{"success": true, "notes": [{"note_id": "afeda2", "title": "FTP/SSH pre-auth RCE fingerprint — 77.68.12.66 (ProFTPD/OpenSSH 8.0) + 45.132.74.81 (OpenSSH 9.6p1) [agent 52bbefbe]", "category": "findings", "tags": ["proftpd", "openssh", "ftp", "ssh", "rce", "fingerprint", "precondition", "mod_copy", "mod_sql", "regresSShion", "52bbefbe", "77.68.12.66", "45.132.74.81"], "created_at": "2026-09-27T21:35:56.981072+00:00", "updated_at": "2026-09-27T21:35:56.981072+00:00", "content": "Agent: FTP/SSH Pre-Auth RCE Verifier (52bbefbe), child of Independent Red Team Lead 2 (15751ced). Fingerprint/precondition verification only — no exploitation, no file writes.\n\n## 77.68.12.66:21 — ProFTPD (origin of promotions.pandabingo.com)\nBanner: `220 ProFTPD Server (ProFTPD) [77.68.12.66]` (version deliberately hidden by ServerIdent).\n`SYST` → `215 UNIX Type: L8`.\n`FEAT` → AUTH TLS, CCC, CLNT, CSID, EPRT, EPSV, HOST, LANG en-US.UTF-8*, MDTM, MFF, MFMT, MLST(...UNIX.groupname;UNIX.ownername;), PBSZ, PROT, RANG STREAM, REST STREAM, SIZE, SSCN, TVFS, UTF8  ⇒ **≥ ProFTPD 1.3.6** (LANG/CSID/HOST are 1.3.6-era features).\n`HELP` → standard huge command set; `MODULES` → `500 MODULES not understood`.\n`SITE HELP` → only `QUOTA`, `RATIO`, `HELP`, `CHGRP`, `CHMOD` (+ RATIO extension) ⇒ **mod_copy NOT loaded**.\n`SITE RATIO` → `214 Current Ratio: (...)`; `SITE QUOTA` → `530 Please login` (mod_ratio + mod_quota present).\n`AUTH TLS` → `234`; TLS cert CN = `linux.prod.activewin.co.uk` (Let's Encrypt), matching host rDNS.\n\n**mod_copy probe (harmless, NO CPTO sent):** `SITE CPFR /zz_no_such_file_52bbefbe` → `500 'SITE CPFR' not understood` ⇒ mod_copy absent.\n\n**Auth (3 attempts, all `530 Login incorrect`):** anonymous(anon@example.com), ftp/ftp, admin/admin ⇒ no anonymous / no trivial default.\n\n**Version:** exact build not obtainable black-box (ServerIdent hides banner; nmap matches only \"ProFTPD\"). Feature set places it ≥1.3.6.\n\n### CVE closure\n- **CVE-2015-3306 / CVE-2019-12815 (mod_copy pre-auth file copy → RCE): RULED OUT** — mod_copy not loaded.\n- **CVE-2010-20103 (ProFTPD 1.3.3c backdoor, pre-auth root RCE): RULED OUT** — build ≥1.3.6, not 1.3.3c.\n- **CVE-2026-42167 (mod_sql RCE <1.3.10rc1; KEV, 13 PoCs; requires SQL backend allowing commands): NEEDS FOLLOW-UP** — mod_sql load/config is not observable over FTP; host does run MariaDB 10.5.29, so plausible. Missing: mod_sql presence + backend config, and exact version.\n- **CVE-2026-44331 (mod_sql reverse-DNS hostname SQLi ≤1.3.9a; requires UseReverseDNS + sqltab): NEEDS FOLLOW-UP** — same mod_sql/config gap.\n- **CVE-2024-48651 (mod_sql supplemental-groups → GID0 privesc): NEEDS FOLLOW-UP** — same mod_sql gap; post-auth anyway.\n- **CVE-2026-63090 / CVE-2026-53994 / CVE-2026-63091 / CVE-2026-35025 (mod_sftp memory corruption; AUTHENTICATED low-priv): NEEDS FOLLOW-UP** — no creds; not pre-auth. Missing: valid FTP cred + exact version vs 1.3.9c/1.3.10rc3.\n- **CVE-2024-57392 (buffer overflow, no released version range; scoped by vulnx to commit 4017eff8): NEEDS FOLLOW-UP** — cannot map to a version black-box.\n\n## 45.132.74.81:21 — NO FTP (filtered). Nothing to assess.\n\n## 77.68.12.66:22 — OpenSSH 8.0 (`SSH-2.0-OpenSSH_8.0`)\n- **CVE-2023-38408 (KEV, ssh-agent PKCS#11 RCE, <9.3p2): RULED OUT for this target** — it is a **client-side ssh-agent** flaw; exploitation requires a victim to forward their agent to an attacker-controlled host. No such attacker-reachable path exists against the exposed sshd. (CVE-2023-51385 likewise is client ProxyCommand.) Banner lacks a vendor suffix; kex advertises `kex-strict-s-v00@openssh.com` (Terrapin mitigation present) ⇒ distro applies backports; patch level not banner-visible but moot for these client-side CVEs. No SSH brute force performed.\n\n## 45.132.74.81:22 — OpenSSH 9.6p1 Ubuntu 3ubuntu13.19\n- **CVE-2024-6387 regreSSHion (pre-auth RCE): RULED OUT** — Ubuntu patched at 1:9.6p1-3ubuntu13.4/.5; package revision `3ubuntu13.19` is far past it; kex-strict present.\n\n## Observation\nAfter the fingerprint pass + 3 failed logins, tcp/21 on 77.68.12.66 flipped from open to `Connection refused` / `connection closed` and stayed that way across ~7 attempts / ~6 min ⇒ likely anti-bruteforce block (e.g. fail2ban) keyed to egress IP; a service flap cannot be excluded. All required evidence was captured before the block.\n\n## Net\nNo confirmed exploitable pre-auth RCE on either origin. Two pre-auth ProFTPD CVE families ruled out with named controls (mod_copy absent; not 1.3.3c); regreSSHion ruled out (backported). Residual ProFTPD risk is entirely mod_sql-config- and version-dependent (needs_follow_up). No vulnerability report filed (nothing confirmed).", "agent_name": "FTP/SSH Pre-Auth RCE Verifier", "agent_id": "52bbefbe"}, {"note_id": "a308f3", "title": "Infra Version & Pre-Auth Precondition Verification (90f93334) — origin 77.68.12.66 & 45.132.74.81", "category": "findings", "tags": ["infra", "version-fingerprint", "precondition", "proftpd", "openssh", "tomcat", "plesk", "nomachine", "90f93334", "lead5"], "created_at": "2026-09-27T21:33:17.572413+00:00", "updated_at": "2026-09-27T21:33:17.572413+00:00", "content": "Author: Infra Version & Pre-Auth Precondition Verifier (90f93334), parent Independent Red Team Lead 5 (cb52f482). Black-box, time-boxed, NON-destructive (no exploitation, no DoS). Raw commands/outputs below.\n\n## Exact-version table (raw evidence)\n\n| asset | service | exact version | evidence | pre-auth RCE precondition | verdict |\n|---|---|---|---|---|---|\n| 77.68.12.66:21 | FTP | **ProFTPD** (banner VERSION-STRIPPED) | `220 ProFTPD Server (ProFTPD) [77.68.12.66]`; FEAT lists AUTH TLS/CCC/CLNT/CSID/EPRT/EPSV/HOST/LANG/MDTM/MFF/MFMT/MLST/PBSZ/PROT/**RANG STREAM**/REST/SIZE/SSCN/TVFS/UTF8 | mod_copy (CVE-2015-3306 / CVE-2019-12815) | **FAILS — mod_copy not loaded** |\n| 77.68.12.66:22 | SSH | **OpenSSH 8.0** | `SSH-2.0-OpenSSH_8.0`; nmap: `OpenSSH 8.0 (protocol 2.0)` | CVE-2023-38408 / CVE-2023-51385 | **FAILS — client-side/agent-forwarding precondition absent** |\n| 77.68.12.66:80 | HTTP | nginx (Ubuntu) | nmap; `Server: nginx/1.24.0 (Ubuntu)` on 45.x too | none | no RCE primitive |\n| 77.68.12.66:8443 | Plesk | **18.0.80.x (build unconfirmed this pass)** | earlier this session: `303 →/login.php`, `/login_up.php3 → 200`, `server: nginx`, `Set-Cookie: plesk-ext-social-login-jwt-session=<HS256 JWT>`; nmap `sw-cp-server` | all in-range Plesk RCE CVEs are AUTHENTICATED; unauth CVEs fixed at 18.0.80.8 | **version gap — 8443 began FILTERING our egress mid-test** |\n| 77.68.12.66:3306 | MariaDB | 10.5.29 | nmap `5.5.5-10.5.29-MariaDB`; handshake completes (ERROR 1045, no host ACL) | creds | open gap (prior: 50k+ creds, 0 hits) |\n| 45.132.74.81:22 | SSH | **OpenSSH 9.6p1 Ubuntu-3ubuntu13.19** | `SSH-2.0-OpenSSH_9.6p1 Ubuntu-3ubuntu13.19`; nmap agrees | CVE-2024-6387 regreSSHion (range 8.5p1–<9.8p1) | **pkg rev 3ubuntu13.19 ≫ patched 3ubuntu13.5 ⇒ distro-backported; race NOT attempted (RoE)** |\n| 45.132.74.81:80/443 | HTTP | nginx 1.24.0 (Ubuntu) → Tomcat 9.0.121 | `Server: nginx/1.24.0 (Ubuntu)`; default page :80 | — | none |\n| 45.132.74.81:443 | Tomcat | **Apache Tomcat/9.0.121** | malformed-request error-page footer `<h3>Apache Tomcat/9.0.121</h3>` (+ `Http11InputBuffer.parseRequestLine`, `NioEndpoint.java:2254`) | /manager or /host-manager deploy | **FAILS — /manager/html, /host-manager/html, /manager/status, /docs/ all 404** |\n| 45.132.74.81:4000 | NoMachine NX | 10.0.59 | nmap `nomachine-nx ... 10.0.59`; my HTTP/bare-TCP probes returned NO banner (service speaks NX protocol; peer resolved via `NXSH-6.0.0`→`NXD-10.0.59`, coverage 1dc941) | CVE-2026-18264 (8.8) | **FAILS — 18264 is REJECTED + authenticated (PR:L); CVE-2026-53694 <9.5.7 ⇒ N/A** |\n| WP fleet | WordPress core | **7.1.2 / 7.1 PRESENT** | betmaze.co.uk `content=\"WordPress 7.1.2\"` + `wp-emoji-release.min.js?ver=7.1.2`; mogobet.com `?ver=7.1`; theonlinecasino.co.uk `content=\"WordPress 7.1\"` | CVE-2026-63030 pre-auth REST batch SQLi→RCE | **NOT in affected range** (advisory fixed in 6.9.5 / 7.0.2 ⇒ 7.1.x patched); medium confidence (no web access) |\n\n## Precondition checks (raw)\n**ProFTPD mod_copy — ABSENT (decisive):**\n```\nSITE HELP -> 214-The following SITE commands are recognized (* =>'s unimplemented)\n               QUOTA\n             The following SITE extensions are recognized:\n               RATIO -- show all ratios in effect\n               HELP\n               CHGRP\n               CHMOD\nSITE CPFR /etc/hostname -> 500 'SITE CPFR' not understood\nSITE CPTO /tmp/irt_ver_probe_zzz -> 503 Bad sequence of commands   (CPFR state never set)\nSITE RATIO -> 214 Current Ratio: ( -0/0 +0/0 (0 0 0 0) = 0/0 )\nUSER anonymous / PASS <email> -> 331 Password required for anonymous / 530 Login incorrect.  (anonymous DENIED)\n```\n=> No `CPFR`/`CPTO` in SITE HELP and explicit `500 not understood` ⇒ `mod_copy` module is not compiled/loaded. CVE-2019-12815 and CVE-2015-3306 **cannot** be triggered regardless of version. No copy was performed (non-destructive). Pure-FTPd CVE-2024-48208 N/A (service is ProFTPD, not Pure-FTPd).\n\n**Tomcat /manager — ABSENT:** `/manager/html`→404, `/host-manager/html`→404, `/manager/status`→404, `/docs/`→404 (no deploy RCE). Tomcat 9.0.121 is also out of range of every known Tomcat RCE CVE (2025-24813 ≤9.0.98; 2024-50379/56337 ≤9.0.97; 2026-65183 ≤9.0.120 local-only).\n\n**OpenSSH:** 77.68.12.66 = 8.0 ⇒ CVE-2024-6387 not applicable (needs ≥8.5p1); CVE-2023-38408 (ssh-agent PKCS#11) / CVE-2023-51385 (ProxyCommand) both require the *client/agent-forwarding* side, i.e. an attacker-controlled agent forwarded to this server — not reachable in a server-only unauthenticated black-box PT ⇒ NOT attacker-reachable. 45.132.74.81 = 9.6p1 Ubuntu-3ubuntu13.19 ⇒ in upstream range for regreSSHion but the Ubuntu revision is far past the fix; black-box binary patch level cannot be PROVEN and the race (DoS-class, hours) was NOT attempted per RoE.\n\n## Ownership ambiguity\n- **77.68.12.66** → TLS cert (8443 and STARTTLS-FTP, identical): `CN=linux.prod.activewin.co.uk`, Let's Encrypt; rDNS `activewin.co.uk`. A third-party-run production host that also serves the in-scope `promotions.pandabingo.com` Plesk vhost. Confirm it is the in-scope property before any write-class action.\n- **45.132.74.81** → TLS cert: `CN=cl.exalt-digital.ru` (unrelated third-party domain); rDNS `starosamuchan.com`. Origin of the in-scope `*.potsofluck.com` subdomains, but the cert/hostname do not belong to the brand ⇒ strong ownership ambiguity.\n\n## Net\nNo pre-auth RCE precondition HOLDS on either origin (mod_copy absent; Tomcat manager absent; NoMachine 18264 rejected+auth; OpenSSH client-side CVEs not reachable; regreSSHion backported). Remaining version gaps: Plesk exact build (8443 filtered mid-test), ProFTPD exact version (banner stripped), MariaDB credential (open gap). **No vulnerability report filed** (nothing exploitable demonstrated).", "agent_name": "Infra Version & Pre-Auth Precondition Verifier", "agent_id": "90f93334"}, {"note_id": "f5d5de", "title": "RCE objectives 1–5 — owner map, Imperva correction, artifact-credential negative (IRTL3)", "category": "methodology", "tags": ["rce", "objectives", "coordination", "imperva", "deconflict", "52175a73", "triage"], "created_at": "2026-09-27T21:28:08.001354+00:00", "updated_at": "2026-09-27T21:28:08.001354+00:00", "content": "RCE-inventory triage (root objective set, objectives 1–5). Written by Independent Red Team Lead 3 (52175a73) to prevent duplicated spend — read before spawning any RCE-triage agent.\n\n## 1. Objective → owner map (verify in view_agent_graph before spawning)\nAll five objectives are already claimed by peer-lead children (12 agents, mostly running):\n- Objective 1 (exact version fingerprinting; OpenSSH backport; WP core CVE-2026-63030): IRTL1 `RCE Version Fingerprint and Preconditions` (e0afd929); IRTL2 `Next.js RSC Version Verifier` (85834038) + `Plesk/Tomcat/WP-Core Verifier` (d05d6fd6); IRTL5 `Infra Version & Pre-Auth Precondition Verifier` (90f93334).\n- Objective 2 (WAF bypass / Imperva Error 15 / egress): IRTL1 `Imperva Blocked-Tenant Reach` (9a1f4de9, completed); IRTL2 `Imperva-Unlock Dynamic Tester` (97643755, completed) + `Edge Cross-Cutting Sweep` (4e714cc6, completed); IRTL4 `Imperva Host Reachability Mapper` (bf860d90, completed); IRTL5 `Next.js RSC Version & Imperva Reach Verifier` (c4b007cb); IRTL1 `Edge Desync Smuggling Sweep` (53dd4764).\n- Objective 3 (credential acquisition — Plesk/Tomcat/WPML): IRTL1 `Plesk Tomcat WP Credential Acquisition` (41cee7a2); IRTL2 `Plesk/Tomcat/WP-Core Verifier` (d05d6fd6); IRTL5 `Credentialed RCE Paths (Plesk/Tomcat/WPML/WP core)` (75add505).\n- Objective 4 (pre-auth preconditions — ProFTPD/Pure-FTPd/RSC): IRTL2 `FTP/SSH Pre-Auth RCE Verifier` (52bbefbe); IRTL5 `Infra Version & Pre-Auth Precondition Verifier` (90f93334); IRTL1 `Potsofluck Origin Services` (99a76c1c, completed).\n- Objective 5 (ABP LINQ + PlayUK SQLi escalation; UAT/PlayUK misconfigs): IRTL1 `ABP LINQ and PlayUK SQLi RCE Escalation` (c48800b6); IRTL2 `ABP-LINQ & PlayUK SQLi Escalation Verifier` (17b22e39); IRTL5 `ABP LINQ Escalation & UAT/PlayUK RCE Sweep` (bba121a7); IRTL4 `PlayUK SQLi Exfil & Priv Escalation Validator` (7d4c18bd).\n\n## 2. Unique correction that changes objectives 1, 2 and 4 — the Imperva edge is NOT an IP deny\nIndependent result from IRTL3 child `Shared-Platform Cross-Tenant Amplifier` (c4f87488): on this fleet the Imperva/Incapsula edge is a **browser-solvable JS challenge**, and it does **not** protect `/_next/static/*`. A real browser load + reload sets `incap_ses_*`; the static asset then returns 200 same-origin even from our \"blocked\" egress IP. ~20 hosts previously recorded unreachable/clean (highstakes, supabet, luckcity, mrrex, mamzinobet, betblink, 21luckybet, lekkerbets, play.betzi, ne-bet, savibet, q88bets, stakespin, rainbetsplash, tangobet, potsofluck, lobby.moneyplay) demonstrably served in-scope content.\n- Objective 2: do not conclude \"blocked\" from a first-request 403 — retry via `agent-browser` (real Chromium solves the challenge). Caveat: the reported \"Error 15\" variant may be stricter than the challenge; verify per host.\n- Objective 1: Next.js/React version on the \"blocked\" ProgressPlay build (buildId `WpePWuKOn3XrgMNqj5LeW`) is fingerprinted from the reachable `/_next/static/**` bundles.\n- Objective 4: CVE-2025-55182 RSC reachability can be tested on those hosts once a browser session exists.\n\n## 3. Objective 3 sub-item \"leaked credentials in artifacts\" — NEGATIVE\nIndependent bounded sweep of /workspace artifacts (181 MB, ~40 dirs) for credential material (psa.shadow / Basic auth / ftp:// / password|username|api_key|secret assignments / long Bearer tokens): no usable credential for Plesk 8443, FTP 21, or NoMachine 4000. Hits were only gitleaks \"generic-api-key\" fingerprints on CMS JSON, source code (e.g. `defaultAdminUserName:\"admin\"`), and probe scripts. Prior peers already attempted `.psa.shadow` traversal (`/workspace/plesk/*`, `mariadb_validate/traversal.py`).\n\n## 4. Standing blockers for the RCE objectives\n1. Single sandbox egress IP (64.111.92.186) — no true IP rotation; alternate egress needs infrastructure outside the sandbox. Prefer the browser-challenge method over egress rotation.\n2. Ownership ambiguity on the two infra origins: 45.132.74.81 (rDNS starosamuchan.com, TLS CN cl.exalt-digital.ru) and 77.68.12.66 (rDNS activewin.co.uk). Their non-web services (FTP 21, Plesk 8443, NoMachine 4000, MariaDB 3306) are off the `web_application` scope type — confirm the host serves the in-scope property before active testing; keep it to version/precondition checks, no exploitation (per root).\n3. Docker is unavailable in the sandbox; no containerised exploit runners.", "agent_name": "Independent Red Team Lead 3", "agent_id": "52175a73"}, {"note_id": "2bdf4b", "title": "Addendum: RCE inventory — CVE status corrections + new in-range candidates (OpenSSH 8.0, ProFTPD mod_copy, WP core 2026-63030)", "category": "findings", "tags": ["rce", "inventory", "cve-mapping", "addendum", "independent", "3b5f3832"], "created_at": "2026-09-27T21:13:19.070549+00:00", "updated_at": "2026-09-27T21:13:19.070549+00:00", "content": "Addendum to note `6a90f6` (Independent RCE-Candidate Inventory Agent 3b5f3832). Source: child Component CVE-Mapper (b36d5cbb), local-vulnx only (no target traffic, no exploitation). Full detail appended to `/workspace/irt_rce_inventory/RCE_INVENTORY.md` §5; child artifacts `/workspace/vulnx_out/*.json`, note `d9456e`.\n\n## CVE status corrections (drop from live-candidate tracking)\nREJECTED: CVE-2026-18264 + CVE-2026-53694 (NoMachine), CVE-2026-75604 (Next.js), CVE-2026-71318 + CVE-2026-71320 (Nuxt island SSTI), CVE-2026-10821 (Yoast).\nFixed/out-of-range at fingerprinted version: CVE-2024-35164 (Guacamole fixed in 1.6.0); all Tomcat RCE CVEs vs 9.0.121 (2025-24813 ≤9.0.98, 2024-50379/56337 ≤9.0.97, 2026-65183 ≤9.0.120); LiteSpeed Cache 7.8.1 vs 2024-28000/50550/47637; ACF 6.8.8 vs 2023-1196.\nNot RCE: Plesk CVE-2025-66430 (pre-auth BAC, no RCE); Strapi CVE-2026-27886 = pre-auth admin reset-token ATO (4.0.0–<5.37.0), not direct RCE.\n\n## NEW in-range RCE-class candidates (version/precondition check only — no 0day)\n1. **OpenSSH 8.0 @ 77.68.12.66:22 — CVE-2023-38408** (v<9.3p2; ssh-agent PKCS#11 cmd inj → RCE; CVSS 9.8; PoC; **KEV**; needs attacker-controlled agent forwarding) and **CVE-2023-51385** (v<9.6; ProxyCommand inj). **IN RANGE** → strongest *new* known RCE row.\n2. **ProFTPD @ 77.68.12.66:21 — CVE-2019-12815** (mod_copy → webshell, ≤1.3.5b) / **CVE-2015-3306** (mod_copy SITE CPFR/CPTO, ≤1.3.5). Version unknown → high-value pre-auth RCE if old.\n3. **Pure-FTPd (if present) — CVE-2024-48208** (<1.0.52; pre-auth domlsd() OOB → RCE; PoC+nuclei). Version unknown.\n4. **WordPress core 7.1.2 — CVE-2026-63030** (pre-auth REST batch SQLi → RCE, 9.8; advisory 6.9.x<6.9.5 / 7.0.x<7.0.2 ⇒ 7.1.x likely patched). Highest-value single CVE to positively exclude on the WP fleet.\n5. **WPML CVE-2024-6386** (<4.6.13, post-auth SSTI) and **SEOPress CVE-2024-5488** (<7.6.1, pre-auth* PHP object injection) on promo.hotwinscasino.com — versions unknown.\n6. **React RSC CVE-2025-55182** in range only for RSC 19.0.0/19.1.0/19.1.1/19.2.0 (per-app version unverified).\n7. **Node.js CVE-2023-32002** (<20.5.1/18.17.1/16.20.1) — verify Node version on Betty/Railway.\n8. LiteSpeed Web Server CVE-2026-31386 remains admin-only.\n\n## Net\nBucket A (known RCE-capable CVEs) gains two rows on 77.68.12.66 (OpenSSH 8.0 / CVE-2023-38408; ProFTPD mod_copy) that need only a version/precondition confirmation. Bucket B (0day-dependent) conclusions unchanged. Confidence: HIGH on the rejected/out-of-range determinations; MEDIUM on in-range verdicts that hinge on unknown versions.", "agent_name": "Independent RCE-Candidate Inventory Agent", "agent_id": "3b5f3832"}, {"note_id": "d9456e", "title": "CVE→RCE component inventory (vulnx) — versions, ranges, pre/post-auth, exploit availability", "category": "findings", "tags": ["cve", "rce", "inventory", "vulnx", "component-mapping", "b36d5cbb", "nonmachine", "guacamole", "wordpress", "nextjs"], "created_at": "2026-09-27T21:11:53.665908+00:00", "updated_at": "2026-09-27T21:11:53.665908+00:00", "content": "Agent: Component CVE-RCE Mapper (b36d5cbb), parent Independent RCE-Candidate Inventory Agent (3b5f3832).\nMethod: LOCAL `vulnx` CLI only (product search + `vulnx id` per CVE). NO target traffic, NO exploitation, NO 0day. Artifacts: /workspace/vulnx_out/*.json (broad product searches + per-CVE id records with description/remediation/is_poc/poc_count/ntps/is_kev).\n\nvulnx field semantics used: requirement_type: none=pre-auth, logged_in=post-auth, admin_privileges=post-auth(admin), user_interaction=needs victim action. is_poc+poc_count = public exploit reference(s); ntps = nuclei-template priority score (blank/none = no template).\n\n## HEADLINE\n- NO fingerprinted component has a CONFIRMED, in-range, PRE-AUTH, network-reachable RCE that is also reachable per the pack.\n- The two \"0day-style\" NoMachine CVEs the pack leaned on are **REJECTED** in vulnx: CVE-2026-18264 (post-auth, port 4000 cmd injection) and CVE-2026-53694 (<9.5.7, out of range) — both status=rejected.\n- Several pack-cited CVEs are REJECTED/fixed: CVE-2026-75604 (Next.js, Windows-only, rejected), CVE-2026-71318 + CVE-2026-71320 (Nuxt island SSTI, both rejected), CVE-2026-18264/53694 (NoMachine, rejected).\n- Every Guacamole RCE CVE is OUT OF RANGE for 1.6.0. Every LiteSpeed-Cache priv-esc/RCE CVE is OUT OF RANGE for 7.8.1. Every actionable Tomcat RCE CVE is OUT OF RANGE for 9.0.121.\n\n## CONTRADICTIONS vs the prior pack (correct these)\n1. CVE-2026-18264 — pack treated as real (auth-gated). vulnx: status=REJECTED. Do not track as valid.\n2. CVE-2026-53694 — pack \"N/A <9.5.7\". vulnx: status=REJECTED too.\n3. CVE-2026-75604 (Next.js) — pack \"Windows-only\". vulnx: status=REJECTED (also Win-only). Not a valid CVE.\n4. CVE-2026-71318 / 71320 (Nuxt) — pack \"ruled out (no island endpoint)\". vulnx: BOTH status=REJECTED.\n5. CVE-2024-35164 (Guacamole) — pack implied a live candidate; vulnx remediation = \"Upgrade to 1.6.0 or later\" → host 1.6.0 is PATCHED.\n6. NoMachine local priv-esc family (CVE-2025-8614, 2026-5053/5054/5055) — all POST-AUTH/local (logged_in), not remote; host 10.0.59.\n\n## TABLE (component | version | CVE | CVSS | status | auth | class/impact | affected range | in-range | exploit/tmpl | notes)\nOpenSSH sshd | 9.6p1 Ubuntu 3ubuntu13.19 | CVE-2024-6387 | 8.1 | modified | pre-auth | race condition → RCE (regreSSHion) | upstream 8.5p1–9.7p1 | N (vendor-backported) | PoC yes (poc_count=100), nuclei ntps=73, KEV | 9.6p1 nominally in upstream range, but Ubuntu 3ubuntu13.x backports the fix (fix at .3; fingerprint .19) → treat as PATCHED; verify.\nOpenSSH sshd | 9.6p1 | CVE-2023-38408 | 9.8 | modified | pre-auth* | ssh-agent PKCS#11 command injection → RCE | < 9.3p2 | N | poc_count=23, ntps=81, KEV | 9.6p1 > 9.3p2, patched.\nOpenSSH sshd | 9.6p1 | CVE-2023-51385 | 6.5 | modified | pre-auth* | ProxyCommand OS command injection | < 9.6 | N | poc_count=25, ntps=51 | fixed in 9.6 → host is exactly 9.6p1, patched.\nOpenSSH sshd | 8.0 (77.68.12.66) | CVE-2023-38408 | 9.8 | modified | pre-auth* | ssh-agent PKCS#11 cmd injection → RCE | < 9.3p2 | Y | poc=23, ntps=81, KEV | 8.0 < 9.3p2 → IN RANGE; precondition = agent forwarding to attacker-controlled host (req none).\nOpenSSH sshd | 8.0 | CVE-2023-51385 | 6.5 | modified | pre-auth* | ProxyCommand injection | < 9.6 | Y | poc=25, ntps=51 | IN RANGE; needs untrusted hostname w/ shell metachars.\nOpenSSH sshd | 8.0 | CVE-2024-6387 | 8.1 | modified | pre-auth | race → RCE | 8.5p1–9.7p1 | N | — | 8.0 below 8.5p1 → not regreSSHion.\nNoMachine NX | 10.0.59 (45.132.74.81:4000) | CVE-2026-18264 | 8.8 | REJECTED | post-auth | cmd injection (web svc :4000) | n/a | N | none | REJECTED; pack over-weighted this.\nNoMachine NX | 10.0.59 | CVE-2026-53694 | n/a | REJECTED | pre-auth | argument/command injection | <9.5.7/8.23.2 | N | poc=1 | REJECTED + out of range.\nNoMachine | 10.0.59 | CVE-2023-39107 | 9.1 | modified | pre-auth | arbitrary file overwrite → privesc | macOS <8.8.1 | N | poc=1 | wrong OS + version.\nNoMachine | 10.0.59 | CVE-2025-8614 / 2026-5055 / 5054 / 5053 | 7.8/7.8/7.8/7.1 | confirmed | POST-auth (local) | uncontrolled search path / path trav / BAAC → privesc RCE (SYSTEM) | version not stated | unclear | ntps=19 | local low-priv first; host is 2026 build 10.0.59.\nApache Guacamole | 1.6.0 | CVE-2024-35164 | 6.8 | modified | pre-auth | terminal cmd injection → RCE (guacd) | <= 1.5.5 | N | none | PATCHED in 1.6.0 (remediation says upgrade to 1.6.0).\nApache Guacamole | 1.6.0 | CVE-2023-43826 | 7.5 | modified | pre-auth* | integer overflow → RCE | 1.5.3 and older | N | none | out of range.\nApache Guacamole | 1.6.0 | CVE-2023-30576 | 6.8 | modified | undefined | use-after-free → RCE | 0.9.10–1.5.1 | N | none | out of range.\nApache Guacamole | 1.6.0 | CVE-2023-30575 | 6.5 | modified | pre-auth | instruction injection | 1.5.1 and older | N | ntps=24 | out of range.\nApache Guacamole | 1.6.0 | CVE-2021-43999 | 8.8 | modified | pre-auth* | SAML response validation → auth bypass | 1.2.0/1.3.0 | N | none | out of range (needs SAML enabled).\nApache Tomcat | 9.0.121 | CVE-2025-24813 | 9.8 | confirmed | pre-auth | path equivalence (partial PUT) → RCE | 9.0.0-M1–9.0.98 (also 10.1<34, 11<2) | N | poc yes, ntps=88, KEV | 121 > 98 → fixed; highest-value Tomcat CVE but not in range.\nApache Tomcat | 9.0.121 | CVE-2024-50379 (+56337) | 9.8 | modified | pre-auth | TOCTOU JSP compile → RCE | 9.0.0.M1–9.0.97 | N | poc yes, ntps=67 | out of range.\nApache Tomcat | 9.0.121 | CVE-2026-65183 | 8.1 | confirmed | local | TOCTOU unix-socket creation | 9.0.42–9.0.120 | N | ntps=50 | 9.0.121 fixed; local-only anyway.\nApache Tomcat | 9.0.121 | CVE-2025-55754 | 9.6 | modified | n/a | ANSI escape injection in logs (not RCE) | 9.0.40–9.0.108 | N | ntps=55 | out of range; mislabelled RCE.\nApache Tomcat | 9.0.121 | CVE-2020-1938 (Ghostcat) | 9.8 | confirmed | pre-auth | AJP file read/include → RCE | <=9.0.30 | N | — | out of range.\nnginx | 1.24.0 (Ubuntu) | (broad) | — | — | — | no in-range RCE | — | N | — | only pre-1.21 CVEs (CVE-2021-23017 etc.) → patched.\nMariaDB server | 10.5.29 | CVE-2026-48165 / 48163 | 8.0 | modified | post-auth | SST (Galera) command injection | 10.6.1+/10.11+/11.4+/11.8+/12.3 | N | ntps=27 | 10.5 branch NOT listed → out of range; needs high-priv DB user / malicious joiner.\nMySQL server | 8.0.42-33 | CVE-2024-21096 | 4.9 | confirmed | post-auth | mysqldump client-side cmd injection | 8.0.36 and prior | N | ntps=26 | out of range; low.\nPlesk Obsidian | 18.0.80 b.8 | CVE-2025-66430 | 9.1 | confirmed | pre-auth | broken access control (NOT RCE) | Plesk 18.0 | likely Y | ntps=60 | in-range authz flaw, no RCE primitive recorded; verify fixed build.\nPlesk Obsidian | 18.0.80 b.8 | CVE-2023-4931 | 6.3 | modified | local | installer DLL hijacking | — | unclear | — | local.\nProFTPD | unknown (77.68.12.66) | CVE-2019-12815 | 9.8 | modified | pre-auth* | mod_copy arbitrary file copy → webshell RCE | <= 1.3.5b | unclear | — | version unknown → verify; classic RCE if old.\nProFTPD | unknown | CVE-2015-3306 | 10.0 | modified | pre-auth | mod_copy SITE CPFR/CPTO → RCE | <= 1.3.5 | unclear | — | version unknown.\nProFTPD | unknown | CVE-2026-63091 | 6.5 | confirmed | post-auth | mod_sftp integer overflow (ASLR bypass) | <1.3.9c/1.3.10rc3 | unclear | ntps=34 | post-auth only.\nPure-FTPd | unknown | CVE-2024-48208 | 8.6 | confirmed | pre-auth | domlsd() OOB read → RCE | < 1.0.52 | unclear | poc=2, ntps=55 | version unknown → verify; strong candidate if old.\nWordPress core | 7.1.2 | CVE-2026-63030 | 9.8 | confirmed | pre-auth | REST batch route confusion + WP_Query SQLi → RCE | 6.9.x<6.9.5 and 7.0.x<7.0.2 | unclear | poc yes, ntps=85 | 7.1.x NOT in advisory range → likely patched; fingerprint may be imprecise → VERIFY. Critically the only pre-auth WP RCE to check.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-28000 | 9.8 | modified | pre-auth* | weak-hash → priv-esc → RCE | 1.9–6.3.0.1 | N | poc=18, ntps=62, KEV | out of range.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-50550 | 8.1 | modified | pre-auth* | privilege escalation | through 6.5.1 | N | ntps=28 | out of range.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-47637 | 8.8 | modified | pre-auth | path traversal (file read) | through 6.4.1 | N | ntps=23 | out of range.\nLiteSpeed web server | (LSWS/LSWS Ent) | CVE-2026-31386 | 7.2 | confirmed | POST-auth (admin) | OS command injection | — | n/a | ntps=17 | requires admin → not pre-auth.\nContact Form 7 | 6.1.7 | (none core) | — | — | — | matches were 3rd-party add-ons | — | N | — | no in-range CF7-core RCE.\nRedirection | 5.9.0 | (none core) | — | — | — | matches were \"Redirection for CF7\" (different plugin) | — | N | — | no core RCE.\nAkismet | 5.7.2 | none | — | — | — | — | — | N | — | no RCE record.\nYoast SEO | 28.3 | CVE-2026-10821 (Premium) | 6.6 | rejected | post-auth | — | — | N | — | rejected; premium only.\nACF | 6.8.8 | CVE-2023-1196 | 8.8 | modified | post-auth (Contrib+) | PHP object injection → RCE if gadget | 6.x<6.1.0 / 5.x<5.12.5 | N | poc, ntps=33 | 6.8.8 out of range.\nresponsive-accordion-and-collapse | 2.5.3 | none | — | — | — | matches were unrelated plugins | — | N | — | no CVE record.\nWPML | (present) | CVE-2024-6386 | 9.9 | modified | POST-auth | authenticated SSTI → RCE | < 4.6.13 | unclear | — | version unknown → verify.\nSEOPress | (present) | CVE-2024-5488 | 9.8 | confirmed | pre-auth* | PHP object injection → RCE if gadget | < 7.6.1 | unclear | — | version unknown → verify.\nLimit-Login-Attempts-Reloaded | absent | none | — | — | — | — | — | N | — | plugin not installed on fleet.\nPHP | 7.4.33 (EOL) | CVE-2024-4577 | 9.8 | confirmed | pre-auth | PHP-CGI argument injection → RCE | Windows PHP-CGI only | N | — | N/A on Linux/FPM host.\nPHP | 7.4.33 (EOL) | (various) | — | — | — | mostly local/DoS | — | N | — | EOL = patch backlog; no confirmed pre-auth net RCE for FPM/CLI.\nNext.js / React (RSC) | several | CVE-2025-55182 | 10.0 | confirmed | pre-auth | RSC unsafe deserialization → RCE | RSC 19.0.0/19.1.0/19.1.1/19.2.0 | unclear | poc=100, ntps=85, KEV | in-range ONLY if app pins those RSC versions; pack verified patched on UAT apps → treat as patched but re-verify each Next.js build.\nNext.js | several | CVE-2026-75604 | 9.0 | REJECTED | pre-auth | path traversal (Win) → RCE | 13.4.0–<15.5.24 / 16.3.3 | N | poc=5 | REJECTED; Windows-only.\nReact (RSC) | — | CVE-2025-67779 / 55184 | 7.5 | modified | pre-auth | DoS | RSC | unclear | — | DoS not RCE.\nNuxt.js / Nitro | several | CVE-2026-71318 | 4.8 | REJECTED | pre-auth | /__nuxt_island/ template injection | 3.1.0–3.21.10 /4.x<4.5.1 | N | none | REJECTED.\nNuxt.js / Nitro | several | CVE-2026-71320 | 8.1 | REJECTED | pre-auth | /__nuxt_island/ template injection (needs runtimeCompiler) | 3.4.0–<3.21.10/4.5.1 | N | none | REJECTED.\nNuxt.js | several | CVE-2023-3224 | 9.8 | modified | pre-auth | SSTI | old | N | — | old version range.\nStrapi | (<5.37.0?) | CVE-2026-27886 | 7.5 | confirmed | pre-auth | query-param bypass → admin reset-token → ATO | 4.0.0–<5.37.0 | unclear | poc=3, ntps=45 | ATO, not direct RCE; verify UAT Strapi version.\nStrapi | — | CVE-2026-22707 | 5.4 | confirmed | POST-auth | stored XSS in Upload Content API | < 5.33.3 | unclear | ntps=27 | post-auth.\nStrapi | — | CVE-2022-27263 | 9.8 | modified | user_interaction | unrestricted file upload | — | unclear | — | old.\nNode.js | unknown | CVE-2023-32002 | 9.8 | modified | n/a | module policy bypass → RCE (loader) | Node <20.5.1/18.17.1/16.20.1 | unclear | — | verify Node version on Betty/Railway.\nNode.js | unknown | CVE-2021-22930 | 9.8 | modified | n/a | UAF | Node <16.6.2 | N | — | old.\nNode.js | unknown | CVE-2026-21636 | 10.0 | confirmed | n/a | privilege escalation (BAAC) | — | unclear | — | no range in record.\nNestJS | unknown | CVE-2025-54782 | 8.8 | confirmed | user_interaction | @nestjs/devtools-integration sandbox escape → RCE | devtool pkg <= 0.2.0 | N | poc, ntps=53 | DEV TOOL only; requires dev to load attacker page → not prod RCE.\nNestJS | unknown | CVE-2024-29409 | 5.5 | confirmed | user_interaction | unrestricted file upload | — | N | — | dev tool.\nExpress.js | unknown | CVE-2022-24999 (qs) | 7.5 | modified | n/a | qs prototype pollution | qs <6.10.3 | unclear | — | dep-level; no RCE sink verified.\nASP.NET MVC 5.2 / .NET 4.8 / IIS 10 | — | CVE-2017-7269 | 9.8 | confirmed | pre-auth | WebDAV ScStoragePathFromUrl overflow | IIS 6.0 only | N | — | OS/product N/A (IIS 10).\nIIS/.NET WebForms ViewState | — | (no CVE) | — | — | post-auth* | unsafe deserialization IF machineKey known | n/a | N | — | class not a CVE; pack: MAC enforced, no key leak.\nTelerik/Kendo/DevExpress | absent | CVE-2019-18935 etc | 9.8 | confirmed | pre-auth | .NET deserialization | — | N/A | — | NOT PRESENT on .NET hosts.\nASP.NET Boilerplate (ABP) | — | none in vulnx | — | — | — | framework; no CVE record | — | N/A | — | app-code dynamic-LINQ (vuln-0027) is not a component CVE.\nEF Core | — | none notable | — | — | — | — | — | N/A | — | 3 records, no RCE.\nAuth.js / NextAuth | — | none | — | — | — | no RCE CVE | — | N/A | — | acedbet.", "agent_name": "Component CVE-RCE Mapper", "agent_id": "b36d5cbb"}, {"note_id": "6a90f6", "title": "RCE-candidate inventory (independent) — components, CVE-RCE mapping, 0day candidates, blockers", "category": "findings", "tags": ["rce", "inventory", "cve-mapping", "exploitability", "independent", "3b5f3832", "0day-candidates"], "created_at": "2026-09-27T20:53:40.409540+00:00", "updated_at": "2026-09-27T20:53:40.409540+00:00", "content": "Author: Independent RCE-Candidate Inventory Agent (3b5f3832), parent Root (7e7a20bf). Inventory/mapping only — NO exploitation, no 0day. Full table: `/workspace/irt_rce_inventory/RCE_INVENTORY.md`; CVE metadata captured in `/workspace/irt_rce_inventory/cve_meta.jsonl`.\n\n## Bucket A — known RCE-capable CVEs vs fingerprinted components (actionable within RoE)\n- **OpenSSH 9.6p1 Ubuntu 3ubuntu13.19 @ 45.132.74.81:22** — CVE-2024-6387 regreSSHion (pre-auth race RCE, CVSS 8.1 AC:H, public PoC). Affected 8.5p1–9.7p1 → in range by upstream version, but Ubuntu pkg rev `3ubuntu13.19` ≫ patched `3ubuntu13.4` ⇒ **very likely distro-backported / not exploitable**. HIGH value to confirm.\n- **NoMachine NX 10.0.59 @ 45.132.74.81:4000** — CVE-2026-18264 cmd injection, CVSS 8.8 but **PR:L (authenticated)**, vulnx status **rejected** (ZDI-26-483). Needs NX creds. CVE-2026-53694 is <9.5.7 ⇒ N/A. Local-privesc CVEs (2026-5055/5054/5053, 2025-8614) need existing local code exec.\n- **ProFTPD @ 77.68.12.66:21** (version unfingerprinted) — confirmed RCE CVEs CVE-2026-63090 (8.8), CVE-2026-42167 (8.1), CVE-2010-20103 (9.8 cmd inj); mostly authenticated.\n- **Plesk Obsidian 18.0.80.8 @ 77.68.12.66:8443** — version-matched & **authenticated**: CVE-2026-58046 (9.9 XML-RPC blind SQLi), CVE-2026-65646 (9.9 BAC file-read+priv-esc), CVE-2026-64636 (7.7 SQLi ≤18.0.80) ⇒ any low-priv panel cred → root/RCE. Unauthenticated RCE/traversal CVEs (67397/68492/67394) are **fixed at 18.0.80.8**; CVE-2025-54336 rejected.\n- **React RSC / Next.js App Router** — CVE-2025-55182 unauth RCE: **patched on tested UAT EKS hosts**; **unverified on all Imperva-blocked Next.js hosts** (ProgressPlay marketing fleet buildId WpePWuKOnX3rgMNqj5LeW, acedbet, play.*). CVE-2026-75604 is Windows-only ⇒ N/A.\n- **Apache Guacamole 1.6.0** — CVE-2024-35164 (≤1.5.5) ⇒ not in range. **LiteSpeed Cache 7.8.1** — CVE-2024-28000/50550 (<6.5.1) ⇒ not in range.\n\n## Bucket B — 0day-dependent RCE candidates (no as-is public RCE CVE)\n- **WordPress core 7.1/7.1.2 (7 hosts)** — authenticated theme/plugin-editor → PHP write; no unauth path found. Admin creds reachable in principle: user-enum + unthrottled XML-RPC/wp-login (vuln-0013/0014). Highest-probability RCE in scope *if* creds obtained. Note WP Engine hosts may set DISALLOW_FILE_EDIT.\n- **PHP 7.4.33 EOL @ playuk.com** — no future patches; but `disable_functions` blocks exec/system/passthru/popen/proc_open/pcntl_exec (webshell command-exec blocked).\n- **Nuxt.js/Nitro marketing fleet (13 hosts)** — CVE-2026-71318 `/__nuxt_island/` template-injection → Nitro RCE (vulnx status rejected); island endpoint absent on all 9 tested hosts ⇒ 0day-dependent.\n- **Strapi behind `/api/cms` (UAT EKS)** — CVE-2026-27886 BAC (confirmed); proxy GET-only + parameterized filters ruled out ⇒ sanitizer-bypass 0day needed for admin ATO→RCE.\n- **IIS/.NET ViewState (jackpot.com, games.betsuna.com)** — ViewState deserialization RCE held shut **only** by machineKey MAC+encryption (auto key); reopens on any machineKey/web.config leak. No vendor RCE components present.\n- **ABP + EF Core @ neonrush.com** — `sorting` Dynamic-LINQ injection CONFIRMED (vuln-0027) but the restricted type provider blocks Process/Reflection/IO ⇒ read-only SQL. A type-provider bypass = RCE; currently single-control.\n- **Node/NestJS “Betty Admin” @ appmanager.tangobet.co.uk** — **admin/admin123 confirmed (vuln-0001)**, but no merge/eval/SSRF/upload sink found ⇒ prototype-pollution→RCE needs a 0day sink.\n- **MySQL 8.0.42 + confirmed SQLi @ api-qa.playuk.com (vuln-0028)** — SQLi→`INTO OUTFILE`→webshell→RCE if FILE privilege + stacked queries + writable webroot (write not proven).\n- **Apache Tomcat 9.0.121 / Guacamole 1.6.0 @ 45.132.74.81** — Tomcat auth-bypass/smuggling CVEs (unconfirmed, recent build); post-auth Guacamole→RDP pivot.\n\n## Blockers\n1. Imperva \"Error 15\" blocks egress IP for ~12 hosts ⇒ app-tier RCE surface unmapped (mrrex, mamzinobet, moneyplay, ne-bet, supabet, betblink, 21luckybet, highstakes, lekkerbets, hotwins, luckcity, play.betzi.co, tangobet apex).\n2. No credentials for the two exposed origins ⇒ highest-value post-auth RCE (NoMachine, Plesk) gated.\n3. Ownership ambiguity 45.132.74.81 (rDNS starosamuchan.com / CN cl.exalt-digital.ru) & 77.68.12.66 (rDNS activewin.co.uk).\n4. Version gaps: ProFTPD, LiteSpeed WS, Nuxt, Strapi, Next.js patch level, headless WP, EB apps.\n5. Plesk sw-cp-server path-traversal untested (8443 refused mid-test) → would yield /etc/psa/.psa.shadow → MariaDB admin cred.\n\nMethod note: CVE facts taken from the shared pack’s `vulnx` results and independently re-checked with the local `vulnx` CLI (rate-limited, no API key). Cross-checked against nmap artifacts (`nmap_potsofluck_scan1/2.txt`, `mariadb_validate/nmap_77.68.12.66.txt`).", "agent_name": "Independent RCE-Candidate Inventory Agent", "agent_id": "3b5f3832"}, {"note_id": "f6a104", "title": "DB access path analysis — Red Team B (service & credential sweep)", "category": "findings", "tags": ["red-team-b", "db-access", "credential-sweep", "exposed-db", "mysql", "postgresql", "mariadb", "negative-result", "mariadb-brute", "open-proof-gap"], "created_at": "2026-09-27T17:51:50.612050+00:00", "updated_at": "2026-09-27T18:12:21.518028+00:00", "content": "Agent: DB Service & Cred Leak Sweeper (c1662cb9, child of Red Team B — DB Access Paths 872744d4).\n\n# Method\n1. Resolved all 47 in-scope apexes + ~200 subdomain prefixes (crt/per-prefix) → 209 resolving names, 128 unique IPs.\n2. `naabu` + `nmap -sV` over DB/exposure ports (3306,5432,5433,1433/1434,1521,27017-19,6379,11211,9200/9300,5984,7474/7687,9042,8086,2181,5672/15672,2375/2379,5985/5986,21,22,25) on every resolved IP.\n3. Default/blank credential attempts against every open DB service (pymysql / psycopg2).\n4. Artifact sweep: 6061 config/backup path probes (.env, wp-config.php.*, .git, .svn, *.sql, backups, actuator, phpinfo, server-status…) over 209 hosts.\n5. JS-bundle secret scan (gitleaks + DB-URI regex) of ~50 bundles from 15 reachable hosts.\n\n# Results table\n| Target | Vector | Status | Evidence / control |\n|---|---|---|---|\n| 35.214.94.72 (headless.mrslot/mrmobi/mrsuperplay, staging3.mrjackvegas, ftp.*) | MySQL 3306 | RULED OUT (host ACL) | ERROR 1130 \"Host '64.111.92.186' is not allowed to connect\"; PG FATAL \"no pg_hba.conf entry\" |\n| 35.214.94.72 | PostgreSQL 5432 | RULED OUT (pg_hba) | FATAL no pg_hba.conf entry for postgres/root |\n| 35.214.89.161 (headless.jazzyspins, ftp.jazzyspins) | MySQL/PG | RULED OUT | Same host-ACL + pg_hba controls |\n| 77.68.12.66 (promotions.pandabingo.com) | MariaDB 10.5.29 :3306 | NEEDS FOLLOW-UP | Reachable (no host ACL); ~100 default/weak creds all 1045 Access denied; no lockout observed. Access not obtained. |\n| 35.214.94.72 / .89.161 / 77.68.12.66 | FTP :21 (Pure-FTPd/ProFTPD) | RULED OUT | Anonymous login 530 rejected |\n| 35.214.x, 77.68.12.66 | Dovecot IMAP 143/993 | observation | Mail service exposed; no DB relevance, not pursued |\n| Fleet (209 hosts) | .env / wp-config backups / .git / *.sql | NO ISSUE | All 200s are SPA catch-all fallbacks (uniform size); only real files: mogobet debug.log + affiliates.dynobet .DS_Store (locale dirs only) |\n| mogobet.com /wp-content/debug.log | DB creds in log | RULED OUT | 2660B log = only PHP array_filter TypeErrors; no creds/queries |\n| Fleet JS bundles | DB connection strings | NO ISSUE | gitleaks: only vuln-0008 game-provider keys; no DB URIs |\n| 35.214.x origins | Direct-origin SiteGround bypass | RULED OUT | Origin still returns sgcaptcha 202 for every path |\n| 77.68.12.66:8443 | Plesk panel / default vhost | see EXTENSION below | Plesk login + \"no Web site at this address\"; no anonymous access |\n| api.jackpot.com (185.64.56.78), git.jackpot.com (91.150.80.242) | DNS-resolved, non-CDN | dead | No open ports (22/80/443/3306 all closed) |\n\n# Heads-up / corrections for downstream agents\n- **53 apexes/subdomains resolve behind CDN edges (Cloudflare 104.x/172.67.x/188.114.x, Imperva 45.60.x/45.223.x) that accept a TCP connection on EVERY scanned port.** Port-scanner hits on those IPs are edge artefacts, not services — always service-verify (nmap -sV / protocol handshake) before treating a port as open.\n- The real in-scope origins with exposed infrastructure are the two GCP hosts (`35.214.94.72`, `35.214.89.161`) and `77.68.12.66`.\n- **No direct DB access achieved** and **no leaked DB credential found** across the fleet.\n\n# Closure\nNo `create_vulnerability_report` filed: no DB-access PoC (access was not obtained) and no leaked credential yielding a connection. The one open item is the internet-exposed MariaDB on 77.68.12.66.\n\n---\n\n# EXTENSION — MariaDB credential test on 77.68.12.66:3306\n\nAgent: **MariaDB Credential Tester (56e41677)**, child of Red Team B (872744d4). This is the dedicated follow-up on the one open item above.\n\n## Target confirmed\n`MariaDB 10.5.29` (raw handshake banner `5.5.5-10.5.29-MariaDB`), TCP/3306 reachable from egress `64.111.92.186`. **No host allowlist** — the server completes the handshake and returns `ERROR 1045 Access denied for user '<user>'@'64.111.92.186'` (not `1130`/host-denied), so the password is the only barrier.\n\n## No user-enumeration oracle\n- Error code is `1045` for **both** existing and non-existent usernames.\n- Auth latency is indistinguishable across 30 samples/user: `root` 45.56 ms mean, `admin` 45.54 ms, `pandabingo` 45.30 ms, `plesk` 45.89 ms, random non-existent usernames 45.12–45.45 ms. Valid accounts cannot be enumerated.\n\n## Bounded online credential test (authorised; no throttling/lockout observed)\n8 workers, ~166 attempts/s, failed-auth attempts only; non-destructive; no `1129` host-block, `max_connect_errors` never tripped.\n\n| Pass | Usernames | Passwords | Attempts | Result |\n|---|---|---|---|---|\n| 1 | 33 (root, admin, pandabingo, panda, plesk, mysql, db, wordpress, wp, www-data, web, bingo, promotions, promos, staging, test, dev, operator, app, game, casino, mariadb, user, guest, administrator, betting, sports, hosting, pleskadmin, admin1, manager, backup, www) | brand/domain-derived (pandabingo/panda/bingo/promotions + 26 suffixes + case variants) + NCSC top-1200 | 22,669 | all `1045` |\n| 2 | 40 Plesk/hosting-style (pma, phpmyadmin, psa, psaadmin, debian-sys-maint, mysqladmin, webadmin, dba, sql, data, pandabingo_wp, wp_pandabingo, pandabingo_admin, bingo_admin, panda_admin, promotions_admin, promos_admin, hosting, webmaster, ftpuser, backup, siteuser, cms, payments, support, service, monitor, reporting, brand words…) + empty username | brand core variants + hosting/DB-specific extras + NCSC top-60 | 7,960 | all `1045` |\n| 3 | 52 usernames incl. `''` | blank, username-as-password, username+`1`, `\" \"`, `null` (blank/reflexive sweep) | 312 | all `1045` |\n| 4 | root, admin | NCSC top-10,000 most-common passwords | 19,994 | all `1045` (6 transient connection errors) |\n\n**Total: 50,935 credential attempts → 0 valid credentials.**\n\nWordlist used: `/home/pentester/tools/wordlists/100k-most-used-passwords-NCSC.txt`.\n\n## Outcome / closure\n- **No credential obtained.** The MariaDB root/app password is not blank, not the username, not a brand/domain-derived variant, and not in the top-10,000 most-common passwords — consistent with a high-entropy (Plesk-generated) password.\n- **Closure state: `open_proof_gap`** (coverage entry `6e15f5` updated). Password strength is untested beyond the curated/common corpus (~51k); a larger/targeted wordlist or the real credential from another source could still succeed. **Not clean.**\n- **The exposure itself is a genuine risk** (internet-facing MariaDB, no IP allowlist, password-only auth), but no unauthorised access was demonstrated, so no `create_vulnerability_report` was filed (no CVSS impact can be evidenced).\n\n## Recommended continuation (same in-scope host; outside this task's 3306-only scope)\n- **`77.68.12.66:8443` Plesk panel** — the most plausible remaining route to this DB: a panel compromise discloses/rotates the DB credentials. The sweeper found only normal auth + a default vhost, so this needs a dedicated Plesk credential/CVE review.\n- **GCP origins `35.214.94.72` / `35.214.89.161`** — MySQL 3306 / PostgreSQL 5432 are internet-listening but enforce host-ACL / `pg_hba.conf` against our egress; reachable only from an allowed network or via SSRF originating on those hosts.\n\n---\n\n# EXTENSION 2 — Plesk panel route to the DB (77.68.12.66:8443)\n\nAgent: **Plesk Panel DB Cred Hunter (339c583b)**, child of Red Team B (872744d4). Goal: reach the MariaDB through the Plesk panel (a panel compromise discloses/rotates the DB credentials) or via a Plesk CVE.\n\n## Target fingerprint\n- **Plesk Obsidian 18.0.80**, build `1800260918.14` (panel asset args `urlArgs=18.0.80-8` → 18.0.80 build 8), server `sw-cp-server`; Plesk hostname `linux.prod.activewin.co.uk`.\n- Same IP runs: FTP 21 (ProFTPD), SSH 22 (OpenSSH 8.0), IMAP 143/993 (Dovecot), MariaDB 3306, HTTP 80 / HTTPS 443 (Plesk default vhost only), panel 8443.\n- `promotions.pandabingo.com` = unconfigured Plesk default vhost (\"Web Server's Default Page\") — no application.\n\n## What was tested, and the controls that hold\n1. **API access is IP-restricted (holds).** Both APIs answer but refuse this egress:\n   - REST: `GET /api/v2/server` → `{\"code\":0,\"message\":\"Access to API is disabled for 64.111.92.186\"}`.\n   - Legacy XML: `POST /enterprise/control/agent.php` (well-formed packet) → `<errcode>1006</errcode><errtext>Access to API is disabled for 64.111.92.186</errtext>`.\n   - Enforced on the **socket IP**: spoofing `X-Forwarded-For`, `X-Real-IP`, `X-Client-IP`, `Forwarded`, `X-Originating-IP`, `Client-IP` (and via the hostname) does not change the 1006 response.\n2. **phpMyAdmin is gated (holds).** `/phpmyadmin/`, `/phpMyAdmin/`, `/domains/databases/phpMyAdmin/` → 303 to `/login.php?success_redirect_url=…`; the default vhost exposes no DB console; no Adminer / Plesk DB manager exposed.\n3. **Panel login enforces credentials (holds).** `/login_up.php` is a React app (`Plesk.run({…})`) posting to `/login_up.php3` with `login_name`/`passwd`/`forgery_protection_token`. Bounded default/weak test — `admin` / {`admin`,`password`,`Plesk123!`,`ActiveWin1`} + 1 control attempt — all rejected (\"Incorrect username or password. Try again.\"). No weak/default credential found. Restore-password (`/get_password.php`) and `/ch_pass_by_secret.php?secret=` return generic \"Invalid secret code\" / \"Please request a new secret code\" — no oracle obtained.\n4. **Other probes:** `/login_up.php3`, `/get_password.php`, `/ch_pass_by_secret.php`, `/admin/force-reset-password` reachable unauth (Plesk core/error pages); `/modules/`, `/domains/`, `/clients/`, `/log/`, `/error_docs/` → 403/404; extension public endpoints (`/modules/social-login/public/index.php`, `/modules/wp-toolkit/public/index.php`) return a generic Plesk \"Server Error\" (500), not a stack trace. The social-login state cookie is an HS256 JWT; its secret is not a common/default value (16-candidate test) and it only holds OAuth `state` (no impact even if forged).\n\n## CVE review (vulnx + advisory status)\n| CVE | Product / type | Affected | Applicable here? |\n|---|---|---|---|\n| CVE-2025-54336 | Plesk Obsidian — Authentication Bypass (9.8) | 18.0.70, **vuln_status: rejected** | No (rejected; also >18.0.70) |\n| CVE-2026-64636 | Plesk Obsidian — SQLi (panel DB read, 7.7) | `<= 18.0.80`, **authenticated** | Version-matched, but needs auth |\n| CVE-2026-58046 | Plesk — XML-RPC API blind SQLi (9.9) | **authenticated** low-priv | Needs auth |\n| CVE-2026-65646 | Plesk — BAC: local file disclosure + priv-esc | **authenticated** | Needs auth |\n| CVE-2026-68492 | Plesk REST API ext — RCE/priv-esc | `18.0.34 < 18.0.80.8` | **Fixed** (we are 18.0.80.8) |\n| CVE-2026-67397 | Plesk — path traversal → root | `<=18.0.79.9`, `18.0.80–18.0.80.5` | **Fixed** (we are 18.0.80.8) |\n| CVE-2026-67394 | Plesk Linux — LPE (cmd inj) | up to `18.0.80.5` | **Fixed** (we are 18.0.80.8) |\n| CVE-2025-66431 / -66428 | Plesk RCE / WP Toolkit priv-esc | older builds, **rejected** | No |\n\n**Net:** every DB-relevant Plesk CVE requires an authenticated session; the only unauthenticated bypass CVE is rejected. No applicable unauthenticated Plesk CVE was confirmed.\n\n## Unresolved gap (not clean)\nThe highest-value unauthenticated avenue — **arbitrary file read via `sw-cp-server` path traversal** (which would yield `/etc/psa/.psa.shadow` and `/etc/psa/private/secret_key` → decrypt the MySQL admin credential) — **could not be conclusively tested**. A first traversal batch (9 prefixes × 10 payloads) produced no hit, and partway through testing **TCP 443 and 8443 began refusing connections from this egress** (21/22/80/143/993/3306 remained open) — consistent with a port/service-level block or the panel/HTTPS services being stopped. The panel never recovered during the test window, so follow-up probes returned only proxy-level \"Failed to connect\". Traversal therefore remains an **open proof gap**, not a clean result.\n\n## Outcome\n- **No DB access obtained** via Plesk: no credential, no CVE exploit, no file read.\n- Coverage entry `8434c8` moved `no_issue_found` → **`needs_follow_up`** with the controls + gap above.\n- No `create_vulnerability_report` filed (no demonstrated unauthorised consequence; the version-matched CVE-2026-64636 requires authentication).", "agent_name": "DB Service & Cred Leak Sweeper", "agent_id": "c1662cb9"}], "filtered_count": 7, "total_count": 99}