<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<html xmlns:v="urn:schemas-microsoft-com:vml" xmlns:o="urn:schemas-microsoft-com:office:office" xmlns:w="urn:schemas-microsoft-com:office:word" xmlns:st1="urn:schemas-microsoft-com:office:smarttags" xmlns="http://www.w3.org/TR/REC-html40">

<head>
<META HTTP-EQUIV="Content-Type" CONTENT="text/html; charset=us-ascii">


<meta name=ProgId content=Word.Document>
<meta name=Generator content="Microsoft Word 10">
<meta name=Originator content="Microsoft Word 10">
<link rel=File-List href="cid:filelist.xml@...8783...">
<title>Message</title>
<o:SmartTagType namespaceuri="urn:schemas-microsoft-com:office:smarttags"
 name="time"/>
<o:SmartTagType namespaceuri="urn:schemas-microsoft-com:office:smarttags"
 name="date"/>
<!--[if gte mso 9]><xml>
 <o:OfficeDocumentSettings>
  <o:DoNotRelyOnCSS/>
 </o:OfficeDocumentSettings>
</xml><![endif]--><!--[if gte mso 9]><xml>
 <w:WordDocument>
  <w:Zoom>110</w:Zoom>
  <w:SpellingState>Clean</w:SpellingState>
  <w:GrammarState>Clean</w:GrammarState>
  <w:DocumentKind>DocumentEmail</w:DocumentKind>
  <w:EnvelopeVis/>
  <w:BrowserLevel>MicrosoftInternetExplorer4</w:BrowserLevel>
 </w:WordDocument>
</xml><![endif]--><!--[if !mso]>
<style>
st1\:*{behavior:url(#default#ieooui) }
</style>
<![endif]-->
<style>
<!--
 /* Font Definitions */
 @font-face
        {font-family:Tahoma;
        panose-1:2 11 6 4 3 5 4 4 2 4;
        mso-font-charset:0;
        mso-generic-font-family:swiss;
        mso-font-pitch:variable;
        mso-font-signature:553679495 -2147483648 8 0 66047 0;}
 /* Style Definitions */
 p.MsoNormal, li.MsoNormal, div.MsoNormal
        {mso-style-parent:"";
        margin:0in;
        margin-bottom:.0001pt;
        mso-pagination:widow-orphan;
        font-size:12.0pt;
        font-family:"Times New Roman";
        mso-fareast-font-family:"Times New Roman";}
a:link, span.MsoHyperlink
        {color:blue;
        text-decoration:underline;
        text-underline:single;}
a:visited, span.MsoHyperlinkFollowed
        {color:purple;
        text-decoration:underline;
        text-underline:single;}
p
        {mso-margin-top-alt:auto;
        margin-right:0in;
        mso-margin-bottom-alt:auto;
        margin-left:0in;
        mso-pagination:widow-orphan;
        font-size:12.0pt;
        font-family:"Times New Roman";
        mso-fareast-font-family:"Times New Roman";}
code
        {font-family:"Courier New";
        mso-ascii-font-family:"Courier New";
        mso-fareast-font-family:"Times New Roman";
        mso-hansi-font-family:"Courier New";
        mso-bidi-font-family:"Courier New";}
span.emailstyle17
        {mso-style-name:emailstyle17;
        font-family:Arial;
        mso-ascii-font-family:Arial;
        mso-hansi-font-family:Arial;
        mso-bidi-font-family:Arial;
        color:windowtext;}
span.emailstyle18
        {mso-style-name:emailstyle18;
        font-family:Arial;
        mso-ascii-font-family:Arial;
        mso-hansi-font-family:Arial;
        mso-bidi-font-family:Arial;
        color:navy;}
span.emailstyle20
        {mso-style-name:emailstyle20;
        font-family:Arial;
        mso-ascii-font-family:Arial;
        mso-hansi-font-family:Arial;
        mso-bidi-font-family:Arial;
        color:navy;}
span.emailstyle21
        {mso-style-name:emailstyle21;
        font-family:Arial;
        mso-ascii-font-family:Arial;
        mso-hansi-font-family:Arial;
        mso-bidi-font-family:Arial;
        color:navy;}
span.emailstyle22
        {mso-style-name:emailstyle22;
        font-family:Arial;
        mso-ascii-font-family:Arial;
        mso-hansi-font-family:Arial;
        mso-bidi-font-family:Arial;
        color:navy;}
span.EmailStyle23
        {mso-style-type:personal;
        mso-style-noshow:yes;
        mso-ansi-font-size:10.0pt;
        mso-bidi-font-size:10.0pt;
        font-family:Arial;
        mso-ascii-font-family:Arial;
        mso-hansi-font-family:Arial;
        mso-bidi-font-family:Arial;
        color:navy;}
span.EmailStyle25
        {mso-style-type:personal-reply;
        mso-style-noshow:yes;
        mso-ansi-font-size:10.0pt;
        mso-bidi-font-size:10.0pt;
        font-family:Arial;
        mso-ascii-font-family:Arial;
        mso-hansi-font-family:Arial;
        mso-bidi-font-family:Arial;
        color:navy;}
span.SpellE
        {mso-style-name:"";
        mso-spl-e:yes;}
@page Section1
        {size:8.5in 11.0in;
        margin:1.0in 1.25in 1.0in 1.25in;
        mso-header-margin:.5in;
        mso-footer-margin:.5in;
        mso-paper-source:0;}
div.Section1
        {page:Section1;}
-->
</style>
<!--[if gte mso 10]>
<style>
 /* Style Definitions */ 
 table.MsoNormalTable
        {mso-style-name:"Table Normal";
        mso-tstyle-rowband-size:0;
        mso-tstyle-colband-size:0;
        mso-style-noshow:yes;
        mso-style-parent:"";
        mso-padding-alt:0in 5.4pt 0in 5.4pt;
        mso-para-margin:0in;
        mso-para-margin-bottom:.0001pt;
        mso-pagination:widow-orphan;
        font-size:10.0pt;
        font-family:"Times New Roman";}
</style>
<![endif]--><!--[if gte mso 9]><xml>
 <o:shapedefaults v:ext="edit" spidmax="1026" />
</xml><![endif]--><!--[if gte mso 9]><xml>
 <o:shapelayout v:ext="edit">
  <o:idmap v:ext="edit" data="1" />
 </o:shapelayout></xml><![endif]-->
</head>

<body bgcolor=white lang=EN-US link=blue vlink=purple style='tab-interval:.5in'>

<div class=Section1>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>Having this sort of implementation can do
a couple of things.<span style='mso-spacerun:yes'>  </span>First off it
can greatly reduce the amount that one sensor is looking at, since it only has
to keep up with what’s going into and out of the firewall.<span
style='mso-spacerun:yes'>  </span>The bits that you are missing is
internal machines attacking internal machines, internal machines running
unwanted services, unknown access points into the network, etc. <span
style='mso-spacerun:yes'> </span>I have seen some customers who don’t
care about that, while most do.<span style='mso-spacerun:yes'>  </span>The
difficulty is even if you want to look for all that stuff it can be difficult
to impossible to place a single or small number of sensors in an efficient manner
to catch all this traffic.<span style='mso-spacerun:yes'>  </span>If you
like you can drop me a line and we can chat off line I would be happy to look
at a network diagram and make some recommendations.<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>Cheers,<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'>Brian<o:p></o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>

<p class=MsoNormal><font size=2 color=navy face=Arial><span style='font-size:
10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>

<div>

<p style='margin-bottom:12.0pt'><font size=2 color=navy face="Times New Roman"><span
style='font-size:10.0pt;color:navy;mso-no-proof:yes'>-------------------------------------------------------------------<br>
Brian Laing<br>
CTO<br>
Blade Software<br>
Cellphone: +1 650.280.2389<br>
Telephone: +1 650 367.9376<br>
eFax: +1 208.575.1374<br>
Blade Software - Because Real Attacks Hurt<br>
<a href="http://www.Blade-Software.com">http://www.Blade-Software.com</a><br>
-------------------------------------------------------------------</span></font><o:p></o:p></p>

</div>

<p class=MsoNormal style='margin-left:.5in'><font size=2 face=Tahoma><span
style='font-size:10.0pt;font-family:Tahoma'>-----Original Message-----<br>
<b><span style='font-weight:bold'>From:</span></b>
snort-users-admin@lists.sourceforge.net [mailto:snort-users-admin@...974...rceforge.net]
<b><span style='font-weight:bold'>On Behalf Of </span></b>Ponte, Paul F<br>
<b><span style='font-weight:bold'>Sent:</span></b> </span></font><st1:date
Month="4" Day="3" Year="2003"><font size=2 face=Tahoma><span style='font-size:
 10.0pt;font-family:Tahoma'>Thursday, April 03, 2003</span></font></st1:date><font
size=2 face=Tahoma><span style='font-size:10.0pt;font-family:Tahoma'> </span></font><st1:time
Hour="19" Minute="4"><font size=2 face=Tahoma><span style='font-size:10.0pt;
 font-family:Tahoma'>7:04 PM</span></font></st1:time><font size=2 face=Tahoma><span
style='font-size:10.0pt;font-family:Tahoma'><br>
<b><span style='font-weight:bold'>To:</span></b>
'snort-users@lists.sourceforge.net'<br>
<b><span style='font-weight:bold'>Subject:</span></b> RE: [Snort-users] IDS
Placement ideas for inside and outside a firewall.</span></font></p>

<p class=MsoNormal style='margin-left:.5in'><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'><o:p> </o:p></span></font></p>

<div>

<p class=MsoNormal style='margin-left:.5in'><font size=2 color=blue face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:blue'>Hi all -</span></font><o:p></o:p></p>

</div>

<div>

<p class=MsoNormal style='margin-left:.5in'><font size=2 color=blue face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:blue'>  I'd like to ask
your opinions on one part of this question.  When we talk about a
sensor on the inside of the firewall, I assume that means it can see all
traffic on the internal subnet.  But what do you give up if you monitor
just traffic passing on a VLAN between the firewall and the router sitting
between it and the rest of the network?  Is this a valid
installation?  What's the danger in not monitoring all of the normal host
to host traffic on your network which doesn't need to cross the firewall? 
I'm considering this kind of deployment, so thanks for your opinions on this.</span></font><o:p></o:p></p>

</div>

<div>

<p class=MsoNormal style='margin-left:.5in'><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'> <o:p></o:p></span></font></p>

</div>

<div>

<p class=MsoNormal style='margin-left:.5in'><font size=2 color=blue face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:blue'>Paul</span></font><o:p></o:p></p>

</div>

<blockquote style='margin-top:5.0pt;margin-right:0in;margin-bottom:5.0pt'>

<p class=MsoNormal style='mso-margin-top-alt:0in;margin-right:0in;margin-bottom:
12.0pt;margin-left:.5in'><font size=2 face=Tahoma><span style='font-size:10.0pt;
font-family:Tahoma'>-----Original Message-----<br>
<b><span style='font-weight:bold'>From:</span></b> Brian Laing
[mailto:Brian.Laing@...8609...] <br>
<b><span style='font-weight:bold'>Sent:</span></b> </span></font><st1:date
Month="4" Day="3" Year="2003"><font size=2 face=Tahoma><span style='font-size:
 10.0pt;font-family:Tahoma'>Thursday, April 03, 2003</span></font></st1:date><font
size=2 face=Tahoma><span style='font-size:10.0pt;font-family:Tahoma'> </span></font><st1:time
Hour="17" Minute="58"><font size=2 face=Tahoma><span style='font-size:10.0pt;
 font-family:Tahoma'>5:58 PM</span></font></st1:time><font size=2 face=Tahoma><span
style='font-size:10.0pt;font-family:Tahoma'><br>
<b><span style='font-weight:bold'>To:</span></b> 'Brei, Matt'; 'David Glosser';
'FWAdmin'; snort-users@lists.sourceforge.net<br>
<b><span style='font-weight:bold'>Subject:</span></b> RE: [Snort-users] IDS
Placement ideas for inside and outside a firewall.</span></font><o:p></o:p></p>

<p class=MsoNormal style='margin-left:.5in'><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'>It can help, but I would
not rely on it for prosecution the fact is the data is too easy to spoof and is
not collected in a forensically sound manager either at the sensor or the
management console.<span style='mso-spacerun:yes'>  </span>By forensically
sound I mean certified to be free from tampering.<span
style='mso-spacerun:yes'>  </span>Not that this data wont help your case,
but its better to rely on it to see where and into what else the attacker may
have gotten into.<o:p></o:p></span></font></p>

<p class=MsoNormal style='margin-left:.5in'><font size=2 color=navy face=Arial><span
style='font-size:10.0pt;font-family:Arial;color:navy'><o:p> </o:p></span></font></p>

<div>

<p style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:12.0pt;
margin-left:.5in'><font size=2 color=navy face="Times New Roman"><span
style='font-size:10.0pt;color:navy;mso-no-proof:yes'>-------------------------------------------------------------------<br>
Brian Laing<br>
CTO<br>
Blade Software<br>
Cellphone: +1 650.280.2389<br>
Telephone: +1 650 367.9376<br>
eFax: +1 208.575.1374<br>
Blade Software - Because Real Attacks Hurt<br>
<a href="http://www.Blade-Software.com">http://www.Blade-Software.com</a><br>
-------------------------------------------------------------------</span></font><o:p></o:p></p>

</div>

<p class=MsoNormal style='margin-left:1.0in'><font size=2 face=Tahoma><span
style='font-size:10.0pt;font-family:Tahoma'>-----Original Message-----<br>
<b><span style='font-weight:bold'>From:</span></b> Brei, Matt
[mailto:mbrei@...8727...] <br>
<b><span style='font-weight:bold'>Sent:</span></b> </span></font><st1:date
Month="4" Day="3" Year="2003"><font size=2 face=Tahoma><span style='font-size:
 10.0pt;font-family:Tahoma'>Thursday, April 03, 2003</span></font></st1:date><font
size=2 face=Tahoma><span style='font-size:10.0pt;font-family:Tahoma'> </span></font><st1:time
Hour="14" Minute="18"><font size=2 face=Tahoma><span style='font-size:10.0pt;
 font-family:Tahoma'>2:18 PM</span></font></st1:time><font size=2 face=Tahoma><span
style='font-size:10.0pt;font-family:Tahoma'><br>
<b><span style='font-weight:bold'>To:</span></b>
brian.laing@...8607...; David Glosser; FWAdmin;
snort-users@lists.sourceforge.net<br>
<b><span style='font-weight:bold'>Subject:</span></b> RE: [Snort-users] IDS
Placement ideas for inside and outside a firewall.</span></font><o:p></o:p></p>

<p class=MsoNormal style='margin-left:1.0in'><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'><o:p> </o:p></span></font></p>

<p class=MsoNormal style='margin-left:1.0in'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'>That's exactly
why I would want one outside of the firewall.  If I were to find a
successful break in, I could then review logs from the external IDS and find
that the same IP had done several scans or whatever that were eventually
blocked by the firewall and not picked up by the internal IDS.  I would
think that this would help build a better case if any type of legal action were
to be taken. </span></font><o:p></o:p></p>

<p class=MsoNormal style='margin-left:1.0in'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'> </span></font><o:p></o:p></p>

<p class=MsoNormal style='margin-left:1.0in'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'>Matt</span></font><o:p></o:p></p>

<p class=MsoNormal style='margin-left:1.0in'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'> </span></font><o:p></o:p></p>

<p class=MsoNormal style='margin-left:1.5in'><font size=2 face=Tahoma><span
style='font-size:10.0pt;font-family:Tahoma'>-----Original Message-----<br>
<b><span style='font-weight:bold'>From:</span></b> Brian Laing
[mailto:Brian.Laing@...8609...] <br>
<b><span style='font-weight:bold'>Sent:</span></b> </span></font><st1:date
Month="4" Day="3" Year="2003"><font size=2 face=Tahoma><span style='font-size:
 10.0pt;font-family:Tahoma'>Thursday, April 03, 2003</span></font></st1:date><font
size=2 face=Tahoma><span style='font-size:10.0pt;font-family:Tahoma'> </span></font><st1:time
Hour="11" Minute="28"><font size=2 face=Tahoma><span style='font-size:10.0pt;
 font-family:Tahoma'>11:28 AM</span></font></st1:time><font size=2 face=Tahoma><span
style='font-size:10.0pt;font-family:Tahoma'><br>
<b><span style='font-weight:bold'>To:</span></b> 'David Glosser'; Brei, Matt;
'FWAdmin'; snort-users@lists.sourceforge.net<br>
<b><span style='font-weight:bold'>Subject:</span></b> RE: [Snort-users] IDS
Placement ideas for inside and outside a firewall.</span></font><o:p></o:p></p>

<p class=MsoNormal style='margin-left:1.5in'><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'> <o:p></o:p></span></font></p>

<p class=MsoNormal style='margin-left:1.5in'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'>I would
agree with this sort of implementation, in many of the installs I have done I
will setup the external sensors to do nothing but logging and ignore the data
till I see something worth looking at on one of the internal servers.  I
use this data to see what else that IP has been doing or what other things have
been attempted against a specific host</span></font><o:p></o:p></p>

<p class=MsoNormal style='margin-left:1.5in'><font size=2 color=navy
face=Arial><span style='font-size:10.0pt;font-family:Arial;color:navy'> </span></font><o:p></o:p></p>

<div>

<p style='mso-margin-top-alt:5.0pt;margin-right:0in;margin-bottom:12.0pt;
margin-left:1.5in'><font size=2 color=navy face="Times New Roman"><span
style='font-size:10.0pt;color:navy'>-------------------------------------------------------------------<br>
Brian Laing<br>
CTO<br>
Blade Software<br>
Cellphone: +1 650.280.2389<br>
Telephone: +1 650 367.9376<br>
eFax: +1 208.575.1374<br>
Blade Software - Because Real Attacks Hurt<br>
<a href="http://www.Blade-Software.com">http://www.Blade-Software.com</a><br>
-------------------------------------------------------------------</span></font><o:p></o:p></p>

</div>

<p class=MsoNormal style='margin-left:2.0in'><font size=2 face=Tahoma><span
style='font-size:10.0pt;font-family:Tahoma'>-----Original Message-----<br>
<b><span style='font-weight:bold'>From:</span></b>
snort-users-admin@lists.sourceforge.net [mailto:snort-users-admin@...974...rceforge.net]
<b><span style='font-weight:bold'>On Behalf Of </span></b>David Glosser<br>
<b><span style='font-weight:bold'>Sent:</span></b> </span></font><st1:date
Month="4" Day="2" Year="2003"><font size=2 face=Tahoma><span style='font-size:
 10.0pt;font-family:Tahoma'>Wednesday, April 02, 2003</span></font></st1:date><font
size=2 face=Tahoma><span style='font-size:10.0pt;font-family:Tahoma'> </span></font><st1:time
Hour="23" Minute="10"><font size=2 face=Tahoma><span style='font-size:10.0pt;
 font-family:Tahoma'>11:10 PM</span></font></st1:time><font size=2 face=Tahoma><span
style='font-size:10.0pt;font-family:Tahoma'><br>
<b><span style='font-weight:bold'>To:</span></b> Brei, Matt; FWAdmin;
snort-users@lists.sourceforge.net<br>
<b><span style='font-weight:bold'>Subject:</span></b> Re: [Snort-users] IDS
Placement ideas for inside and outside a firewall.</span></font><o:p></o:p></p>

<p class=MsoNormal style='margin-left:2.0in'><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'> <o:p></o:p></span></font></p>

<div>

<p class=MsoNormal style='margin-left:2.0in'><font size=2 face="Times New Roman"><span
style='font-size:10.0pt'>If you've never set up any IDS before, I'm not sure
you would want to place it outside your firewall immediately You'lll get
overwhelmed with probes,scans, script kiddies etc. </span></font><o:p></o:p></p>

</div>

<div>

<p class=MsoNormal style='margin-left:2.0in'><font size=2 face="Times New Roman"><span
style='font-size:10.0pt'>First place the box (with the "snorting" NIC
unnumbered). On the port monitoring the *internal* interface of your firewall.
Let it work on all of the stuff your firewall lets through. Once you have that
under control, then place another box (or another NIC on the same box) to
monitor your internal servers (since breakins can come from internal users). </span></font><o:p></o:p></p>

</div>

<div>

<p class=MsoNormal style='margin-left:2.0in'><font size=2 face="Times New Roman"><span
style='font-size:10.0pt'>Once you have these two under control, then you can
worry monitoring stuff outside the firewall,  which I believe is called
*attack detection*. But do you care that much about the stuff your firewall is
successfully blocking?</span></font><o:p></o:p></p>

</div>

<div>

<p class=MsoNormal style='margin-left:2.0in'><font size=3 face="Times New Roman"><span
style='font-size:12.0pt'> <o:p></o:p></span></font></p>

</div>

<div>

<p class=MsoNormal style='margin-left:2.0in'><font size=2 face="Times New Roman"><span
style='font-size:10.0pt'>--snip-</span></font><o:p></o:p></p>

</div>

<blockquote style='border:none;border-left:solid black 1.5pt;padding:0in 0in 0in 3.0pt;
margin-left:3.4pt;margin-top:5.0pt;margin-right:0in;margin-bottom:5.0pt'>

<div>

<p class=MsoNormal style='margin-left:2.0in'><font size=2 face=Arial><span
style='font-size:10.0pt;font-family:Arial'> I am trying to convince my
company to implement IDS on our network but I have a few questions. I know
I would want one on both sides of the firewall, </span></font><o:p></o:p></p>

</div>

</blockquote>

</blockquote>

<p class=MsoNormal style='mso-margin-top-alt:0in;margin-right:0in;margin-bottom:
12.0pt;margin-left:.5in'><font size=3 face="Courier New"><span
style='font-size:12.0pt;font-family:"Courier New"'><br>
<br>
</span></font><font size=2 color=blue face="Courier New"><span
style='font-size:10.0pt;font-family:"Courier New";color:blue'><br>
<code><font face="Courier New">The International Fund for Animal Welfare (IFAW
-- <a href="http://www.ifaw.org">www.ifaw.org</a>) works to improve the welfare
of wild and domestic animals throughout the world by reducing commercial
exploitation of animals, protecting wildlife habitats, and assisting animals in
distress. IFAW seeks to motivate the public to prevent cruelty to animals and
to promote animal welfare and conservation policies that advance the well-being
of both animals and people.</font></code><br>
<br>
<code><font face="Courier New">This transmission is intended only for use by
the addressee(s) named herein and may contain information that is proprietary,
confidential and/or legally privileged. If you are not the intended recipient,
you are hereby notified that any disclosure, copying, distribution, or use of
the information contained herein (including any reliance thereon) is STRICTLY
PROHIBITED. If you received this transmission in error, please immediately
contact the sender and destroy the material in its entirety, whether in
electronic or hard copy format. Thank you.</font></code></span></font><o:p></o:p></p>

</div>

</body>

</html>