZS6{cZ zW9G~ZTjg@k5gbxLKFmh_!r-||e`1zph51XGgGBq@k%pmF4w_Kkt3a>>8z0tHRJ2>k ziG1axfs;lW2y?qo#kYtQE2H52IaEHej>j6&0?X1jRqUym{6eA?r7E zu^e?(W%ZDC^)(+`15tp7yLfBC5;Mqj`{{*Uf0cWW=SBP`nL|!+7Rm09g#bm`J+n6D|RhZFT7RO1kQYF^CnGK2Xn87{@{w z!bEor{I{4wO6+G!>{X2GiAZ>a(Lfi5FJLt|*Kx=ilghv|0)Z;?KnFc78w>$AI$4~a zSokM@ZU{GkXoBagCzL?XYiiu_Gw|OZ({M$-px2?V)n_N-E=vS1+Y~VV6!4naVLD`h9RUp@ zj17_+7-~(K>Z;?t;hdw3SU+RGOPWxQrw4)TBiYZwwASF=g+X`}sWVE%y9vR0#C9(u zJ7}z4i@#5<)bDGn;eO&jVH=5FkflLEL>NSJ`4f{7yhQ3jL%3&`DD`NW^WZ*Zq>>fYZ0=`lknJ$9@Il9$Qf)PQB-Q?XQTllQWze6Ka4VH zxDWu{CdRNH71!SAErY%zn6KJIphO3ZUo8f%hKr~4%+sctlM&G`j&>7ux>?=yB=rrn z;P!+Oy?1HwEl%_|O)}s}Cm(Nwx6CEqS9BF`R;Ksol$jq#g zU|&lG;1-#1QK1_$1DYQIKrtMoiyy7e1zNlxrgkHEpfHD-cU6+_RDC& zW08BNymE?N@A1NKk!8U623GZcK!b%VSY;v5(OLjdbKMQO{c7S)xx&2D&pb$NNdBk|kal(VAe6+Q#h zVqD;fy2^!kC>4hkx6(P-aK@4l7m9&)=5_kh=Fvag#=$@mH5jNLNmF?g}e z6Vs9g9eQMD>@V}+xIfIta@=#y^e^d+gj!1=g&#m}jTWR53EN`}K?LmQ*rj@`NwVmY zeuID{fIt08=tW;RX@$r=uP_qWM>I}BFSnE^}nJP*ql{21N9^2w8sA66|-ZO~v(QeVkE6rSSyR+;o2}exsy# z{JKA({W|ZmTk+y0ysqctEeE)QGU^3IB+09gLVy9|*Yg9=_n&hh?$e0*2HqSNB6~n< z^a>>v0JO(xM{lzQa+r5V9*}ZH~@`7j|=k;$=Y+I zjsWKu?L*;+$%;$NRug=n>3q!{xa@F0C?T55n46Ur#*~exd_{2)T%{ein`mf=VFWqg z+@ululOqN_9X^;72q=JbW)#evx+bjbMt$vQV4JXgZ?drmd=eAOg%2dKSdqZYzM_Sj z@N-t5yMGr~lpkx0^R3vUxYkapy!P5bq_U305h?p((A1z`ir$-*w!3nC)PA#~=}#gY z|COCYEMt-xYj`r^Y3&i<RZS{rTxIr;W%(0fl#zNzz;V*Ew_%} zV9K0aWx*aLi46I%ws_DJjNu(ThzPSV{-B`~;PAyL?m9TplBB6bnQD?+Y%`i*C^Gip z?YR=di;KYM^}m@t%G)GFoR`%c?Kk4(`t_t=z5NWeB(-4wNP@ z<>4#pZUHmhW-B+qeXPrkSMZk)N^vqCp+1C>A~FmfH&~RPI9Rh>Wxu?la_KQx3K?t{ zq~&=Uj%a#Ab~BD@?FX((>&s2fD59v|=)V0lzHq553p1wC9dAF|<^*+5$<48E_*g#i zfcp(iK=aYp)EBCmVm{aA`OtX~VWW92UX4xqEZO=h`c7T-Lw&{_nHk~TJdrWpt4I9N zkKo6jPzc5GGQRT_Pye7*2nswZb-c2=SW^nnVXcU8C2BlJP!!s_U<|*9un|0TVc1?+ z*%5Kv++aaAGyEd|6-=1KU}}zO7kt4{lBreGY-$LN+l2bG4gxh8T%Qixrs8}N@^0D6 z581=cmda^(uDEE2o{;cW$N`ZW6t=oO_1n}Fn99sK{}sOTR4s~#1^_b=zUf;7k{{ie zzk6Vxq^QNzCJjQO5a+>qq1FnS{WBWXatVR87%8m7oDAz%D^8Zh|5%wX7X?fhNKM9T zsU{0-YSrKD5NobQ@28qP8L3v4>DF&_sG=QrwO?g-`@raKcDEYtK#{x+ygjKPKYG%6 zi#km0IK?ec3k!c#^56xn>9`kkad#CtTvFGNO7t{^YJ_G?;6aZm4@BYd)&{>T<(rR? z1RnQg=)tqQ%>?kDtH&$WTLa3&ms18UxMk=W*hO*!AH#*UqVoAT2wndyiep%qM3^** z^rx_)0F+H>5o}dn{=w8kVNH`Gg|>n?_$%RJp2@+7C*X!Y62mhTu$5$Ni}(G2R7Nu( zGw!x)bbP$*;Gi&*_h9pK_Cf+G%i73|GNsl22uaB{N~|N?6KzGt2JU&%{@@-cp#$C1g|TrLeo@U( zYuOjo$w?vRfj+rFyG#nhNO)jQ5J3AucbMRRMFZP9_^=qYeEDR(q+GRdL15%A$Mj5m7xn zhj~e4r+DpV8O4nQ$U#OgY$aWzQpe>|I!u6cgDs$mC$Wi%VPxb)MSMsZ#H9L5>4~$_ zt7ctLb>E0i3a!@GF`LOP6R4y+MdnbIBHNwv1neoO-X;i>It69Qq5)w>s&FjKWjqm) zQ*R*3kpFLeV#U>Du!bSQHS`?InL5PY8!&wA#k>Z7MrHy%!9-cf6fqeC?oms*2P9*? zxaU~n{U&psYt{M!Te-%zlIl7;Em?mLXh$I%v+yQgH3RBg7gi;U~>t9XVXXo;I;9D1T0UP9zo>ikRT)W_-ixOT?CLQHmuG0sGKYg9lpVh}_mm4=3^Fqf40Omx z=G4^B4bGzIb*ClZF^acxMn;M^3YdsXTyl6A?v6IMsmG|^neAiOeWIjvZoYgg7X0zd{lb11puhw z=Ok(+CH07`Lfl)h`aRBZTFRvu&02JZ?fmxlLW|j$6>3Y`mK;VuORF(0#z#0grd!*2 zw{^X0eDodZgitP*^|?{cx;8tLQapqY)MWlg1ecoq<)pT0Qwc7Km2y zj~H)DE)Na@b809F)YTu^l^vs0kZBU;c8#j@$%=O5lNjq72#{FyM2_=Rn=}+DYUXKIXTW)oKSDg*-Z|sNe!LYb62rt;j7S` zS(EO!_zwWv+%dZ0@B8A};0n=L*p8OYN|}ageu&6!co2YJiH(A<#1( zy{q@U^hZ1m=9yd`WwR5tazc9FUjcmS+^@B))3fdJFiFYy)APJa)4G!DWP#`l0k@ES zwj6&v-*V2IJG(jwTnfh}_>A_d(sq2_ZIPG6j9n{I34+p-2Wfeark?p0MI^5@jN=<4 z2Wyk&=TA#ptRVEFAY^Rc)XAti%h13c3~+A}1v{-zW1#Je(9(tRAhFEq0h}R<$7`o% zpoQJRPU=}Nw1A}q+sD>Oo3}7gsXn7PfI9DJ;ijK8t@2G^kaWicIOtUC_qH&Tp|l)N z2*Q}CHL|GZM`^EOd8F*kYedOJ_^q^rQSvxSdx1`=a#%7>oVRCRm`s5$p@Dt$^7+)h zNl<&p+dh781}&z(+&t-3_;a7I_sgWG8_+oC^I67n?|BLUY&(i56#rHT+-Nov&$)me z58ZXQYg#WK_;LiSP7jt!4L=N$Q1&JEN1Z>-3P!P79iJ(bGfBxR`-l--rkd)hnbuaY zW|1LpXl9QKQ$^*-unksO81^nnpJ7a;&2oEfK(<%7d8SwDi<|eDT!FKbG)df*o~%Ab zp(5yXEOJQhV8}SB0|S7DxG$J#hy;8$CcSH8UfLX|Ms9-`Yqy@*Fye;xvl)%C08U}Spv`)628401|zCZ^v4XsT^yzql?g zh8OeWlIi3ho-Veg6W9tjho?7EkL1kv-i`Jx_QeIKb8G?VpS{69V;h0*Q6M9fsDQ3w z)0Q;qyz~(fZuN6#NsZ*4SfkW~unTCF-2n{@fVowBx%o1L3aOPPi5*)Y9_7uImK6)V zU^K$GSxogLd3@JES(*!gZ0})NaY#(a`_lxWzt?R?`^Ju0x5q)x4i=o@h%Q&0`iiE` zhO!j{iiAgDU3O{RD+4obwGFx$ajsn?95yZ43>Iv|Y zdPU0q*_CRScd^kbrW?PH{QU?Iia%N|{hyx?cpR_=$e!n(6`_G2mK@ygS6~J19;oCrQ8$QDdW0FRN0rFT1eP{UNHT`?Rf{V;JWY(vHeBj|)^Z z6D%gD+y@)YO;6lSrKc$0TW@M9`)V~3pbZx`+HaTu+vMdfK<6>92@6}YAXLW3*Y~0t zfrF$YUy=AX`C385)#h9e0HqtPhSDg|``YC3OH|*8Ktlf#OU`nX9twTwVNAE&H&|~KOJol%~T$fu*D{@v<7u+4S$7GHlugv3zrGy+2+csXw>Fm-1srF zqhAS2blx&RT0$GPz~`0(n46Ze7z!c$Isnw7d}jbzu?V<;dOHjxGN*8CR?32|n|xRL zh@~5tZ-sG#ki8BlQ4IJVq12wCc61>kZ!I23(T9&Ho_HLPH;6bifrjP1G2BpjxmpfpQZdvAHRtkziq_Q+N|b}(@OhR3wPpFxUR@^nx6WfpnLA*?D&~ZO9l1f zh$CY2#7Mb8N{*u;P=;roEcjzlmbl~h4cOjSpQ=3Myn`uDw$>ON^qAq1*&1^-Zo&y( zvWKJXlQ1}*UviFG=+Lw(V6W*=eAkzoAD>}1vO~db(Uai8ghEV;YL0$%JUK^%2V@k* z8mT>DYPJX=7c;Yt9;v<&360&12re zA8jB$C$ZG_x5Qq6YE~NM#TmlbOGe?y*z7p45FF&u0_YS$Im1P)>%&|$7U_wDZU;;G zq@uunjWJbGnL`V2E?eEak0h+}jR!Y=NwSw}bZ>xnr!(MJys4U_;st>grgh#YX-2G*uc@S_;HfdKVT`q-iu7Zt z&n^Mi+DID6&71Q#NMtC>lO|yVJ$j3$z<|38h{c)2#Z?x^L^@fBTAFb)Lc1(w!xl)W z7FBBz;yr(afvyISKQQZ)^f4Z%%j;uC(1X*TI|^G`^sEs)4(m4<^y#{{oC;GeKg`KS z0Z33gCM-D_O??4wN1P@A*gx3VPvRy))A>VE##ZI%ErizO8bb9LVB!N?$`tV0Wq5$o zDLBH27llk=djl>27CC2CAa*fLm4_o1E|$MxQC zztkJ*+lB5*yj{ih#N9~x-_li7erviB$PQMaBKxzd>ggy~r+MSU`XP+0AvBsYnvomw}tkmjvuR zr4I$8#E0{t*%mjI$wfst*JPG7>!$*bAr{*YpXuQYgEdM%tJShk01PbbVT&FbFhmo% zq{O=cj7$hU5$xLyqhrU*`9uAtT|rA|C0-j{8LA!qF?8%GOQvVIfQe4fG z6E-1+ht>3|4jK^LLJ9c@SeTBYKk%H$TQR_I5`@e!j6veq5g!Ii$xk*9KoEWF>)Tng z>+a7oJd1;^Hil6H{nokt`95O-dJ}o@g<@hLR91-aV*Np^? ze^?vDz8P_Pc9@At0`~APAfJS71(Ih-dFB+^^$#oZf_)u|IA}sV6}fmd{VNvqv+$dk=<#$ppNb8`6s@}xsqx!gbKQ6MG-k&j-LKc2(Ef0}6#GBz z1}$Yh&o#_v6TjRo8eJc`x!Uc@Udj33+$qA4n66NfgJxwjT&tL2nw#eprY55*Ackxu zr3-6+P@SF%y5+vU`Jf(K>3Em*q=SD16-4%p-@&M|AO>B!VT0<8+%CFdi#Tw|Ob%1W zk&Vl?Ifyj?EMQ`w>(#Y6+(AKgR*YMXOx|qXhgeod%1kBrsn3diZDDelqMOF=L6Abi zy@e&DV#W3KV=S9ACIw4cs+mp8)h?ihf=6gqptU=0cw=hmX@{F`Ef)HA&6piHM2UPH z8rqgMIy7pP_d;!!&2&6Soxd-2SJsgwD4{CGpH5UeBB_#CTvE``np=sDRZzg!q*rkv zlF3%fSelJ$cuN{Xw!hVHoL{cf>#{kFt?FGSg|)W8N$x^nQAC~zvQ)v>;>jNSkx4e< zjsc329nJ$Dw=qgVm!Q32a4apLAGbu*IVkzc=9>YgQd0X|R_LZ963G+92nBLT1QJ10 zpxkTfb1^(z`G^+^l>nA0Xd%}t_?6xImA&$Oa$m^ag}&`^Xd;HoPawSo(W&Q@d$kijf=LD4wXBPmkvqlTc$9bjW?& zW|yCwy}TY#tLuqH$7B!o|q==&&^Y-c#fdEuIi&&P-n~jfvsQ7B-V`2pLawM&}3qjtYxR z@QwwROf1oa5d)~YM1XfQmrTHT+|WLzOw}|w)4HN;MzSS)kXErg@2A~4B|LcpluqtE zC9D3qkF5~)#wE+#rgPDhPEqpGI{}v z+5|H;pEW)W+XRU`bfk1zeb2l`9s&q6bGTSw=-s|)mZ)So<@w21Uy@A;_!y3A-L8qc zjy|(_=epmYpIioM42!4XF^Rmw>s7T&bK+u6)veECdS~tOb?bZdGPT0?6xv zgh}7U>*!vGj9UV^T^5`PEbL#gPJ1)+7RsNA%_5N7asWp3^}Au~#di)2vsG#&KtRW$ z+KM&o;Ts`f94Z`0eM+H*Mj-xl9>Mhy96Dpx&@q?uJd!#u^Z{5crLHW84zkE(Ryll_ z>V|wGZFE}H}4)`d6dzB zST8Ee!ta=tMapubi7JgThY8A@2p3k%amEO&zb5x3Xp(CnxO!OI3T6eFek zm>@R_+~b0DU*=k9rZnk^cb^mItnuD!F#0KWQ4eH zY|tx4E;Sz2{vYCj@cFrCyx%}`aNMWKZUdjLmqxt@&j|cK#daSf@@5}P@xUz{K6lL1 zDvRVs`AwQ`6eCtw{VZ}iM2Nl@&26NPMG9r2b;NEUgS19Om3TprxUWwYhEy4Gu(?-> z2|v^dRy}>%;q9E6f;7UpHlRHeh>wt(%{!(9!%+&YSyugLKdTT7Uu-YU$}ctkDa}Hn z5Ur<&bktz#1^t8-3*h$OHaQ)6dOK=Kn3zz9z96rzW+w6KkL)!a`HJT+qp7Y6#$-aQ*j|GcZA$rWT)?% zPhHrY*(uvvRLoeb^X6ZRPO_fV+``hjsa)d*_pYsKkjq`IR#{Rle08)=+6(dM1D<#( ziqx8WuD-g)HEdFmN-PXM;{aw)!dc@GH<=%t5~Z952@giP>7%0PRbrg$;K?W~JfwzA zE7C=r^Cg@u_yxJ^qAngdXq^$J@x2F#=0nb?_&XD|Hpg=#X3>Fqkgz^x_4jXAEkJ{t zTd>+1h)ePs=9A0e_YNqEFM(dy0SZZ;uUJ=afa1r%KIH|~RwtJN4{LrGRsOHO-HD&U z&cxV?3sL9R*j&?^u_`mVYYjGjjBK92^!f>by*oDLn(BDoK0P?W1O^$CuTK{>A2(`+ zn=R_POAPk?9#5mj%G^@R@?0z*w!?1hHiE%RGhBcJ&U4tC$V<@t#^4Z>0AZvF8^dS( zPa(p^#Np6NdQ`OuzyT$)KsfRw(jE&ziYd$ThW05CH*zrfuz4{}Vemf1Du4qPb1`<= zWdgLOhEaYe+641{j5C587(RpKPv1}opARt*Pf^-W@IP9rqH-g9z%FqOjN7@3HizQ&lx5;#fbOqn!XTMfXmX+ zP@2_((?Q&bBw|9-r4PygGk2otN9=Gw)4}j?Myo$0Bq+>vhsd&>({>y7`7d-#$F?<{|0TrLPX@ z_yX_Pf_yY%1Nx^@83-+8kr(o<5?tgf4u#R8!C`8sD7Vu^G=AN?mk8kevq8kctweYY zM}_&eRXvc5LX*QKmwQ+n5&|Zp9~}s_u2=)*xl{s(0|SK{OmX$VZDPvnToAUz<`rbj zYw3t(7MYGZE6*6Q15LT{vqGnnTE{%-aCID3aSVgIm~zgFfefPVaHu8%;+xP0imon4 zt-M^Ds5t9eCzWHY3>mFfGikSjGhn8F2KUM%I4PkY7>2R{b&f`19v6*iTb`me(rK}} z8#gu@zBD~jxZR)RoaH|c!Lv?z?`|B&u30%yMT0p;dl{smo7~e`n2xq%;Pmcy?z4(A zx1zmnhx>ilx(6@ICl)-IguSA&Zktd{7)QvghSA(WKknS zw5E(v@Diohj+mDWga!ktH5_lYEf5sojM*w@h*TBX`86)f!-eL7yOj0TkDDqWf_64^ zWb(!EhU3lL1VFFqgRChtB`!TI!o`4+n)(z*bsfJ#s$ry1pyVb_2X0m}fSH4!KzFuh z-l|XrKI2&=HyvLsqiTA%k~jn-96>QF(3CJ_fJ@I%U))Q{`Q&E(@ET2kLE4SZE2}Ny z7$H{CL_))jRI5jI9M*%Jv<*EdOzhEFvOiKMuBY%y3?T;XhG=M?RKT!fJf3tQIz%b6 zV9Va5^oUCu!-M^%f4;G7IXAT@g4MezTEGSN9{f&M4?%^Me!qtI2d4GdHlP5az;E0Q zz58Z6;HIUqBK-Bo-IL$T)sx@nk;0DFyMxt7L<>$zC;FP7t|z@S%_GPizN5{fsMP2A zv=s*wnxw#C?@JNv!zEn^>bYOi1+Qjl*yhOgF3^hS( z1<6LFnuruN8a;zL_)G~&JcIuL9}YW>A~7XWNK%Kq0X=zM7_~y1AMbg5os(^(A&(Qy z`o<5sIkrQ=$jA&ChUEC*tm(U$>?Sadv5}L4`nG1KS(F<35jK=!;eO}hA#3{VDku%s-Uhqcz8JYR2L}y0rQojfP|hKD<43%hoUj%v{H&#;%Zr2nII^6$4lOno zALQN^lh4nSD=*-ktSz1BJI?ven{lIKzV`E%{eWx7*FWO40L;OhrH%cLO(IZ z=s?4q=fR2-jD`VU|DcMwmSDzd}9H#ftTQ%Wp9x0h1Ai*zd5l&Z; z2=4?VX#%0{b$g&d$?mJ37_sdXE|q105e)J=FdM0Bau?m`bh6bd-vBu?3Bv&~w9_Er z9|6x}aHk`hD-kOL4N@1m>!~94#V&x<+c*6t$BQNuz@PEJ(DlFlXs;;?*6C)X926C7 z#u1<=%T)mfOi{qncRXcu#u6yJpr*P6wz&}{_-Gc6y-EJK-!vn>L9$51H)O99&)8Y> z5_k7tkL%6RzX;4aX^OM3E^>bE7}v$&egs+>o%^0|Q=L~eWZ%1}=HQBDNgl7#Rx=pQ zmO}8WfQ`hpCtn)G&uU9Kp3u}VC4YjQl@@P$r*B+8u7Nzddj^Ud=z?}`3*$wKS7j<3 zhHdSFi_M9f#QUOk$0-sfUYk`D=PsD4Qa`?=Ebi~mQ$4()sv0xW3I(INb3um?9^_vH z1zqGrx{YVOwcq~cPKh02$BUu#Wl4mfq7~kCac9Di27U7qPqZ{Gfu>OH$zmX4pimZz z1lVUFdAxV)0ITM~E$8i*9*1L))p=Pwr<95qh}b@?+bVXx&A1r#zZew*9Q%s9z%-zl z-29U~xyaDXPNnI5*mE?M8TS}@NZ*%b{zG<>Yy@Gkfu&0pOafQzXUS`B{4W1 zuN^%~#yt3hWSA(7{=`3+ljFSe!_eobdpJ@C0J4WscTV`z(LC}T4A}ti&@fE$4kIZX z0+j|5DiCHS5<F|=Zp+Bw&`QfBlSTZo4^VI%{J zfVeCK2_gjb?Sndgmr$hh5ACwiV!)R;SgI~yTG-%{(W-Yg8ybyRZxjaizYnJY>dH!r z2fHlv3lh$-W;-UjAS+Wrs@c1hR1Y3h>0S=G90n#YwXwg8PNJ)|nU=g&6$aILy|v_3 zSzAvo?47C!w()dVI4VlMb?sQZ%*mF2##Pd4quZTcv!~V@^(N7)o2=~GNvlrhiawv( z8tk3(4)VmCVK%{zm<}_?6scd+D=a@%xfQVYgyo zqJ2u#xxsbp{}sdi<4kV-P8_S+nPk)|zo`gVSlxX+r?}hi0ESVBH5BWmu{`Zoad{AI zrAAs`v80yMYU%~gTyi$X(c97UdXhV!*hu-ww&$hRN8QEt%#`|fYq$naZWGm;^gXA0 zlk}pDKR`v~dm9%ZF3V)BC6pDr-6i_zEU_g!LZI!1`+Ogb`+OxNH~YvU6+sr%v^0Shxlz`C1+QWrQ?=5 ziYj$&|(dYSUbD8XVJN zV99LQ#B@I{)pM-~-yXZ}@?T!^kDfLhy#tooKi@C?Iy2SPGd;kAAD!7UuswKvLO#Qp z-M3Vi4vwndPQ6@wj5|uq&MBW@&hh&nVJbF6gD(V^zVr`OpY?O-FO)&CQD|> z43!)rHE2wG_)LvV5$@o%&6bYB&^S4p8*()Ehg%77qx=Sy8|Y%H_>V`jKg7~fv|f|4 zyS#Vq0KE=;@}!6_yqig0taiO0I@LnnYXsn=iKkg*I*QFwHvkIXPd!v!M&O6usy`m+ zQ)YnPd3ufot?gt@vIQsPwg@x>kma_3y-0U-;H{I}VXcidW8q&FhFe<8K@0o5D7Dga zXaYP~wYcr9Lu!Y1Hu<^$uVhDcgcDrBGm9}Uo9&$EL8n;z-Xpfti1u}FXGS?*>+wQ&@lvQTuDN@WL&F(E*tGy^=W3ahdzH$$N6AvKszCA z+CPY1TVZU2_AYBNu=;^7@`9-(bs&DS?BEv##q2 zt(n;~Yu3yh)@QFrcTgZ*o(91yKPSFSOZn3p>JyzpePU2yt8ZBZaP+v}vWC!H)!UFA z53=DR#%ZzQ8V^+QPI>!XL$-#n;4SkG8iGSN{x2CH} z`YbiI6f{<{=|WsfDiC~UrI*Yrd-ud;>UcWFV`4MYYPa6W&4oI&WLY841ZiX5-gvsU zg_LLNRmdV~iB#DwA?>Zk+vIEplN`_-S+k!s`Z(e<`R3f?yPxo>BJ;CAEYk}&mxxLB zcfB}QQu_P)1LD2&Y%Fz$WE==~U0#UZ*#CMY?)dawb@Jn3w$tpGn%G}E?Y?=hjF0M7 zs2Ck`RLVJ<>q6giHzx%hKe#h=eS<>4sm_@tgz@gx4T=vFWFRNmd8uHDCe9ymxF2l|(og4cuSR@Vjd`ypb282wGaUHHwOe4*J){5NVho37+%F@KN2fxg z-GOB@#Rr6km+UE%jOsbs$@ijE=1$*oZTdTfcoS;x@8%KT?fGC_KFu79y>gqalPOlC z>i$+QJ^^VOVk%xXRFv9<=PCQf14L4dS0DRxyq}AVq(BDK+G&%G)h9<0{ z$)!**=x^+Af+>Lg>)-#-N0;-PoC-z?pOu6D{7qE-O|JdBJ~X)&O>F%K>Gt=%v$}vf z(Yk2zD*F0285jMDZsQpS=>Bfk89^3}BLKo6XO`npPbOu2bb?jf)uYjkL00vAV!r)zL{&rk7q&udS=7opa!JL-whfz`f}?< zQNiu?eUp77(e(MASxwfjwsB6wBwIc;q#n>)Vs9ons`KquG_IYL_EIZw&tv#<7D zP@R8f)|%hXz(t3eTOCLBOj!#ZOQYP$YS%tGhF28e&nN1asIzc2#%r5t6h9B)fAHKe zPT$Sux)V~XPMBBdWAw#n77Z+q>pz}vliW8U3l-7;y^Kt0QFm1)lYJ%KJY(8v<_ekv zy&U2J5AuM&tJ3j%beU~}=3pKgVd0|GMt)>m5*&JmVxIbkME2IR#D}*J#V+&v zgx>G@NZueNF5o8}u<3pH(&xH($)RcaW(iT!VbX)cYgB$L$^<6yny03oo75tdtR!R- zYD20J#g2?41#2>iVhC8VSsf%qhOeAOhOfrOL~{RGvBIG@9h3J_TJvX|s;A6Rz_!Xz=K2D!7eJiV_Itu3|4zR3 zFH;^PVHTm6fo|IOnkS`jW!<0FUAm72x`yn#s`!Pr*B#?tBkm>U-(k9X5B?%YC-(N-Hl|eRQ09-VF-yfh?T@zh-xfCSZ?hDm#`hGvPu$>me!poQ6 zr{l!y9KOkvUh^&LwIRiJYBAT zg2|UYyt=rRe??2drWCjL;iYRMcTN(PwyyLWfE8&sy}Is~lqc$};~sGMFxS&ghF0Ye zB!v9J@@Eu}FqRg|wdsA>N8TryOL4?}M1LeM^3YiJG&&%tA(BOQT5982O7DxlK!w-e zS^LJn2kc%rLe9(!>{8Xn7)#mo5%fm%JB8N3M?41onehd054F1Jloj3my4z=e^(unc!COkzJRT*i zWH*ei5Jts*D{WTa6mMzVOqTcSbv~@vh`nsW!*l1Ancd9(WlgX!_P0A*(ahr%iQIy^ zTIBCnzlMt5JLJS|*}PK|PUT@F(BED{1J1soSo_usku~=O6vG34Q!MkWHC$KO_GEKu zYao|Hwem2e`SP?~;&{QrW|)tMM~K?R_mSam5B)2cEevle`8jr!^ORmBjajFSXcK?; zh28ZXkr?ErKo*T|1`8c&CXHG|r#rjY+d(`5v%t4f%M2a#-z_*G9-rQYN@pVj8G0{d z>NML|B@NSXc7NK6N19}bagvpd&Jo`j?A){)=`HGAiudyQvee77{`6jRb{OZ3Mfv+$ z0WTb+S-msPi><5B+Q8xM%$d?Eq~q7!pP(_F4Z_R?t~)2L?_9|2SGPEppVj*K6u?X_ z_tJ4(LQDzA%(l<=I_votbP%v!8^lT77(>2fySx{-$CISktU%Gh+2b|;)iCZYZe9@W z1w!{d7q=e=STnLu{fQ1E5`!XsQL}%Jjb9L)p`KBjR0<<`-84aY@s^Y*Wm4MWrHTtK zw{uEJ1IP+IWqfHj-}zo*C*MpUA3F*PJW0NYNA{k4jKJ(An_qF@ef5i$(oRe{n*$f+ z%t$@RIkd_5z_!^z9$c{(^WxZ&Xr#GEF2}M2d(^xYU^Da5CO=lpNo{@1DZ!<|b)!F@ z6Z&xHC7YY}P4gQSanU*MvO^S=gZKi?3L^x9^r>6Q58Vu=yz?L8*JC0@6o%8~}( z5PoiXg+FK1x9aumnhBf2O`$%eD771vYz`{4DilJUF-shYshqc-(;GhtlPvtG%$_!^ z|B~WKgwwdro3EOuP#kJhK$%Hu%%`6>26d%7uL znPi&Az^d4n0w2Q$T%H$(-`|jaa$)xbXEj**WWM31P7eJ9!q>^9;?e4O*`rK0y>}}d zQ$+K%ot;#&kBwO*HjAr`7gX!qn7(zABag1Vqv0xe$SxPOMQy2S`TBO7oNR4+d+LpR z&f&T_!LGt>ej{3uPX2}GN_Pn>hTRh$eG1`E70g_H6hZjgJo0LO9g6Q)>nUWw>5)=ZaZNth z-{`J^7_2+u+bv%$a2@tMPFeNtO3*cxF`VmBZm82v(=~NMsx5MHlPeTU1!k1>D0_JG zrYjiT`(XJ>^w?wXPP!SYxO=5I=K3SVVQ%e2q;T5(yDP1M{eB5Wmes_O*Wwi_l*{#~ zjo31JaPH$d;pG>CnTp_jVw4rs1*%1;lsB@12BsDCFIq~$S`1k^E-Y4+3{~opFW0)h zEA)sL^t~37J;}H)(mqh-6X>`4+;d6qro zkw~2Ij5(TUvg$81qT^|erp*G;su=>cAnm716>hLOYMypp8-v<`MXLQOvE3*Go|JB@AN;K50Do7?3et^Q z77c#01-!{DC~opNt4K>hg6W6jeBisNzTSjuzLlB|1qF_y{fQ%Ab5%@C^bU{ar^j~o zk3@`fx9LwP?_Gp8$vw9Pv;25z-tI;9I+{F?J|3?*$ucV?EYY$nC{g#0?%R0nJ2qGo zTW;Jn*sq_^xOxuUrzKqX$|;x?Xd=|lDHzZ(<)pA}y)>+U$EoixBO-z};KwF{%bFCC z-}L6F`Fb0Sb0KtmOf<#a4H=(F8H|;$mGbH)@TX#xxiSgkj66=D91u>%owEngBRu=1 z+PLMpzFt^+X5$3DbL=&rKdfqxEQ!ktRNY|^=+<5s`?)-WWM;4?esTJBbsjJO644$t zwyKRUyNi&c%MOljpPp8K!PW=w1-W=Dc#@Qn;wjQV zK1<(AI-O}?nAdx+S3VVbqVG7G)4h%pg~#r0Zi)Kb ztGXrPGxhpveV+CFdPvWd|Ke18N%_Ow&>kY{OpV?NK_czcd(<5_BWp{ob=rM&LB!k5w9 zJMBbeY9!%T3f&#XN!!5A-^mS~j#3yXDoV(L9i`UsIT#t(wV-UCMzIef@!7iMX4SdJ z9fLmv%fK}JE*5aoYS@`;7+c8P>G#FC|EtzE-^L`6w9K<)JaD>bzvO;-R^Hyxuj#s{ z5aC6haEnHIgW=3Ko5#Ilol*uLJ~b_9O`yL~yFioWTCewSOEU9oQ z8rd#lqA7>)Fk-4Y1pvsqg)G z;oH{4apiaq@x-k!)IpZ{{9C3>#(uW5js<)q@Z>~g);rja3%t{6>2SH>TK2kLysIJK zhcUMgRNM%v5qiDez?}BJBzuB>GA-3-`FoLw+sepEvEg{T1A>Y5)l~|Q$D%H66;o=f zUumPV?=bN?-pc z6zcB<9^1MSy5VEJvp+0eydn0GU#)pGvsgm6zI=UWv7yQM*VMt3)yR44yGE)LXtbwI_S^#Q|q^ zhiA;2j4Qjgjd!z*2o9H}rulw~g(qs>-=fCzqt;CHG`^A4w4Q<|b-RJnvnciFOZ|VhInSRp=>V%wYL^161C7J@JFrteREp~OVH{S0BnKqR;X-z@Z7M1de zpPqTY>V%F|x#A&XESHZ5r@MFQrhA8~T%7oBmX?++k4(MV_y6WpyzX!9e)_0-Uniq_ z3N=>8u6ujDzN99=>)VHgqIIq5suv29b;UW}{*Q*U7#x-Mp0~i&W*;AH)XevZkA^3_ zBk-+e-sFDwJ}S=Z%@?Yh?v82tuphhbqOWpFj~&hUM$~0H@7EU8D;9Q)l=1ME=-tsa zzxN^kIf<*b=Z(9cLPyyT3>PV_rR6G#Gm@z1NXoU}u~nN_yUyQlxvp#(lq0+r1U>q;Ly?kFyRFGC6-f)y{ukd$W(G$j?CD!4?E z?m>yfHsU-6hYn!Fp?$qIn{ka6rWUe2tx_dAi~2PibM5{IKDw6Q8Icv6jRS52TLmNthF%^vtJC^T+ z(`~D|sw{0-aTo}5sK)M75$9i4QQ9+KR(=hH8sBPtPPJ(-!i8FFew{!k9d{uoD9Pc% z15s?%VSZsfKi*G#&*b3Yo;y$|rO91?lgNZ`Gt0N;zGmb>J3tFM45^bY0iimC!o z3rT6Ab6iw-;1*TYB&2RFCv%CqBQJ`XJZ5mkqi0~Sef@)sLI3rW33|`9#xGBJ24AkH z8!`*r47BbUAT}AB3iw`Db=BG7sAvYpJhJAt(LKfC&?p;F{wAh6OVbLvQj>Ap+C~p2s4}mmcU9 zTOc6ey20af2Ni1R$|7YSTGhA7vOz)LWz7%Q`zjYUxr?F(Jef)^i}Ez0Ex6Xk<1h8`txep04!HNZ;?_urvM z+VLhOSX`qRgEgL1Eqiaycn2wH(&KU>7e9Zl5z5pSP`=i61B$E;UVbowK#kw~Rekk~ zAp3XClq8vu7#Z3;5$U*a!7L~8Mu#< z*crJ&AvxIHkCh0???I^Oa#zV#wu#&|sEequaxPfrL$r}bEGBHYA9j82n95OUKXDcJ zV$vHQI>FO0#rjG4`Q|f$if$~0H0O)qsje2B6VGP{#P$=?UUnC5Y1O!s#YifS8>te! z?KZWp+ueXcBAs=%J$GkrUfMoYO`(tf=No&;Dsmy%%dR}905albY^|c9IP|KO z0xJfjH)BPAO>y+QKsHijbNR>cl-i`M9qqbLnvYxed-!^rvdQxWnkplSg7sYNx&B;J zL}d=MBB6z`6Av#&q zt=Z1WxK=`Q3tvHdx0CtD=BxW_C*RlQyHTIBm*cp9QhZKWYk}R2h@Yx8pU-y^W%O*= z$gdsj+#(GZQtr-;Rs+D3es=WOt?%_nb6D zv9L)GWKB&eYtHr>-|c=O_PAEkoQhJFcNAY&!}hC%sRo(2Hypg)zzW31Xhh5PknPEg z1ywZumCn3p^s);v&3b0SzK>%}M?=4fGd0IWKU9w={NdV5GL8aA|N2>5TBDVvh={8ysPMzz2;A9x_Juqe6(JjHwHWIy?j`uP=}XBbE{TM{)${)Lz#kJk z;d-Zns}zP4*1Zx612S*pEnNaVpZ=UVLZTp&y=w<%*&YQ?C=$N5*(?M@TBZ$^2rE)g zeKhZu)#kmwI;Ghu?cF>`VW!No`r<{C8tYH3`r6@p($_w9i6D^yr3GKi(!K|aduxtN za`!4dC6--v*Y%P6>TE&RbSa$YUL|diTaG>bV#p~|Ctt4`X?2lcCAPq;11yLDOwPzU z^UJz>FejDPT3uD{rp>~m`_N6VQ}ai1X_r1>x#=(OSRHL^DO+DwRQ?Kn6wi@?RYqt< zoU|ejr#^u>(k?X#jw!Elj6KD=njR2k?ICZxvo?HGBG$&qnrFUJTQ+t}TxE|Yvox9c zeRu+||8qzBH;46ve8q0i{lV)a2%4&!@^H0=@=pat`o8u;bhjQ6yfPfa-`*4G&B1QS zX&2GX0oSAl8w&7_7G*6@TnVhL_9MJsmQ}9&L0_77dnR39C@a&!XOW9TH%j3K2|fw6 zqL3)F3JW#uJg-Oiv$B*DD4t;v4*!tGQxhrEJW={<$^!g#Tb+z0G2s@>#;mCi0+!4M~T{3<;?KfaC0@#W=}W5Hb5 z>;2xDs&~U*4u6ulY#z{(BzMKr6$^WX%@v)n^%!G`cuCegbkE&U9^!0>OM;Hx9+KOk z2H##Wc2@Jztk7+<9OwzW6L~2zeBx!7Dpo-YtonIe*_5#+&E9^+du)NGXVg2NX4TsuP={e{yYQKN%9^J<6$6>sllzxsGRE*V|1fl!X5{ zoyhOukMDVf8v{aVkOu3AH6m&E41^j(ek{{{uNA$JEyke#p1UKSaZ&iFvapyvyMm+1 zR;Fva+xACR67Sb;{-}E%_0m}ZOAapnPO~`-3$(D+={nK&U)_9VNo!o|va9-ovh^`k zw4X$aXET53fbJ(>*nhMFHn6NXWFcr~@X^v7uG8*RRN*Q_T>;V?m0hVRry__L$hdVDK72nh;Yqfbw>xhHFd|U zs!|L zZVgpd(#M#WiwtHsGzLfWP(CN8%$>p-yl8|C6ZkQ7SLnO@Hwop6yh36g7|yfn7ZQ^x zRZKVW_%+v_xf$=jd%{3lX7=T0ah`$R@K+=Lnp`W90?@ee_y7|;ra|O$A3x;sx^rB- z!EMzZ$e<8PfNTuzNd{Z3pPX@8o1XAnVfG2w{vuu(o@=*I`aQjC{bP3iG-E}0XuIgj z5YzXDW9aL`+I#cnR0!CJw)g7Lr-jeG3aZ17#3m9qSYg9ML#b~?ZyoWEt9+a$DL)l; z!7pu>DGP+mNCvKxuD5wIfKP~@5`V^?ZtL@nH*fhyaD&LalX>B#puMcA+47AW+7TP~ zbHPS8qiqy3AW(9B3-D*}FELS9x$q;!jCH(7kUm2XNU#q=u5pCNn!Ew$VwHcK zpWp}EYs-L$(g!ciR>ZD@cT*f_#P~k-IqE)lu(zn#5${i6-WczD8JOuQH@58dyO0sd=Yxo+$L-YCp`S=clO)fHJ-6;BE{7!+bX@+$$reV=6aCMwRTO4 zHIQq#$Sbl%u02oTkV@bZ#4T2TbCT|+ZJWm2c~hsXU=n$Az|bnd)WKo+^XHB#*j-8fW*rRj{tK4dPPlXN3%9tLg5s7#f@=JiIkYW#sj2i2H55eE34a-fmoX zf?sUgm%4gg|M8YzxVD7++}f(K=j?lZulf4WIF%<|8@W3yPA01Y?I2LG`$gZd0gQZ4*H|ytP<5L~xH2gUq4f zM8Wen7v?L*Z@f3u&tzF{>Zz?dV#vk5m~~^vo}Wq+wTJ!qSM~jk<=dePvOA5~PfC?~ z7=DnSe7D+fdYrD3qkOf7azmo>)ji+D8mG}GS65v$EEJ>6>)uUVj`0k$vScQ-6$me- z$u3pYFo$2qLz#0}%T8{0s5&DrNdj9*o&LutKMN(fP9vURl3@N|reLvfJ!%7^IXisd z`>9MibDYs{+z0EpM;BkVULt2{pQH{NZq)|$kG3IhY8wY*m1?wt?*14W$ZuFFSLg2- zUsY90#mC2ev(y-D?2&VqFJ(ORihkg$rMm;=^KPp#Eb$Gdu&eM!Jt4Rqo*Q#GgTqxrKc~YVc0YmCJ44SnSndKR|BEfggbM`R zAsr#&rcZ9ciGOU*t7_%GkrMExXE5$I>-$uovD!8cUH-ILxK@}$e*A6iME{9fgB#RoLpufu!fEoc&yXOYj%ZY0YZ;nK#3_ zanOnF-u*(ClRfw{EB8ipX{LT3a%84-ee%HuQ;(pd)#uQj+YeYS1d=MK#&G4)bQC+m z^oqi?IN8XlvI6ImAz_gYiK+KcH8k(YZOOu}_t_UV-(w3WdY+Tf7*o@}F z^s#wd)7Bh2C*z_wog$LWam!^Xxm=ker|vqhR28n;eAJXwbe;%!DmkQk%PLO4D7}Kz zc$hYDI{bt{ke3*^b%tbW8E4K&YH2TlY>d1L70z0 zERJ~%1Aa}BtZ%}zoIxJ$tqOI!$9T)dO)S`4OIj7PwIeCvt~K(vx|-(2{7NMp*&fnw z;(>f8@jz{+7Pz<+YW^>>$-Wr=`q7RE>>3OnCN^cYQ1uArkyC} z-RgwE$PHbS+lqvK{`pcn+oT3p8pPy`sJWXpS=B71HL4A5ytRx%^rJS^l{}Wi_Yd{U zcP(QTvn-c3SNI(ncFU^u9sqCFD)n=aCy{{d%V#NuJ)UCsy2bKI2E`M}PlK{P?tLE~ zd*7<(?L`I6T*TySSZ?4XXz&qB=a9DR%Q&m2Zqtee2d&YOIwq$Nd!EA&@?)XJVB6hY zHCvq*ecE+BW1fctl3!f2^n42%s%t)fV$|6iCfSDzIF=ZpMp?fv6)dxC91v^=fB0_d zP~bg`v%(nXuF2G<125_JDjwroq04;Dd&$^$=~MFyviVd^+uoGv!LP;oZpV*5t&jP? z<1kRY?9)KH`(>qd0eCeH)(W5f)>crm7)x)8;vgOYVQTj9CG5*VQlH#}op6r09unxq zg}30o<)6@eemjmw-=5}0SRPIuyBGz;h;Dsc%w|qISx|c@NlX_0lPaKqOj%wvzERDMRrWHStw4i;t7-HG-%p~Y ze#go$!TxxD#gf;Z_e7Q3)L-Z_wv^s|!B+NcQ;oWncAudyFIo4Yr9DxTx3>&tfAv+36y-~KZ0M=2NtNm+doY$|*qlGdF{8=FlY>de24A7PmWi8>u}%4)$nmxZ__}OK(K_SC zTKdGq8j6uYbgw4#YQz52{z&+^#{=dNs1KwATc$TQv6=G6Q%6jF8`V- z%<8l&IdSsZ?P_>kZSE>6t;u{oa$~M8GFJEV?fpzgwh{eoKPQMczhlSk((g^Ic)}ke zjoTmIDzteOX!TmO^p!sJFl4IoyS9cjqujdslMmZhIvsEDzx4a6azr&BXf{g;g=^4d zPO8uT;`pMV!hZ}4(C%68E`46C>f*kLZ9e`Us{cy?%zlJ=8X#~$C`kN6;fs)yl&@X! z<6P3Z@O(S*Zi%SxLL~~Gb?-**Ox6}A^F+2vx=xVOz}2ab1(%iIUGn*wBB|NYCb<(g zP}Xz$QD9-eS|j-}Rp83ZY8h=Kv6^v!_Jc}huY2XO1#JPxM#Qog?Z~D4DSXzX;~aFD zhUfaO43eA1@+MjSqWQtb9BvYnm%#b~|2sK{UAL9IQ+I%gYt;+`dw}E}T*n%zCpA2uNxNZ9GIJ>PU zO@DmjHrbp@Xg1|CqM`@Oe>Ss?_xRL-S%GPkm$VX}bz!{R({Lq^X#OO0L9Rvj&MYVV zna@LODWQ}BwhkT>RQEIc<+!`)vhpCm!AksFeGicHeKbe!<|}D#r+t~PBi#l z^S8zBX1i=9wGVAlyT0<&k194N)RyUP?srhH7Lm_QS!aqd7Op(s*=f$ow6I;0O0j75 zjll%b7grBdK1HUv%jz2<#6|A88ZwF3U4_8}R6jFOD;%t6iXl-V5VBZ;oJHsF2$dtX z_lFT?6DpPxVl9`R=g&@4#a$v-U1!N=$xO=-;df>b_tR!#$jr(L*=8w_xcHH>?;4$D z62A>e^b4}}%evh$EE!Bc8=-xtU2I=X^oL>zXv=P|saPiF>b|g*QbHzK7tm!(MEk-y z2f7i)Jzwn~mvP-SO}=}@94kM5QiQ|V z6-O>T|H`6^x1SdU_fQmn3bqX*H1Dm7B-$j6vM`^cJvJi3oIu{QWpj2hG1-Wa}PMGn5& zYEhWYa2Bm2_>9N;rNWIRRfME}?&%n}APX}q?Nw{*I3_2Ry#2ThEGTnY)|jLO9EWZ^ zMFj3`Dx4RG@b)sXx1$rg;mxvp>REmIrOkpgwDkCLz~$X5?xBrk>bj~*g9LpHO78;n z@(Usq=CFSQz?W zF_{0ARpfV^AsZNZmO|uz5xL*w`U@vT0f}>Zx*>Fd{Wadgzg3Jb3|+A>=$Xhg|<(;`jf@=KVhs%8xip#e|Wo z3IU*Jq3A&9Iy#j7@33@qxH^FS&L?#iRu5pmWze5zVfMcm-U~}{eQ}xh2Q_yL*EB}F~Z`{hV=Is{T(HH#>M!b&DrSDN9Ptc zAT0g|(c>kK3M|HIP3poMw|E~&3|6w5wjkdOnqJS4`_+&t>XFAWf5#Lb38H#;@@A8<64Y5ayKLldnhya8(8nlC%wasqk870 z7Wi4KE_yGNQMC4Q+)>RbOe8u~GJ0=uy?mENklk+}>X`Gxgu>MPwE4kAc*_3uXPrBa z`+|6+10Ik1PdOw?gTp@XzakJ75s4VmbUaDWIk2)fxO18`b}tJEq`$>cva+Vjn6fGH z#)&(vfd3YuCL2M2S|#o+x-06Lg|#?oH^V#9Z>r$c;_>z}b9nF3v?c&AB8+cK#YbH# zQy8J|8MP_8%&Ytf`wC%1K2~$HI~&sWbEs^$w<}2CA{qXQ5)#Pz9uaO692%YwCfnUg zhBP81u#k4`b=7q(c$M{@nSLVlJ@YN31D>QCaY%OiXR2d{jIyqc&s{wPHS{g_c4&5eYbgF+pvXh z;pOoUEKx&(;J*kJV1V0kh65R+{`&mSeZXkXuAygf*g$#zk%Rr`8unMV zKQLglXt}@c8lkxuR?a|*Ilvhse+S0@GX`GP%-zh<#Rlz}&e{t!2(5n>3T}qZM&~8q z;q2h-;_1wb##F4_%`5>GwzF3K*1BnCZsq6(IP<@z`9JDJH}0=Ff|f;x$^+@|&i(|R z7krjG@T@L*pc}wv{Hp(4B7xG*dH@|-j&9st7Yi*bcQykd_3QFL0xTz>b7lVXDGT(t zm6!Wjti7I^xxJOe?^=|cz-$1)~dR!~XSbY(lCYPQcKD&h)f^D1Jbe4Gj6OOCc?^2>|Fn zN5t!{l{FCvcu*t}=+F~#<=)YiSa@e18 z5F`Y!9!v~&P8Wtm0R#G{9N-x-FfbB|cHe)UzLCI$wB&b1G~P=M|J zp(_kKOMr-pp|=x%VsId7*?A0d9ur2-oIiC@aJ0E#V!-HNVn}oX&OhYfD7Y|YpF++g z{*;4&z~~u`p^E@vwgmzb2AE)f%0WO-w70<2MPgzQ5DW%*k3ZxfAUFyW0}#w{13^GY z2r#QLbW!L9{SOR|LcuWm1p+?vYJbQz6efm%!Oyo(SQudHVd_H8^(g{|K(lTz>VTm= zF9rrb_iPB*d0T@3rh#cg5Mk6g8%H4ENX-6&pbY`DUI_5O7#OfwJ3mGMG56ea01zey zJngyXfI#5Fm^K7~AmEr75`;QGk07Y?^8*S3*o=Sn9}-Ach>1a<;PZU|g$QHz3!r;` z9zmh#73&fu=9NdxQ%mm1w#m9U})X*eFa0J6V(3EJ_rnj!oa`~6a>xa z{!vf~8Xy5%8z|=(m-yUGv1_A^$2SXQ- zLvO18C=UUg5YLx~0H4Evxq#U|1Of`Mp)t!to$CWY?%aBW1l;NQ@=%yI1iTjze$HNy zQ204Njs%0xtsh9RurP*gfRJFwIsXi-c<1(iNH7fj<-#9*g#P3*5)6R>M*in> z02rE8|3|+7e(l^|1&#fS9|B|cGav`Y95=vkfHCJA;18haEam?k4?qrq>BrG>nD&Q8 zFnuf_hr(P3(Q=r54`6Wg0p^c-p-{lFVPG&|eqhQ0m@tM7fnmT8hHaoROy3S1PlYjU z1CRqI9A>?6V8d}9L!E02uvNyeKQICWEP5Ea00zR;1ynK5J%BD8b4>vwfL=Xc2NKgJ zfr$z_x4t2O7c87>3*go;%R>qyF!xfx0T?hqjORcK12gG7cFu-?RSVPq0cSAKxv>P! zWte^ln1E;BBK%<+NWeJ$VH@su&Fmbl?h^fVnAdc10gkt4-!GgU-_O$A1JZwekDzp& z%|Hwefk~r;Wl;#ItSnR-29g7sf<#CQ!{x3+fr?NPZ2z;!*#Te6&d2KP$P66C-Q3OY Vx}Tk*fi?r16(TM!IW>8r{{wOJ<{JP2 literal 0 HcmV?d00001 diff --git a/xml/xslt/auto.xslt b/xml/xslt/auto.xslt index 15715f0..8cbc7f2 100644 --- a/xml/xslt/auto.xslt +++ b/xml/xslt/auto.xslt @@ -1,7 +1,9 @@ + xmlns:fo="http://www.w3.org/1999/XSL/Format" version="2.0" + xmlns:svg="http://www.w3.org/2000/svg" xmlns:math="http://www.w3.org/2005/xpath-functions/math" + extension-element-prefixes="math"> @@ -266,8 +268,9 @@ - - + + + - + + + - + + @@ -389,11 +394,300 @@ - + + + + + + , - + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + 0 + 1 + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + % + + + + + + none + + + + + + + + + + + + + % + + + + + + + + + + + + + + + + + + + + #FF5C00 + #FE9920 + #D9D375 + #B9A44C + #BEC5AD + #7CA982 + #566E3D + #5B5F97 + #C200FB + #A9E5BB + #98C1D9 + #5B5F97 + burlywood + cornflowerblue + cornsilk + black + + + From 52ea04520f001b650c40934e0834e8b1b6a933ea Mon Sep 17 00:00:00 2001 From: skyanth Date: Thu, 12 Jan 2017 12:39:23 +0100 Subject: [PATCH 05/63] Added pie charts to generated report starter --- xml/xslt/off2rep.xsl | 22 ++++++++++++++++------ 1 file changed, 16 insertions(+), 6 deletions(-) diff --git a/xml/xslt/off2rep.xsl b/xml/xslt/off2rep.xsl index 4949516..c1e5e62 100644 --- a/xml/xslt/off2rep.xsl +++ b/xml/xslt/off2rep.xsl @@ -32,15 +32,15 @@ - client_info.xml - + client_info.xml + - - + + - + FirstName LastName @@ -61,7 +61,9 @@ needed for date on frontpage and in signature boxes; it is possible to add a new <version> after each review; in that case, make sure to update the date/time - T10:00:00 + T10:00:00 actual date-time here; you can leave the number attribute alone ROS Writer name of the author here; for internal use only @@ -104,6 +106,14 @@ Summary of Findings generated from Findings section +

    + Findings by Threat Level + +
    +
    + Findings by Type + +
    Summary of Recommendations From e0fbfb9a19345ddfc37935398e17d0550ed2a0d0 Mon Sep 17 00:00:00 2001 From: skyanth Date: Thu, 12 Jan 2017 12:52:23 +0100 Subject: [PATCH 06/63] Better styling for pie chart legend --- xml/xslt/auto.xslt | 2 +- xml/xslt/styles.xslt | 5 ++++- 2 files changed, 5 insertions(+), 2 deletions(-) diff --git a/xml/xslt/auto.xslt b/xml/xslt/auto.xslt index 8cbc7f2..a54a8c7 100644 --- a/xml/xslt/auto.xslt +++ b/xml/xslt/auto.xslt @@ -518,7 +518,7 @@ - + diff --git a/xml/xslt/styles.xslt b/xml/xslt/styles.xslt index de6b8ab..a651937 100644 --- a/xml/xslt/styles.xslt +++ b/xml/xslt/styles.xslt @@ -241,6 +241,9 @@ + + #eeeeee + @@ -270,7 +273,7 @@ - + #FF5C00 From 1241f2c5eaf1b968f9665f3586a7d7e59dfaebb1 Mon Sep 17 00:00:00 2001 From: skyanth Date: Fri, 13 Jan 2017 10:47:45 +0100 Subject: [PATCH 07/63] Changes to pie charts Improved line direction for smaller percentages, placed percentage for larger slices outside the pie --- xml/xslt/auto.xslt | 47 +++++++++++++++++++++++++++++++++++----------- 1 file changed, 36 insertions(+), 11 deletions(-) diff --git a/xml/xslt/auto.xslt b/xml/xslt/auto.xslt index a54a8c7..1745cb6 100644 --- a/xml/xslt/auto.xslt +++ b/xml/xslt/auto.xslt @@ -615,19 +615,19 @@ + select="math:sin(3.1415292 * (($angle - $part_half) div 180.0)) * ($radius * 1.15)"/> - + select="math:cos(3.1415292 * (($angle - $part_half) div 180.0)) * ($radius * 1.15)"/> + - - - + + + - + - + % @@ -635,17 +635,32 @@ + + + + +10 + -10 + + + + + + + + + none - + - + + @@ -655,6 +670,16 @@ + From bcde8dd4bb50c83636443ae53c1dd85c3f3cb0b9 Mon Sep 17 00:00:00 2001 From: skyanth Date: Tue, 17 Jan 2017 14:35:07 +0100 Subject: [PATCH 08/63] =?UTF-8?q?added=20correct=20address-group=20ref=20t?= =?UTF-8?q?o=20=E2=80=98party=E2=80=99=20element?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- xml/dtd/common.xsd | 4 +--- 1 file changed, 1 insertion(+), 3 deletions(-) diff --git a/xml/dtd/common.xsd b/xml/dtd/common.xsd index ce7bb90..cd6ce65 100644 --- a/xml/dtd/common.xsd +++ b/xml/dtd/common.xsd @@ -119,9 +119,7 @@ - - - + From 5b524601ce3b82805aba234302fcae2f03f01121 Mon Sep 17 00:00:00 2001 From: melanierieback Date: Wed, 18 Jan 2017 00:20:06 +0100 Subject: [PATCH 09/63] Update README.md --- README.md | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/README.md b/README.md index c998f7d..0e02ec7 100644 --- a/README.md +++ b/README.md @@ -29,7 +29,7 @@ Listo! That's all you need. Now you can build PDF reports using the content. ### Toolchain To convert the XML content into PDF files the tools the *Apache FOP* library and the *Java* library *Saxon* will be used -It is easiest to install the toolchain using Ansible: check out the role PeterMosmans.docbuilder (https://galaxy.ansible.com/PeterMosmans/docbuilder/) +It is easiest to install the toolchain using Ansible: https://github.com/radicallyopensecurity/docbuilder To edit (and view) the content you'll need a XML editor - which could be any text editor like *JEdit*, to a full IDE- for editing of course ;). Preferably something that can check XML file validity. To view the resulting PDF files a PDF viewer is necessary. From 1e35927430d4dc6bd91dc704d4b71b687398881e Mon Sep 17 00:00:00 2001 From: Peter Mosmans Date: Wed, 25 Jan 2017 14:46:21 +1100 Subject: [PATCH 10/63] Ignore casing of gitlab labels --- chatops/python/gitlab-to-pentext.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/chatops/python/gitlab-to-pentext.py b/chatops/python/gitlab-to-pentext.py index 9fd6e14..f047a57 100644 --- a/chatops/python/gitlab-to-pentext.py +++ b/chatops/python/gitlab-to-pentext.py @@ -7,7 +7,7 @@ Gitlab bridge for PenText: imports and updates gitlab issues into PenText This script is part of the PenText framework https://pentext.org - Copyright (C) 2016 Radically Open Security + Copyright (C) 2016-2017 Radically Open Security https://www.radicallyopensecurity.com Author(s): Peter Mosmans @@ -150,9 +150,9 @@ def list_issues(gitserver, options): per_page=99): if issue.state == 'closed' and not options['closed']: continue - if 'finding' in issue.labels: + if 'finding' in [x.lower() for x in issue.labels]: add_finding(issue, options) - if 'non-finding' in issue.labels: + if 'non-finding' in [x.lower() for x in issue.labels]: add_non_finding(issue, options) except Exception as exception: print_error('could not find any issues ({0})'.format(exception), -1) @@ -176,7 +176,7 @@ def parse_arguments(): description=textwrap.dedent('''\ gitlab-to-pentext - imports and updates gitlab issues into PenText (XML) format -Copyright (C) 2015-2016 Radically Open Security (Peter Mosmans) +Copyright (C) 2015-2017 Radically Open Security (Peter Mosmans) This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by From 36444aaa72766547cf79df60697122a21d89d909 Mon Sep 17 00:00:00 2001 From: Peter Mosmans Date: Mon, 30 Jan 2017 15:00:31 +1100 Subject: [PATCH 11/63] Use client name consistently (title page and properties) --- xml/xslt/meta.xslt | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/xml/xslt/meta.xslt b/xml/xslt/meta.xslt index 0f5e3ad..fd6d87f 100644 --- a/xml/xslt/meta.xslt +++ b/xml/xslt/meta.xslt @@ -85,7 +85,7 @@ - + From 957812f7d7b8ee5c74803f3362c63a774518cedd Mon Sep 17 00:00:00 2001 From: Peter Mosmans Date: Wed, 1 Feb 2017 19:35:26 +1100 Subject: [PATCH 12/63] Fix: logmessage failed when learning new words --- chatops/python/validate_report.py | 8 ++++---- 1 file changed, 4 insertions(+), 4 deletions(-) diff --git a/chatops/python/validate_report.py b/chatops/python/validate_report.py index 720acd5..bf3ed55 100644 --- a/chatops/python/validate_report.py +++ b/chatops/python/validate_report.py @@ -6,10 +6,10 @@ Cross-checks findings, validates XML files, offerte and report files. This script is part of the PenText framework https://pentext.org - Copyright (C) 2015-2016 Radically Open Security + Copyright (C) 2015-2017 Radically Open Security https://www.radicallyopensecurity.com - Author(s): Peter Mosmans + Author: Peter Mosmans This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by @@ -97,7 +97,7 @@ def parse_arguments(): description=textwrap.dedent('''\ validate_report - validates offer letters and reports -Copyright (C) 2015-2016 Radically Open Security (Peter Mosmans) +Copyright (C) 2015-2017 Radically Open Security (Peter Mosmans) This program is free software: you can redistribute it and/or modify it under the terms of the GNU General Public License as published by @@ -590,7 +590,7 @@ def main(): else: logging.warning('Validation failed') if options['spelling'] and options['learn']: - logging.log(STATUS('Don\'t forget to check the vocabulary file %s', VOCABULARY)) + logging.log(STATUS, 'Don\'t forget to check the vocabulary file %s', VOCABULARY) if __name__ == "__main__": From 24160a79906f1a2292d28d9f633b9c8c08c0dbed Mon Sep 17 00:00:00 2001 From: skyanth Date: Fri, 10 Feb 2017 14:18:36 +0100 Subject: [PATCH 13/63] =?UTF-8?q?prefix=20finding=20ids=20with=20=E2=80=98?= =?UTF-8?q?f=E2=80=99=20so=20xml=20remains=20valid?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- scripts/gitlab-to-pentext.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/gitlab-to-pentext.py b/scripts/gitlab-to-pentext.py index a02fd6a..4c9fe31 100644 --- a/scripts/gitlab-to-pentext.py +++ b/scripts/gitlab-to-pentext.py @@ -41,7 +41,7 @@ def add_finding(issue, options): title), options) threatLevel = 'Moderate' finding_type = 'TODO' - finding_id = '{0}-{1}'.format(issue.iid, valid_filename(title)) + finding_id = 'f{0}-{1}'.format(issue.iid, valid_filename(title)) filename = 'findings/{0}.xml'.format(finding_id) finding = collections.OrderedDict() finding['title'] = title From 69c97349db4b4b4b3e7b60ae0ef5809298f247c0 Mon Sep 17 00:00:00 2001 From: skyanth Date: Fri, 10 Feb 2017 14:25:33 +0100 Subject: [PATCH 14/63] replace double quote with - for valid xml id --- scripts/gitlab-to-pentext.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/gitlab-to-pentext.py b/scripts/gitlab-to-pentext.py index 4c9fe31..970e784 100644 --- a/scripts/gitlab-to-pentext.py +++ b/scripts/gitlab-to-pentext.py @@ -234,7 +234,7 @@ def valid_filename(filename): """ valid_filename = '' for char in filename.strip(): - if char in [':', '/', '.', '\\', ' ', '[', ']', '(', ')', '\'']: + if char in [':', '/', '.', '\\', ' ', '[', ']', '(', ')', '\'', '"']: if len(char) and not valid_filename.endswith('-'): valid_filename += '-' else: From 757a363547d322ff7176213636b7e9e97a32b496 Mon Sep 17 00:00:00 2001 From: skyanth Date: Fri, 10 Feb 2017 14:27:13 +0100 Subject: [PATCH 15/63] =?UTF-8?q?prefix=20nonfinding=20ids=20with=20?= =?UTF-8?q?=E2=80=98nf=E2=80=99=20so=20xml=20remains=20valid?= MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit --- scripts/gitlab-to-pentext.py | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/scripts/gitlab-to-pentext.py b/scripts/gitlab-to-pentext.py index 970e784..fa24615 100644 --- a/scripts/gitlab-to-pentext.py +++ b/scripts/gitlab-to-pentext.py @@ -81,7 +81,7 @@ def add_non_finding(issue, options): title = validate_report.capitalize(issue.title.strip()) print_status('{0} - {1} - {2}'.format(issue.state, issue.labels, title), options) - non_finding_id = '{0}-{1}'.format(issue.iid, valid_filename(title)) + non_finding_id = 'nf{0}-{1}'.format(issue.iid, valid_filename(title)) filename = 'non-findings/{0}.xml'.format(non_finding_id) non_finding = collections.OrderedDict() non_finding['title'] = title From a100067951e866db1b7ee51866e78595b7ba55dc Mon Sep 17 00:00:00 2001 From: skyanth Date: Mon, 20 Feb 2017 14:05:57 +0100 Subject: [PATCH 16/63] Only generate pie chart when there are findings --- xml/xslt/auto.xslt | 20 +++++++++++++++++--- 1 file changed, 17 insertions(+), 3 deletions(-) diff --git a/xml/xslt/auto.xslt b/xml/xslt/auto.xslt index 1745cb6..fd82f94 100644 --- a/xml/xslt/auto.xslt +++ b/xml/xslt/auto.xslt @@ -406,11 +406,25 @@ + + + + + + + + + + Pie chart can only be generated when there are findings in the report. Get to work! ;) + + + + - - - + + + From 1f02bfe0eeccfb6ed158301332f941eb2783803e Mon Sep 17 00:00:00 2001 From: Peter Mosmans Date: Tue, 21 Feb 2017 19:35:18 +1100 Subject: [PATCH 17/63] Implemented markdown to XML conversion using pandoc --- chatops/python/gitlab-to-pentext.py | 89 ++++++++++++----------------- 1 file changed, 37 insertions(+), 52 deletions(-) diff --git a/chatops/python/gitlab-to-pentext.py b/chatops/python/gitlab-to-pentext.py index f047a57..d2ad9ed 100644 --- a/chatops/python/gitlab-to-pentext.py +++ b/chatops/python/gitlab-to-pentext.py @@ -24,28 +24,27 @@ from __future__ import print_function from __future__ import unicode_literals import argparse -import collections import os import sys import textwrap try: import gitlab - import jxmlease + import pypandoc # Path of this script. The validate_report module is on the same path. sys.path.append(os.path.dirname(__file__)) import validate_report except ImportError as exception: - print('[-] This script needs python-gitlab, jxmlease and validate_report library', + print('[-] This script needs python-gitlab, pypandoc and validate_report library', file=sys.stderr) print("validate_report is part of the pentext framework", file=sys.stderr) print("Install python-gitlab with: sudo pip install python-gitlab", file=sys.stderr) - print("Install jxmlease with: sudo pip install jxmlease", file=sys.stderr) - print("", file=sys.stderr) + print("Install pypandoc with: sudo pip install pypandoc\n", file=sys.stderr) print("Currently missing: " + exception.message, file=sys.stderr) sys.exit(-1) - +DECLARATION = '\n' + def add_finding(issue, options): """ Writes issue as XML finding to file. @@ -57,26 +56,21 @@ def add_finding(issue, options): finding_type = 'TODO' finding_id = '{0}-{1}'.format(issue.iid, valid_filename(title)) filename = 'findings/{0}.xml'.format(finding_id) - finding = collections.OrderedDict() - finding['title'] = title - finding['description'] = unicode.replace(issue.description, - '\r\n', '\n') - finding['technicaldescription'] = '' + finding = u'{0}\n'.format(title) + finding += '{0}\n\n'.format(convert_text(issue.description)) + technical_description = '' for note in [x for x in issue.notes.list() if not x.system]: - finding['technicaldescription'] += unicode.replace(note.body, - '\r\n', '\n') - finding['impact'] = {} - finding['impact']['p'] = 'TODO' - finding['recommendation'] = {} - finding['recommendation']['ul'] = {} - finding['recommendation']['ul']['li'] = 'TODO' - finding_xml = jxmlease.XMLDictNode(finding, tag='finding', - xml_attrs={'id': finding_id, - 'threatLevel': threat_level, - 'type': finding_type}) + technical_description += u'{0}\n'.format(convert_text(note.body)) + finding += '\n{0}\n\n'.format(technical_description) + finding += '\nTODO\n\n' + finding += '\n
      \n
    • \nTODO\n
    • \n
    \n
    \n' + finding = u'{0}\n{4}\n'.format(DECLARATION, + finding_id, + threat_level, + finding_type, + finding) if options['dry_run']: - print_line('[+] {0}'.format(filename)) - print(finding_xml.emit_xml()) + print_line('[+] {0}\n{1}'.format(filename, finding)) else: if os.path.isfile(filename) and not options['overwrite']: print_line('Finding {0} already exists (use --overwrite to overwrite)'. @@ -84,8 +78,15 @@ def add_finding(issue, options): else: if options['y'] or ask_permission('Create file ' + filename): with open(filename, 'w') as xmlfile: - xmlfile.write(finding_xml.emit_xml().encode('utf-8')) - print_line('[+] Created {0}'.format(filename)) + xmlfile.write(finding) + print_line('[+] Created {0}'.format(filename)) + + +def convert_text(text): + """ + Convert (gitlab) markdown to 'XML' (actually HTML5). + """ + return unicode.replace(pypandoc.convert_text(text, 'html5', format='markdown_github'), '\r\n', '\n') def add_non_finding(issue, options): @@ -97,18 +98,15 @@ def add_non_finding(issue, options): title), options) non_finding_id = '{0}-{1}'.format(issue.iid, valid_filename(title)) filename = 'non-findings/{0}.xml'.format(non_finding_id) - non_finding = collections.OrderedDict() - non_finding['title'] = title - non_finding['p'] = unicode.replace(issue.description, - '\r\n', '\n') + non_finding = u'{0}\n{1}\n'.format(title, + convert_text(issue.description)) for note in [x for x in issue.notes.list() if not x.system]: - non_finding['p'] += unicode.replace(note.body, - '\r\n', '\n') - non_finding_xml = jxmlease.XMLDictNode(non_finding, tag='non-finding', - xml_attrs={'id': non_finding_id}) + non_finding += u'

    {0}

    \n'.format(convert_text(note.body)) + non_finding = u'{0}\n{2}\n\n'.format(DECLARATION, + non_finding_id, + non_finding) if options['dry_run']: - print_line('[+] {0}'.format(filename)) - print(non_finding_xml.emit_xml()) + print_line('[+] {0}\n{1}'.format(filename, non_finding)) else: if os.path.isfile(filename) and not options['overwrite']: print_line('Non-finding {0} already exists (use --overwrite to overwrite)'. @@ -116,8 +114,8 @@ def add_non_finding(issue, options): else: if options['y'] or ask_permission('Create file ' + filename): with open(filename, 'w') as xmlfile: - xmlfile.write(non_finding_xml.emit_xml().encode('utf-8')) - print_line('[+] Created {0}'.format(filename)) + xmlfile.write(non_finding) + print_line('[+] Created {0}'.format(filename)) def ask_permission(question): @@ -128,26 +126,13 @@ def ask_permission(question): return raw_input().lower() == 'y' -def convert_markdown(text): - """ - Replace markdown monospace with monospace tags - """ - result = text - return result - # print('EXAMINING ' + text + ' END') - # monospace = re.findall("\`\`\`(.*?)\`\`\`", text, re.DOTALL) - # if len(monospace): - # result = {} - # result['monospace'] = ''.join(monospace) - - def list_issues(gitserver, options): """ Lists all issues for options['issues'] """ try: for issue in gitserver.project_issues.list(project_id=options['issues'], - per_page=99): + per_page=999): if issue.state == 'closed' and not options['closed']: continue if 'finding' in [x.lower() for x in issue.labels]: From 04b9154e970f73e8af4a62fefa324e2bdaaaf088 Mon Sep 17 00:00:00 2001 From: Peter Mosmans Date: Tue, 21 Feb 2017 19:39:03 +1100 Subject: [PATCH 18/63] Added changed prerequisites for pandoc --- chatops/README.md | 9 +++++++-- 1 file changed, 7 insertions(+), 2 deletions(-) diff --git a/chatops/README.md b/chatops/README.md index 8edf7e7..ee933f9 100644 --- a/chatops/README.md +++ b/chatops/README.md @@ -37,10 +37,15 @@ The scripts use multiple environment variables, that can be set by the user unde ## Prerequisites -The Bash scripts use the python-gitlab command-line interface to talk to the gitlab instance. This interface can be installed using `sudo pip install git+https://github.com/gpocentek/python-gitlab`. Obviously, Python needs to be installed as well. +### python-gitlab +The Bash scripts use the *python-gitlab* command-line interface to talk to the gitlab instance. This interface can be installed using `sudo pip install git+https://github.com/gpocentek/python-gitlab`. Obviously, Python needs to be installed as well. This command line interface expects a configuration file `.python-gitlab.cfg` for the user under which rosbot is running, which it uses to connect to gitlab. Make sure it contains the correct details so that you can connect to gitlab. -If you want to convert and build documents, the pentext toolchain is necessary. Use the ansible playbook https://galaxy.ansible.com/PeterMosmans/docbuilder/ or install the tools (Java, Saxon and Apache FOP) by hand, see https://github.com/radicallyopensecurity/pentext/blob/master/xml/doc/Tools%20manual.md for more information. +If you want to convert and build documents, the pentext toolchain is necessary. Use the Ansible playbook https://galaxy.ansible.com/PeterMosmans/docbuilder/ or install the tools (Java, Saxon and Apache FOP) by hand, see https://github.com/radicallyopensecurity/pentext/blob/master/xml/doc/Tools%20manual.md for more information. + +### Python libraries +Pandoc is necessary in order to automatically convert gitlab issues written in markdown to XML format. +The *pypandoc* library is also necessary: `sudo pip install pypandoc`. ## Test the configuration Test out whether the configuration is successful by manually executing the Bash script [bash/test_pentext](bash/test_pentext) - this should return an OK. From 8efe8fc01cb353ae2b1349b6dfca525ec8c6325d Mon Sep 17 00:00:00 2001 From: Peter Mosmans Date: Wed, 22 Feb 2017 11:59:40 +1100 Subject: [PATCH 19/63] Recognize keywords 'recommendation' and 'impact' in notes Treat them accordingly. Note that the keyword can only be used in one note, and has to be on the first line of the note. Re-order notes (oldest note first). --- chatops/python/gitlab-to-pentext.py | 23 ++++++++++++++++------- 1 file changed, 16 insertions(+), 7 deletions(-) diff --git a/chatops/python/gitlab-to-pentext.py b/chatops/python/gitlab-to-pentext.py index d2ad9ed..d30df18 100644 --- a/chatops/python/gitlab-to-pentext.py +++ b/chatops/python/gitlab-to-pentext.py @@ -58,13 +58,21 @@ def add_finding(issue, options): filename = 'findings/{0}.xml'.format(finding_id) finding = u'{0}\n'.format(title) finding += '{0}\n\n'.format(convert_text(issue.description)) + impact = 'TODO' + recommendation = '
      \n
    • \nTODO\n
    • \n
    \n'; technical_description = '' - for note in [x for x in issue.notes.list() if not x.system]: - technical_description += u'{0}\n'.format(convert_text(note.body)) - finding += '\n{0}\n\n'.format(technical_description) - finding += '\nTODO\n\n' - finding += '\n
      \n
    • \nTODO\n
    • \n
    \n
    \n' - finding = u'{0}\n{4}\n'.format(DECLARATION, + for note in [x for x in reversed(issue.notes.list()) if not x.system]: + if len(note.body.splitlines()): + if 'impact' in note.body.split()[0].lower(): + impact = convert_text(''.join(note.body.splitlines(True)[1:])) + elif 'recommendation' in note.body.split()[0].lower(): + recommendation = convert_text(''.join(note.body.splitlines(True)[1:])) + else: + technical_description += u'{0}\n'.format(convert_text(note.body)) + finding += '\n{0}\n\n\n'.format(technical_description) + finding += '\n{0}\n\n\n'.format(impact) + finding += '\n{0}\n\n\n'.format(recommendation) + finding = u'{0}\n{4}'.format(DECLARATION, finding_id, threat_level, finding_type, @@ -100,7 +108,7 @@ def add_non_finding(issue, options): filename = 'non-findings/{0}.xml'.format(non_finding_id) non_finding = u'{0}\n{1}\n'.format(title, convert_text(issue.description)) - for note in [x for x in issue.notes.list() if not x.system]: + for note in [x for x in reversed(issue.notes.list()) if not x.system]: non_finding += u'

    {0}

    \n'.format(convert_text(note.body)) non_finding = u'{0}\n{2}\n\n'.format(DECLARATION, non_finding_id, @@ -191,6 +199,7 @@ def preflight_checks(): Checks if all tools are there. Exits with 0 if everything went okilydokily. """ + gitserver = None try: gitserver = gitlab.Gitlab.from_config('remote') gitserver.auth() From b5b209cbd3c2d64d529cfa9ed6cebb31a5b0a282 Mon Sep 17 00:00:00 2001 From: skyanth Date: Wed, 22 Feb 2017 09:42:48 +0100 Subject: [PATCH 20/63] prefixed finding & non-finding IDs with letter to keep xml valid --- chatops/python/gitlab-to-pentext.py | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/chatops/python/gitlab-to-pentext.py b/chatops/python/gitlab-to-pentext.py index d30df18..d246d30 100644 --- a/chatops/python/gitlab-to-pentext.py +++ b/chatops/python/gitlab-to-pentext.py @@ -54,7 +54,7 @@ def add_finding(issue, options): title), options) threat_level = 'Moderate' finding_type = 'TODO' - finding_id = '{0}-{1}'.format(issue.iid, valid_filename(title)) + finding_id = 'f{0}-{1}'.format(issue.iid, valid_filename(title)) filename = 'findings/{0}.xml'.format(finding_id) finding = u'{0}\n'.format(title) finding += '{0}\n\n'.format(convert_text(issue.description)) @@ -104,7 +104,7 @@ def add_non_finding(issue, options): title = validate_report.capitalize(issue.title.strip()) print_status('{0} - {1} - {2}'.format(issue.state, issue.labels, title), options) - non_finding_id = '{0}-{1}'.format(issue.iid, valid_filename(title)) + non_finding_id = 'nf{0}-{1}'.format(issue.iid, valid_filename(title)) filename = 'non-findings/{0}.xml'.format(non_finding_id) non_finding = u'{0}\n{1}\n'.format(title, convert_text(issue.description)) From 834eee27338cbc7a0749388818a9b5a7922dec95 Mon Sep 17 00:00:00 2001 From: Peter Mosmans Date: Thu, 23 Feb 2017 18:43:57 +1100 Subject: [PATCH 21/63] Implemented true Unicode (UTF-8) support Added first Pentext classes: Finding and NonFinding --- chatops/python/gitlab-to-pentext.py | 221 +++++++++++++++++----------- 1 file changed, 137 insertions(+), 84 deletions(-) diff --git a/chatops/python/gitlab-to-pentext.py b/chatops/python/gitlab-to-pentext.py index d246d30..b5eff5a 100644 --- a/chatops/python/gitlab-to-pentext.py +++ b/chatops/python/gitlab-to-pentext.py @@ -24,6 +24,7 @@ from __future__ import print_function from __future__ import unicode_literals import argparse +import io import os import sys import textwrap @@ -34,7 +35,7 @@ try: # Path of this script. The validate_report module is on the same path. sys.path.append(os.path.dirname(__file__)) import validate_report -except ImportError as exception: +except (NameError, ImportError) as exception: print('[-] This script needs python-gitlab, pypandoc and validate_report library', file=sys.stderr) print("validate_report is part of the pentext framework", file=sys.stderr) @@ -43,51 +44,135 @@ except ImportError as exception: print("Currently missing: " + exception.message, file=sys.stderr) sys.exit(-1) -DECLARATION = '\n' - -def add_finding(issue, options): + +class BaseItem(object): """ - Writes issue as XML finding to file. + Base class for Pentext items """ - title = validate_report.capitalize(issue.title.strip()) - print_status('{0} - {1} - {2}'.format(issue.state, issue.labels, - title), options) - threat_level = 'Moderate' - finding_type = 'TODO' - finding_id = 'f{0}-{1}'.format(issue.iid, valid_filename(title)) - filename = 'findings/{0}.xml'.format(finding_id) - finding = u'{0}\n'.format(title) - finding += '{0}\n\n'.format(convert_text(issue.description)) - impact = 'TODO' - recommendation = '
      \n
    • \nTODO\n
    • \n
    \n'; - technical_description = '' - for note in [x for x in reversed(issue.notes.list()) if not x.system]: - if len(note.body.splitlines()): - if 'impact' in note.body.split()[0].lower(): - impact = convert_text(''.join(note.body.splitlines(True)[1:])) - elif 'recommendation' in note.body.split()[0].lower(): - recommendation = convert_text(''.join(note.body.splitlines(True)[1:])) - else: - technical_description += u'{0}\n'.format(convert_text(note.body)) - finding += '\n{0}\n\n\n'.format(technical_description) - finding += '\n{0}\n\n\n'.format(impact) - finding += '\n{0}\n\n\n'.format(recommendation) - finding = u'{0}\n{4}'.format(DECLARATION, - finding_id, - threat_level, - finding_type, - finding) - if options['dry_run']: - print_line('[+] {0}\n{1}'.format(filename, finding)) + + DECLARATION = '\n' + + def __init__(self, item_type): + if item_type not in ('finding', 'non-finding'): + raise ValueError('Only finding and non-finding are currently supported') + self.item_type = item_type + self.__path = '{0}s'.format(self.item_type) + self.root_open = '<{0}>\n'.format(self.item_type) + self.root_close = '\n'.format(self.item_type) + self.title = '' + self.content = '' + + @property + def filename(self): + """ + Filename. + """ + return '{0}/{1}.xml'.format(self.__path, valid_filename(self.identifier)) + + def __str__(self): + """ + Return a XML version of the class + """ + return self.DECLARATION + self.root_open + self.element('title') + \ + self.content + self.root_close + + def element(self, attribute): + """ + Return opening and closing attribute tags, including attribute value. + """ + return '<{0}>{1}\n'.format(attribute, getattr(self, attribute)) + + def write_file(self): + """ + Write item as XML to file. + """ + try: + with io.open(self.filename, 'w') as xmlfile: + xmlfile.write(unicode(self)) + print_line('[+] Wrote {0}'.format(self.filename)) + except IOError: + print_error('Could not write to %s', self.filename) + + +class Finding(BaseItem): + """ + Encapsulates finding. + """ + + def __init__(self): + BaseItem.__init__(self, 'finding') + self.threat_level = 'Moderate' + self.finding_type = 'TODO' + self.description = '

    TODO

    ' + self.technicaldescription = '

    TODO

    ' + self.impact = '

    TODO

    ' + self.recommendation = '
    • TODO
    ' + + def __str__(self): + """ + Return a XML version of the class + """ + self.root_open = '\n'.format(self.identifier, + self.threat_level, + self.finding_type) + self.content = self.element('description') + \ + self.element('technicaldescription') + \ + self.element('impact') + \ + self.element('recommendation') + return BaseItem.__str__(self) + + +class NonFinding(BaseItem): + """ + Encapsulates non-finding. + """ + + def __init__(self): + BaseItem.__init__(self, 'non-finding') + + +def from_issue(issue): + """ + Parse gitlab issue and return Finding, NonFinding or None + """ + if 'finding' in [x.lower() for x in issue.labels]: + item = Finding() + item.description = convert_text(issue.description) + for note in [x for x in reversed(issue.notes.list()) if not x.system]: + if len(note.body.splitlines()): + if 'impact' in note.body.split()[0].lower(): + item.impact = convert_text(''.join(note.body.splitlines(True)[1:])) + elif 'recommendation' in note.body.split()[0].lower(): + item.recommendation = convert_text(''.join(note.body.splitlines(True)[1:])) + else: + item.technicaldescription += u'{0}\n'.format(convert_text(note.body)) + elif 'non-finding' in [x.lower() for x in issue.labels]: + item = NonFinding() + for note in [x for x in reversed(issue.notes.list()) if not x.system]: + item.content += convert_text(note.body) + '\n' else: - if os.path.isfile(filename) and not options['overwrite']: - print_line('Finding {0} already exists (use --overwrite to overwrite)'. - format(filename)) - else: - if options['y'] or ask_permission('Create file ' + filename): - with open(filename, 'w') as xmlfile: - xmlfile.write(finding) - print_line('[+] Created {0}'.format(filename)) + return None + item.title = validate_report.capitalize(issue.title.strip()) + item.identifier = 'f{0}-{1}'.format(issue.iid, valid_filename(item.title)) + return item + + +def add_item(issue, options): + """ + Convert issue into XML finding and create file. + """ + item = from_issue(issue) + if not item: + return + if os.path.isfile(item.filename) and not options['overwrite']: + print_line('{0} {1} already exists (use --overwrite to overwrite)'. + format(item.item_type, item.filename)) + return + if options['dry_run']: + print_line('[+] {0}\n{1}'.format(item.filename, item)) + else: + if options['y'] or ask_permission('Create file ' + item.filename): + item.write_file() def convert_text(text): @@ -97,35 +182,6 @@ def convert_text(text): return unicode.replace(pypandoc.convert_text(text, 'html5', format='markdown_github'), '\r\n', '\n') -def add_non_finding(issue, options): - """ - Adds a non-finding. - """ - title = validate_report.capitalize(issue.title.strip()) - print_status('{0} - {1} - {2}'.format(issue.state, issue.labels, - title), options) - non_finding_id = 'nf{0}-{1}'.format(issue.iid, valid_filename(title)) - filename = 'non-findings/{0}.xml'.format(non_finding_id) - non_finding = u'{0}\n{1}\n'.format(title, - convert_text(issue.description)) - for note in [x for x in reversed(issue.notes.list()) if not x.system]: - non_finding += u'

    {0}

    \n'.format(convert_text(note.body)) - non_finding = u'{0}\n{2}\n\n'.format(DECLARATION, - non_finding_id, - non_finding) - if options['dry_run']: - print_line('[+] {0}\n{1}'.format(filename, non_finding)) - else: - if os.path.isfile(filename) and not options['overwrite']: - print_line('Non-finding {0} already exists (use --overwrite to overwrite)'. - format(filename)) - else: - if options['y'] or ask_permission('Create file ' + filename): - with open(filename, 'w') as xmlfile: - xmlfile.write(non_finding) - print_line('[+] Created {0}'.format(filename)) - - def ask_permission(question): """ Ask question and return True if user answered with y. @@ -138,17 +194,11 @@ def list_issues(gitserver, options): """ Lists all issues for options['issues'] """ - try: - for issue in gitserver.project_issues.list(project_id=options['issues'], - per_page=999): - if issue.state == 'closed' and not options['closed']: - continue - if 'finding' in [x.lower() for x in issue.labels]: - add_finding(issue, options) - if 'non-finding' in [x.lower() for x in issue.labels]: - add_non_finding(issue, options) - except Exception as exception: - print_error('could not find any issues ({0})'.format(exception), -1) + for issue in gitserver.project_issues.list(project_id=options['issues'], + per_page=999): + if issue.state == 'closed' and not options['closed']: + continue + add_item(issue, options) def list_projects(gitserver): @@ -205,6 +255,9 @@ def preflight_checks(): gitserver.auth() except gitlab.config.GitlabDataError as exception: print_error('could not connect {0}'.format(exception), -1) + for path in ('findings', 'non-findings'): + if not os.path.isdir(path): + print_error('Path {0} does not exist: Is this a Pentext repository ?'.format(path), -1) return gitserver @@ -246,7 +299,7 @@ def valid_filename(filename): """ result = '' for char in filename.strip(): - if char in ['*', ':', '/', '.', '\\', ' ', '[', ']', '(', ')', '\'']: + if char in ['*', ':', '/', '.', '\\', ' ', '[', ']', '(', ')', '\'', '\"']: if len(char) and not result.endswith('-'): result += '-' else: From 4d4f7ac7dbb49362af378e32d5d6bd584a242dbc Mon Sep 17 00:00:00 2001 From: skyanth Date: Fri, 24 Feb 2017 14:09:45 +0100 Subject: [PATCH 22/63] added pie chart - summary table links for threatLevel type --- xml/xslt/auto.xslt | 140 +++++++++++++++++++++++++++++++++++++++------ 1 file changed, 121 insertions(+), 19 deletions(-) diff --git a/xml/xslt/auto.xslt b/xml/xslt/auto.xslt index fd82f94..6a78164 100644 --- a/xml/xslt/auto.xslt +++ b/xml/xslt/auto.xslt @@ -36,6 +36,84 @@ + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + + summaryTableThreatLevel + + + + + + + + + + + + + + + + @@ -66,26 +144,26 @@ + select="$findingSummaryTable/findingEntry[@status = $status][ancestor::*[@id = $Ref]]"> + select="$findingSummaryTable/findingEntry[@status = $status]"> + select="$findingSummaryTable/findingEntry[ancestor::*[@id = $Ref]]"> - + @@ -99,29 +177,30 @@ - + + + + + + + + + - + - - - - - - - - + - + @@ -415,10 +494,13 @@ - Pie chart can only be generated when there are findings in the report. Get to work! ;) + + Pie chart can only be generated when + there are findings in the report. Get to work! ;) + - + @@ -559,6 +641,22 @@ + ( + + + + + summaryTableThreatLevel + + + + + + + + ) @@ -659,8 +757,12 @@ - - + + + + + + From b5fa8c53b93a954c8d55a6ad23541617e9d69b25 Mon Sep 17 00:00:00 2001 From: skyanth Date: Fri, 24 Feb 2017 14:34:51 +0100 Subject: [PATCH 23/63] added @includepage for generated links --- xml/RELEASE_NOTES.md | 13 ++++++++++++ xml/dtd/common.xsd | 49 ++++++++++++++++++++++++++------------------ xml/xslt/inline.xslt | 4 +++- 3 files changed, 45 insertions(+), 21 deletions(-) diff --git a/xml/RELEASE_NOTES.md b/xml/RELEASE_NOTES.md index 9e6b20e..9739b9a 100644 --- a/xml/RELEASE_NOTES.md +++ b/xml/RELEASE_NOTES.md @@ -1,6 +1,19 @@ RELEASE NOTES ============= +February 24th, 2017 +------------------- + +###Pie chart linking + +All pie charts now show a finding count in the legend label. + +The threat level pie chart legend finding count now additionally links to the summary table. + +The summary table is now ordered on threat level severity and each finding ID in the table links to the actual finding. + +Generated links (e.g. `
    `) now have an optional attribute `@includepage` which can be set to `yes` or `no` (default is `yes`). If set to `yes`, the link will be generated as it was up till now (e.g. "SID-001 (page 4)"); if set to `no`, the link will be generated without the page number in parenthesis. + January 12th, 2017 ------------------ diff --git a/xml/dtd/common.xsd b/xml/dtd/common.xsd index cd6ce65..8e8057c 100644 --- a/xml/dtd/common.xsd +++ b/xml/dtd/common.xsd @@ -105,7 +105,7 @@ - + @@ -125,7 +125,7 @@ - + @@ -242,7 +242,7 @@ - + @@ -313,6 +313,15 @@ + + + + + + + + + @@ -390,15 +399,15 @@ - + - + - + @@ -417,7 +426,7 @@ - + @@ -426,8 +435,8 @@ - - + + @@ -436,7 +445,7 @@ - + @@ -445,7 +454,7 @@ - + @@ -454,15 +463,15 @@ - - - - - - - - - + + + + + + + + + diff --git a/xml/xslt/inline.xslt b/xml/xslt/inline.xslt index 3e540cc..9931d14 100644 --- a/xml/xslt/inline.xslt +++ b/xml/xslt/inline.xslt @@ -56,9 +56,11 @@ - (page + + (page ) + From a43b364fd192ad3f167c8ad9100341f976d748ad Mon Sep 17 00:00:00 2001 From: skyanth Date: Fri, 24 Feb 2017 16:47:00 +0100 Subject: [PATCH 24/63] the big pre/code/monospace switch --- xml/RELEASE_NOTES.md | 7 +++++ xml/doc/offerte/Offerte Writing Procedure.md | 9 +++--- xml/doc/report/Report Writing - Procedure.md | 8 +++--- xml/dtd/common.xsd | 30 +++++++------------- xml/dtd/genericdocument.xsd | 2 -- xml/dtd/offerte.xsd | 2 -- xml/dtd/pentestreport.xsd | 7 ----- xml/xslt/block.xslt | 7 ----- xml/xslt/inline.xslt | 6 ++-- xml/xslt/styles.xslt | 11 +++---- 10 files changed, 33 insertions(+), 56 deletions(-) diff --git a/xml/RELEASE_NOTES.md b/xml/RELEASE_NOTES.md index 9739b9a..bcb7e59 100644 --- a/xml/RELEASE_NOTES.md +++ b/xml/RELEASE_NOTES.md @@ -14,6 +14,13 @@ The summary table is now ordered on threat level severity and each finding ID in Generated links (e.g. ``) now have an optional attribute `@includepage` which can be set to `yes` or `no` (default is `yes`). If set to `yes`, the link will be generated as it was up till now (e.g. "SID-001 (page 4)"); if set to `no`, the link will be generated without the page number in parenthesis. +###The big pre/code/monospace switch + +To have better compatibility with HTML and markdown-to-xml scripts, we have slimmed down and mixed up the `
    `, `` and `` tags. I tried to describe what was what and is now something else, but it became way too confusing. To keep it simple, just know this:
    +
    +- `
    ` is for **terminal output and code blocks**, just like the triple back-tick (```) in markdown
    +- `` is for the **inline monospace font**, just like the single back-tick (`) in markdown
    +
     January 12th, 2017
     ------------------
     
    diff --git a/xml/doc/offerte/Offerte Writing Procedure.md b/xml/doc/offerte/Offerte Writing Procedure.md
    index 85aec22..7601890 100644
    --- a/xml/doc/offerte/Offerte Writing Procedure.md	
    +++ b/xml/doc/offerte/Offerte Writing Procedure.md	
    @@ -197,7 +197,6 @@ As said, after the title, anything goes (well, almost):
         -   lists (ordered `
      ` or unordered `