<?php
header('Cache-Control: no-store');

// Includes
include_once("include/create_session.php");
include_once("include/config.php");
include_once("include/opendb.php");
include_once("include/functions.php");
?>
<!doctype html>
<html lang="en" prefix="og: http://ogp.me/ns#">
  <head>
    <meta charset="utf-8">
    <?php
    if(isset($_GET['key']) || isset($_GET['alert_on'])) {
    ?>
<meta name="robots" content="noindex" />
    <?php
    }
    else {
    ?>
<meta name="robots" content="all" />
    <?php
    }
    ?>
<meta name="viewport" content="width=device-width, initial-scale=1, shrink-to-fit=no" />
    <link rel="canonical" href="https://bazaar.abuse.ch/hunting/" />
    <title>MalwareBazaar | Hunting</title>
    <meta name="description" content="Hunting malware samples on MalwareBazaar" />
    <meta name="keywords" content="malware, sample, binaries, binary, download, hash, hunting, live" />
    <!-- Twitter Card -->
    <meta name="twitter:card" content="summary">
    <meta name="twitter:title" content="MalwareBazaar - Live malware hunting">
    <meta name="twitter:description" content="Hunt for malware samples on MalwareBazaar">
    <meta name="twitter:url" content="https://bazaar.abuse.ch/hunting/">
    <meta name="twitter:image" content="https://bazaar.abuse.ch/images/abusech_twitter.png">
    <link rel="icon" href="/favicon.ico">
    <!-- Bootstrap core CSS -->
    <link href="/css/bootstrap.min.css" rel="stylesheet">
    <!-- Font Awesome CSS -->
    <link href="/css/all.min.css" rel="stylesheet">
    <!-- Datatables CSS -->
    <link href="/css/datatables.min.css" rel="stylesheet">
    <!-- Custom styles -->
    <link href="/css/jumbotron.css" rel="stylesheet">
    <link href="/css/custom.css" rel="stylesheet">
    <!-- Google Analytics -->
    <script async src="https://www.googletagmanager.com/gtag/js?id=G-5GQV3CJ17N"></script>
    <script>
      window.dataLayer = window.dataLayer || [];
      function gtag(){dataLayer.push(arguments);}
      gtag('js', new Date());

      gtag('config', 'G-5GQV3CJ17N');
    </script>
  </head>

  <body>
    <header class="fixed-top">
      <div class="d-flex justify-content-center align-items-center temp-banner">
        <div class="container d-flex justify-content-center align-items-center">
          <p style="margin-bottom: 0 !important; text-align: center">
            🤲🏼 <strong>NEW</strong> | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile?
            <a href="https://community.abuse.ch" target="_blank">Go to the Community Hub →</a>
          </p>
        </div>
      </div>
      <nav class="navbar navbar-expand-md navbar-dark bg-grey">
        <div class="container">
          <a class="navbar-brand" href="/">
            <img src="/images/malwarebazaar_logo.svg" style="height: 50px" alt="MalwareBazaar">
          </a>
          <button class="navbar-toggler" type="button" data-toggle="collapse" data-target="#navbarsExampleDefault" aria-controls="navbarsExampleDefault" aria-expanded="false" aria-label="Toggle navigation">
            <span class="navbar-toggler-icon"></span>
          </button>
          <div class="collapse navbar-collapse" id="navbarsExampleDefault">
            <ul class="navbar-nav ml-auto">
              <li class="nav-item">
                <a class="nav-link" href="/browse/" title="Browse MalwareBazaar database"><i class="fa fa-fw fa-search"></i> Browse</a>
              </li>
              <li class="nav-item">
                <a class="nav-link" href="/upload/" title="Upload a malware sample"><i class="fas fa-fw fa-cloud-upload-alt"></i> Upload</a>
              </li>
              <li class="nav-item active">
                <a class="nav-link" href="/hunting/" title="Live Hunting Alerts"><i class="far fa-bell"></i> Hunting Alerts</a>
              </li>
              <li class="nav-item dropdown">
                 <a class="nav-link dropdown-toggle" href="#" id="navbarDropdown" role="button" data-toggle="dropdown" aria-haspopup="true" aria-expanded="false">
                   <i class="fas fa-database"></i> Access Data
                 </a>
                 <div class="dropdown-menu" aria-labelledby="navbarDropdown">
                   <a class="dropdown-item" href="/api/" title="API"><i class="fa fa-fw fa-code"></i> API</a>
                   <a class="dropdown-item" href="/export/" title="Export"><i class="fas fa-file-export"></i> Export</a>
                 </div>
              </li>
            <li class="nav-item dropdown">
               <a class="nav-link dropdown-toggle" href="#" id="navbarDropdown" role="button" data-toggle="dropdown" aria-haspopup="true" aria-expanded="false">
                 <i class="fab fa-readme"></i> Resources
               </a>
               <div class="dropdown-menu" aria-labelledby="navbarDropdown">
                 <a class="dropdown-item" href="/about/" title="About"><i class="fa fa-fw fa-archway"></i> About</a>
                 <a class="dropdown-item" href="https://community.abuse.ch/?platform=malwarebazaar#leaderboard" title="Community Hubs"><i class="fas fa-users"></i> Community Hub</a>
                 <a class="dropdown-item" href="/statistics/" title="Statistics"><i class="fa fa-fw fa-chart-pie"></i> Statistics</a>
                 <a class="dropdown-item" href="/faq/" title="FAQ"><i class="fas fa-question-circle"></i> FAQ</a>
               </div>
            </li>
              <?php
              user_info();
              ?>
            </ul>
          </div>
        </div>
      </nav>
    </header>

    <!-- Main content -->
    <main class="container">
      <h1 class="mt-5">Hunting Alerts</h1>
      <?php
      if(isset($_GET['key'])) {
      ?>
      <div class="alert alert-warning mt-5 mb-5" role="alert">
        <h4 class="alert-heading"><i class="fas fa-exclamation-triangle"></i> Attention</h4>
         Do <strong>not</strong> share this link with anyone. This is your <strong>personal</strong>, secret link. Sharing it with others will allow them to view and edit your hunting rules without your consent!
      </div>
      <?php
      }
      if(!isset($_SESSION['authenticated'])) {
        ?>
        <div class="alert alert-info" role="alert">
          In order to use this feature, you need to login with <a href="/login/" target="_parent" title="Login with your abuse.ch account">your abuse.ch account</a>
        </div>
        <?php
      }
      else {
      ?>
      <p>You can hunt for newly observed malware samples on MalwareBazaar by setting up an alert for:</p>
      <ul>
        <li>Tag</li>
        <li>Signature</li>
        <li>YARA rule</li>
        <li>ClamAV signature</li>
        <li>Vendor detection</li>
      </ul>
      <p>You will receive these notificiations by email on the email address stored in your abuse.ch profile. If you are looking for automation (pull) instead of alerting (push), please have a look at the <a href="/api/" target="_parent" title="MalwareBazaar API">MalwareBazaar API</a> which actually offers almost the same functionality.</p>
      <h2>Setup a new Hunting Rule</h2>
      <hr>
      <p>To setup a hunting rule, please use the form below.</p>
      <form id="new_alert">
        <div class="form-group required row">
          <label for="alert_on" class="col-sm-2 col-form-label">Alert on</label>
          <div class="col-sm-10">
            <select class="form-control form-control" name="alert_on" id="alert_on">
              <?php
              if(isset($_GET['alert_on'])) {
              ?>
              <option ="" disabled hidden>Choose...</option>
              <?php
              }
              else {
              ?>
              <option ="" selected disabled hidden>Choose...</option>
              <?php
              }
              ?>
              <option value="tag">Tag (exact match)</option>
              <?php
              if(isset($_GET['alert_on'])) {
                if($_GET['alert_on'] == 'signature') {
              ?>
              <option value="signature" selected>Signature (exact match)</option>
              <?php
                }
              }
              else {
              ?>
              <option value="signature">Signature (exact match)</option>
              <?php
              }
              if(isset($_GET['alert_on'])) {
                if($_GET['alert_on'] == 'yara') {
              ?>
              <option value="yara_rule" selected>YARA rule (exact match)</option>
              <?php
                }
              }
              else {
              ?>
              <option value="yara_rule">YARA rule (exact match)</option>
              <?php
              }
              if(isset($_GET['alert_on'])) {
                if($_GET['alert_on'] == 'clamav') {
              ?>
              <option value="clamav_signature" selected>ClamAV signature (exact match)</option>
              <?php
                }
              }
              else {
              ?>
              <option value="clamav_signature">ClamAV signature (exact match)</option>
              <?php
              }
              if(isset($_GET['alert_on'])) {
                if($_GET['alert_on'] == 'vendor') {
              ?>
              <option value="vendor_detection" selected>Vendor detection (wildcard match)</option>
              <?php
                }
              }
              else {
              ?>
              <option value="vendor_detection">Vendor detection (wildcard match)</option>
              <?php
              }
              ?>
            </select>
          </div>
        </div>
        <div class="form-group required row">
          <label for="search_term" class="col-sm-2 col-form-label">Search term</label>
          <div class="col-sm-10">
            <?php
            if(isset($_GET['search_term'])) {
              if(preg_match("/^[a-z0-9\-\.\_\ ]*$/i", $_GET['search_term'])) {
            ?>
            <input class="form-control form-control" type="text" name="search_term" id="search_term" value="<?php echo $_GET['search_term']; ?>">
            <?php
              }
              else {
                ?>
                <input class="form-control form-control" type="text" name="search_term" id="search_term" placeholder="ZLoader">
                <?php
              }
            }
            else {
            ?>
            <input class="form-control form-control" type="text" name="search_term" id="search_term" placeholder="ZLoader">
            <?php
            }
            ?>
            <small id="search_term_info" class="form-text text-muted">
              Allowed characters: A-Za-z0-9.-_ and spaces
            </small>
          </div>
        </div>
        <div class="form-group required row">
          <label for="notify_value" class="col-sm-2 col-form-label">E-Mail</label>
          <div class="col-sm-10">
            <input class="form-control form-control" type="text" name="notify_value" id="notify_value" value="<?php echo get_userinfo($_SESSION['auth_uuid'], 'Email'); ?>" disabled>
          </div>
        </div>
        <div class="d-flex justify-content-center">
          <button type="button" id="save_alert" name="save_alert" class="btn btn-primary"><i class="fas fa-edit"></i> Save</button>
        </div>
      </form>
      <div class="d-flex justify-content-center mt-4" id="status-msg"></div>
      <?php
      if(isset($_GET['key'])) {
        if(preg_match("/^[a-z0-9]{32}$/", $_GET['key'])) {
          // Check if email_token exists
          $res = mysqli_query($conn, "SELECT email FROM tbl_hunting_email WHERE email_token = '".validateinput($_GET['key'])."' LIMIT 1");
          if(!mysqli_num_rows($res)) {
          ?>
            <div class="alert alert-warning" role="alert"><i class="fas fa-exclamation-triangle"></i> No notifications configured (yet)</div>
          <?php
          }
          else {
            $row = mysqli_fetch_array($res, MYSQLI_ASSOC);
            $email = $row['email'];
            $res = mysqli_query($conn, "SELECT date_added, alert_on, search_term, notify_type, notify_value, email_token, email_status, (SELECT count(id) FROM tbl_hunting_notified WHERE fk_hunting_id = h.id) AS not_cnt FROM tbl_hunting AS h WHERE notify_value = '$email' ORDER BY date_added DESC;");
            ?>
        <h2>Your Hunting Rules</h2>
        <hr>
        <p>The following table shows all hunting rules associated with the email address <strong><?php echo $email; ?></strong>. You can edit them at any time by clicking on the corresponding icon.</p>
        <table id="hunting_rules" class="table table-sm table-hover table-bordered">
          <thead>
           <tr><th>Date added</th><th>Alert on</th><th>Search term</th><th>Who to notify?</th><th>Status</th><th>Hits</th><th>Action</th></tr>
          </thead>
          <tbody>
          <?php
            while ($row = mysqli_fetch_array($res, MYSQLI_ASSOC)) {
              $timestamp = preg_replace("/ .*$/", "", $row['date_added']);
              if($row['alert_on'] == 'tag') {
                $alert_on = 'Tag (exact match)';
              }
              elseif($row['alert_on'] == 'signature') {
                $alert_on = 'Signature (exact match)';
              }
              elseif($row['alert_on'] == 'yara_rule') {
                $alert_on = 'YARA rule (exact match)';
              }
              elseif($row['alert_on'] == 'clamav_signature') {
                $alert_on = 'ClamAV signature (exact match)';
              }
              else {
                $alert_on = 'Vendor detection (wildcard match)';
              }
              $action = "<a href=\"#\" target=\"_parent\" title=\"Delete this hunting rule\" class=\"badge badge-danger\" id=\"delete_".$row['email_token']."\" onclick=\"delete_notification('".$row['email_token']."'); return false;\"><i class=\"far fa-trash-alt\"></i> Delete</a>";
              if($row['email_status'] == 'unverified') {
                $action .= " <a href=\"#\" target=\"_parent\" title=\"Re-send validation email\" class=\"badge badge-info\" id=\"resend_".$row['email_token']."\" onclick=\"resend_token('".$row['email_token']."'); return false;\"><i class=\"far fa-paper-plane\"></i> Resend email</a>";
                $status = "<span class=\"badge badge-warning\"><i class=\"fas fa-exclamation-triangle\"></i> Email not verified</span>";
              }
              else {
                $status = "<span class=\"badge badge-success\"><i class=\"fas fa-bullseye\"></i> Hunting</span>";
              }
              echo "<tr><td>$timestamp</td><td>$alert_on</td><td>".$row['search_term']."</td><td><i class=\"far fa-envelope\"></i> ".$row['notify_value']."</td><td>$status</td><td>".number_format($row['not_cnt'],0,'',"'")."</td><td>$action</td></tr>\n";
            }
            ?>
            </tbody>
          </table>
          <?php
          }
        }
        elseif(preg_match("/^[a-z0-9]{30}$/i", $_GET['key'])) {
          // Check if email_token exists
          $res = mysqli_query($conn, "SELECT id FROM tbl_hunting WHERE notify_value = '".validateinput($_GET['key'])."' LIMIT 1");
          if(!mysqli_num_rows($res)) {
          ?>
            <div class="alert alert-warning" role="alert"><i class="fas fa-exclamation-triangle"></i> No notifications configured (yet)</div>
          <?php
          }
          else {
            $res = mysqli_query($conn, "SELECT date_added, alert_on, search_term, notify_type, notify_value, email_token, email_status, (SELECT count(id) FROM tbl_hunting_notified WHERE fk_hunting_id = h.id) AS not_cnt FROM tbl_hunting AS h WHERE notify_value = '".validateinput($_GET['key'])."' ORDER BY date_added DESC");
            ?>
          <h2>Your Hunting Rules</h2>
          <hr>
          <p>The following table shows all hunting rules associated with the PushOver account <strong><?php echo $_GET['key']; ?></strong>. You can edit them at any time by clicking on the corresponding icon.</p>
          <table id="hunting_rules" class="table table-sm table-hover table-bordered">
          <thead>
           <tr><th>Date added (UTC)</th><th>Alert on</th><th>Search term</th><th>Who to notify?</th><th>Status</th><th>Hits</th><th>Action</th></tr>
          </thead>
          <tbody>
          <?php
            while ($row = mysqli_fetch_array($res, MYSQLI_ASSOC)) {
              $timestamp = preg_replace("/ .*$/", "", $row['date_added']);
              if($row['alert_on'] == 'tag') {
                $alert_on = 'Tag (exact match)';
              }
              elseif($row['alert_on'] == 'signature') {
                $alert_on = 'Signature (exact match)';
              }
              elseif($row['alert_on'] == 'yara_rule') {
                $alert_on = 'YARA rule (exact match)';
              }
              elseif($row['alert_on'] == 'clamav_signature') {
                $alert_on = 'ClamAV signature (exact match)';
              }
              else {
                $alert_on = 'Vendor detection (wildcard match)';
              }
              $action = "<a href=\"#\" target=\"_parent\" title=\"Delete this hunting rule\" class=\"badge badge-danger\" id=\"delete_".$row['notify_value']."\" onclick=\"delete_notification('".$row['notify_value']."')\"><i class=\"far fa-trash-alt\"></i> Delete</a>";
              $status = "<span class=\"badge badge-success\"><i class=\"fas fa-bullseye\"></i> Hunting</span>";
              $notify = "<i class=\"far fa-envelope\"></i> ".$row['notify_value'];
              if($row['notify_type'] == 'pushover') {
                $notify = "<i class=\"fas fa-mobile-alt\"></i> ".$row['notify_value'];
              }
              echo "<tr><td>$timestamp</td><td>$alert_on</td><td>".$row['search_term']."</td><td>$notify</td><td>$status</td><td>".number_format($row['not_cnt'],0,'',"'")."</td><td>$action</td></tr>\n";
            }
            ?>
            </tbody>
          </table>
          <?php
          }
        }
        else {
        ?>
        <div class="alert alert-danger" role="alert"><i class="fas fa-exclamation-triangle"></i> Illegal token/key</div>
        <?php
        }
      }
      else {
        if(isset($_SESSION['authenticated'])) {
          ?>
          <h2>Your Hunting Rules</h2>
          <hr>
          <p>The following table shows all live hunting rules associated your account. You can edit them at any time by clicking on the corresponding icon.</p>
          <table id="hunting_rules" class="table table-sm table-hover table-bordered">
            <thead>
             <tr><th>Date added</th><th>Search term</th><th>Alert on</th><th>Status</th><th>Hits</th><th>Action</th></tr>
            </thead>
            <tbody>
            <?php
              $res = mysqli_query($conn, "SELECT h.id, date_added, alert_on, search_term, (SELECT count(id) FROM tbl_hunting_notified WHERE fk_hunting_id = h.id) AS hits FROM tbl_hunting AS h WHERE notify_value = '".get_userinfo($_SESSION['auth_uuid'], 'Email')."'");
              while ($row = mysqli_fetch_array($res, MYSQLI_ASSOC)) {
                $timestamp = preg_replace("/ .*$/", "", $row['date_added']);
                if($row['alert_on'] == 'tag') {
                  $alert_on = 'Tag (exact match)';
                }
                elseif($row['alert_on'] == 'signature') {
                  $alert_on = 'Signature (exact match)';
                }
                elseif($row['alert_on'] == 'yara_rule') {
                  $alert_on = 'YARA rule (exact match)';
                }
                elseif($row['alert_on'] == 'clamav_signature') {
                  $alert_on = 'ClamAV signature (exact match)';
                }
                else {
                  $alert_on = 'Vendor detection (wildcard match)';
                }
                $action = "<a href=\"#\" target=\"_parent\" title=\"Delete this hunting rule\" class=\"badge badge-danger\" id=\"delete_".$row['id']."\" onclick=\"delete_alert('".$row['id']."'); return false;\"><i class=\"far fa-trash-alt\"></i> Delete</a>";
                $status = "<span class=\"badge badge-success\"><i class=\"fas fa-bullseye\"></i> Hunting</span>";
                echo "<tr><td>$timestamp</td><td>".$row['search_term']."</td><td>$alert_on</td><td>$status</td><td>".number_format($row['hits'], 0, '', "'")."</td><td>$action</td></tr>\n";
              }
              ?>
              </tbody>
            </table>
          <?php
        }
      }
    }
      ?>
    </main>

    <!-- Footer -->
    <footer class="footer">
      <div class="content-container">
        <div class="d-block d-md-flex align-items-center">
          <div class="d-flex gap-4 social-links">
            <a href="https://x.com/abuse_ch" rel="noopener" target="_blank">
              <svg
                height="24"
                width="24"
                fill="white"
                xmlns="http://www.w3.org/2000/svg"
                viewBox="0 0 512 512"
              >
                <path
                  d="M389.2 48h70.6L305.6 224.2 487 464H345L233.7 318.6 106.5 464H35.8L200.7 275.5 26.8 48H172.4L272.9 180.9 389.2 48zM364.4 421.8h39.1L151.1 88h-42L364.4 421.8z"
                />
              </svg>
            </a>
            <a
              href="https://www.linkedin.com/company/abuse-ch/"
              rel="noopener"
              target="_blank"
            >
              <svg
                height="24"
                width="24"
                fill="white"
                xmlns="http://www.w3.org/2000/svg"
                viewBox="0 0 448 512"
              >
                <path
                  d="M416 32H31.9C14.3 32 0 46.5 0 64.3v383.4C0 465.5 14.3 480 31.9 480H416c17.6 0 32-14.5 32-32.3V64.3c0-17.8-14.4-32.3-32-32.3zM135.4 416H69V202.2h66.5V416zm-33.2-243c-21.3 0-38.5-17.3-38.5-38.5S80.9 96 102.2 96c21.2 0 38.5 17.3 38.5 38.5 0 21.3-17.2 38.5-38.5 38.5zm282.1 243h-66.4V312c0-24.8-.5-56.7-34.5-56.7-34.6 0-39.9 27-39.9 54.9V416h-66.4V202.2h63.7v29.2h.9c8.9-16.8 30.6-34.5 62.9-34.5 67.2 0 79.7 44.3 79.7 101.9V416z"
                />
              </svg>
            </a>
            <a href="https://ioc.exchange/@abuse_ch" rel="noopener" target="_blank">
              <svg
                height="24"
                width="24"
                fill="white"
                xmlns="http://www.w3.org/2000/svg"
                viewBox="0 0 448 512"
              >
                <path
                  d="M433 179.1c0-97.2-63.7-125.7-63.7-125.7-62.5-28.7-228.6-28.4-290.5 0 0 0-63.7 28.5-63.7 125.7 0 115.7-6.6 259.4 105.6 289.1 40.5 10.7 75.3 13 103.3 11.4 50.8-2.8 79.3-18.1 79.3-18.1l-1.7-36.9s-36.3 11.4-77.1 10.1c-40.4-1.4-83-4.4-89.6-54a102.5 102.5 0 0 1 -.9-13.9c85.6 20.9 158.7 9.1 178.8 6.7 56.1-6.7 105-41.3 111.2-72.9 9.8-49.8 9-121.5 9-121.5zm-75.1 125.2h-46.6v-114.2c0-49.7-64-51.6-64 6.9v62.5h-46.3V197c0-58.5-64-56.6-64-6.9v114.2H90.2c0-122.1-5.2-147.9 18.4-175 25.9-28.9 79.8-30.8 103.8 6.1l11.6 19.5 11.6-19.5c24.1-37.1 78.1-34.8 103.8-6.1 23.7 27.3 18.4 53 18.4 175z"
                />
              </svg>
            </a>
            <a
              href="https://bsky.app/profile/abuse-ch.bsky.social"
              rel="noopener"
              target="_blank"
            >
              <svg
                height="24"
                width="24"
                fill="white"
                xmlns="http://www.w3.org/2000/svg"
                viewBox="0 0 512 512"
              >
                <path
                  d="M111.8 62.2C170.2 105.9 233 194.7 256 242.4c23-47.6 85.8-136.4 144.2-180.2c42.1-31.6 110.3-56 110.3 21.8c0 15.5-8.9 130.5-14.1 149.2C478.2 298 412 314.6 353.1 304.5c102.9 17.5 129.1 75.5 72.5 133.5c-107.4 110.2-154.3-27.6-166.3-62.9l0 0c-1.7-4.9-2.6-7.8-3.3-7.8s-1.6 3-3.3 7.8l0 0c-12 35.3-59 173.1-166.3 62.9c-56.5-58-30.4-116 72.5-133.5C100 314.6 33.8 298 15.7 233.1C10.4 214.4 1.5 99.4 1.5 83.9c0-77.8 68.2-53.4 110.3-21.8z"
                />
              </svg>
            </a>
          </div>
          <div class="footer-policies md:flex-row col">
            <a href="https://abuse.ch/terms-and-conditions/" class="nav-link-w">Terms and Conditions</a>
            <span class="d-md-block d-none">|</span>
            <a href="https://abuse.ch/terms-of-use/" class="nav-link-w">Terms of Use</a>
            <span class="d-md-block d-none">|</span>
            <a href="https://abuse.ch/privacy-policy/" class="nav-link-w">Privacy Policy</a>
            <span class="d-md-block d-none">|</span>
            <a href="https://abuse.ch/cookie-policy/" class="nav-link-w">Cookie Policy</a>
          </div>
        </div>
      </div>
    </footer>

    <!-- JavaScript
    ================================================== -->
    <!-- Placed at the end of the document so the pages load faster -->
    <script src="/js/jquery-3.5.1.min.js"></script>
    <script src="/js/bootstrap.min.js"></script>
    <script src="/js/clipboard.min.js"></script>
    <script src="/js/datatables.min.js"></script>
    <script src="/js/hunting_m91jdnas71.min.js"></script>
  </body>
</html>
