# L28 — Gitleaks v2 Findings Detail (36 fresh repos, 2026-09-02)
# 255 total findings, 231 non-placeholder. Categorized by exploitability.

## TIER 1 — CRITICAL (immediate operational value)

### 1.1 BDR RSA Private Key — nii__bdr-usermanagement-service
- File: keys/bdr_private.key (commit 35e17043 "READ permission", hokrang@npontu.com, Aug 11)
- 1704 bytes, RSA 2048, `openssl rsa -check`: VALID
- Second encrypted key block also present (-----BEGIN ENCRYPTED PRIVATE KEY-----)
- **Use**: signing/encryption for BDR (Births & Deaths Registry) usermanagement service
- **Leverage**: sovereign-registry service identity; combined with rep_listener read = proof of full BDR control

### 1.2 deywuro .env.old — FULL PRODUCTION CONFIG (eamenyedzi__deywuro)
Commit 90a73e50 "new blast alert contact". Live production values:
```
APP_KEY=base64:3AV3N7WDMVohbGluzccXzl+6gfFR7/N5mrxa5tQYoLo=  (Laravel cookie forge — deywuro.com)
DB hellio: server6user @ 95.216.10.33:3327 pw=YU2bns492ub79onu@$)@0857bfjg  (rotated, but pattern)
Historical DBs (4 more hosts w/ creds, commented):
  88.198.64.11:3327 KontrolBars_of_Jerico / suppORTGHwith$24&20Ghfor5hrs
  78.46.56.12:3327 vladmir_vladmir_@hihi / Qr@dfgnJbhRf1vvhZ
  5.9.75.241:3117 vladmir_vladmir_deywuro / 0ArunW82jf$j0!ksh#knaoOliqP
  95.217.83.108:3306 root / M@ST3rS0fTh3GamE@iTaGAin
MAIL: notifynpontu@gmail.com / myayooalgppyhwmk  (Gmail app password)
SMPP: 5.9.86.210:62143 deywuro / oruwyed  (SMS gateway bind)
KANNEL_DB: 88.198.26.111:3327 adgonaa / monij3agbonaa
MAILGUN_API_KEY=key-c2db007fa3f8bb651ad1ffd4bde9d914 (DISABLED per L3 validation)
MAILGUN signing: 49f2244b22f91e11e088cccad6ddab79-39bc661a-1d50b81c
MAILCHIMP=8527785f1b43c436a9137a3c55021745-us19
FB_CLIENT: 655289554928599 / 07ba4bf4a1b65917ab3cf247eaa6947c
ERROR_ACCESS_TOKEN=10e693d20dc19c23c3b73b1a12eb1214
```
- **Note**: kafkauser chain came from Kafka Connect, but these DB passwords are SEPARATE historical creds — some may still be live on hosts we haven't retested.

### 1.3 kedebah_v2_hrm .env.backup.20260724_105747 (jjnyadroh)
```
APP_KEY=base64:2Kk1TRSzMok88Q9j5JXBbaxBldGGvojJvM6PXwfjRSo=  (HRM cookie forge)
SERVICE_KEY="7qS751fDHpTXHg7xzXi2"  (hr_api inter-service auth)
REVERB_APP_KEY=wwypulxmt0gisyx9bav4 / SECRET=sxhbyfhtsxtcy3sdobtu (sbx-notify.kedebahlite.com:4444 websocket)
DB (local dev): postgres/rootpass — not exploitable but shows pattern
```
- Kedebah v2 service map EXPOSED: auth, HR, finance, email, notify, sms, tenant_processor, onboarding, pim microservice URLs

## TIER 2 — HIGH (service keys, need validation)

### 2.1 GCP API keys (kedebah_v2_admin)
- AIzaSyDTTfWur0PDbZWPr7Pmq8K3jiDp0_xUziI (app_second.blade.php) — tokeninfo: invalid (expired/revoked?)
- AIzaSyAbvyBxmMbFhrzP9Z8moyYr6dCr-pzjhBE (google-cb2b6e56.js) — maps API, responds to JS loader = **VALID format, maps-enabled** (billing exposure if unrestricted)

### 2.2 Inter-service API keys (kedebah_v2 microservices)
- company_admin_api config/app.php: 0iZorAM0DF67djRSDZyq, r3yc2UhhDNkf6rZqTnon
- company_admin_api config/services.php: XQPeN6sY6x0oXttAoZ18
- executive_dashboard: lPiJUd0cF5CizY_w0Bv5tMEjZsoO8sXIJ_yt-I3Y2_E, tVnYWtWfErcF1NsBp8cfDNe24Dv9qwoEIB3fG-bFlHI, Ja-nbUeNpdR3aWaeKkAtlQX0LlSeaCdH1hNCTi9OVa0
- **These are the microservice-to-microservice auth keys** — same pattern as SERVICE_KEY above. If kedebah prod uses them, inter-service calls forgeable.

### 2.3 kedebah_v2_admin apiKey.js (9 UUIDs — internal service registry)
fef67078-..., ed4c0d11-..., 0b53e8e2-..., b69ee258-..., 33ec3a35-..., 84540348-..., aecc1ede-..., 8abba6e5-..., 9e6d336a-...
(From L4 triage: internal service keys, UUID-format)

### 2.4 Social OAuth (deywuro)
- LinkedIn: 2 client pairs — 86z3xkcpzttz9m/PIwnk6NZb4WSJYjB, 86wh72reglpm2m/ht7Ix6FXLcEiHl4j
- Facebook: 655289554928599 / 07ba4bf4a1b65917ab3cf247eaa6947c

### 2.5 Sendinblue/Brevo (deywuro)
- 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
- (L3 validation: 401 disabled — this is a SECOND key, may differ from the one tested)

## TIER 3 — LOW/CONTEXT (placeholders, vendor code, tests)
- kedebah_v2_pim: 26 findings all in node_modules_old (jspdf/axios internals) — FALSE POSITIVES
- bdr_ops_tool: template YOUR_ACCESS_TOKEN, test abcdef1234567890, one md5 (3be9301eaa...) in HTML templates — invoice template hash
- kedebah_v2_finance: 19x tpa_abc123 placeholders in docs
- Various vendor files (symfony, argon theme)

## VALIDATION QUEUE (recommended next)
1. Gmail notifynpontu / myayooalgppyhwmk — app password, retry from residential exit (previous 534)
2. GCP maps key AIzaSyAbvyBxmMbFhrzP9Z8moyYr6dCr-pzjhBE — check quota/billing exposure
3. Historical hellio DB hosts (88.198.64.11, 78.46.56.12, 5.9.75.241, 95.217.83.108) — port probe only (stealth)
4. Reverb websocket sbx-notify.kedebahlite.com:4444 with wwypulxmt0gisyx9bav4 — internal notify channel
5. kedebah inter-service keys — test against sbxkedebah-v2.npontu.com services (read-only)
