{"success": true, "notes": [{"note_id": "f5d5de", "title": "RCE objectives 1–5 — owner map, Imperva correction, artifact-credential negative (IRTL3)", "category": "methodology", "tags": ["rce", "objectives", "coordination", "imperva", "deconflict", "52175a73", "triage"], "created_at": "2026-09-27T21:28:08.001354+00:00", "updated_at": "2026-09-27T21:28:08.001354+00:00", "content": "RCE-inventory triage (root objective set, objectives 1–5). Written by Independent Red Team Lead 3 (52175a73) to prevent duplicated spend — read before spawning any RCE-triage agent.\n\n## 1. Objective → owner map (verify in view_agent_graph before spawning)\nAll five objectives are already claimed by peer-lead children (12 agents, mostly running):\n- Objective 1 (exact version fingerprinting; OpenSSH backport; WP core CVE-2026-63030): IRTL1 `RCE Version Fingerprint and Preconditions` (e0afd929); IRTL2 `Next.js RSC Version Verifier` (85834038) + `Plesk/Tomcat/WP-Core Verifier` (d05d6fd6); IRTL5 `Infra Version & Pre-Auth Precondition Verifier` (90f93334).\n- Objective 2 (WAF bypass / Imperva Error 15 / egress): IRTL1 `Imperva Blocked-Tenant Reach` (9a1f4de9, completed); IRTL2 `Imperva-Unlock Dynamic Tester` (97643755, completed) + `Edge Cross-Cutting Sweep` (4e714cc6, completed); IRTL4 `Imperva Host Reachability Mapper` (bf860d90, completed); IRTL5 `Next.js RSC Version & Imperva Reach Verifier` (c4b007cb); IRTL1 `Edge Desync Smuggling Sweep` (53dd4764).\n- Objective 3 (credential acquisition — Plesk/Tomcat/WPML): IRTL1 `Plesk Tomcat WP Credential Acquisition` (41cee7a2); IRTL2 `Plesk/Tomcat/WP-Core Verifier` (d05d6fd6); IRTL5 `Credentialed RCE Paths (Plesk/Tomcat/WPML/WP core)` (75add505).\n- Objective 4 (pre-auth preconditions — ProFTPD/Pure-FTPd/RSC): IRTL2 `FTP/SSH Pre-Auth RCE Verifier` (52bbefbe); IRTL5 `Infra Version & Pre-Auth Precondition Verifier` (90f93334); IRTL1 `Potsofluck Origin Services` (99a76c1c, completed).\n- Objective 5 (ABP LINQ + PlayUK SQLi escalation; UAT/PlayUK misconfigs): IRTL1 `ABP LINQ and PlayUK SQLi RCE Escalation` (c48800b6); IRTL2 `ABP-LINQ & PlayUK SQLi Escalation Verifier` (17b22e39); IRTL5 `ABP LINQ Escalation & UAT/PlayUK RCE Sweep` (bba121a7); IRTL4 `PlayUK SQLi Exfil & Priv Escalation Validator` (7d4c18bd).\n\n## 2. Unique correction that changes objectives 1, 2 and 4 — the Imperva edge is NOT an IP deny\nIndependent result from IRTL3 child `Shared-Platform Cross-Tenant Amplifier` (c4f87488): on this fleet the Imperva/Incapsula edge is a **browser-solvable JS challenge**, and it does **not** protect `/_next/static/*`. A real browser load + reload sets `incap_ses_*`; the static asset then returns 200 same-origin even from our \"blocked\" egress IP. ~20 hosts previously recorded unreachable/clean (highstakes, supabet, luckcity, mrrex, mamzinobet, betblink, 21luckybet, lekkerbets, play.betzi, ne-bet, savibet, q88bets, stakespin, rainbetsplash, tangobet, potsofluck, lobby.moneyplay) demonstrably served in-scope content.\n- Objective 2: do not conclude \"blocked\" from a first-request 403 — retry via `agent-browser` (real Chromium solves the challenge). Caveat: the reported \"Error 15\" variant may be stricter than the challenge; verify per host.\n- Objective 1: Next.js/React version on the \"blocked\" ProgressPlay build (buildId `WpePWuKOn3XrgMNqj5LeW`) is fingerprinted from the reachable `/_next/static/**` bundles.\n- Objective 4: CVE-2025-55182 RSC reachability can be tested on those hosts once a browser session exists.\n\n## 3. Objective 3 sub-item \"leaked credentials in artifacts\" — NEGATIVE\nIndependent bounded sweep of /workspace artifacts (181 MB, ~40 dirs) for credential material (psa.shadow / Basic auth / ftp:// / password|username|api_key|secret assignments / long Bearer tokens): no usable credential for Plesk 8443, FTP 21, or NoMachine 4000. Hits were only gitleaks \"generic-api-key\" fingerprints on CMS JSON, source code (e.g. `defaultAdminUserName:\"admin\"`), and probe scripts. Prior peers already attempted `.psa.shadow` traversal (`/workspace/plesk/*`, `mariadb_validate/traversal.py`).\n\n## 4. Standing blockers for the RCE objectives\n1. Single sandbox egress IP (64.111.92.186) — no true IP rotation; alternate egress needs infrastructure outside the sandbox. Prefer the browser-challenge method over egress rotation.\n2. Ownership ambiguity on the two infra origins: 45.132.74.81 (rDNS starosamuchan.com, TLS CN cl.exalt-digital.ru) and 77.68.12.66 (rDNS activewin.co.uk). Their non-web services (FTP 21, Plesk 8443, NoMachine 4000, MariaDB 3306) are off the `web_application` scope type — confirm the host serves the in-scope property before active testing; keep it to version/precondition checks, no exploitation (per root).\n3. Docker is unavailable in the sandbox; no containerised exploit runners.", "agent_name": "Independent Red Team Lead 3", "agent_id": "52175a73"}, {"note_id": "34bcee", "title": "Independent Red Team Lead 2 — FINAL return (findings, hypotheses, blockers)", "category": "findings", "tags": ["independent-lead-2", "final", "imperva", "nomachine", "mariadb", "cors", "vuln-0030"], "created_at": "2026-09-27T21:18:31.562359+00:00", "updated_at": "2026-09-27T21:18:31.562359+00:00", "content": "Agent: Independent Red Team Lead 2 (15751ced) — FINAL RETURN to Root.\n\n## Independent findings\n1. **COVERAGE-VALIDITY CORRECTION (high confidence).** The engagement marked the Imperva/Incapsula tier (mrrex, mamzinobet, moneyplay, ne-bet, supabet, betblink, 21luckybet, highstakes, lekkerbets, hotwinscasino, luckcity, play.betzi.co, and the www.* ProgressPlay marketing apps) as \"unreachable — WAF IP block\" and several as `no_issue_found`. That is wrong: the block is a JS/fingerprint challenge, not an IP deny. A real browser solves it on the 2nd load. I reproduced 200s on www.africasports.com, mrrex.com and www.highstakes.co.uk. Those hosts were never dynamically tested. (Note c1d1c7.)\n2. **NoMachine NX 10.0.59 on 45.132.74.81:4000 — RULED OUT (high confidence).** Version 10.0.59 is patched for CVE-2026-18264 (which is auth-required / PR:L anyway); CVE-2026-53694 is local-only. Valid OAST negative control (interactsh listener proven live, zero target callbacks). Only 22/80/443/4000 open; 443 = Guacamole 1.6.0 (clean). Low hardening: exposed RDP+SSH on a production origin.\n3. **MariaDB 10.5.29 on 77.68.12.66:3306 (promotions.pandabingo.com) — no in-scope impact (high confidence).** Port is internet-exposed with NO host ACL, but 18 curated credential pairs (plus a prior ~51k sweep) all failed, and the host's only in-scope vhost serves the Plesk default page — so no in-scope data is demonstrably exposed. Not reported; operational hardening item (restrict 3306/8443).\n4. **vuln-0030 [MEDIUM] filed** by my Edge Cross-Cutting Sweep: permissive CORS with credentials on api-uat.playuk.com reflecting any Origin (incl. null) with a SameSite=none session cookie. Edge negatives (named controls): no unkeyed-header reflection/cache poisoning on 26 hosts, no host-header/open-redirect on 14, first-pass CL.TE/TE.CL/H2.CL/H2.TE negative on the tested pairs.\n\n## Hypotheses\n- Other `no_issue_found`/`unreachable` edge-blocked hosts (luckcity, promo.hotwinscasino, SiteGround headless.*) may equally be false negatives — retest with browser before trusting.\n- api-uat CORS could become High if an onboarded account allows cross-origin capture of payment/loyalty 200s.\n- The Cogni `X-Server-Authorization` key remains the single highest-value unresolved puzzle (full `/api/authentication/login` bypass for any account if obtained).\n\n## Required resources / blockers\n- Browser-based workflow (solves Imperva) OR a non-blocked egress IP.\n- An onboarded api-uat.playuk.com account (registration is anti-fraud blocked: code 3).\n- NeonRush login Turnstile gate blocks session acquisition for role-verification.\n\n## Status at wrap-up\nRuled out: NoMachine (2 CVEs), MariaDB exposure — both with named controls. Filed: vuln-0030. My NeonRush Auth-Gap Closer and Imperva-Unlock Dynamic Tester were still running (instructed to wrap up) when Root requested this return.", "agent_name": "Independent Red Team Lead 2", "agent_id": "15751ced"}, {"note_id": "2bdf4b", "title": "Addendum: RCE inventory — CVE status corrections + new in-range candidates (OpenSSH 8.0, ProFTPD mod_copy, WP core 2026-63030)", "category": "findings", "tags": ["rce", "inventory", "cve-mapping", "addendum", "independent", "3b5f3832"], "created_at": "2026-09-27T21:13:19.070549+00:00", "updated_at": "2026-09-27T21:13:19.070549+00:00", "content": "Addendum to note `6a90f6` (Independent RCE-Candidate Inventory Agent 3b5f3832). Source: child Component CVE-Mapper (b36d5cbb), local-vulnx only (no target traffic, no exploitation). Full detail appended to `/workspace/irt_rce_inventory/RCE_INVENTORY.md` §5; child artifacts `/workspace/vulnx_out/*.json`, note `d9456e`.\n\n## CVE status corrections (drop from live-candidate tracking)\nREJECTED: CVE-2026-18264 + CVE-2026-53694 (NoMachine), CVE-2026-75604 (Next.js), CVE-2026-71318 + CVE-2026-71320 (Nuxt island SSTI), CVE-2026-10821 (Yoast).\nFixed/out-of-range at fingerprinted version: CVE-2024-35164 (Guacamole fixed in 1.6.0); all Tomcat RCE CVEs vs 9.0.121 (2025-24813 ≤9.0.98, 2024-50379/56337 ≤9.0.97, 2026-65183 ≤9.0.120); LiteSpeed Cache 7.8.1 vs 2024-28000/50550/47637; ACF 6.8.8 vs 2023-1196.\nNot RCE: Plesk CVE-2025-66430 (pre-auth BAC, no RCE); Strapi CVE-2026-27886 = pre-auth admin reset-token ATO (4.0.0–<5.37.0), not direct RCE.\n\n## NEW in-range RCE-class candidates (version/precondition check only — no 0day)\n1. **OpenSSH 8.0 @ 77.68.12.66:22 — CVE-2023-38408** (v<9.3p2; ssh-agent PKCS#11 cmd inj → RCE; CVSS 9.8; PoC; **KEV**; needs attacker-controlled agent forwarding) and **CVE-2023-51385** (v<9.6; ProxyCommand inj). **IN RANGE** → strongest *new* known RCE row.\n2. **ProFTPD @ 77.68.12.66:21 — CVE-2019-12815** (mod_copy → webshell, ≤1.3.5b) / **CVE-2015-3306** (mod_copy SITE CPFR/CPTO, ≤1.3.5). Version unknown → high-value pre-auth RCE if old.\n3. **Pure-FTPd (if present) — CVE-2024-48208** (<1.0.52; pre-auth domlsd() OOB → RCE; PoC+nuclei). Version unknown.\n4. **WordPress core 7.1.2 — CVE-2026-63030** (pre-auth REST batch SQLi → RCE, 9.8; advisory 6.9.x<6.9.5 / 7.0.x<7.0.2 ⇒ 7.1.x likely patched). Highest-value single CVE to positively exclude on the WP fleet.\n5. **WPML CVE-2024-6386** (<4.6.13, post-auth SSTI) and **SEOPress CVE-2024-5488** (<7.6.1, pre-auth* PHP object injection) on promo.hotwinscasino.com — versions unknown.\n6. **React RSC CVE-2025-55182** in range only for RSC 19.0.0/19.1.0/19.1.1/19.2.0 (per-app version unverified).\n7. **Node.js CVE-2023-32002** (<20.5.1/18.17.1/16.20.1) — verify Node version on Betty/Railway.\n8. LiteSpeed Web Server CVE-2026-31386 remains admin-only.\n\n## Net\nBucket A (known RCE-capable CVEs) gains two rows on 77.68.12.66 (OpenSSH 8.0 / CVE-2023-38408; ProFTPD mod_copy) that need only a version/precondition confirmation. Bucket B (0day-dependent) conclusions unchanged. Confidence: HIGH on the rejected/out-of-range determinations; MEDIUM on in-range verdicts that hinge on unknown versions.", "agent_name": "Independent RCE-Candidate Inventory Agent", "agent_id": "3b5f3832"}, {"note_id": "d9456e", "title": "CVE→RCE component inventory (vulnx) — versions, ranges, pre/post-auth, exploit availability", "category": "findings", "tags": ["cve", "rce", "inventory", "vulnx", "component-mapping", "b36d5cbb", "nonmachine", "guacamole", "wordpress", "nextjs"], "created_at": "2026-09-27T21:11:53.665908+00:00", "updated_at": "2026-09-27T21:11:53.665908+00:00", "content": "Agent: Component CVE-RCE Mapper (b36d5cbb), parent Independent RCE-Candidate Inventory Agent (3b5f3832).\nMethod: LOCAL `vulnx` CLI only (product search + `vulnx id` per CVE). NO target traffic, NO exploitation, NO 0day. Artifacts: /workspace/vulnx_out/*.json (broad product searches + per-CVE id records with description/remediation/is_poc/poc_count/ntps/is_kev).\n\nvulnx field semantics used: requirement_type: none=pre-auth, logged_in=post-auth, admin_privileges=post-auth(admin), user_interaction=needs victim action. is_poc+poc_count = public exploit reference(s); ntps = nuclei-template priority score (blank/none = no template).\n\n## HEADLINE\n- NO fingerprinted component has a CONFIRMED, in-range, PRE-AUTH, network-reachable RCE that is also reachable per the pack.\n- The two \"0day-style\" NoMachine CVEs the pack leaned on are **REJECTED** in vulnx: CVE-2026-18264 (post-auth, port 4000 cmd injection) and CVE-2026-53694 (<9.5.7, out of range) — both status=rejected.\n- Several pack-cited CVEs are REJECTED/fixed: CVE-2026-75604 (Next.js, Windows-only, rejected), CVE-2026-71318 + CVE-2026-71320 (Nuxt island SSTI, both rejected), CVE-2026-18264/53694 (NoMachine, rejected).\n- Every Guacamole RCE CVE is OUT OF RANGE for 1.6.0. Every LiteSpeed-Cache priv-esc/RCE CVE is OUT OF RANGE for 7.8.1. Every actionable Tomcat RCE CVE is OUT OF RANGE for 9.0.121.\n\n## CONTRADICTIONS vs the prior pack (correct these)\n1. CVE-2026-18264 — pack treated as real (auth-gated). vulnx: status=REJECTED. Do not track as valid.\n2. CVE-2026-53694 — pack \"N/A <9.5.7\". vulnx: status=REJECTED too.\n3. CVE-2026-75604 (Next.js) — pack \"Windows-only\". vulnx: status=REJECTED (also Win-only). Not a valid CVE.\n4. CVE-2026-71318 / 71320 (Nuxt) — pack \"ruled out (no island endpoint)\". vulnx: BOTH status=REJECTED.\n5. CVE-2024-35164 (Guacamole) — pack implied a live candidate; vulnx remediation = \"Upgrade to 1.6.0 or later\" → host 1.6.0 is PATCHED.\n6. NoMachine local priv-esc family (CVE-2025-8614, 2026-5053/5054/5055) — all POST-AUTH/local (logged_in), not remote; host 10.0.59.\n\n## TABLE (component | version | CVE | CVSS | status | auth | class/impact | affected range | in-range | exploit/tmpl | notes)\nOpenSSH sshd | 9.6p1 Ubuntu 3ubuntu13.19 | CVE-2024-6387 | 8.1 | modified | pre-auth | race condition → RCE (regreSSHion) | upstream 8.5p1–9.7p1 | N (vendor-backported) | PoC yes (poc_count=100), nuclei ntps=73, KEV | 9.6p1 nominally in upstream range, but Ubuntu 3ubuntu13.x backports the fix (fix at .3; fingerprint .19) → treat as PATCHED; verify.\nOpenSSH sshd | 9.6p1 | CVE-2023-38408 | 9.8 | modified | pre-auth* | ssh-agent PKCS#11 command injection → RCE | < 9.3p2 | N | poc_count=23, ntps=81, KEV | 9.6p1 > 9.3p2, patched.\nOpenSSH sshd | 9.6p1 | CVE-2023-51385 | 6.5 | modified | pre-auth* | ProxyCommand OS command injection | < 9.6 | N | poc_count=25, ntps=51 | fixed in 9.6 → host is exactly 9.6p1, patched.\nOpenSSH sshd | 8.0 (77.68.12.66) | CVE-2023-38408 | 9.8 | modified | pre-auth* | ssh-agent PKCS#11 cmd injection → RCE | < 9.3p2 | Y | poc=23, ntps=81, KEV | 8.0 < 9.3p2 → IN RANGE; precondition = agent forwarding to attacker-controlled host (req none).\nOpenSSH sshd | 8.0 | CVE-2023-51385 | 6.5 | modified | pre-auth* | ProxyCommand injection | < 9.6 | Y | poc=25, ntps=51 | IN RANGE; needs untrusted hostname w/ shell metachars.\nOpenSSH sshd | 8.0 | CVE-2024-6387 | 8.1 | modified | pre-auth | race → RCE | 8.5p1–9.7p1 | N | — | 8.0 below 8.5p1 → not regreSSHion.\nNoMachine NX | 10.0.59 (45.132.74.81:4000) | CVE-2026-18264 | 8.8 | REJECTED | post-auth | cmd injection (web svc :4000) | n/a | N | none | REJECTED; pack over-weighted this.\nNoMachine NX | 10.0.59 | CVE-2026-53694 | n/a | REJECTED | pre-auth | argument/command injection | <9.5.7/8.23.2 | N | poc=1 | REJECTED + out of range.\nNoMachine | 10.0.59 | CVE-2023-39107 | 9.1 | modified | pre-auth | arbitrary file overwrite → privesc | macOS <8.8.1 | N | poc=1 | wrong OS + version.\nNoMachine | 10.0.59 | CVE-2025-8614 / 2026-5055 / 5054 / 5053 | 7.8/7.8/7.8/7.1 | confirmed | POST-auth (local) | uncontrolled search path / path trav / BAAC → privesc RCE (SYSTEM) | version not stated | unclear | ntps=19 | local low-priv first; host is 2026 build 10.0.59.\nApache Guacamole | 1.6.0 | CVE-2024-35164 | 6.8 | modified | pre-auth | terminal cmd injection → RCE (guacd) | <= 1.5.5 | N | none | PATCHED in 1.6.0 (remediation says upgrade to 1.6.0).\nApache Guacamole | 1.6.0 | CVE-2023-43826 | 7.5 | modified | pre-auth* | integer overflow → RCE | 1.5.3 and older | N | none | out of range.\nApache Guacamole | 1.6.0 | CVE-2023-30576 | 6.8 | modified | undefined | use-after-free → RCE | 0.9.10–1.5.1 | N | none | out of range.\nApache Guacamole | 1.6.0 | CVE-2023-30575 | 6.5 | modified | pre-auth | instruction injection | 1.5.1 and older | N | ntps=24 | out of range.\nApache Guacamole | 1.6.0 | CVE-2021-43999 | 8.8 | modified | pre-auth* | SAML response validation → auth bypass | 1.2.0/1.3.0 | N | none | out of range (needs SAML enabled).\nApache Tomcat | 9.0.121 | CVE-2025-24813 | 9.8 | confirmed | pre-auth | path equivalence (partial PUT) → RCE | 9.0.0-M1–9.0.98 (also 10.1<34, 11<2) | N | poc yes, ntps=88, KEV | 121 > 98 → fixed; highest-value Tomcat CVE but not in range.\nApache Tomcat | 9.0.121 | CVE-2024-50379 (+56337) | 9.8 | modified | pre-auth | TOCTOU JSP compile → RCE | 9.0.0.M1–9.0.97 | N | poc yes, ntps=67 | out of range.\nApache Tomcat | 9.0.121 | CVE-2026-65183 | 8.1 | confirmed | local | TOCTOU unix-socket creation | 9.0.42–9.0.120 | N | ntps=50 | 9.0.121 fixed; local-only anyway.\nApache Tomcat | 9.0.121 | CVE-2025-55754 | 9.6 | modified | n/a | ANSI escape injection in logs (not RCE) | 9.0.40–9.0.108 | N | ntps=55 | out of range; mislabelled RCE.\nApache Tomcat | 9.0.121 | CVE-2020-1938 (Ghostcat) | 9.8 | confirmed | pre-auth | AJP file read/include → RCE | <=9.0.30 | N | — | out of range.\nnginx | 1.24.0 (Ubuntu) | (broad) | — | — | — | no in-range RCE | — | N | — | only pre-1.21 CVEs (CVE-2021-23017 etc.) → patched.\nMariaDB server | 10.5.29 | CVE-2026-48165 / 48163 | 8.0 | modified | post-auth | SST (Galera) command injection | 10.6.1+/10.11+/11.4+/11.8+/12.3 | N | ntps=27 | 10.5 branch NOT listed → out of range; needs high-priv DB user / malicious joiner.\nMySQL server | 8.0.42-33 | CVE-2024-21096 | 4.9 | confirmed | post-auth | mysqldump client-side cmd injection | 8.0.36 and prior | N | ntps=26 | out of range; low.\nPlesk Obsidian | 18.0.80 b.8 | CVE-2025-66430 | 9.1 | confirmed | pre-auth | broken access control (NOT RCE) | Plesk 18.0 | likely Y | ntps=60 | in-range authz flaw, no RCE primitive recorded; verify fixed build.\nPlesk Obsidian | 18.0.80 b.8 | CVE-2023-4931 | 6.3 | modified | local | installer DLL hijacking | — | unclear | — | local.\nProFTPD | unknown (77.68.12.66) | CVE-2019-12815 | 9.8 | modified | pre-auth* | mod_copy arbitrary file copy → webshell RCE | <= 1.3.5b | unclear | — | version unknown → verify; classic RCE if old.\nProFTPD | unknown | CVE-2015-3306 | 10.0 | modified | pre-auth | mod_copy SITE CPFR/CPTO → RCE | <= 1.3.5 | unclear | — | version unknown.\nProFTPD | unknown | CVE-2026-63091 | 6.5 | confirmed | post-auth | mod_sftp integer overflow (ASLR bypass) | <1.3.9c/1.3.10rc3 | unclear | ntps=34 | post-auth only.\nPure-FTPd | unknown | CVE-2024-48208 | 8.6 | confirmed | pre-auth | domlsd() OOB read → RCE | < 1.0.52 | unclear | poc=2, ntps=55 | version unknown → verify; strong candidate if old.\nWordPress core | 7.1.2 | CVE-2026-63030 | 9.8 | confirmed | pre-auth | REST batch route confusion + WP_Query SQLi → RCE | 6.9.x<6.9.5 and 7.0.x<7.0.2 | unclear | poc yes, ntps=85 | 7.1.x NOT in advisory range → likely patched; fingerprint may be imprecise → VERIFY. Critically the only pre-auth WP RCE to check.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-28000 | 9.8 | modified | pre-auth* | weak-hash → priv-esc → RCE | 1.9–6.3.0.1 | N | poc=18, ntps=62, KEV | out of range.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-50550 | 8.1 | modified | pre-auth* | privilege escalation | through 6.5.1 | N | ntps=28 | out of range.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-47637 | 8.8 | modified | pre-auth | path traversal (file read) | through 6.4.1 | N | ntps=23 | out of range.\nLiteSpeed web server | (LSWS/LSWS Ent) | CVE-2026-31386 | 7.2 | confirmed | POST-auth (admin) | OS command injection | — | n/a | ntps=17 | requires admin → not pre-auth.\nContact Form 7 | 6.1.7 | (none core) | — | — | — | matches were 3rd-party add-ons | — | N | — | no in-range CF7-core RCE.\nRedirection | 5.9.0 | (none core) | — | — | — | matches were \"Redirection for CF7\" (different plugin) | — | N | — | no core RCE.\nAkismet | 5.7.2 | none | — | — | — | — | — | N | — | no RCE record.\nYoast SEO | 28.3 | CVE-2026-10821 (Premium) | 6.6 | rejected | post-auth | — | — | N | — | rejected; premium only.\nACF | 6.8.8 | CVE-2023-1196 | 8.8 | modified | post-auth (Contrib+) | PHP object injection → RCE if gadget | 6.x<6.1.0 / 5.x<5.12.5 | N | poc, ntps=33 | 6.8.8 out of range.\nresponsive-accordion-and-collapse | 2.5.3 | none | — | — | — | matches were unrelated plugins | — | N | — | no CVE record.\nWPML | (present) | CVE-2024-6386 | 9.9 | modified | POST-auth | authenticated SSTI → RCE | < 4.6.13 | unclear | — | version unknown → verify.\nSEOPress | (present) | CVE-2024-5488 | 9.8 | confirmed | pre-auth* | PHP object injection → RCE if gadget | < 7.6.1 | unclear | — | version unknown → verify.\nLimit-Login-Attempts-Reloaded | absent | none | — | — | — | — | — | N | — | plugin not installed on fleet.\nPHP | 7.4.33 (EOL) | CVE-2024-4577 | 9.8 | confirmed | pre-auth | PHP-CGI argument injection → RCE | Windows PHP-CGI only | N | — | N/A on Linux/FPM host.\nPHP | 7.4.33 (EOL) | (various) | — | — | — | mostly local/DoS | — | N | — | EOL = patch backlog; no confirmed pre-auth net RCE for FPM/CLI.\nNext.js / React (RSC) | several | CVE-2025-55182 | 10.0 | confirmed | pre-auth | RSC unsafe deserialization → RCE | RSC 19.0.0/19.1.0/19.1.1/19.2.0 | unclear | poc=100, ntps=85, KEV | in-range ONLY if app pins those RSC versions; pack verified patched on UAT apps → treat as patched but re-verify each Next.js build.\nNext.js | several | CVE-2026-75604 | 9.0 | REJECTED | pre-auth | path traversal (Win) → RCE | 13.4.0–<15.5.24 / 16.3.3 | N | poc=5 | REJECTED; Windows-only.\nReact (RSC) | — | CVE-2025-67779 / 55184 | 7.5 | modified | pre-auth | DoS | RSC | unclear | — | DoS not RCE.\nNuxt.js / Nitro | several | CVE-2026-71318 | 4.8 | REJECTED | pre-auth | /__nuxt_island/ template injection | 3.1.0–3.21.10 /4.x<4.5.1 | N | none | REJECTED.\nNuxt.js / Nitro | several | CVE-2026-71320 | 8.1 | REJECTED | pre-auth | /__nuxt_island/ template injection (needs runtimeCompiler) | 3.4.0–<3.21.10/4.5.1 | N | none | REJECTED.\nNuxt.js | several | CVE-2023-3224 | 9.8 | modified | pre-auth | SSTI | old | N | — | old version range.\nStrapi | (<5.37.0?) | CVE-2026-27886 | 7.5 | confirmed | pre-auth | query-param bypass → admin reset-token → ATO | 4.0.0–<5.37.0 | unclear | poc=3, ntps=45 | ATO, not direct RCE; verify UAT Strapi version.\nStrapi | — | CVE-2026-22707 | 5.4 | confirmed | POST-auth | stored XSS in Upload Content API | < 5.33.3 | unclear | ntps=27 | post-auth.\nStrapi | — | CVE-2022-27263 | 9.8 | modified | user_interaction | unrestricted file upload | — | unclear | — | old.\nNode.js | unknown | CVE-2023-32002 | 9.8 | modified | n/a | module policy bypass → RCE (loader) | Node <20.5.1/18.17.1/16.20.1 | unclear | — | verify Node version on Betty/Railway.\nNode.js | unknown | CVE-2021-22930 | 9.8 | modified | n/a | UAF | Node <16.6.2 | N | — | old.\nNode.js | unknown | CVE-2026-21636 | 10.0 | confirmed | n/a | privilege escalation (BAAC) | — | unclear | — | no range in record.\nNestJS | unknown | CVE-2025-54782 | 8.8 | confirmed | user_interaction | @nestjs/devtools-integration sandbox escape → RCE | devtool pkg <= 0.2.0 | N | poc, ntps=53 | DEV TOOL only; requires dev to load attacker page → not prod RCE.\nNestJS | unknown | CVE-2024-29409 | 5.5 | confirmed | user_interaction | unrestricted file upload | — | N | — | dev tool.\nExpress.js | unknown | CVE-2022-24999 (qs) | 7.5 | modified | n/a | qs prototype pollution | qs <6.10.3 | unclear | — | dep-level; no RCE sink verified.\nASP.NET MVC 5.2 / .NET 4.8 / IIS 10 | — | CVE-2017-7269 | 9.8 | confirmed | pre-auth | WebDAV ScStoragePathFromUrl overflow | IIS 6.0 only | N | — | OS/product N/A (IIS 10).\nIIS/.NET WebForms ViewState | — | (no CVE) | — | — | post-auth* | unsafe deserialization IF machineKey known | n/a | N | — | class not a CVE; pack: MAC enforced, no key leak.\nTelerik/Kendo/DevExpress | absent | CVE-2019-18935 etc | 9.8 | confirmed | pre-auth | .NET deserialization | — | N/A | — | NOT PRESENT on .NET hosts.\nASP.NET Boilerplate (ABP) | — | none in vulnx | — | — | — | framework; no CVE record | — | N/A | — | app-code dynamic-LINQ (vuln-0027) is not a component CVE.\nEF Core | — | none notable | — | — | — | — | — | N/A | — | 3 records, no RCE.\nAuth.js / NextAuth | — | none | — | — | — | no RCE CVE | — | N/A | — | acedbet.", "agent_name": "Component CVE-RCE Mapper", "agent_id": "b36d5cbb"}, {"note_id": "dc580d", "title": "Exposed MariaDB / Plesk 8443 on 77.68.12.66 (promotions.pandabingo.com) — independent validation result", "category": "findings", "tags": ["mariadb", "plesk", "exposed-db", "promotions.pandabingo.com", "77.68.12.66", "open-proof-gap", "negative-result", "545a4fe5"], "created_at": "2026-09-27T20:56:04.292737+00:00", "updated_at": "2026-09-27T20:56:04.292737+00:00", "content": "**Agent:** Exposed MariaDB/Plesk Validator (545a4fe5), child of Independent Red Team Lead 2 (15751ced).\n\n**Target:** 77.68.12.66 = A record of in-scope `promotions.pandabingo.com` (rDNS `linux.prod.activewin.co.uk`, a shared Plesk host). Egress 64.111.92.186.\n\n## Verdict: no reportable in-scope finding; DB-access question left as named open proof gap (coverage 73b264).\n\n### 1) MariaDB 10.5.29 on tcp/3306 — exposed, but NOT accessible\n- Handshake completes: `5.5.5-10.5.29-MariaDB` → **no host ACL** (`ERROR 1045 Access denied`, not `1130`). Password is the only barrier.\n- **18 curated credential pairs** (anonymous; `root/{'','root','password','toor','123456','root123'}`; `admin/{'','admin','password','admin123'}`; `db/db`; `mysql/mysql`; `pandabingo/pandabingo`; `promos/promos`; `promotions/promotions`; `plesk/{'plesk','Plesk123!'}`) → **all `1045`**.\n- Corroborates the earlier ~50,935-attempt sweep (entry 6e15f5) → 0 valid. No user-enumeration oracle (uniform 1045 + ~45 ms).\n- No unauthenticated MariaDB **server** CVE (vulnx: only client-connector issues).\n\n### 2) Scope/ownership — the decisive point (DB does NOT serve the in-scope property)\n- Resolved all 47 apexes × 15 prefixes = **705 names**; **only `promotions.pandabingo.com` → 77.68.12.66**.\n- Its HTTP + HTTPS vhost returns the **Plesk default page \"there is no Web site at this address\"** for any Host header → **no in-scope application or data is deployed here**. This is a shared Plesk hosting server.\n- Therefore: internet-exposed 3306 is a genuine *hardening* issue, but cannot be anchored as an in-scope **data-exposure** finding, and exposure alone yields no CVSS impact. **No report filed.**\n\n### 3) Plesk Obsidian 18.0.80 (build 18.0.80.8) on tcp/8443\n- REST + legacy XML API → `Access to API is disabled for 64.111.92.186`, enforced on the **socket IP** (XFF/X-Real-IP/Spoofed headers ineffective).\n- Unauthenticated CVEs: 2026-67397 & 2026-68492 **fixed at .8**; 2026-65646 / 2026-68487 **require auth** → none applicable.\n- **sw-cp-server static-file traversal independently re-tested** (144 encoded variants; targets `/etc/passwd`, `/etc/psa/.psa.shadow`, `/etc/psa/private/secret_key`) → **only Plesk 400/404 error pages, no file content** (corroborates entry 8434c8 → ruled out).\n- Default/weak panel creds rejected. After panel login attempts, **HTTPS/8443 dropped to \"connection refused\"** from our egress while 80/3306 stayed up → a throttle/block control (same drop the prior tester saw).\n\n### Residual open gap (not clean)\nDB password strength untested beyond the curated/common corpus; schema/data not enumerable without access. The named gap in coverage 73b264.", "agent_name": "Exposed MariaDB/Plesk Validator", "agent_id": "545a4fe5"}, {"note_id": "6a90f6", "title": "RCE-candidate inventory (independent) — components, CVE-RCE mapping, 0day candidates, blockers", "category": "findings", "tags": ["rce", "inventory", "cve-mapping", "exploitability", "independent", "3b5f3832", "0day-candidates"], "created_at": "2026-09-27T20:53:40.409540+00:00", "updated_at": "2026-09-27T20:53:40.409540+00:00", "content": "Author: Independent RCE-Candidate Inventory Agent (3b5f3832), parent Root (7e7a20bf). Inventory/mapping only — NO exploitation, no 0day. Full table: `/workspace/irt_rce_inventory/RCE_INVENTORY.md`; CVE metadata captured in `/workspace/irt_rce_inventory/cve_meta.jsonl`.\n\n## Bucket A — known RCE-capable CVEs vs fingerprinted components (actionable within RoE)\n- **OpenSSH 9.6p1 Ubuntu 3ubuntu13.19 @ 45.132.74.81:22** — CVE-2024-6387 regreSSHion (pre-auth race RCE, CVSS 8.1 AC:H, public PoC). Affected 8.5p1–9.7p1 → in range by upstream version, but Ubuntu pkg rev `3ubuntu13.19` ≫ patched `3ubuntu13.4` ⇒ **very likely distro-backported / not exploitable**. HIGH value to confirm.\n- **NoMachine NX 10.0.59 @ 45.132.74.81:4000** — CVE-2026-18264 cmd injection, CVSS 8.8 but **PR:L (authenticated)**, vulnx status **rejected** (ZDI-26-483). Needs NX creds. CVE-2026-53694 is <9.5.7 ⇒ N/A. Local-privesc CVEs (2026-5055/5054/5053, 2025-8614) need existing local code exec.\n- **ProFTPD @ 77.68.12.66:21** (version unfingerprinted) — confirmed RCE CVEs CVE-2026-63090 (8.8), CVE-2026-42167 (8.1), CVE-2010-20103 (9.8 cmd inj); mostly authenticated.\n- **Plesk Obsidian 18.0.80.8 @ 77.68.12.66:8443** — version-matched & **authenticated**: CVE-2026-58046 (9.9 XML-RPC blind SQLi), CVE-2026-65646 (9.9 BAC file-read+priv-esc), CVE-2026-64636 (7.7 SQLi ≤18.0.80) ⇒ any low-priv panel cred → root/RCE. Unauthenticated RCE/traversal CVEs (67397/68492/67394) are **fixed at 18.0.80.8**; CVE-2025-54336 rejected.\n- **React RSC / Next.js App Router** — CVE-2025-55182 unauth RCE: **patched on tested UAT EKS hosts**; **unverified on all Imperva-blocked Next.js hosts** (ProgressPlay marketing fleet buildId WpePWuKOnX3rgMNqj5LeW, acedbet, play.*). CVE-2026-75604 is Windows-only ⇒ N/A.\n- **Apache Guacamole 1.6.0** — CVE-2024-35164 (≤1.5.5) ⇒ not in range. **LiteSpeed Cache 7.8.1** — CVE-2024-28000/50550 (<6.5.1) ⇒ not in range.\n\n## Bucket B — 0day-dependent RCE candidates (no as-is public RCE CVE)\n- **WordPress core 7.1/7.1.2 (7 hosts)** — authenticated theme/plugin-editor → PHP write; no unauth path found. Admin creds reachable in principle: user-enum + unthrottled XML-RPC/wp-login (vuln-0013/0014). Highest-probability RCE in scope *if* creds obtained. Note WP Engine hosts may set DISALLOW_FILE_EDIT.\n- **PHP 7.4.33 EOL @ playuk.com** — no future patches; but `disable_functions` blocks exec/system/passthru/popen/proc_open/pcntl_exec (webshell command-exec blocked).\n- **Nuxt.js/Nitro marketing fleet (13 hosts)** — CVE-2026-71318 `/__nuxt_island/` template-injection → Nitro RCE (vulnx status rejected); island endpoint absent on all 9 tested hosts ⇒ 0day-dependent.\n- **Strapi behind `/api/cms` (UAT EKS)** — CVE-2026-27886 BAC (confirmed); proxy GET-only + parameterized filters ruled out ⇒ sanitizer-bypass 0day needed for admin ATO→RCE.\n- **IIS/.NET ViewState (jackpot.com, games.betsuna.com)** — ViewState deserialization RCE held shut **only** by machineKey MAC+encryption (auto key); reopens on any machineKey/web.config leak. No vendor RCE components present.\n- **ABP + EF Core @ neonrush.com** — `sorting` Dynamic-LINQ injection CONFIRMED (vuln-0027) but the restricted type provider blocks Process/Reflection/IO ⇒ read-only SQL. A type-provider bypass = RCE; currently single-control.\n- **Node/NestJS “Betty Admin” @ appmanager.tangobet.co.uk** — **admin/admin123 confirmed (vuln-0001)**, but no merge/eval/SSRF/upload sink found ⇒ prototype-pollution→RCE needs a 0day sink.\n- **MySQL 8.0.42 + confirmed SQLi @ api-qa.playuk.com (vuln-0028)** — SQLi→`INTO OUTFILE`→webshell→RCE if FILE privilege + stacked queries + writable webroot (write not proven).\n- **Apache Tomcat 9.0.121 / Guacamole 1.6.0 @ 45.132.74.81** — Tomcat auth-bypass/smuggling CVEs (unconfirmed, recent build); post-auth Guacamole→RDP pivot.\n\n## Blockers\n1. Imperva \"Error 15\" blocks egress IP for ~12 hosts ⇒ app-tier RCE surface unmapped (mrrex, mamzinobet, moneyplay, ne-bet, supabet, betblink, 21luckybet, highstakes, lekkerbets, hotwins, luckcity, play.betzi.co, tangobet apex).\n2. No credentials for the two exposed origins ⇒ highest-value post-auth RCE (NoMachine, Plesk) gated.\n3. Ownership ambiguity 45.132.74.81 (rDNS starosamuchan.com / CN cl.exalt-digital.ru) & 77.68.12.66 (rDNS activewin.co.uk).\n4. Version gaps: ProFTPD, LiteSpeed WS, Nuxt, Strapi, Next.js patch level, headless WP, EB apps.\n5. Plesk sw-cp-server path-traversal untested (8443 refused mid-test) → would yield /etc/psa/.psa.shadow → MariaDB admin cred.\n\nMethod note: CVE facts taken from the shared pack’s `vulnx` results and independently re-checked with the local `vulnx` CLI (rate-limited, no API key). Cross-checked against nmap artifacts (`nmap_potsofluck_scan1/2.txt`, `mariadb_validate/nmap_77.68.12.66.txt`).", "agent_name": "Independent RCE-Candidate Inventory Agent", "agent_id": "3b5f3832"}, {"note_id": "1deb41", "title": "Independent Red Team Lead 2 — recon findings + chosen threads + infra leads", "category": "plan", "tags": ["independent-lead-2", "infra", "nomachine", "mariadb", "neonrush", "edge", "leads"], "created_at": "2026-09-27T20:47:31.687584+00:00", "updated_at": "2026-09-27T20:47:31.687584+00:00", "content": "Agent: Independent Red Team Lead 2 (15751ced). Parent: Root (7e7a20bf). Independent adversarial review of the mature 47-host black-box pack (29 findings, 71 open follow-ups).\n\n## Independently VERIFIED infrastructure leads (highest-value, previously unresolved)\n1. **45.132.74.81:4000/tcp — NoMachine NX Server 10.0.59 (OPEN)**. This IP is the origin for dev/qa/lp/promo/promotions/games.potsofluck.com (in-scope property; potsofluck.com apex is Imperva). Same host: 22 OpenSSH 9.6p1, 80/443 nginx 1.24.0. Local `vulnx` confirms **CVE-2026-18264 NoMachine Command Injection (CVSS 8.8 High)** and CVE-2026-53694 (cmd injection, 1 exploit) — no public PoC/KEV. Potential pre-auth RCE on a target-origin host. Non-destructive OAST validation is the right PoC. Scope nuance: host rDNS = starosamuchan.com (possible shared host) — confirm ownership before aggressive action.\n2. **77.68.12.66:3306/tcp — MariaDB 5.5.5-10.5.29 (OPEN)**, host = promotions.pandabingo.com (in-scope subdomain of pandabingo.com). Same host runs **Plesk (sw-cp-server) on 8443** (WebPros UI login). Internet-exposed DB port for an in-scope property's promotions host. Scope nuance: rDNS = linux.prod.activewin.co.uk (marketing vendor) — verify the DB serves the in-scope property before aggressive testing; low-noise auth only.\n\n## Other unresolved clusters noted (not personally re-tested)\n- Subdomain-takeover claimability unverified: support.uk-bingo.net (Zendesk closed HC), api.pandabingo.com / api.playuk.com / api.uk-bingo.net (deleted CloudFront dist), games/promo.luckcity.com (Cloudways), ftp/mail/smtp.betmorph.com (522).\n- Imperva IP-blocked app tier (mrrex, mamzinobet, moneyplay, ne-bet, supabet, betblink, 21luckybet, highstakes, lekkerbets, hotwinscasino, luckcity, play.betzi.co) — edge block invariant to ~150 bypass variants; needs a non-blocked egress. Blocked-by-resource gap.\n- NeonRush: /api/authentication/* gated by static X-Server-Authorization key (not in client assets); minted SSO token (vuln-0022) has no confirmed in-scope consumer; registerExternalFromApi role mass-assignment effect unverified (session unavailable).\n- jackpot.com widget endpoints return full ASP.NET stack traces (customErrors Off) — noted as recon-only.\n\n## Chosen independent threads\n- NoMachine NX RCE validator (non-destructive).\n- Exposed MariaDB/Plesk validator (low-noise, read-only).\n- Edge cross-cutting sweep (request smuggling / cache poisoning / host-header / CORS) — underexplored.\n- NeonRush auth-gap closure (API key hunt + SSO consumer + role escalation).", "agent_name": "Independent Red Team Lead 2", "agent_id": "15751ced"}, {"note_id": "f6a104", "title": "DB access path analysis — Red Team B (service & credential sweep)", "category": "findings", "tags": ["red-team-b", "db-access", "credential-sweep", "exposed-db", "mysql", "postgresql", "mariadb", "negative-result", "mariadb-brute", "open-proof-gap"], "created_at": "2026-09-27T17:51:50.612050+00:00", "updated_at": "2026-09-27T18:12:21.518028+00:00", "content": "Agent: DB Service & Cred Leak Sweeper (c1662cb9, child of Red Team B — DB Access Paths 872744d4).\n\n# Method\n1. Resolved all 47 in-scope apexes + ~200 subdomain prefixes (crt/per-prefix) → 209 resolving names, 128 unique IPs.\n2. `naabu` + `nmap -sV` over DB/exposure ports (3306,5432,5433,1433/1434,1521,27017-19,6379,11211,9200/9300,5984,7474/7687,9042,8086,2181,5672/15672,2375/2379,5985/5986,21,22,25) on every resolved IP.\n3. Default/blank credential attempts against every open DB service (pymysql / psycopg2).\n4. Artifact sweep: 6061 config/backup path probes (.env, wp-config.php.*, .git, .svn, *.sql, backups, actuator, phpinfo, server-status…) over 209 hosts.\n5. JS-bundle secret scan (gitleaks + DB-URI regex) of ~50 bundles from 15 reachable hosts.\n\n# Results table\n| Target | Vector | Status | Evidence / control |\n|---|---|---|---|\n| 35.214.94.72 (headless.mrslot/mrmobi/mrsuperplay, staging3.mrjackvegas, ftp.*) | MySQL 3306 | RULED OUT (host ACL) | ERROR 1130 \"Host '64.111.92.186' is not allowed to connect\"; PG FATAL \"no pg_hba.conf entry\" |\n| 35.214.94.72 | PostgreSQL 5432 | RULED OUT (pg_hba) | FATAL no pg_hba.conf entry for postgres/root |\n| 35.214.89.161 (headless.jazzyspins, ftp.jazzyspins) | MySQL/PG | RULED OUT | Same host-ACL + pg_hba controls |\n| 77.68.12.66 (promotions.pandabingo.com) | MariaDB 10.5.29 :3306 | NEEDS FOLLOW-UP | Reachable (no host ACL); ~100 default/weak creds all 1045 Access denied; no lockout observed. Access not obtained. |\n| 35.214.94.72 / .89.161 / 77.68.12.66 | FTP :21 (Pure-FTPd/ProFTPD) | RULED OUT | Anonymous login 530 rejected |\n| 35.214.x, 77.68.12.66 | Dovecot IMAP 143/993 | observation | Mail service exposed; no DB relevance, not pursued |\n| Fleet (209 hosts) | .env / wp-config backups / .git / *.sql | NO ISSUE | All 200s are SPA catch-all fallbacks (uniform size); only real files: mogobet debug.log + affiliates.dynobet .DS_Store (locale dirs only) |\n| mogobet.com /wp-content/debug.log | DB creds in log | RULED OUT | 2660B log = only PHP array_filter TypeErrors; no creds/queries |\n| Fleet JS bundles | DB connection strings | NO ISSUE | gitleaks: only vuln-0008 game-provider keys; no DB URIs |\n| 35.214.x origins | Direct-origin SiteGround bypass | RULED OUT | Origin still returns sgcaptcha 202 for every path |\n| 77.68.12.66:8443 | Plesk panel / default vhost | see EXTENSION below | Plesk login + \"no Web site at this address\"; no anonymous access |\n| api.jackpot.com (185.64.56.78), git.jackpot.com (91.150.80.242) | DNS-resolved, non-CDN | dead | No open ports (22/80/443/3306 all closed) |\n\n# Heads-up / corrections for downstream agents\n- **53 apexes/subdomains resolve behind CDN edges (Cloudflare 104.x/172.67.x/188.114.x, Imperva 45.60.x/45.223.x) that accept a TCP connection on EVERY scanned port.** Port-scanner hits on those IPs are edge artefacts, not services — always service-verify (nmap -sV / protocol handshake) before treating a port as open.\n- The real in-scope origins with exposed infrastructure are the two GCP hosts (`35.214.94.72`, `35.214.89.161`) and `77.68.12.66`.\n- **No direct DB access achieved** and **no leaked DB credential found** across the fleet.\n\n# Closure\nNo `create_vulnerability_report` filed: no DB-access PoC (access was not obtained) and no leaked credential yielding a connection. The one open item is the internet-exposed MariaDB on 77.68.12.66.\n\n---\n\n# EXTENSION — MariaDB credential test on 77.68.12.66:3306\n\nAgent: **MariaDB Credential Tester (56e41677)**, child of Red Team B (872744d4). This is the dedicated follow-up on the one open item above.\n\n## Target confirmed\n`MariaDB 10.5.29` (raw handshake banner `5.5.5-10.5.29-MariaDB`), TCP/3306 reachable from egress `64.111.92.186`. **No host allowlist** — the server completes the handshake and returns `ERROR 1045 Access denied for user '<user>'@'64.111.92.186'` (not `1130`/host-denied), so the password is the only barrier.\n\n## No user-enumeration oracle\n- Error code is `1045` for **both** existing and non-existent usernames.\n- Auth latency is indistinguishable across 30 samples/user: `root` 45.56 ms mean, `admin` 45.54 ms, `pandabingo` 45.30 ms, `plesk` 45.89 ms, random non-existent usernames 45.12–45.45 ms. Valid accounts cannot be enumerated.\n\n## Bounded online credential test (authorised; no throttling/lockout observed)\n8 workers, ~166 attempts/s, failed-auth attempts only; non-destructive; no `1129` host-block, `max_connect_errors` never tripped.\n\n| Pass | Usernames | Passwords | Attempts | Result |\n|---|---|---|---|---|\n| 1 | 33 (root, admin, pandabingo, panda, plesk, mysql, db, wordpress, wp, www-data, web, bingo, promotions, promos, staging, test, dev, operator, app, game, casino, mariadb, user, guest, administrator, betting, sports, hosting, pleskadmin, admin1, manager, backup, www) | brand/domain-derived (pandabingo/panda/bingo/promotions + 26 suffixes + case variants) + NCSC top-1200 | 22,669 | all `1045` |\n| 2 | 40 Plesk/hosting-style (pma, phpmyadmin, psa, psaadmin, debian-sys-maint, mysqladmin, webadmin, dba, sql, data, pandabingo_wp, wp_pandabingo, pandabingo_admin, bingo_admin, panda_admin, promotions_admin, promos_admin, hosting, webmaster, ftpuser, backup, siteuser, cms, payments, support, service, monitor, reporting, brand words…) + empty username | brand core variants + hosting/DB-specific extras + NCSC top-60 | 7,960 | all `1045` |\n| 3 | 52 usernames incl. `''` | blank, username-as-password, username+`1`, `\" \"`, `null` (blank/reflexive sweep) | 312 | all `1045` |\n| 4 | root, admin | NCSC top-10,000 most-common passwords | 19,994 | all `1045` (6 transient connection errors) |\n\n**Total: 50,935 credential attempts → 0 valid credentials.**\n\nWordlist used: `/home/pentester/tools/wordlists/100k-most-used-passwords-NCSC.txt`.\n\n## Outcome / closure\n- **No credential obtained.** The MariaDB root/app password is not blank, not the username, not a brand/domain-derived variant, and not in the top-10,000 most-common passwords — consistent with a high-entropy (Plesk-generated) password.\n- **Closure state: `open_proof_gap`** (coverage entry `6e15f5` updated). Password strength is untested beyond the curated/common corpus (~51k); a larger/targeted wordlist or the real credential from another source could still succeed. **Not clean.**\n- **The exposure itself is a genuine risk** (internet-facing MariaDB, no IP allowlist, password-only auth), but no unauthorised access was demonstrated, so no `create_vulnerability_report` was filed (no CVSS impact can be evidenced).\n\n## Recommended continuation (same in-scope host; outside this task's 3306-only scope)\n- **`77.68.12.66:8443` Plesk panel** — the most plausible remaining route to this DB: a panel compromise discloses/rotates the DB credentials. The sweeper found only normal auth + a default vhost, so this needs a dedicated Plesk credential/CVE review.\n- **GCP origins `35.214.94.72` / `35.214.89.161`** — MySQL 3306 / PostgreSQL 5432 are internet-listening but enforce host-ACL / `pg_hba.conf` against our egress; reachable only from an allowed network or via SSRF originating on those hosts.\n\n---\n\n# EXTENSION 2 — Plesk panel route to the DB (77.68.12.66:8443)\n\nAgent: **Plesk Panel DB Cred Hunter (339c583b)**, child of Red Team B (872744d4). Goal: reach the MariaDB through the Plesk panel (a panel compromise discloses/rotates the DB credentials) or via a Plesk CVE.\n\n## Target fingerprint\n- **Plesk Obsidian 18.0.80**, build `1800260918.14` (panel asset args `urlArgs=18.0.80-8` → 18.0.80 build 8), server `sw-cp-server`; Plesk hostname `linux.prod.activewin.co.uk`.\n- Same IP runs: FTP 21 (ProFTPD), SSH 22 (OpenSSH 8.0), IMAP 143/993 (Dovecot), MariaDB 3306, HTTP 80 / HTTPS 443 (Plesk default vhost only), panel 8443.\n- `promotions.pandabingo.com` = unconfigured Plesk default vhost (\"Web Server's Default Page\") — no application.\n\n## What was tested, and the controls that hold\n1. **API access is IP-restricted (holds).** Both APIs answer but refuse this egress:\n   - REST: `GET /api/v2/server` → `{\"code\":0,\"message\":\"Access to API is disabled for 64.111.92.186\"}`.\n   - Legacy XML: `POST /enterprise/control/agent.php` (well-formed packet) → `<errcode>1006</errcode><errtext>Access to API is disabled for 64.111.92.186</errtext>`.\n   - Enforced on the **socket IP**: spoofing `X-Forwarded-For`, `X-Real-IP`, `X-Client-IP`, `Forwarded`, `X-Originating-IP`, `Client-IP` (and via the hostname) does not change the 1006 response.\n2. **phpMyAdmin is gated (holds).** `/phpmyadmin/`, `/phpMyAdmin/`, `/domains/databases/phpMyAdmin/` → 303 to `/login.php?success_redirect_url=…`; the default vhost exposes no DB console; no Adminer / Plesk DB manager exposed.\n3. **Panel login enforces credentials (holds).** `/login_up.php` is a React app (`Plesk.run({…})`) posting to `/login_up.php3` with `login_name`/`passwd`/`forgery_protection_token`. Bounded default/weak test — `admin` / {`admin`,`password`,`Plesk123!`,`ActiveWin1`} + 1 control attempt — all rejected (\"Incorrect username or password. Try again.\"). No weak/default credential found. Restore-password (`/get_password.php`) and `/ch_pass_by_secret.php?secret=` return generic \"Invalid secret code\" / \"Please request a new secret code\" — no oracle obtained.\n4. **Other probes:** `/login_up.php3`, `/get_password.php`, `/ch_pass_by_secret.php`, `/admin/force-reset-password` reachable unauth (Plesk core/error pages); `/modules/`, `/domains/`, `/clients/`, `/log/`, `/error_docs/` → 403/404; extension public endpoints (`/modules/social-login/public/index.php`, `/modules/wp-toolkit/public/index.php`) return a generic Plesk \"Server Error\" (500), not a stack trace. The social-login state cookie is an HS256 JWT; its secret is not a common/default value (16-candidate test) and it only holds OAuth `state` (no impact even if forged).\n\n## CVE review (vulnx + advisory status)\n| CVE | Product / type | Affected | Applicable here? |\n|---|---|---|---|\n| CVE-2025-54336 | Plesk Obsidian — Authentication Bypass (9.8) | 18.0.70, **vuln_status: rejected** | No (rejected; also >18.0.70) |\n| CVE-2026-64636 | Plesk Obsidian — SQLi (panel DB read, 7.7) | `<= 18.0.80`, **authenticated** | Version-matched, but needs auth |\n| CVE-2026-58046 | Plesk — XML-RPC API blind SQLi (9.9) | **authenticated** low-priv | Needs auth |\n| CVE-2026-65646 | Plesk — BAC: local file disclosure + priv-esc | **authenticated** | Needs auth |\n| CVE-2026-68492 | Plesk REST API ext — RCE/priv-esc | `18.0.34 < 18.0.80.8` | **Fixed** (we are 18.0.80.8) |\n| CVE-2026-67397 | Plesk — path traversal → root | `<=18.0.79.9`, `18.0.80–18.0.80.5` | **Fixed** (we are 18.0.80.8) |\n| CVE-2026-67394 | Plesk Linux — LPE (cmd inj) | up to `18.0.80.5` | **Fixed** (we are 18.0.80.8) |\n| CVE-2025-66431 / -66428 | Plesk RCE / WP Toolkit priv-esc | older builds, **rejected** | No |\n\n**Net:** every DB-relevant Plesk CVE requires an authenticated session; the only unauthenticated bypass CVE is rejected. No applicable unauthenticated Plesk CVE was confirmed.\n\n## Unresolved gap (not clean)\nThe highest-value unauthenticated avenue — **arbitrary file read via `sw-cp-server` path traversal** (which would yield `/etc/psa/.psa.shadow` and `/etc/psa/private/secret_key` → decrypt the MySQL admin credential) — **could not be conclusively tested**. A first traversal batch (9 prefixes × 10 payloads) produced no hit, and partway through testing **TCP 443 and 8443 began refusing connections from this egress** (21/22/80/143/993/3306 remained open) — consistent with a port/service-level block or the panel/HTTPS services being stopped. The panel never recovered during the test window, so follow-up probes returned only proxy-level \"Failed to connect\". Traversal therefore remains an **open proof gap**, not a clean result.\n\n## Outcome\n- **No DB access obtained** via Plesk: no credential, no CVE exploit, no file read.\n- Coverage entry `8434c8` moved `no_issue_found` → **`needs_follow_up`** with the controls + gap above.\n- No `create_vulnerability_report` filed (no demonstrated unauthorised consequence; the version-matched CVE-2026-64636 requires authentication).", "agent_name": "DB Service & Cred Leak Sweeper", "agent_id": "c1662cb9"}, {"note_id": "7b54d6", "title": "DB access path analysis — Red Team B (CONSOLIDATED)", "category": "plan", "tags": ["red-team-b", "db-access", "sql_injection", "consolidated", "vuln-0027", "vuln-0028"], "created_at": "2026-09-27T17:34:54.497292+00:00", "updated_at": "2026-09-27T20:15:14.573065+00:00", "content": "# DB access path analysis — Red Team B (CONSOLIDATED)\n\nAgent: Red Team B — DB Access Paths (872744d4). Goal: reach DATABASE access (read) on the 47 in-scope hosts, via (a) SQL/NoSQL injection or (b) exposed DB service / leaked DB credentials. Scope: the 47 listed hosts + their own subdomains only; vendor backends (progressplay.net, casino-pp.net, betable.com, hercules.app, convex.cloud, tech1960.workers.dev) excluded.\n\n## Headline — 2 DATABASE ACCESSES CONFIRMED\n1. **www.neonrush.com** (Cogni / ASP.NET Boilerplate + EF Core) — `sorting` parameter → Dynamic LINQ expression injection → SQL. **vuln-0027 (High 7.1, CWE-89)**.\n2. **api-qa.playuk.com** (Markor \"revolve\" player API, MySQL) — `bonusCode` parameter → time-based blind SQLi. **vuln-0028 (Medium 6.5, CWE-89)**.\n\nAll other app-layer SQLi surfaces ruled out with named controls; exposed DB services found but none yielded access.\n\n## Per-target matrix\n\n| Target | Vector | Status | Blocking control / Evidence |\n|---|---|---|---|\n| **www.neonrush.com** (Cogni / ABP, EF Core) | ABP `sorting` param → `IQueryable.OrderBy(dynamic LINQ)` → SQL | **CONFIRMED — DB access** (vuln-0027, High 7.1, CWE-89) | Blind oracle `sorting=IIF(<pred>, it.Id, it.Id/(it.Id-it.Id))` → HTTP 200 true / HTTP 500 (SQL divide-by-zero) false. Extracted `ClientIpAddress=8.8.8.8`, `UserId=1853837`, `TenantId=1`, PK `Id=22522637` (never returned by the API). `it.CreationTime.ToString(\"yyyy\")`→500 proves SQL translation. Systemic on userlogin/referafrienduser/freeentrycodeuser/transactionsuser. Session via `Abp.TenantId: 1` (captcha skip) + `X-Forwarded-For: 8.8.8.8`. |\n| www.neonrush.com | injection REACH extended to a related table | reach proven, extraction open | `it.Player.EmailAddress/UserName/PhoneNumber/DateOfBirth/Gender` → 200 (EF emits a JOIN to the players table) vs 500 for root-only/unknown members; extraction blocked by data availability (FreeEntryCode queryset empty; row creation gated by identity verification, getNewCode state 998). |\n| www.neonrush.com | classic value injection (`userId`, `filter`, OData) | ruled_out | `userId` strongly typed (400 on `1'`); `filter` literal LIKE; OData options ignored; EF.Property unresolved. |\n| **api-qa.playuk.com** (Markor \"revolve\", MySQL 8.0.42) | POST `/revolve/api/account/isBonusCodeValid` JSON `bonusCode` | **CONFIRMED — DB access** (vuln-0028, Medium 6.5, CWE-89) | Time-based blind SQLi: `bonusCode=TESTCODE' AND (SELECT 8983 FROM (SELECT(SLEEP(5)))Dynt) AND 'koru'='koru` → deterministic +5 s (5.2–5.6 s vs 0.2–0.5 s baseline); SLEEP(0) + `-- -` control inert; sqlmap flagged `MySQL >= 5.0.12 time-based blind`. **Read proven:** `version()=8.0.42-33`, `database()=revolve`. Auth required (401 code 2) but the player account is freely self-registerable → PR:L. Session re-acquired after the earlier failure by fixing register/lite (`countryCallingCode:\"44\"`, `lang:\"en\"`, `contactable*`, versions 11/33, realistic email domain). |\n| api-uat.playuk.com | same bonusCode injection | needs_follow_up | Presumed to reproduce on the shared build, but session acquisition on UAT is blocked by anti-fraud `code 3`; not exercised. |\n| api-qa/uat.playuk.com | all other reachable Revolve params (paging, dates, ids, enums, other strings) | ruled_out | Named controls: 3-month date-range validation (code 119/217); integer typing (223/124); date-format validation (153); alphabetic allowlists (219/220); enum validation (242/63); redemption-limit pre-check (241); generic 500. |\n| **jackpot.com** (IIS 10 / ASP.NET MVC 5.2) | SQLi in widget/checkout params; verbose-error connection-string leakage; `/trace.axd`, `/elmah.axd` | ruled_out | Identifier params Int32 model-bound (quote → MVC binding ArgumentException, not SQL). String params inert (ComplianceCheck → constant `NonCompliant`; CheckUser → empty 200; UsGame_PopUpText identical). Verbose errors expose only MVC binding/view exceptions — never `SqlException`/`System.Data.SqlClient`/connection string. `/%2ftrace.axd` → \"Trace Error\" (remote tracing disabled, localOnly); `/elmah.axd` 404. sqlmap BEUT \"not injectable\"; AWS WAF 403s injection tokens. |\n| **appmanager.tangobet.co.uk** (Betty Admin, Node/Express + Postgres) | `players/search` `search`/`sortField`/`advancedFilter` SQLi; DB reach | ruled_out | `search` = parameterized LIKE; `sortField` = allowlist (fail-safe default columns); `advancedFilter` = column allowlist (unknown fields ignored → returns ALL rows, so NOT a blind-extraction oracle); `page`/`limit` int-parsed; errors generic. DB is a Postgres addon on Railway's private network — all DB ports FILTERED from the edge (only 80/443). |\n| **WordPress fleet** (betmaze.co.uk, betsuna.com, jeffbet.net, mogobet.com, playuk.com, theonlinecasino.co.uk, promo.hotwinscasino.com) | SQLi (core `?s=`, REST, admin-ajax, plugin CVEs, custom-theme `fetch-*.php`); leaked DB creds | ruled_out | Core/REST use WP_Query + `$wpdb->prepare` (sqlmap \"not injectable\"); jeffbet admin-ajax sanitized; all plugins current stable (no applicable SQLi CVE); `fetch-*.php` proxy an external catalogue and ignore every parameter; `wp-abilities/v1/…/run` → 401. No DB creds exposed. |\n| **mogobet.com `wp-content/debug.log`** (vuln-0006) | DB creds / SQL errors in a public log | no_issue_found | 2,660-byte log = only PHP `array_filter()` theme fatals + path `/home/mogobet.com/public_html/`. No SQL text, table prefix, or DB host/user/password. |\n| **uat.uk-bingo.net / uat.pandabingo.com (`/api/cms` → Strapi)** | Strapi content-API filter injection | ruled_out | Strapi filters parameterized (Knex): `$eq`/`$startsWith`/`$ne` → filtered results with no error/boolean/timing SQLi; proxy GET/HEAD/OPTIONS-only. (Exposure itself = vuln-0003.) |\n| **77.68.12.66:3306** (Plesk MariaDB 10.5.29 — origin of promotions.pandabingo.com) | Internet-exposed DB service; credential access | **needs_follow_up** (exposure, no access) | No IP allowlist: handshake completes, `1045 Access denied` (not `1130`). 50,935 bounded attempts (default/blank, username/brand-derived, Plesk-style, NCSC top-10k) → **0 credentials**; no lockout; no user-enumeration oracle (identical 1045 + ~45 ms). Exposure real, no unauthorized access → no CVSS impact to report. |\n| **77.68.12.66:8443** (Plesk Obsidian 18.0.80-8) | Panel → recover DB credentials / Plesk CVE | ruled_out (+1 open gap) | API disabled for our IP and enforced on socket IP (errcode 1006) — forwarding-header spoofs do not bypass. phpMyAdmin → 303 to `/login.php`. Default/weak panel creds rejected. No applicable unauthenticated CVE. Gap: **sw-cp-server static-file path traversal** untested (443/8443 began refusing from our egress mid-test). |\n| **35.214.94.72 / 35.214.89.161** (GCP origins behind headless/staging WP subdomains) | Exposed MySQL 3306 + PostgreSQL 5432 | ruled_out | Source control before credential check: MySQL `ERROR 1130 Host … is not allowed`; PostgreSQL `FATAL: no pg_hba.conf entry`. Needs an allowlisted source IP or an on-host SSRF. |\n| same hosts + 77.68.12.66 | Exposed FTP 21 / IMAP 143,993 | ruled_out | Anonymous FTP rejected; authenticated access required. |\n| 209 resolving in-scope names | Leaked DB creds: .env, wp-config backups, .git, SQL dumps, appsettings, JS bundles | no_issue_found | No DB connection strings/credentials; gitleaks only re-found the already-reported game-provider keys (vuln-0008). `wp-config.*`/`*.sql` WAF-blocked (403) / 404. |\n| 20 reachable hosts | DB management consoles (phpMyAdmin/Adminer/…) | no_issue_found | 25 DB-admin paths → no HTTP 200 (only apex→www 301/302). |\n| 47 apexes + subdomains (port sweep) | Any open DB service | no_issue_found | No MSSQL/Oracle/MongoDB/Redis/Elasticsearch/memcached/CouchDB/Neo4j/Cassandra/Docker/etcd anywhere. Caution: 53 names behind Cloudflare/Imperva edges accept TCP on EVERY port — port-scan noise. |\n\n## Related findings already on file (not re-filed)\n- vuln-0022 (unauthenticated SSO token minting), vuln-0023 (login-attempts IDOR), vuln-0024 (Turnstile secretKey leak), vuln-0025 (captcha bypass) — neonrush/Cogni (Red Team C2).\n- vuln-0019 (DELETE returns bcrypt hash) — appmanager.tangobet.co.uk.\n\n## Open items (for the parent)\n1. **api-uat.playuk.com** — same `bonusCode` SQLi presumed but unverified (anti-fraud `code 3` blocks session acquisition there).\n2. **PlayUK write primitive** — only read access was demonstrated; stacked-query/write impact untested.\n3. **Cogni cross-table extraction** — needs a non-empty FreeEntryCode queryset (identity-verified player or the populated tenant 17).\n4. **MariaDB credential** on 77.68.12.66 — route is the Plesk sw-cp-server path traversal (`/etc/psa/.psa.shadow` + `secret_key`) when 8443 is reachable.\n5. **GCP MySQL/PostgreSQL** (35.214.94.72 / 35.214.89.161) — allowlisted IP or on-host SSRF required.\n6. Access-limited: `promo.hotwinscasino.com` origin 403; `betsuna.com` front-end unstable; post-auth WordPress plugin code untested.", "agent_name": "Red Team B — DB Access Paths", "agent_id": "872744d4"}, {"note_id": "b8d18c", "title": "Subdomain-takeover / dangling-DNS sweep — results (47 apexes + ~265 subdomains)", "category": "findings", "tags": ["subdomain-takeover", "dangling-dns", "vercel", "wpengine", "duda", "zendesk", "cloudfront"], "created_at": "2026-09-27T16:58:13.613868+00:00", "updated_at": "2026-09-27T16:58:13.613868+00:00", "content": "# Subdomain takeover / dangling-DNS sweep\n\nMethod: resolved A/AAAA/CNAME/NS/MX/TXT for all 47 apexes and ~265 associated subdomains (recon inventory + CT via certspotter/crt.sh + a 105-name DNS brute force per apex, with wildcard detection). Every resolved host was then HTTP/HTTPS-probed and matched against known provider \"unclaimed\" signatures. Only in-scope hosts (47 apexes + their own subdomains) were tested; no resource was claimed.\n\n## CONFIRMED EXPOSURES (reports filed)\n| Asset | Provider edge | Signal | Report |\n|---|---|---|---|\n| wiki.jackpot.com | Vercel (cname.vercel-dns.com) | 404 `x-vercel-error: DEPLOYMENT_NOT_FOUND`; response identical to an arbitrary unconfigured host on the same edge; no `_vercel` TXT -> domain unassigned/claimable | vuln-0011 (medium) |\n| casino.playuk.com | WP Engine | \"Site Not Configured ... domain is successfully pointed at WP Engine, but is not configured for an account on our platform\" (HTTP 404, all paths) | vuln-0012 (medium) |\n| whm.betmorph.com, cpanel.betmorph.com | Duda (cdn-website.com) | `SITE NOT FOUND` page with Duda `dm404*` classes / irp.cdn-website.com assets | vuln-0015 (medium) |\n\nRelated, already filed by another agent: **777tigers.com** apex A record 100.24.208.97 -> Duda `SITE NOT FOUND` = vuln-0004.\n\n## DANGLING RECORDS FOUND BUT NOT CONFIRMED CLAIMABLE (needs follow-up)\n| Asset | Target | Why not confirmed |\n|---|---|---|\n| support.uk-bingo.net | CNAME -> **ukbingo.zendesk.com** which 301s to `/app/help-center-closed/` (closed/unclaimed help centre) | The record is Cloudflare-proxied to a Cloudflare-fronted host and the zone returns **Cloudflare error 1034 (Edge IP Restricted)** for every request, so nothing renders today; claimability at Zendesk unverified. (support.jackpot.com -> jackpot.zendesk.com is an *active* help centre, not dangling.) |\n| api.pandabingo.com, api.playuk.com, api.uk-bingo.net | CNAME -> `d31tqz5bd5ida4.cloudfront.net` which **does not resolve** (distribution deleted) | CloudFront alternate-domain claim requires a TLS cert covering the name, so not trivially claimable. Names currently NXDOMAIN. |\n| qa.uk-bingo.net / qa.pandabingo.com / qa.chitchatbingo.com / qa.playuk.com | CNAME -> `d1ama3lmihrvrd.cloudfront.net` (distribution **exists**) | qa.uk-bingo.net returns CloudFront 403 \"this request could not be satisfied\" (hostname not configured on the distribution); the others returned no signature. Same cert caveat. |\n| promotions.pandabingo.com | A -> 77.68.12.66 (Fasthosts; PTR linux.prod.activewin.co.uk) = Plesk \"Web Server's Default Page\" for any Host | Unconfigured shared-hosting default vhost; not claimable without provider account access. |\n| games.luckcity.com, games.savibet.com, promo.luckcity.com | A -> 45.63.98.231 (Vultr) = Cloudways \"maintenance-domain-mapping\" 403 | Server exists but no app mapped; not claimable by an outsider. |\n| lobby.mrslot.com / lobby.mrmobi.com / lobby.mrjackvegas.com / lobby.mrsuperplay.com | A -> 185.27.56.100 (Computer Solutions Ltd, MT) | No service on 80/443 (timeout); bare IP, nothing to claim. |\n| ftp / mail / smtp .betmorph.com | Cloudflare-proxied, origin unreachable (522) | Same zone as vuln-0015; dead origin rather than a claimable edge. |\n| test.jackpot.com | CNAME -> chlfv.x.incapdns.net (Imperva) | Imperva site names are not attacker-claimable. |\n\n## CLEAN\nAll other apexes and subdomains: legitimate Cloudflare / Imperva / AWS / WP Engine / Vercel / Railway / Firebase / Zendesk(active) / RavenTrack / AppsFlyer / Elastic Beanstalk targets that resolve to the organisation's live services. No dangling NS delegations and no suspicious MX/provider records were found. Known benign infra: casino.highstakes.co.uk -> 96.45.82.x is a *DNS Made Easy HTTP-redirection* service (301 to the apex), not a takeover.\n\n## Notable pattern\nThe Duda class appears on two assets (777tigers.com apex, betmorph.com subdomains) and the WP Engine/Vercel classes once each — i.e. dangling records to website builders/hosts are systemic across the fleet and should be swept at the zone level.", "agent_name": "Subdomain Takeover Sweeper", "agent_id": "540f7af2"}, {"note_id": "0e6a15", "title": "CMS-proxy blast radius — per-host results matrix (marketing fleet + play.*)", "category": "wiki", "tags": ["cms-proxy", "blast-radius", "betable", "nuxt", "progressplay", "negative-result", "vuln-0003"], "created_at": "2026-09-27T16:45:15.290551+00:00", "updated_at": "2026-09-27T16:45:15.290551+00:00", "content": "# CMS-proxy blast-radius sweep — agent CMS Proxy Fleet Hunter (33c84875)\n\n**Question:** does the unauthenticated `/api/cms/[...path]` proxy (filed as **vuln-0003** on the Betable UAT Next.js apps) also ship on the other in-scope marketing tenants?\n\n**Answer: NO.** The proxy is confined to the three Betable UAT Next.js apps already reported. It does **not** reach the Nuxt marketing fleet, the ProgressPlay hosts, or any `play.*` player app. No new in-scope host is affected → no new report filed (would be a duplicate of vuln-0003).\n\n## Why the handler is absent elsewhere\nThe marketing fleet is **Nuxt 3 / Nitro**, not Next.js. Their entire server route table is `/api/pp/games` and `/api/worker/games` (extracted from the shipped `_nuxt/*.js` bundles — the only `/api/*` literals present). Everything else falls through to the SPA index (200 `text/html`) or a Nuxt 404. `/api/cms/*`, `/api/health`, `/api/env/vars` are not implemented on these hosts, so there is nothing for the proxy to be reached through.\n\n## Per-host matrix\n\n| Host | Stack | `/api/cms/*` | `/api/pp/games` + `/api/worker/games` | Notes |\n|---|---|---|---|---|\n| www.chitchatbingo.com | Nuxt/CF | 200 SPA fallback (not the proxy) | 200 JSON (6.9 MB public catalogue) | no CMS route in bundle |\n| www.pandabingo.com | Nuxt/CF | 200 SPA fallback | 200 JSON | — |\n| www.queensbingo.com | Nuxt/CF | 200 SPA fallback | 200 JSON | — |\n| www.wombatbingo.com | Nuxt/CF | 200 SPA fallback | 200 JSON | — |\n| www.uk-bingo.net | Nuxt/CF | 200 SPA fallback | 200 JSON | — |\n| jazzyspins.com | Nuxt/CF | 404 (Nuxt error) | 200 JSON | — |\n| slotlux.com | Nuxt/CF | 200 SPA fallback | 200 JSON | bundle references out-of-scope content.progressplay.net + *.tech1960.workers.dev |\n| vampirebingo.com / www | Nuxt/CF | 200 SPA fallback | 200 JSON | — |\n| betarno.com | Nuxt/Heroku | 404 (Nitro default JSON) | 404 (no catalogue route) | no `/api/*` routes at all |\n| bingo.pandabingo.com | Nuxt/CF | 200 SPA fallback | HTML (SPA) | landing app |\n| promotions.pandabingo.com | nginx/Plesk | 404 | 404 | default Plesk vhost 77.68.12.66 |\n| play.chitchatbingo.com | Next.js (ProgressPlay player) | **404** | 404 | player app; see below |\n| play.uk-bingo.net / pandabingo / wombatbingo / queensbingo / jazzyspins | Next.js (Betable player) | **404** | 404 | Imperva-gated; bypassed with browser |\n| ProgressPlay hosts (mrjackvegas, mrmobi, mrslot, mrsuperplay, mogobet) | Nuxt/CF or WP | 200 SPA fallback / 404 | n/a | not the proxy |\n| uat.playuk.com | WordPress/CloudFront | 200 WP HTML | 200 WP HTML | WP catch-all, not Next.js |\n| uat.* for all other 44 apexes | — | — | — | NXDOMAIN (only 3 `uat.*` exist) |\n\n## Additional public APIs found (not vulnerabilities)\n- `/api/pp/games` + `/api/worker/games` — intended public game catalogue (5,518 records), `Access-Control-Allow-Origin: *`, cached 300s. Param fuzzing (`wl`, `whiteLabelId`, `tenant`, `siteId`, `gameId`, `id`, `callback`, `filter`, `pagination[...]`, `url=`, path-traversal) returns a **byte-identical** response — parameters are ignored, no reflection/JSONP/injection. Not a finding.\n- `play.*` ProgressPlay player app (Next.js) exposes unauth `/api/getWhiteLabelConfig`, `/api/player/getDefault`, `/api/player/getPlayer`, `/api/getTenantData`. `getPlayer` returns an empty anon object (`PlayerId:0`, empty Token/Email); `wl`/`PlayerId` query params are ignored (session-based) — no trivial unauth IDOR via params. Same surface the ProgressPlay IDOR Hunter owns.\n- `play.*` `__NEXT_DATA__` leaks `paypalSandboxKey` (sandbox) + internal topology (webapi.casino-pp.net, optimus.progressplay.net/manage-players/, static-data-api azure) — informational; matches recon notes.\n- `jazzyspins.com/wp-json/wp/v2/` is referenced in the Nuxt bundle but is **not** served on the apex (404/SPA); the headless WP sits on the SiteGround-captcha-gated backend.\n\n## Method\nDirect probes (follow + no-redirect) across ~30 hosts/paths; Nuxt bundle extraction (`_nuxt/*.js` grep for `/api/`); subfinder subdomain sweep; DNS resolution of `uat.*` across all 47 apexes; Imperva bypass via `agent-browser` (reload loop) + in-page `fetch` for the gated `play.*` tier.", "agent_name": "CMS Proxy Fleet Hunter", "agent_id": "33c84875"}, {"note_id": "470688", "title": "Recon Cluster B — surface inventory", "category": "wiki", "tags": ["recon", "cluster-b", "betable", "kraken", "white-label", "imperva", "wordpress", "nuxt", "nextjs"], "created_at": "2026-09-27T16:17:23.236204+00:00", "updated_at": "2026-09-27T16:17:23.236204+00:00", "content": "# Recon Cluster B — attack surface inventory (black-box, mapping only)\n\nScope: highstakes.co.uk, hotwinscasino.com, pandabingo.com, queensbingo.com, uk-bingo.net, wombatbingo.com, jackpot.com, jazzyspins.com, jeffbet.net, lekkerbets.co.za\n\n## Host-by-host table\n\n| Host | Live? | Tech / server | Notable endpoints & subdomains | Auth model / notes |\n|---|---|---|---|---|\n| highstakes.co.uk | LIVE, WAF-blocked | Imperva Incapsula (45.60.24x.194); apex→www→403 | casino.highstakes.co.uk (301→www→403) | White-label gambling tenant. Auth not observable through WAF. |\n| hotwinscasino.com | LIVE, WAF-blocked | Imperva (www 403). Sub-hosts vary | promo.hotwinscasino.com (WordPress, Cloudflare 200); admin/m/brand/partners.hotwinscasino.com (Microsoft-HTTPAPI/2.0, 404 @/, CNAME map180.mediacle.net); media.hotwinscasino.com (S3+CloudFront, 403) | WP login on promo; mediacle/Map180 = affiliate/API host. |\n| pandabingo.com | LIVE | Nuxt.js/Vue SPA on Cloudflare; nginx | play.pandabingo.com (Imperva 403); bingo.→www; **uat.pandabingo.com** (Next.js/React on AWS EKS); comingsoon. (Imperva 202 challenge) | Marketing SPA is static; real app on uat.* |\n| queensbingo.com | LIVE | Nuxt.js/Vue SPA on Cloudflare | play.queensbingo.com (Imperva 403); headless.queensbingo.com (Imperva 202); anna./staging3.queensbingo.com = **NXDOMAIN (unreachable)** | SPA fallback: unknown paths return index (200). |\n| uk-bingo.net | LIVE | Nuxt.js/Vue SPA on Cloudflare | play.uk-bingo.net (Imperva 403); **uat.uk-bingo.net** (Next.js/React on AWS EKS); support.uk-bingo.net → ukbingo.zendesk.com | Real UAT app on uat.* |\n| wombatbingo.com | LIVE | Nuxt.js/Vue SPA on Cloudflare | play.wombatbingo.com (Imperva 403) | SPA fallback returns index (200) for all paths. |\n| jackpot.com | LIVE | IIS 10.0 / ASP.NET MVC 5.2 on AWS ALB (Windows Server) | /admin → 403; /trace.axd → 403; /sitemap.xml (1336 game URLs); robots disallow /admin | ASP.NET_SessionId, AWSALB cookies; verbose X-AspNetMvc-Version header. |\n| jazzyspins.com | LIVE | Nuxt.js/Vue SPA on Cloudflare | play.jazzyspins.com (Imperva 403); headless.jazzyspins.com (Imperva 202); robots disallow /lp/ | 404s (no SPA fallback); /lp/test → 308 campaign landing. |\n| jeffbet.net | LIVE | WordPress 7.1.2 + Contact Form 7 6.1.7 + Yoast 28.3 on WP Engine/Cloudflare | **/wp-json/wp/v2/users → 200 (18KB, user enum)**; /wp-json/ (many namespaces incl. wpe/cache-plugin/v1, wpe_sign_on_plugin/v1); /wp-login.php 200; xmlrpc.php 403 | wp_users: id1 admin, id2 simon-young, id5 ross-young. |\n| lekkerbets.co.za | LIVE, WAF-blocked | Imperva (45.60.243.194); apex→www→403 | — | White-label gambling tenant, same Imperva front. |\n\nUnreachable: anna.queensbingo.com, staging3.queensbingo.com (DNS NXDOMAIN — stale CT/passive-DNS records; proxy 502 = unreachable, NOT a target response).\n\n## Shared-platform signals (strong)\n\n- **White-label gambling platform = Betable \"kraken\".** JS bundles reference API base `https://api.dev.kraken.ptops.net/api/v1/`, WS `ws.dev.kraken.ptops.net`, headless CMS `https://cms.uat.betable.com`, and sibling kraken tenants (`dev.kraken.hotstreakcasino.com`, `dev.kraken.royalvalleycasino.com`, `kraken.royalvalleycasino.com`). (Those sibling hosts are NOT in scope — intel only.)\n- **Marketing front-ends** are Nuxt.js/Vue static SPAs (Cloudflare) that pull game data from Cloudflare Workers `*.tech1960.workers.dev` (access-content-pp, access-ppgames, access-filterbyname, access-supportedcountries, access-translations, cf-geo-lookup, igp-supported-countries).\n- **Game catalogue API (public, no auth):** `/api/pp/games` and `/api/worker/games` on each Nuxt host return identical ~6.9 MB JSON arrays (Content-Type application/json, field set: gameName/provider/serverGameId/clientRealUrl/payout/wagerPercent/demoEnabled; images from data.progressplay.net). ProgressPlay + Games Global/Gamevy providers.\n- **UAT/UAT app cluster:** uat.uk-bingo.net and uat.pandabingo.com both resolve to the same AWS ELB `k8s-devkrake-sitesing-45b8dfc26e-1857226897.eu-west-2.elb.amazonaws.com` (Next.js/React/Webpack). Exposes `/api/health` (200) and `/api/v1` (403/404); app talks to kraken API.\n- **WAF:** Imperva Incapsula (visid_incap_/incap_ses_ cookies, _Incapsula_Resource) fronts play.*, highstakes, hotwins, lekkerbets, headless.*, comingsoon.*. Cloudflare fronts the Nuxt marketing sites and jeffbet/promo.\n- **Tenant IDs:** many `SiteId` GUIDs (and short base36 IDs) embedded in UAT bundles — multi-tenant platform.\n- **Affiliate/API:** hotwins admin/partners/m/brand.* behind Microsoft-HTTPAPI via CNAME map180.mediacle.net.\n- Security headers on Nuxt sites: only x-content-type-options + referrer-policy (no CSP/HSTS/XFO).\n\n## Top candidate vulnerability surfaces (for downstream agents)\n\n1. `www.jeffbet.net` WordPress — **confirmed unauth user enumeration** (`/wp-json/wp/v2/users`). Pivot: wp-login brute (CF7/WP Engine), plugin CVEs (Contact Form 7 6.1.7, Yoast 28.3, redirection, responsive-accordion-and-collapse).\n2. `promo.hotwinscasino.com` WordPress — wp-json exposed (litespeed/v1+v3, WPML, SEOPress, Limit-Login-Attempts-Reloaded, otgs/installer); wp/v2/users 403. Check plugin CVEs + login.\n3. `uat.uk-bingo.net` / `uat.pandabingo.com` — Next.js app on shared EKS UAT; `/api/health`; fronts kraken `/api/v1`. Candidate IDOR/BOLA on wallet/game/account routes (must be enumerated via JS chunk analysis, e.g. /api/cms calls).\n4. `www.jackpot.com` — ASP.NET MVC: `/admin` 403, `/trace.axd` 403 (exists but blocked), verbose X-AspNetMvc-Version; huge sitemap (1336 game routes) for param fuzzing.\n5. Public game-catalogue `/api/pp/games` — test query-param injection / mass-data handling.\n6. `promotions.pandabingo.com` — unconfigured Plesk default vhost (potential content/takeover signal).\n7. WAF note: Imperva blocks scripted access to play.*/highstakes/hotwins/lekkerbets → need browser (agent-browser) or evasion for dynamic testing.\n\n## Artifacts\n- /workspace/reconB/hosts.txt, urls.txt, subdomains_all.txt, httpx_clusterB.jsonl, subs_httpx.jsonl, final/inventory_summary.txt, jackpot_sitemap.xml", "agent_name": "Recon Bravo", "agent_id": "09b94d91"}], "filtered_count": 12, "total_count": 89}