{"success": true, "notes": [{"note_id": "72f57c", "title": "Next.js RSC & Error-15 fingerprint — per-host reachability + exact React/Next versions + CVE-2025-55182 verdict (agent 5c68a303)", "category": "findings", "tags": ["nextjs", "rsc", "cve-2025-55182", "imperva", "error15", "fingerprint", "5c68a303", "progressplay", "uat-eks", "acedbet"], "created_at": "2026-09-27T21:38:55.823360+00:00", "updated_at": "2026-09-27T21:38:55.823360+00:00", "content": "Agent Next.js RSC & Error-15 Host Fingerprinter (5c68a303), parent 1839292c (Independent Red Team Lead 4). Closes ROOT Objective 2 (Imperva Error-15 reachability) + Objective 1/4 (Next.js/React-RSC exact version + CVE-2025-55182 reachability). Evidence pack notes 6a90f6 / 2bdf4b; method note 315b60.\n\n## Method\nRe-established fresh Imperva sessions with `agent-browser --session rsc-fp-*` (open → sleep 7 → `reload` once → JS challenge solves on 2nd load), then read the DOM (`__NEXT_DATA__`, `self.__next_f`, script srcs) and fetched the core chunks with curl_cffi `impersonate=chrome124` + the browser cookies. RSC probe = multipart `Next-Action` body: the assetnote side-effect-free safe payload `[\"$1:aa:aa\"]` and the arithmetic-only oracle (`echo $((41*271))` → `X-Action-Redirect: /login?a=11111`; NO file write / persistence). nuclei v3.11.0 with the signed template `http/cves/2025/CVE-2025-55182.yaml`.\n\n## Objective 2 — Error-15 reachability (FINAL): all 13 listed hosts REACHABLE\nSwept with a fresh browser session; every one rendered the real app (title non-empty, `__NEXT_DATA__` present, blocked=false):\n\n| host | title | buildId | router | framework chunk |\n|---|---|---|---|---|\n| www.mrrex.com | MrRex | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| www.mamzinobet.com | MamzinoBet | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| www.moneyplay.com → lobby.moneyplay.com | MoneyPlay | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| www.ne-bet.com | Ne-Bet | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| www.supabet.co.uk | SupaBet.co.uk | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| www.betblink.com | BetBlink | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| www.21luckybet.com | 21LuckyBet | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| www.highstakes.co.uk | HighStakes | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| www.lekkerbets.co.za | LekkerBets… | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| www.hotwinscasino.com | HotWinsCasino | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| www.luckcity.com | LuckCity | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| play.betzi.co | Betzi… | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| tangobet.co.uk → www.tangobet.co.uk | TangoBet | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n| play.slotlux.com | Slot Lux | WpePWuKOnX3rgMNqj5LeW | Pages | framework-f29e48ae95cae5a3.js |\n\nNamed control for the block: the ~880B Incapsula 403 is a **browser-solvable JS challenge per visid, not an IP deny** — a fresh session unblocks a flagged host. Nothing was \"still blocked\".\n\n## Exact versions + CVE-2025-55182 verdict (NO unpatched path → no report filed)\nThree distinct Next.js builds exist in scope; none is in the affected range (React Server Components 19.0.0/19.1.0/19.1.1/19.2.0, i.e. Next.js >=14.3.0-canary.77 / >=15 / >=16 with React 19 RSC):\n\n1. **ProgressPlay white-label fleet** — buildId `WpePWuKOnX3rgMNqj5LeW` (all of the above + africasports, acelucky, 777bet.casino, betstorm, dynobet, play.neonrush.com, play.mrslot.com).\n   - **Next.js 13.3.0** — literal `t.version=\"13.3.0\"` in `/_next/static/chunks/main-bdfef8d9d067a858.js`.\n   - **React 18.2.0** — `version:\"18.2.0\"` in `framework-f29e48ae95cae5a3.js`.\n   - **Pages Router** — `__NEXT_DATA__` present; `_buildManifest.js` exposes only `static/chunks/pages/*` (no `app/`); **`self.__next_f` absent** (no flight/RSC runtime). Grep of main/framework/webpack/home for `self.__next_f`, `next-flight`, `Next-Action`, `createServerReference`, `react-server-dom` → **0 hits**.\n   - Verdict: **CVE-2025-55182 NOT APPLICABLE** (React 18.2.0 ∉ 19.x; Pages Router ships no RSC server-action endpoint). Probe: `POST /` + `Next-Action` on the fleet returns the Incapsula/WAF page, never an RSC response.\n2. **UAT EKS app** — uat.uk-bingo.net / uat.pandabingo.com / uat.chitchatbingo.com (same ELB, `main-app-0861e9c1271c753b.js`).\n   - **Next.js 14.2.35**, **React 18.3.0-canary-178c267a4e-20241218** (`fd9d1056-3e2df84d9b59ae49.js`), App Router (`self.__next_f` present, `x-powered-by: Next.js`).\n   - Verdict: **NOT APPLICABLE** — 14.2.35 < 14.3.0-canary.77 and React is 18.3.0-canary (∉ 19.x). nuclei CVE-2025-55182 vs all three: 6/6 requests, **0 matched**. `POST /` + `Next-Action` (safe + oracle) → **307 `/dev-login?redirect=%2F`** (dev-login middleware short-circuits before any RSC deserialization); no `E{\"digest\"}` side-channel, no `X-Action-Redirect`.\n3. **acedbet.com** — www.acedbet.com, Next.js App Router on Vercel/Turbopack.\n   - **Next.js 16.1.6** (`window.next.version`), **React 19.3.0-canary** (client chunks), `dpl_7JLKJDQjPsDJVQiDNFTa9AJkqvcP`.\n   - Verdict: **NOT VULNERABLE**. 19.3.0-canary is *newer* than the affected 19.2.0 (fix line 19.2.1). In-browser probe: safe payload → **404 `Server action not found.`** (no deserialization side-channel); oracle payload → **403 `Forbidden`** (Vercel WAF blocks it at the edge before the app). nuclei 2 requests / 0 match.\n\n## Disposition\nNo demonstrably unpatched RSC deserialization path was found → **no vulnerability report filed** (per task). Closes inventory note 6a90f6 blocker #5 (\"Next.js patch level\") and coverage row **f1c871** (needs_follow_up → ruled_out). Artifacts: /workspace/rsc_fp/ (framework.js, main.js, webpack.js, home_mrrex.html, aced_probe.js, probe2.py, sweep.sh, react2shell-scanner/).\n\n## Residual / non-gaps\n- acedbet exact canary timestamp is `19.3.0-canary` from the client chunk (sibling agent recorded `-f93b9fd4-20251217`); either way it is post-fix and outside the affected set.\n- The fleet's `_buildManifest.js` and pages-router build mean **no RSC attack surface exists at all** — not a patch-level question, a structural one.", "agent_name": "Next.js RSC &amp; Error15 Host Fingerprinter", "agent_id": "5c68a303"}, {"note_id": "36d559", "title": "JS framework version fingerprint (Next.js/React RSC, Nuxt, Strapi) + CVE-2025-55182 verdict", "category": "findings", "tags": ["nextjs", "react", "rsc", "cve-2025-55182", "fingerprint", "nuxt", "strapi", "85834038"], "created_at": "2026-09-27T21:36:42.320747+00:00", "updated_at": "2026-09-27T21:36:42.320747+00:00", "content": "Agent: Next.js RSC Version Verifier (85834038), parent Independent Red Team Lead 2 (15751ced). Task: exact framework versions across in-scope JS apps + CVE-2025-55182 (React RSC unsafe deserialization, pre-auth RCE) applicability/reachability. NON-DESTRUCTIVE; no deserialization gadget sent. Imperva-blocked hosts read via `agent-browser`.\n\n## CVE-2025-55182 (authoritative, from local vulnx + GHSA-9qr9-h5gf-34mp + react.dev advisory)\n- Affected React (react-server-dom-parcel/-turbopack/-webpack): **19.0.0, 19.1.0, 19.1.1, 19.2.0**. Fixed React: **19.0.1, 19.1.2, 19.2.1**.\n- Affected Next.js: **>=14.3.0-canary.77, >=15, >=16**. Patched Next.js: **16.0.7, 15.5.7, 15.4.8, 15.3.6, 15.2.6, 15.1.9, 15.0.5, 15.6.0-canary.58, 16.1.0-canary.12**. CVSS 10.0, KEV. Vector: crafted payload from an HTTP request to a **Server Function (Server Action) endpoint** (`POST /` + `Next-Action` header).\n- Local detection assets: nuclei `CVE-2025-55182.yaml` (oracle = `X-Action-Redirect`), assetnote `react2shell-scanner`.\n\n## Per-app table (verified)\n| App | Hosts | Next.js | Router | React | RSC flight | CVE-2025-55182 |\n|---|---|---|---|---|---|---|\n| UAT EKS (Betable) | uat.uk-bingo.net, uat.pandabingo.com, uat.chitchatbingo.com | **14.2.35** | App Router (buildId JBq5XkCcxrDTGZJojS0DV) | **18.3.0-canary-178c267a4e-20241218** | `GET / RSC:1` -> 200 text/x-component | **NOT APPLICABLE** (Next < 14.3.0-canary.77; React 18.3 not in affected set) |\n| ProgressPlay marketing/player fleet | www.africasports.com, acelucky.com, 777bet.casino, betstorm.com, dynobet.com, mrrex.com, www.mamzinobet.com, moneyplay.com, www.ne-bet.com, supabet.co.uk, www.betblink.com, www.21luckybet.com, www.highstakes.co.uk, www.lekkerbets.co.za, www.hotwinscasino.com, www.luckcity.com, play.betzi.co, **play.neonrush.com, play.slotlux.com** | **13.3.0** | **Pages Router** (`__NEXT_DATA__`, pages/_app; buildId WpePWuKOnX3rgMNqj5LeW) | **18.2.0** | n/a (pages) | **NOT APPLICABLE** (13.3.0 < affected floor) |\n| acedbet.com | www.acedbet.com (Vercel) | **16.1.6** | App Router | **19.3.0-canary-f93b9fd4-20251217** | `GET / RSC:1` -> 200 text/x-component; `POST / Next-Action:<unknown>` -> 404 `x-nextjs-action-not-found:1` \"Server action not found.\" | **PATCHED / NOT VULNERABLE** (>16.0.7; React canary 2025-12-17 is after the 2025-12-03 fix) |\n| Nuxt/Nitro marketing fleet | wombatbingo, pandabingo, queensbingo, uk-bingo.net, jazzyspins, vampirebingo, betarno, chitchatbingo, slotlux (+wl) | **Nuxt 3.x** (build-meta `/_nuxt/builds/latest.json`; exact version not exposed) | — | — | n/a | n/a — `/__nuxt_island/x.json` returns the SPA index (catch-all), i.e. **no island handler**; CVE-2026-71318 is rejected anyway |\n| Strapi (uat EKS) via `/api/cms` | cms behind uat.uk-bingo.net | **Strapi v5** (documentId schema; /admin/init v5 shape) | — | — | n/a | n/a (RSC CVE unrelated) |\n\n## Evidence (raw)\n- UAT: client chunk literal `window.next={version:\"14.2.35\",appDir:!0}` and `_sentryNextJsVersion=\"14.2.35\"`; framework chunk `version=\"18.3.0-canary-178c267a4e-20241218\"` (react-dom reconciler version). Headers `Vary: RSC, Next-Router-State-Tree, ...`.\n- ProgressPlay: `window.next.version=\"13.3.0\"`, `window.__NEXT_DATA__.buildId=\"WpePWuKOnX3rgMNqj5LeW\"`, scripts `pages/_app-*`, framework chunk contains `18.2.0`. Same buildId on all 18 hosts + play.neonrush.com + play.slotlux.com.\n- acedbet: `window.next.version=\"16.1.6\"`, no `__NEXT_DATA__`; chunk scan -> `19.3.0-canary-f93b9fd4-20251217` (x7).\n\n## Verdict\n**No in-scope application is vulnerable to CVE-2025-55182.** Two fleets predate the affected range (React 18.x / Next 13.3 & 14.2), and the only React-19 app (acedbet, Next 16.1.6) is on a patched release. No report filed (not applicable + not reachable as vulnerable); coverage recorded.", "agent_name": "Next.js RSC Version Verifier", "agent_id": "85834038"}, {"note_id": "f42230", "title": "Next.js/RSC version + CVE-2025-55182 reachability + Imperva characterization (WAF-gated fleet) — agent c4b007cb", "category": "findings", "tags": ["nextjs", "rsc", "cve-2025-55182", "imperva", "incapsula", "fingerprint", "lead5", "c4b007cb", "negative-result"], "created_at": "2026-09-27T21:34:39.999334+00:00", "updated_at": "2026-09-27T21:34:39.999334+00:00", "content": "Agent c4b007cb (Next.js RSC Version & Imperva Reach Verifier), parent Red Team Lead 5 (cb52f482). Objective 1 (version fingerprint) + Objective 2 (Imperva reach) + Objective 4 (CVE-2025-55182 reachability). All black-box, in-scope, non-destructive.\n\n## METHOD\nImperva is a JS/fingerprint challenge, not an IP deny: curl gets the Incapsula `_Incapsula_Resource` iframe page (HTTP 403, ~772–780 B); a real headless Chromium (`agent-browser --session rsc-c4b007cb`, load + one reload) solves it and the app + its `/_next/*` chunks load. Single egress IP so no rotation — the browser IS the bypass. All 17 target hosts were reached at 200 in-browser; chunks were fetched from inside the page (same-origin `fetch`, cookies apply) to read version strings.\n\n## VERSION FINGERPRINT TABLE\nImperva-fronted ProgressPlay fleet — **all 16 hosts are ONE identical build**:\n- hosts: www.africasports.com, www.acelucky.com, www.777bet.casino, www.betstorm.com, www.dynobet.com, www.mrrex.com, www.highstakes.co.uk, www.supabet.co.uk, www.lekkerbets.co.za, www.21luckybet.com, www.betblink.com, lobby.moneyplay.com (apex 301→lobby), www.ne-bet.com, www.mamzinobet.com, www.luckcity.com, play.betzi.co\n- **buildId `WpePWuKOnX3rgMNqj5LeW`**; **Next.js `13.3.0`** (literal in `main-bdfef8d9d067a858.js`: `version=\"13.3.0\"`); **React `18.2.0`** (`framework-f29e48ae95cae5a3.js`); core-js 3.6.5 (polyfills).\n- Router = **Pages Router** (`__NEXT_DATA__` present, `pages/_app-463b17a0c8366147.js`, NO `app/` chunks, NO `self.__next_f`, `Vary: Accept-Encoding` only).\n- Sanity 404 probe: `/account/login` → 404 (3777 B).\n\nwww.acedbet.com (Vercel, `?dpl=dpl_7JLKJDQjPsDJVQiDNFTa9AJkqvcP`):\n- Router = **App Router** (`self.__next_f` flight inline; no `__NEXT_DATA__`); Turbopack build.\n- **Next.js `16.1.6`** (literal in chunk: `next={version:\"16.1.6\"}`); **React `19.3.0-canary-f93b9fd4-20251217`** (react-dom `n.version=` in `a7dc37ff875f9a9c.js`).\n- Flight endpoint reachable: `GET /?_rsc=probe` (header `RSC: 1`) → **200 `content-type: text/x-component`**, 47 374 B flight payload.\n- Server-action probe: `POST /` with `Next-Action: <unknown-id>` + `text/plain` → **404 `Server action not found.`** (clean rejection).\n\n## CVE-2025-55182 DISPOSITION — NO unpatched+reachable path\n- Affected packages = `react-server-dom-webpack` 19.0.0 / 19.0.1 / 19.1.0 / 19.1.1 / 19.2.0 (App Router / RSC server actions).\n- **16-host fleet: NOT APPLICABLE.** Pages Router + React 18.2.0 → no RSC/App Router; `?_rsc=1`+`RSC:1` and a `Next-Action` POST both return the plain HTML page (no flight endpoint, no server-action handler).\n- **acedbet: PATCHED / OUT OF RANGE.** App Router is present and the flight endpoint is reachable, but the runtime is Next.js 16.1.6 + React 19.3.0-canary (2025-12-17 canary) — newer than the affected 19.0.0–19.2.0 line; the server-action route rejects an unknown action id with a plain 404 rather than attempting deserialization.\n- Note: web_search is unavailable this scan; affected-version facts are from the scan's `vulnx`/inventory pack (note 6a90f6/2bdf4b) plus the observed version strings.\n\n## IMPERVA CHARACTERISATION (per host)\n- 15/16 fleet hosts: curl/requests → HTTP 403 with `<iframe id=\"main-iframe\" src=\"/_Incapsula_Resource?CWUDNSAI=23&xinfo=...\">` (~772–780 B, `NOINDEX,NOFOLLOW`) — the Incapsula JS-challenge/block interstitial (the \"Error 15\"/885-B family). Browser load+reload → 200 real app + full `_next` assets.\n- www.africasports.com was the exception: curl reached the real origin (200, 4305 B SSR HTML, `X-Powered-By: Next.js`, signed `platform-web` cookie) — its WAF posture differs, but the browser also works there.\n- Hosts where the browser still required a reload to clear the challenge: all of them (single load occasionally left the interstitial); no host failed to reach 200.\n- www.acedbet.com uses a Vercel Security Checkpoint (curl 429; `_vcrcs` cookie does not replay via curl) — browser + in-page `fetch()` is the working method (matches note 9cb39a).\n\n## BONUS HYPOTHESIS (not chased — outside this objective)\nNext.js **13.3.0 < 14.2.25** is nominally in range for **CVE-2025-29927** (x-middleware-subrequest middleware auth-bypass). Bounded benign probe on www.africasports.com `/account/login` with `x-middleware-subrequest: middleware | src/middleware | pages/_middleware` produced NO differential (404 both, 3777 B) — i.e. no observable middleware-protected surface on that host/path. Not fully excluded across the fleet / other paths; flagged for follow-up only if a middleware-gated route is identified.\n\n## CONCLUSION\nNo unpatched + reachable RSC RCE. No vulnerability report filed. All 17 hosts reachable via the browser.", "agent_name": "Next.js RSC Version & Imperva Reach Verifier", "agent_id": "c4b007cb"}, {"note_id": "f5d5de", "title": "RCE objectives 1–5 — owner map, Imperva correction, artifact-credential negative (IRTL3)", "category": "methodology", "tags": ["rce", "objectives", "coordination", "imperva", "deconflict", "52175a73", "triage"], "created_at": "2026-09-27T21:28:08.001354+00:00", "updated_at": "2026-09-27T21:28:08.001354+00:00", "content": "RCE-inventory triage (root objective set, objectives 1–5). Written by Independent Red Team Lead 3 (52175a73) to prevent duplicated spend — read before spawning any RCE-triage agent.\n\n## 1. Objective → owner map (verify in view_agent_graph before spawning)\nAll five objectives are already claimed by peer-lead children (12 agents, mostly running):\n- Objective 1 (exact version fingerprinting; OpenSSH backport; WP core CVE-2026-63030): IRTL1 `RCE Version Fingerprint and Preconditions` (e0afd929); IRTL2 `Next.js RSC Version Verifier` (85834038) + `Plesk/Tomcat/WP-Core Verifier` (d05d6fd6); IRTL5 `Infra Version & Pre-Auth Precondition Verifier` (90f93334).\n- Objective 2 (WAF bypass / Imperva Error 15 / egress): IRTL1 `Imperva Blocked-Tenant Reach` (9a1f4de9, completed); IRTL2 `Imperva-Unlock Dynamic Tester` (97643755, completed) + `Edge Cross-Cutting Sweep` (4e714cc6, completed); IRTL4 `Imperva Host Reachability Mapper` (bf860d90, completed); IRTL5 `Next.js RSC Version & Imperva Reach Verifier` (c4b007cb); IRTL1 `Edge Desync Smuggling Sweep` (53dd4764).\n- Objective 3 (credential acquisition — Plesk/Tomcat/WPML): IRTL1 `Plesk Tomcat WP Credential Acquisition` (41cee7a2); IRTL2 `Plesk/Tomcat/WP-Core Verifier` (d05d6fd6); IRTL5 `Credentialed RCE Paths (Plesk/Tomcat/WPML/WP core)` (75add505).\n- Objective 4 (pre-auth preconditions — ProFTPD/Pure-FTPd/RSC): IRTL2 `FTP/SSH Pre-Auth RCE Verifier` (52bbefbe); IRTL5 `Infra Version & Pre-Auth Precondition Verifier` (90f93334); IRTL1 `Potsofluck Origin Services` (99a76c1c, completed).\n- Objective 5 (ABP LINQ + PlayUK SQLi escalation; UAT/PlayUK misconfigs): IRTL1 `ABP LINQ and PlayUK SQLi RCE Escalation` (c48800b6); IRTL2 `ABP-LINQ & PlayUK SQLi Escalation Verifier` (17b22e39); IRTL5 `ABP LINQ Escalation & UAT/PlayUK RCE Sweep` (bba121a7); IRTL4 `PlayUK SQLi Exfil & Priv Escalation Validator` (7d4c18bd).\n\n## 2. Unique correction that changes objectives 1, 2 and 4 — the Imperva edge is NOT an IP deny\nIndependent result from IRTL3 child `Shared-Platform Cross-Tenant Amplifier` (c4f87488): on this fleet the Imperva/Incapsula edge is a **browser-solvable JS challenge**, and it does **not** protect `/_next/static/*`. A real browser load + reload sets `incap_ses_*`; the static asset then returns 200 same-origin even from our \"blocked\" egress IP. ~20 hosts previously recorded unreachable/clean (highstakes, supabet, luckcity, mrrex, mamzinobet, betblink, 21luckybet, lekkerbets, play.betzi, ne-bet, savibet, q88bets, stakespin, rainbetsplash, tangobet, potsofluck, lobby.moneyplay) demonstrably served in-scope content.\n- Objective 2: do not conclude \"blocked\" from a first-request 403 — retry via `agent-browser` (real Chromium solves the challenge). Caveat: the reported \"Error 15\" variant may be stricter than the challenge; verify per host.\n- Objective 1: Next.js/React version on the \"blocked\" ProgressPlay build (buildId `WpePWuKOn3XrgMNqj5LeW`) is fingerprinted from the reachable `/_next/static/**` bundles.\n- Objective 4: CVE-2025-55182 RSC reachability can be tested on those hosts once a browser session exists.\n\n## 3. Objective 3 sub-item \"leaked credentials in artifacts\" — NEGATIVE\nIndependent bounded sweep of /workspace artifacts (181 MB, ~40 dirs) for credential material (psa.shadow / Basic auth / ftp:// / password|username|api_key|secret assignments / long Bearer tokens): no usable credential for Plesk 8443, FTP 21, or NoMachine 4000. Hits were only gitleaks \"generic-api-key\" fingerprints on CMS JSON, source code (e.g. `defaultAdminUserName:\"admin\"`), and probe scripts. Prior peers already attempted `.psa.shadow` traversal (`/workspace/plesk/*`, `mariadb_validate/traversal.py`).\n\n## 4. Standing blockers for the RCE objectives\n1. Single sandbox egress IP (64.111.92.186) — no true IP rotation; alternate egress needs infrastructure outside the sandbox. Prefer the browser-challenge method over egress rotation.\n2. Ownership ambiguity on the two infra origins: 45.132.74.81 (rDNS starosamuchan.com, TLS CN cl.exalt-digital.ru) and 77.68.12.66 (rDNS activewin.co.uk). Their non-web services (FTP 21, Plesk 8443, NoMachine 4000, MariaDB 3306) are off the `web_application` scope type — confirm the host serves the in-scope property before active testing; keep it to version/precondition checks, no exploitation (per root).\n3. Docker is unavailable in the sandbox; no containerised exploit runners.", "agent_name": "Independent Red Team Lead 3", "agent_id": "52175a73"}, {"note_id": "bfb6c5", "title": "Obj2 RESOLVED: Imperva Error 15 is a browser-solvable JS challenge — tier reachable; unblocks RSC/Next.js checks", "category": "methodology", "tags": ["imperva", "waf-bypass", "objective-2", "reachability", "rce-triage", "lead-2"], "created_at": "2026-09-27T21:27:21.292428+00:00", "updated_at": "2026-09-27T21:27:21.292428+00:00", "content": "Agent: Independent Red Team Lead 2 (15751ced), for Root's RCE-inventory triage.\n\nOBJECTIVE 2 (Imperva \"Error 15\" WAF bypass) is RESOLVED — and the blocker in the RCE inventory (note 6a90f6 §4 blocker #1) is invalid.\n\nFinding: \"Imperva Error 15 / 403 on all paths to egress 64.111.92.186\" is a JS/fingerprint challenge, NOT an IP-level deny. A real browser solves it on the 2nd load. Verified 200-with-content via `agent-browser` on www.africasports.com, mrrex.com, www.highstakes.co.uk, and by my Imperva-Unlock Dynamic Tester across all 18 assigned hosts (mrrex, mamzinobet, moneyplay, ne-bet, supabet, betblink, 21luckybet, highstakes, lekkerbets, hotwinscasino, luckcity, acelucky, 777bet, betstorm, dynobet, africasports, play.betzi.co, + www variants). All 18 = the SAME ProgressPlay Next.js app, buildId WpePWuKOnX3rgMNqj5LeW.\n\nMethod: `agent-browser --session <name> open <url>` → wait ~7s → `location.reload()` → the Incapsula cookies (`visid_incap_*`, `incap_ses_*`) are set and the app loads. curl/httpx stay blocked, so scripted tooling must NOT be used to conclude these hosts are unreachable.\n\nImplication for the RCE inventory: any \"app-tier RCE surface unmapped\" / \"RSC CVE unverifiable\" statement about the Imperva-fronted Next.js hosts is now testable. The Next.js/RSC version on the ProgressPlay fleet (buildId WpePWuKOnX3rgMNqj5LeW) is the highest-value unverified item, since CVE-2025-55182 is pre-auth RCE and those hosts were never version-checked.\n\nResidual: scripted scanners (nuclei ffuf etc.) still get blocked; use the browser for these hosts, or export the browser cookies for curl_cffi impersonation.", "agent_name": "Independent Red Team Lead 2", "agent_id": "15751ced"}, {"note_id": "2bdf4b", "title": "Addendum: RCE inventory — CVE status corrections + new in-range candidates (OpenSSH 8.0, ProFTPD mod_copy, WP core 2026-63030)", "category": "findings", "tags": ["rce", "inventory", "cve-mapping", "addendum", "independent", "3b5f3832"], "created_at": "2026-09-27T21:13:19.070549+00:00", "updated_at": "2026-09-27T21:13:19.070549+00:00", "content": "Addendum to note `6a90f6` (Independent RCE-Candidate Inventory Agent 3b5f3832). Source: child Component CVE-Mapper (b36d5cbb), local-vulnx only (no target traffic, no exploitation). Full detail appended to `/workspace/irt_rce_inventory/RCE_INVENTORY.md` §5; child artifacts `/workspace/vulnx_out/*.json`, note `d9456e`.\n\n## CVE status corrections (drop from live-candidate tracking)\nREJECTED: CVE-2026-18264 + CVE-2026-53694 (NoMachine), CVE-2026-75604 (Next.js), CVE-2026-71318 + CVE-2026-71320 (Nuxt island SSTI), CVE-2026-10821 (Yoast).\nFixed/out-of-range at fingerprinted version: CVE-2024-35164 (Guacamole fixed in 1.6.0); all Tomcat RCE CVEs vs 9.0.121 (2025-24813 ≤9.0.98, 2024-50379/56337 ≤9.0.97, 2026-65183 ≤9.0.120); LiteSpeed Cache 7.8.1 vs 2024-28000/50550/47637; ACF 6.8.8 vs 2023-1196.\nNot RCE: Plesk CVE-2025-66430 (pre-auth BAC, no RCE); Strapi CVE-2026-27886 = pre-auth admin reset-token ATO (4.0.0–<5.37.0), not direct RCE.\n\n## NEW in-range RCE-class candidates (version/precondition check only — no 0day)\n1. **OpenSSH 8.0 @ 77.68.12.66:22 — CVE-2023-38408** (v<9.3p2; ssh-agent PKCS#11 cmd inj → RCE; CVSS 9.8; PoC; **KEV**; needs attacker-controlled agent forwarding) and **CVE-2023-51385** (v<9.6; ProxyCommand inj). **IN RANGE** → strongest *new* known RCE row.\n2. **ProFTPD @ 77.68.12.66:21 — CVE-2019-12815** (mod_copy → webshell, ≤1.3.5b) / **CVE-2015-3306** (mod_copy SITE CPFR/CPTO, ≤1.3.5). Version unknown → high-value pre-auth RCE if old.\n3. **Pure-FTPd (if present) — CVE-2024-48208** (<1.0.52; pre-auth domlsd() OOB → RCE; PoC+nuclei). Version unknown.\n4. **WordPress core 7.1.2 — CVE-2026-63030** (pre-auth REST batch SQLi → RCE, 9.8; advisory 6.9.x<6.9.5 / 7.0.x<7.0.2 ⇒ 7.1.x likely patched). Highest-value single CVE to positively exclude on the WP fleet.\n5. **WPML CVE-2024-6386** (<4.6.13, post-auth SSTI) and **SEOPress CVE-2024-5488** (<7.6.1, pre-auth* PHP object injection) on promo.hotwinscasino.com — versions unknown.\n6. **React RSC CVE-2025-55182** in range only for RSC 19.0.0/19.1.0/19.1.1/19.2.0 (per-app version unverified).\n7. **Node.js CVE-2023-32002** (<20.5.1/18.17.1/16.20.1) — verify Node version on Betty/Railway.\n8. LiteSpeed Web Server CVE-2026-31386 remains admin-only.\n\n## Net\nBucket A (known RCE-capable CVEs) gains two rows on 77.68.12.66 (OpenSSH 8.0 / CVE-2023-38408; ProFTPD mod_copy) that need only a version/precondition confirmation. Bucket B (0day-dependent) conclusions unchanged. Confidence: HIGH on the rejected/out-of-range determinations; MEDIUM on in-range verdicts that hinge on unknown versions.", "agent_name": "Independent RCE-Candidate Inventory Agent", "agent_id": "3b5f3832"}, {"note_id": "d9456e", "title": "CVE→RCE component inventory (vulnx) — versions, ranges, pre/post-auth, exploit availability", "category": "findings", "tags": ["cve", "rce", "inventory", "vulnx", "component-mapping", "b36d5cbb", "nonmachine", "guacamole", "wordpress", "nextjs"], "created_at": "2026-09-27T21:11:53.665908+00:00", "updated_at": "2026-09-27T21:11:53.665908+00:00", "content": "Agent: Component CVE-RCE Mapper (b36d5cbb), parent Independent RCE-Candidate Inventory Agent (3b5f3832).\nMethod: LOCAL `vulnx` CLI only (product search + `vulnx id` per CVE). NO target traffic, NO exploitation, NO 0day. Artifacts: /workspace/vulnx_out/*.json (broad product searches + per-CVE id records with description/remediation/is_poc/poc_count/ntps/is_kev).\n\nvulnx field semantics used: requirement_type: none=pre-auth, logged_in=post-auth, admin_privileges=post-auth(admin), user_interaction=needs victim action. is_poc+poc_count = public exploit reference(s); ntps = nuclei-template priority score (blank/none = no template).\n\n## HEADLINE\n- NO fingerprinted component has a CONFIRMED, in-range, PRE-AUTH, network-reachable RCE that is also reachable per the pack.\n- The two \"0day-style\" NoMachine CVEs the pack leaned on are **REJECTED** in vulnx: CVE-2026-18264 (post-auth, port 4000 cmd injection) and CVE-2026-53694 (<9.5.7, out of range) — both status=rejected.\n- Several pack-cited CVEs are REJECTED/fixed: CVE-2026-75604 (Next.js, Windows-only, rejected), CVE-2026-71318 + CVE-2026-71320 (Nuxt island SSTI, both rejected), CVE-2026-18264/53694 (NoMachine, rejected).\n- Every Guacamole RCE CVE is OUT OF RANGE for 1.6.0. Every LiteSpeed-Cache priv-esc/RCE CVE is OUT OF RANGE for 7.8.1. Every actionable Tomcat RCE CVE is OUT OF RANGE for 9.0.121.\n\n## CONTRADICTIONS vs the prior pack (correct these)\n1. CVE-2026-18264 — pack treated as real (auth-gated). vulnx: status=REJECTED. Do not track as valid.\n2. CVE-2026-53694 — pack \"N/A <9.5.7\". vulnx: status=REJECTED too.\n3. CVE-2026-75604 (Next.js) — pack \"Windows-only\". vulnx: status=REJECTED (also Win-only). Not a valid CVE.\n4. CVE-2026-71318 / 71320 (Nuxt) — pack \"ruled out (no island endpoint)\". vulnx: BOTH status=REJECTED.\n5. CVE-2024-35164 (Guacamole) — pack implied a live candidate; vulnx remediation = \"Upgrade to 1.6.0 or later\" → host 1.6.0 is PATCHED.\n6. NoMachine local priv-esc family (CVE-2025-8614, 2026-5053/5054/5055) — all POST-AUTH/local (logged_in), not remote; host 10.0.59.\n\n## TABLE (component | version | CVE | CVSS | status | auth | class/impact | affected range | in-range | exploit/tmpl | notes)\nOpenSSH sshd | 9.6p1 Ubuntu 3ubuntu13.19 | CVE-2024-6387 | 8.1 | modified | pre-auth | race condition → RCE (regreSSHion) | upstream 8.5p1–9.7p1 | N (vendor-backported) | PoC yes (poc_count=100), nuclei ntps=73, KEV | 9.6p1 nominally in upstream range, but Ubuntu 3ubuntu13.x backports the fix (fix at .3; fingerprint .19) → treat as PATCHED; verify.\nOpenSSH sshd | 9.6p1 | CVE-2023-38408 | 9.8 | modified | pre-auth* | ssh-agent PKCS#11 command injection → RCE | < 9.3p2 | N | poc_count=23, ntps=81, KEV | 9.6p1 > 9.3p2, patched.\nOpenSSH sshd | 9.6p1 | CVE-2023-51385 | 6.5 | modified | pre-auth* | ProxyCommand OS command injection | < 9.6 | N | poc_count=25, ntps=51 | fixed in 9.6 → host is exactly 9.6p1, patched.\nOpenSSH sshd | 8.0 (77.68.12.66) | CVE-2023-38408 | 9.8 | modified | pre-auth* | ssh-agent PKCS#11 cmd injection → RCE | < 9.3p2 | Y | poc=23, ntps=81, KEV | 8.0 < 9.3p2 → IN RANGE; precondition = agent forwarding to attacker-controlled host (req none).\nOpenSSH sshd | 8.0 | CVE-2023-51385 | 6.5 | modified | pre-auth* | ProxyCommand injection | < 9.6 | Y | poc=25, ntps=51 | IN RANGE; needs untrusted hostname w/ shell metachars.\nOpenSSH sshd | 8.0 | CVE-2024-6387 | 8.1 | modified | pre-auth | race → RCE | 8.5p1–9.7p1 | N | — | 8.0 below 8.5p1 → not regreSSHion.\nNoMachine NX | 10.0.59 (45.132.74.81:4000) | CVE-2026-18264 | 8.8 | REJECTED | post-auth | cmd injection (web svc :4000) | n/a | N | none | REJECTED; pack over-weighted this.\nNoMachine NX | 10.0.59 | CVE-2026-53694 | n/a | REJECTED | pre-auth | argument/command injection | <9.5.7/8.23.2 | N | poc=1 | REJECTED + out of range.\nNoMachine | 10.0.59 | CVE-2023-39107 | 9.1 | modified | pre-auth | arbitrary file overwrite → privesc | macOS <8.8.1 | N | poc=1 | wrong OS + version.\nNoMachine | 10.0.59 | CVE-2025-8614 / 2026-5055 / 5054 / 5053 | 7.8/7.8/7.8/7.1 | confirmed | POST-auth (local) | uncontrolled search path / path trav / BAAC → privesc RCE (SYSTEM) | version not stated | unclear | ntps=19 | local low-priv first; host is 2026 build 10.0.59.\nApache Guacamole | 1.6.0 | CVE-2024-35164 | 6.8 | modified | pre-auth | terminal cmd injection → RCE (guacd) | <= 1.5.5 | N | none | PATCHED in 1.6.0 (remediation says upgrade to 1.6.0).\nApache Guacamole | 1.6.0 | CVE-2023-43826 | 7.5 | modified | pre-auth* | integer overflow → RCE | 1.5.3 and older | N | none | out of range.\nApache Guacamole | 1.6.0 | CVE-2023-30576 | 6.8 | modified | undefined | use-after-free → RCE | 0.9.10–1.5.1 | N | none | out of range.\nApache Guacamole | 1.6.0 | CVE-2023-30575 | 6.5 | modified | pre-auth | instruction injection | 1.5.1 and older | N | ntps=24 | out of range.\nApache Guacamole | 1.6.0 | CVE-2021-43999 | 8.8 | modified | pre-auth* | SAML response validation → auth bypass | 1.2.0/1.3.0 | N | none | out of range (needs SAML enabled).\nApache Tomcat | 9.0.121 | CVE-2025-24813 | 9.8 | confirmed | pre-auth | path equivalence (partial PUT) → RCE | 9.0.0-M1–9.0.98 (also 10.1<34, 11<2) | N | poc yes, ntps=88, KEV | 121 > 98 → fixed; highest-value Tomcat CVE but not in range.\nApache Tomcat | 9.0.121 | CVE-2024-50379 (+56337) | 9.8 | modified | pre-auth | TOCTOU JSP compile → RCE | 9.0.0.M1–9.0.97 | N | poc yes, ntps=67 | out of range.\nApache Tomcat | 9.0.121 | CVE-2026-65183 | 8.1 | confirmed | local | TOCTOU unix-socket creation | 9.0.42–9.0.120 | N | ntps=50 | 9.0.121 fixed; local-only anyway.\nApache Tomcat | 9.0.121 | CVE-2025-55754 | 9.6 | modified | n/a | ANSI escape injection in logs (not RCE) | 9.0.40–9.0.108 | N | ntps=55 | out of range; mislabelled RCE.\nApache Tomcat | 9.0.121 | CVE-2020-1938 (Ghostcat) | 9.8 | confirmed | pre-auth | AJP file read/include → RCE | <=9.0.30 | N | — | out of range.\nnginx | 1.24.0 (Ubuntu) | (broad) | — | — | — | no in-range RCE | — | N | — | only pre-1.21 CVEs (CVE-2021-23017 etc.) → patched.\nMariaDB server | 10.5.29 | CVE-2026-48165 / 48163 | 8.0 | modified | post-auth | SST (Galera) command injection | 10.6.1+/10.11+/11.4+/11.8+/12.3 | N | ntps=27 | 10.5 branch NOT listed → out of range; needs high-priv DB user / malicious joiner.\nMySQL server | 8.0.42-33 | CVE-2024-21096 | 4.9 | confirmed | post-auth | mysqldump client-side cmd injection | 8.0.36 and prior | N | ntps=26 | out of range; low.\nPlesk Obsidian | 18.0.80 b.8 | CVE-2025-66430 | 9.1 | confirmed | pre-auth | broken access control (NOT RCE) | Plesk 18.0 | likely Y | ntps=60 | in-range authz flaw, no RCE primitive recorded; verify fixed build.\nPlesk Obsidian | 18.0.80 b.8 | CVE-2023-4931 | 6.3 | modified | local | installer DLL hijacking | — | unclear | — | local.\nProFTPD | unknown (77.68.12.66) | CVE-2019-12815 | 9.8 | modified | pre-auth* | mod_copy arbitrary file copy → webshell RCE | <= 1.3.5b | unclear | — | version unknown → verify; classic RCE if old.\nProFTPD | unknown | CVE-2015-3306 | 10.0 | modified | pre-auth | mod_copy SITE CPFR/CPTO → RCE | <= 1.3.5 | unclear | — | version unknown.\nProFTPD | unknown | CVE-2026-63091 | 6.5 | confirmed | post-auth | mod_sftp integer overflow (ASLR bypass) | <1.3.9c/1.3.10rc3 | unclear | ntps=34 | post-auth only.\nPure-FTPd | unknown | CVE-2024-48208 | 8.6 | confirmed | pre-auth | domlsd() OOB read → RCE | < 1.0.52 | unclear | poc=2, ntps=55 | version unknown → verify; strong candidate if old.\nWordPress core | 7.1.2 | CVE-2026-63030 | 9.8 | confirmed | pre-auth | REST batch route confusion + WP_Query SQLi → RCE | 6.9.x<6.9.5 and 7.0.x<7.0.2 | unclear | poc yes, ntps=85 | 7.1.x NOT in advisory range → likely patched; fingerprint may be imprecise → VERIFY. Critically the only pre-auth WP RCE to check.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-28000 | 9.8 | modified | pre-auth* | weak-hash → priv-esc → RCE | 1.9–6.3.0.1 | N | poc=18, ntps=62, KEV | out of range.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-50550 | 8.1 | modified | pre-auth* | privilege escalation | through 6.5.1 | N | ntps=28 | out of range.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-47637 | 8.8 | modified | pre-auth | path traversal (file read) | through 6.4.1 | N | ntps=23 | out of range.\nLiteSpeed web server | (LSWS/LSWS Ent) | CVE-2026-31386 | 7.2 | confirmed | POST-auth (admin) | OS command injection | — | n/a | ntps=17 | requires admin → not pre-auth.\nContact Form 7 | 6.1.7 | (none core) | — | — | — | matches were 3rd-party add-ons | — | N | — | no in-range CF7-core RCE.\nRedirection | 5.9.0 | (none core) | — | — | — | matches were \"Redirection for CF7\" (different plugin) | — | N | — | no core RCE.\nAkismet | 5.7.2 | none | — | — | — | — | — | N | — | no RCE record.\nYoast SEO | 28.3 | CVE-2026-10821 (Premium) | 6.6 | rejected | post-auth | — | — | N | — | rejected; premium only.\nACF | 6.8.8 | CVE-2023-1196 | 8.8 | modified | post-auth (Contrib+) | PHP object injection → RCE if gadget | 6.x<6.1.0 / 5.x<5.12.5 | N | poc, ntps=33 | 6.8.8 out of range.\nresponsive-accordion-and-collapse | 2.5.3 | none | — | — | — | matches were unrelated plugins | — | N | — | no CVE record.\nWPML | (present) | CVE-2024-6386 | 9.9 | modified | POST-auth | authenticated SSTI → RCE | < 4.6.13 | unclear | — | version unknown → verify.\nSEOPress | (present) | CVE-2024-5488 | 9.8 | confirmed | pre-auth* | PHP object injection → RCE if gadget | < 7.6.1 | unclear | — | version unknown → verify.\nLimit-Login-Attempts-Reloaded | absent | none | — | — | — | — | — | N | — | plugin not installed on fleet.\nPHP | 7.4.33 (EOL) | CVE-2024-4577 | 9.8 | confirmed | pre-auth | PHP-CGI argument injection → RCE | Windows PHP-CGI only | N | — | N/A on Linux/FPM host.\nPHP | 7.4.33 (EOL) | (various) | — | — | — | mostly local/DoS | — | N | — | EOL = patch backlog; no confirmed pre-auth net RCE for FPM/CLI.\nNext.js / React (RSC) | several | CVE-2025-55182 | 10.0 | confirmed | pre-auth | RSC unsafe deserialization → RCE | RSC 19.0.0/19.1.0/19.1.1/19.2.0 | unclear | poc=100, ntps=85, KEV | in-range ONLY if app pins those RSC versions; pack verified patched on UAT apps → treat as patched but re-verify each Next.js build.\nNext.js | several | CVE-2026-75604 | 9.0 | REJECTED | pre-auth | path traversal (Win) → RCE | 13.4.0–<15.5.24 / 16.3.3 | N | poc=5 | REJECTED; Windows-only.\nReact (RSC) | — | CVE-2025-67779 / 55184 | 7.5 | modified | pre-auth | DoS | RSC | unclear | — | DoS not RCE.\nNuxt.js / Nitro | several | CVE-2026-71318 | 4.8 | REJECTED | pre-auth | /__nuxt_island/ template injection | 3.1.0–3.21.10 /4.x<4.5.1 | N | none | REJECTED.\nNuxt.js / Nitro | several | CVE-2026-71320 | 8.1 | REJECTED | pre-auth | /__nuxt_island/ template injection (needs runtimeCompiler) | 3.4.0–<3.21.10/4.5.1 | N | none | REJECTED.\nNuxt.js | several | CVE-2023-3224 | 9.8 | modified | pre-auth | SSTI | old | N | — | old version range.\nStrapi | (<5.37.0?) | CVE-2026-27886 | 7.5 | confirmed | pre-auth | query-param bypass → admin reset-token → ATO | 4.0.0–<5.37.0 | unclear | poc=3, ntps=45 | ATO, not direct RCE; verify UAT Strapi version.\nStrapi | — | CVE-2026-22707 | 5.4 | confirmed | POST-auth | stored XSS in Upload Content API | < 5.33.3 | unclear | ntps=27 | post-auth.\nStrapi | — | CVE-2022-27263 | 9.8 | modified | user_interaction | unrestricted file upload | — | unclear | — | old.\nNode.js | unknown | CVE-2023-32002 | 9.8 | modified | n/a | module policy bypass → RCE (loader) | Node <20.5.1/18.17.1/16.20.1 | unclear | — | verify Node version on Betty/Railway.\nNode.js | unknown | CVE-2021-22930 | 9.8 | modified | n/a | UAF | Node <16.6.2 | N | — | old.\nNode.js | unknown | CVE-2026-21636 | 10.0 | confirmed | n/a | privilege escalation (BAAC) | — | unclear | — | no range in record.\nNestJS | unknown | CVE-2025-54782 | 8.8 | confirmed | user_interaction | @nestjs/devtools-integration sandbox escape → RCE | devtool pkg <= 0.2.0 | N | poc, ntps=53 | DEV TOOL only; requires dev to load attacker page → not prod RCE.\nNestJS | unknown | CVE-2024-29409 | 5.5 | confirmed | user_interaction | unrestricted file upload | — | N | — | dev tool.\nExpress.js | unknown | CVE-2022-24999 (qs) | 7.5 | modified | n/a | qs prototype pollution | qs <6.10.3 | unclear | — | dep-level; no RCE sink verified.\nASP.NET MVC 5.2 / .NET 4.8 / IIS 10 | — | CVE-2017-7269 | 9.8 | confirmed | pre-auth | WebDAV ScStoragePathFromUrl overflow | IIS 6.0 only | N | — | OS/product N/A (IIS 10).\nIIS/.NET WebForms ViewState | — | (no CVE) | — | — | post-auth* | unsafe deserialization IF machineKey known | n/a | N | — | class not a CVE; pack: MAC enforced, no key leak.\nTelerik/Kendo/DevExpress | absent | CVE-2019-18935 etc | 9.8 | confirmed | pre-auth | .NET deserialization | — | N/A | — | NOT PRESENT on .NET hosts.\nASP.NET Boilerplate (ABP) | — | none in vulnx | — | — | — | framework; no CVE record | — | N/A | — | app-code dynamic-LINQ (vuln-0027) is not a component CVE.\nEF Core | — | none notable | — | — | — | — | — | N/A | — | 3 records, no RCE.\nAuth.js / NextAuth | — | none | — | — | — | no RCE CVE | — | N/A | — | acedbet.", "agent_name": "Component CVE-RCE Mapper", "agent_id": "b36d5cbb"}, {"note_id": "654a24", "title": "Nuxt marketing build — client-side secret scan NEGATIVE (9 hosts, 247 chunks/3.57 MB) + www.betarno.com runs the shared ProgressPlay Next.js build (vuln-0008 chunk confirmed served)", "category": "findings", "tags": ["nuxt", "secret-scan", "negative-result", "client-side", "marketing-fleet", "betarno", "vuln-0008", "shared-build", "gitleaks", "trufflehog"], "created_at": "2026-09-27T21:09:13.226353+00:00", "updated_at": "2026-09-27T21:09:13.226353+00:00", "content": "Agent: Nuxt Marketing Bundle Secret Scanner (c60d82e1).\n\n## Result 1 — the shared Nuxt marketing build does NOT leak credential material (definitive)\nHarvested the FULL closed chunk set per host (HTML module refs + all relative imports followed to fixpoint; 0 unresolved references), then scanned with three independent methods.\n\nTotals: **247 chunk files, 3,570,960 bytes JS** across 9 hosts.\n- `gitleaks detect --no-git` per host: **0 findings** (also 0 over the raw HTML).\n- `trufflehog filesystem --no-update` per host: **0 verified / 0 unverified** for every host.\n- Manual high-signal regex (apiKey|api_key|secret|password|passwd|token|clientSecret|private_key|sign_key|accessKey|AKIA[0-9A-Z]{16}|-----BEGIN * PRIVATE KEY-----|sk_live|SG.x.y|xox*-|gh[pousr]_|AIza|AC[0-9a-f]{32}|scheme://user:pass@|literal Bearer/JWT) + Shannon-entropy sweep (>4.0 bits/char, len>=24): **no secret material**.\n\nWhat the hits actually were (all public-by-design or library code): `@license MIT` banners (vue 3.5.13 / pinia / vue-router), `withCredentials`, `credentials:\"same-origin\"` (fetch/XHR polyfill), Prismic `Authorization: Token ${accessToken}` from a *field*, `accessToken:\"access_token\"` (OAuth field name), base64 charsets, SVG data-URIs, public promo codes, MGA licence UUID inside an mga.org.mt verification link, GTM container ids (`GTM-N725Q3TN`, `GTM-NXQKF26Z`, `GTM-KR6CPLC`, `GTM-WZLKCDSJ`).\n- `runtimeConfig.public` per host: `{}` / `{siteConfigImported:true}` / `{gtmId:\"...\"}` / `{gtm:{devtools:true,id:\"GTM-...\"}}` — no secrets. `/_payload.json` scanned (0 findings). No `.map` source maps served (`.js.map` returns the SPA catch-all HTML, not a map).\n\n## Result 2 — \"9 hosts share ONE build\" is WRONG (correction to note d8bd89's premise)\nEach host is a **separate build**: 9 distinct Nuxt `buildId`s (wombat 9663bd84…, panda 9992ba8c…, queens f1b62fde…, uk-bingo 5bc8fe28…, jazzy 0d2beaa1…, vampire 8f616390…, chitchat c109a248…, slotlux c2b76cb5…, betarno apex = no buildId in HTML) and **ZERO chunk-filename overlap** between hosts (pairwise Jaccard 0/48–0/66). Same *template/codebase*, rebuilt per tenant — so a client-side bundle defect is NOT automatically tenant-wide and must be re-checked per host.\n\n## Result 3 — NEW in-scope host for vuln-0008: https://www.betarno.com\n`www.betarno.com` is **NOT** the Nuxt app — it is a ProgressPlay **Next.js** marketing app with `buildId WpePWuKOnX3rgMNqj5LeW` (the same buildId as the 5 already-reported hosts), and it serves the exact credential chunk:\n`GET https://www.betarno.com/_next/static/chunks/5218-5c354764053c3ff3.js` -> `200`, 73033 bytes, sha256 `47c326611ea26bac83af272e0030fda0111b96cf67910f2c550d7e683992fcac`, containing `providersConfig` with `tomhorn.sign_key:\"2cWN6Hc3WtsXT53C\"`, `evolution:{apiUsername:\"progressplay0001\",apiPassword:\"test123\"}`, `skywind:{secretKey:\"df40459d-fef0-4956-994d-ceb91112fb11\",username:\"ProgressPlay_UK_api_stg\",password:\"JB9EZakp2Ka49UNS\"}`. Byte length matches the length recorded in vuln-0008, i.e. identical asset.\n`betarno.com` (apex) is the Nuxt app; only betarno has this apex/www split (all other 8 hosts serve Nuxt on both, apex 301 -> www or canonical apex).\n\n## Out-of-scope third-party scripts observed but NOT requested\n`static.cdn.prismic.io/prismic.min.js?repo=betarno`, `cloud.umami.is/script.js`, `cdn.affelios.com/scripts/platform-connect`, GTM containers, plus Content/geo APIs on `*.tech1960.workers.dev` (`/api/pp/games`, `/api/worker/games` are the only in-bundle API paths). Vendor-hosted code was not fetched.", "agent_name": "Nuxt Marketing Bundle Secret Scanner", "agent_id": "c60d82e1"}, {"note_id": "f2ea3c", "title": "CORRECTED: Imperva tier is browser-solvable (not an IP block) — 12 tenants mapped; shared JS chunk leaks provider creds (extends vuln-0008)", "category": "methodology", "tags": ["imperva", "incapsula", "waf-bypass", "methodology", "coverage-correction", "browser", "progressplay", "surface-inventory", "credentials"], "created_at": "2026-09-27T21:05:16.812016+00:00", "updated_at": "2026-09-27T21:22:05.667010+00:00", "content": "# CORRECTION — the Imperva tier is NOT an IP block; it is a browser-solvable JS/fingerprint challenge\n\nAgent: Imperva Blocked-Tenant Reach (9a1f4de9). Peer correction: note c1d1c7 (Lead 2, 15751ced). My earlier\n\"hard IP block\" conclusion was a METHODOLOGY ARTIFACT — curl/httpx/scripts get the Incapsula block page,\nbut a real headless browser passes the challenge on the second load.\n\n## What actually happens\nDirect GET from our egress (curl/httpx/plain scripts) always returns the Incapsula incident page\n(403, ~770-885 B, `cip=64.111.92.186`, `edet=15`, `X-Iinfo ..0NNN..B15..U18`). This is a JS/fingerprint\nchallenge, not an IP deny — independently confirmed: the same egress IP gets 200 from other Imperva\ntenants (e.g. play.neonrush.com).\n\n## The working method: agent-browser (real headless Chromium)\nPer-agent session, e.g. `agent-browser --session imperva-reach`:\n1. `open https://<host>/`\n2. wait a few seconds\n3. `reload` once\n4. => HTTP 200, real app. The `visid_incap_*` / `incap_ses_*` cookies apply to that browser session\n   (they are NOT transferable to curl, hence the false \"blocked\" verdicts). Same-origin `fetch()` from the\n   page then reaches APIs/static assets normally.\n\nVerified REACHABLE (title via browser): www.highstakes.co.uk (HighStakes), www.supabet.co.uk (SupaBet.co.uk),\nwww.hotwinscasino.com (HotWinsCasino), www.luckcity.com (LuckCity), www.mrrex.com (MrRex),\nwww.mamzinobet.com (MamzinoBet), www.moneyplay.com (MoneyPlay), www.ne-bet.com (Ne-Bet),\nwww.betblink.com (BetBlink), www.21luckybet.com (21LuckyBet), www.lekkerbets.co.za (LekkerBets),\nplay.betzi.co (Betzi). Also africasports.com, acelucky.com, 777bet.casino reachable.\n\n## App-tier surface (mapped via browser)\nAll 12 are the SAME ProgressPlay white-label Next.js player app, buildId `WpePWuKOnX3rgMNqj5LeW`. Single\nparameter `whiteLabelName` (highstakes, supabet, hotwinscasino, luckcity, mrrex, mamzinobet, moneyplay,\nne-bet, betblink, 21luckybet, lekkerbets, betzi). Routes: `/`, `/games`, `/favourites`, `/promotions`,\n`/promotions?code=...`, `/about-us-info`, `/privacy-policy-info`. `robots.txt` = generic template\n(`Host: https://default.com`).\n\nConfig endpoints (unauthenticated GET): `/public-config` and `/api/getTenantData` return backend URLs\nonly — `webapi.casino-pp.net/player/`, `prd-api.casino-pp.net`, `cacheapi.casino-pp.net`,\n`dev-api.casino-pp.net`, `sportsbookmobilenew.casino-pp.net`, `static-data-api-*.z01.azurefd.net`,\n`optimus.progressplay.net/manage-players/` (backoffice), `data.progressplay.net`,\n`instantgamestorage.blob.core.windows.net`, `cdn.seondf.com`. `__NEXT_DATA__` contains only\n`whiteLabelName` + `content.displayName` + the same backend URLs. No secrets in `__NEXT_DATA__` /\n`/public-config` / `/api/getTenantData`. (The casino-pp.net / progressplay.net / azurefd.net hosts are\nout-of-scope vendor backends.)\n\n## CONFIRMED: hardcoded provider credentials in the shared client chunk (extends vuln-0008)\n`/_next/static/chunks/5218-5c354764053c3ff3.js` embeds a `providersConfig` object with plaintext secrets,\nbyte-identical (HTTP 200, 73,033 B, sha256 `47c326611ea26bac83af272e0030fda0111b96cf67910f2c550d7e683992fcac`)\non ALL 12 of these hosts:\n```javascript\nevolution:{apiUsername:\"progressplay0001\",apiPassword:\"test123\"}\nskywind:{secretKey:\"df40459d-fef0-4956-994d-ceb91112fb11\",username:\"ProgressPlay_UK_api_stg\",password:\"JB9EZakp2Ka49UNS\"}\ntomhorn:{sign_key:\"2cWN6Hc3WtsXT53C\",partnerID:\"A11FF5FC-FD37-481C-9626-6D36FB92D81B\"}\n```\nThis is the SAME chunk/root cause as vuln-0008 (which listed 22 other hosts). The 12 hosts above are now\nrecorded as additional affected hosts on that report (no new report filed — duplicate).\n\n## Alt read path (works but read-only)\n`https://r.jina.ai/<url>` and `https://api.allorigins.win/get?url=` also fetch these from a non-blocked\negress and return content/JSON — useful for bulk/JSON reads, but GET-only (no headers/body) so it cannot\nreplace the browser for interactive testing.\n\n## Origin discovery (negative, and moot now)\nNo origin IP leaked for the Imperva-fronted apex/www (crt.sh/SAN, OTX/ThreatMiner passive DNS, URLScan,\nViewDNS, MX/SPF). Not needed — the browser reaches the real app.\n\n## Non-Imperva in-scope subdomains (light-mapped)\nhotwinscasino admin/brand/m/partners -> 52.201.86.102 (map180.mediacle.net) 404; promo/media -> 403;\nbonus.supabet.co.uk -> CloudFront 401; app.luckcity.com -> Firebase 301; games/promo.luckcity.com ->\n45.63.98.231 (Cloudways) 403; pro/promo.21luckybet.com -> Cloudflare 403; blog.lekkerbets.co.za -> 67.225.177.94.", "agent_name": "Imperva Blocked-Tenant Reach", "agent_id": "9a1f4de9"}, {"note_id": "6a90f6", "title": "RCE-candidate inventory (independent) — components, CVE-RCE mapping, 0day candidates, blockers", "category": "findings", "tags": ["rce", "inventory", "cve-mapping", "exploitability", "independent", "3b5f3832", "0day-candidates"], "created_at": "2026-09-27T20:53:40.409540+00:00", "updated_at": "2026-09-27T20:53:40.409540+00:00", "content": "Author: Independent RCE-Candidate Inventory Agent (3b5f3832), parent Root (7e7a20bf). Inventory/mapping only — NO exploitation, no 0day. Full table: `/workspace/irt_rce_inventory/RCE_INVENTORY.md`; CVE metadata captured in `/workspace/irt_rce_inventory/cve_meta.jsonl`.\n\n## Bucket A — known RCE-capable CVEs vs fingerprinted components (actionable within RoE)\n- **OpenSSH 9.6p1 Ubuntu 3ubuntu13.19 @ 45.132.74.81:22** — CVE-2024-6387 regreSSHion (pre-auth race RCE, CVSS 8.1 AC:H, public PoC). Affected 8.5p1–9.7p1 → in range by upstream version, but Ubuntu pkg rev `3ubuntu13.19` ≫ patched `3ubuntu13.4` ⇒ **very likely distro-backported / not exploitable**. HIGH value to confirm.\n- **NoMachine NX 10.0.59 @ 45.132.74.81:4000** — CVE-2026-18264 cmd injection, CVSS 8.8 but **PR:L (authenticated)**, vulnx status **rejected** (ZDI-26-483). Needs NX creds. CVE-2026-53694 is <9.5.7 ⇒ N/A. Local-privesc CVEs (2026-5055/5054/5053, 2025-8614) need existing local code exec.\n- **ProFTPD @ 77.68.12.66:21** (version unfingerprinted) — confirmed RCE CVEs CVE-2026-63090 (8.8), CVE-2026-42167 (8.1), CVE-2010-20103 (9.8 cmd inj); mostly authenticated.\n- **Plesk Obsidian 18.0.80.8 @ 77.68.12.66:8443** — version-matched & **authenticated**: CVE-2026-58046 (9.9 XML-RPC blind SQLi), CVE-2026-65646 (9.9 BAC file-read+priv-esc), CVE-2026-64636 (7.7 SQLi ≤18.0.80) ⇒ any low-priv panel cred → root/RCE. Unauthenticated RCE/traversal CVEs (67397/68492/67394) are **fixed at 18.0.80.8**; CVE-2025-54336 rejected.\n- **React RSC / Next.js App Router** — CVE-2025-55182 unauth RCE: **patched on tested UAT EKS hosts**; **unverified on all Imperva-blocked Next.js hosts** (ProgressPlay marketing fleet buildId WpePWuKOnX3rgMNqj5LeW, acedbet, play.*). CVE-2026-75604 is Windows-only ⇒ N/A.\n- **Apache Guacamole 1.6.0** — CVE-2024-35164 (≤1.5.5) ⇒ not in range. **LiteSpeed Cache 7.8.1** — CVE-2024-28000/50550 (<6.5.1) ⇒ not in range.\n\n## Bucket B — 0day-dependent RCE candidates (no as-is public RCE CVE)\n- **WordPress core 7.1/7.1.2 (7 hosts)** — authenticated theme/plugin-editor → PHP write; no unauth path found. Admin creds reachable in principle: user-enum + unthrottled XML-RPC/wp-login (vuln-0013/0014). Highest-probability RCE in scope *if* creds obtained. Note WP Engine hosts may set DISALLOW_FILE_EDIT.\n- **PHP 7.4.33 EOL @ playuk.com** — no future patches; but `disable_functions` blocks exec/system/passthru/popen/proc_open/pcntl_exec (webshell command-exec blocked).\n- **Nuxt.js/Nitro marketing fleet (13 hosts)** — CVE-2026-71318 `/__nuxt_island/` template-injection → Nitro RCE (vulnx status rejected); island endpoint absent on all 9 tested hosts ⇒ 0day-dependent.\n- **Strapi behind `/api/cms` (UAT EKS)** — CVE-2026-27886 BAC (confirmed); proxy GET-only + parameterized filters ruled out ⇒ sanitizer-bypass 0day needed for admin ATO→RCE.\n- **IIS/.NET ViewState (jackpot.com, games.betsuna.com)** — ViewState deserialization RCE held shut **only** by machineKey MAC+encryption (auto key); reopens on any machineKey/web.config leak. No vendor RCE components present.\n- **ABP + EF Core @ neonrush.com** — `sorting` Dynamic-LINQ injection CONFIRMED (vuln-0027) but the restricted type provider blocks Process/Reflection/IO ⇒ read-only SQL. A type-provider bypass = RCE; currently single-control.\n- **Node/NestJS “Betty Admin” @ appmanager.tangobet.co.uk** — **admin/admin123 confirmed (vuln-0001)**, but no merge/eval/SSRF/upload sink found ⇒ prototype-pollution→RCE needs a 0day sink.\n- **MySQL 8.0.42 + confirmed SQLi @ api-qa.playuk.com (vuln-0028)** — SQLi→`INTO OUTFILE`→webshell→RCE if FILE privilege + stacked queries + writable webroot (write not proven).\n- **Apache Tomcat 9.0.121 / Guacamole 1.6.0 @ 45.132.74.81** — Tomcat auth-bypass/smuggling CVEs (unconfirmed, recent build); post-auth Guacamole→RDP pivot.\n\n## Blockers\n1. Imperva \"Error 15\" blocks egress IP for ~12 hosts ⇒ app-tier RCE surface unmapped (mrrex, mamzinobet, moneyplay, ne-bet, supabet, betblink, 21luckybet, highstakes, lekkerbets, hotwins, luckcity, play.betzi.co, tangobet apex).\n2. No credentials for the two exposed origins ⇒ highest-value post-auth RCE (NoMachine, Plesk) gated.\n3. Ownership ambiguity 45.132.74.81 (rDNS starosamuchan.com / CN cl.exalt-digital.ru) & 77.68.12.66 (rDNS activewin.co.uk).\n4. Version gaps: ProFTPD, LiteSpeed WS, Nuxt, Strapi, Next.js patch level, headless WP, EB apps.\n5. Plesk sw-cp-server path-traversal untested (8443 refused mid-test) → would yield /etc/psa/.psa.shadow → MariaDB admin cred.\n\nMethod note: CVE facts taken from the shared pack’s `vulnx` results and independently re-checked with the local `vulnx` CLI (rate-limited, no API key). Cross-checked against nmap artifacts (`nmap_potsofluck_scan1/2.txt`, `mariadb_validate/nmap_77.68.12.66.txt`).", "agent_name": "Independent RCE-Candidate Inventory Agent", "agent_id": "3b5f3832"}, {"note_id": "8fc1cc", "title": "Independent Red Team Lead 5 — fresh probes: NeonRush captcha-free tenant set (CORRECTED); jackpot ALB-bypass reach", "category": "methodology", "tags": ["lead5", "neonrush", "multi-tenant", "turnstile", "correction", "jackpot", "alb-bypass", "probe", "intel"], "created_at": "2026-09-27T20:47:01.654943+00:00", "updated_at": "2026-09-27T21:29:23.195031+00:00", "content": "Author: Independent Red Team Lead 5 (cb52f482). Built on notes 8171f4 / d98b4e / 153658 / c0181c / 62f58e / 7b54d6 / 4dceb7.\n\n## CORRECTION (2026-09-27 21:29, from child 5e4b89fa) — ignore the tenant set originally stated below\n`turnstilepolicy/getvalidationpolicy` is FLOW-KEYED: with NO `turnstileFlow` param it answers \"Turnstile is disabled\" for EVERY tenant 1..60, so the set I originally reported (2,3,6,8,10,13,14,15,16) was an artefact — do not rely on it.\nGROUND TRUTH (via `POST /api/services/app/playeraccount/register` per tenant): captcha-free + session issued ONLY for tenant 1 (CogniSweeps), tenant 5 (Lucky.Me; needs a >=12-char password) and tenant 11 (Big Shot Games); tenants 7 & 10 pass the challenge but registration is disabled; the rest enforce the robot check; ids>30 fall back to tenant 17 (fails closed).\nIMPACT: tenants 5 and 11 are POPULATED with real players — `userlogin/getuserloginattempts?userId=<N>` reads foreign users' clientIpAddress/browserInfo/creationTime without scoping. This was escalated into report vuln-0023 (revised Medium->HIGH 7.5, C:H, PR:N). See note 0b75cf.\n\n## 1) NeonRush (www.neonrush.com / Cogni ABP) — multi-tenant probe (superseded by the correction above)\n## 2) jackpot.com — ALB `/%2f` bypass reach (still valid)\nProbed 18 restricted paths (raw vs `%2f`-encoded):\n- `/%2fadmin` / `/%2fadmin/` / `/%2fadmin%2f` → 200, 8880B = \"Content Admin Area\" login (bypass works).\n- `/%2fweb.config`, `/web.config`, `/%2fApp_Data/`, `/%2fbin/`, `/%2fViews/web.config`, `/%2felmah.axd`, `/%252fadmin` → 404.\n- `/%2fadmin/web.config`, `/%2fAdmin/users`, `/%2fadmin/export`, `/%2fadmin/upload`, `/%2fadmin/api/users` → 404.\n- `/%2ftrace.axd` → 403 \"Trace Error\" (remote tracing localOnly); `/%2f..%2fweb.config` → 400.\n=> The bypass reaches only the login-gated MVC admin app; no config/secret file surfaced on direct probe.\n\n## Live parallel work (avoid duplication)\nOther independent leads + my subagents own: NeonRush tenant data, ProgressPlay play.* IDOR, WP credentialed path, infra/RCE version fingerprinting, Next.js/RSC patch status, Plesk/Tomcat credentialed paths, ABP LINQ escalation.", "agent_name": "Independent Red Team Lead 5", "agent_id": "cb52f482"}, {"note_id": "e2a03b", "title": "RCE path analysis — Red Team A / App APIs", "category": "findings", "tags": ["rce", "red-team-a", "app-api", "betty", "neonrush", "abp", "revolve", "nextjs", "prototype-pollution", "cve-2025-55182"], "created_at": "2026-09-27T17:45:28.269507+00:00", "updated_at": "2026-09-27T17:45:28.269507+00:00", "content": "Agent: Node API RCE Hunter (63991be6), child of Red Team A (6e6cf884). Objective: reach RCE / decisive internal pivot through the in-scope application APIs, or name the control that blocks it.\n\n## Verdict per surface\n| Target | RCE vector tested | Result | Blocking control |\n|---|---|---|---|\n| appmanager.tangobet.co.uk (Betty Admin, Node/NestJS) | Prototype pollution via advancedFilter/sortField/search → gadget | NOT reached | JSON-only typed DTOs; no recursive merge of request data (11 JSON + 5 qs + 3 form vectors, zero behavioural change) |\n| appmanager.tangobet.co.uk | SQL/NoSQLi (search/sort/operator/field) | NOT reached | parameterised queries; sortField whitelisted; unknown operators fail open (data exposure only) |\n| appmanager.tangobet.co.uk | SSRF via any admin feature | n/a | No URL/host-consuming feature exists in the API |\n| appmanager.tangobet.co.uk | Hidden exec/import/upload routes; XXE; method override | NOT reached | Fixed NestJS route table (404s); JSON-only parser (XML→500); override ignored |\n| www.neonrush.com (ABP/.NET) | Unauth file upload/import/exec across all 191 services | NOT reached | ABP auth: all RCE-capable services 401 \"Current user did not login\" |\n| www.neonrush.com | Unauth SSO token minting (generateJwt) | REPORTED vuln-0022 (medium) | — (missing auth; consumer OOS, gap noted) |\n| www.neonrush.com | Authenticated document/KYC upload → path traversal; tenantBaseSiteUrl SSRF | UNVERIFIED | Login/registration gated by Cloudflare Turnstile (sitekey 0x4AAAAAAChdt0aXJQzhuYXQ; field `cf-turnstile-response`); blocks sandbox egress |\n| api-uat/api-qa.playuk.com (revolve) | File upload / filename traversal | n/a | No upload route (KYC via SumSub); no filename/path param |\n| api-uat/api-qa.playuk.com | loginWithToken auth bypass | NOT reached | Token validated (code 190 Invalid Token) |\n| play.neonrush.com | /api/record/saveLastAction prototype pollution | NOT reached | Incapsula WAF 403s `__proto__`/`constructor`/`prototype` in body |\n| uat.uk-bingo.net / uat.pandabingo.com / uat.chitchatbingo.com (Next.js App Router) | CVE-2025-55182 React Server Components unauth RCE | NOT reached | Patched RSC runtime (verified nuclei template + manual payload, no oracle) |\n| Same UAT apps | Write/deserialization via /api/cms, /api/env/vars | n/a | Proxy is GET/HEAD/OPTIONS only (405); env vars only NEXT_PUBLIC_* |\n| Fleet (51 Next.js targets) | CVE-2025-55182 sweep | no match | Imperva-blocked hosts unverified (edge 403) |\n\n## Highest-value remaining path (not yet closed)\n`www.neonrush.com` authenticated ABP surface — `accountVerification.submitProofDocuments` (multipart KYC documents), `documentUser.create`, `profile.updateProfilePicture` (arbitrary file write → possible webroot write / stored content), and `pushCashPayment.authorizePayment(…, tenantBaseSiteUrl)` (server-side URL construction → SSRF to internal). All are behind ABP login, which is Turnstile-gated and failed from the sandbox datacenter IP (widget returned a failure state in a real headless browser). Re-test from a non-blocked/residential egress.\n\n## Containment note\nMinted `generateJwt` tokens (iss https://id.neonrush.com, aud cogniplay-sso) did NOT authenticate the ABP session endpoint, so in-scope impersonation could not be demonstrated — the consumer is an external SSO platform.\n\n## Cross-cutting observations (not RCE)\n- `api/services/app/paypalpayment/createorder` is anonymously reachable (returns business error \"Invalid Amount\", not 401) — unauth payment-order creation surface, business-logic impact unproven.\n- `/AbpServiceProxies/GetAll` + `/AbpScripts/GetScripts` publish the full 191-route API map unauthenticated.", "agent_name": "Node API RCE Hunter", "agent_id": "63991be6"}], "filtered_count": 12, "total_count": 99}