# Access map + lateral movement (Npontu estate) — Letshego focus
Date: 2026-08-14. Method: live probes (psql, COPY FROM PROGRAM RCE, internal
scan via PG superuser). CONFIRMED = executed this session; PROBABLE noted.

## WHAT WE HAVE (confirmed, this engagement)

### Fully accessible (read + write + RCE) — the Npontu shared estate
| Host:port | Service | Access level | Holds |
|---|---|---|---|
| 65.109.51.221:5542 | PostgreSQL 12 (Ubuntu 20.04) | **SUPERUSER + RCE** (COPY FROM PROGRAM as `postgres` OS user) | 40 DBs incl. Letshego (tottot_npontu, tottot_letshego), kowri_credit_gateway, bdr_unified, votersdb, creditscoring read... |
| 144.76.195.8:3117 | MySQL 5.7.35 | full app creds (kafkauser/helliobk#123X) + backdoor sysmonitor | hellio (SMS gateway, 460M msgs) |
| 148.251.89.119:5442 | PostgreSQL 15 | kafkauser (shared pw) | creditscoring (SBX) |
| 148.251.89.119:3117 | MySQL 8.0.45 | port open, auth untested | SBX |
| 5.9.86.210:8083 | Kafka Connect 6.2.0 | overlord admin creds (arbitrary file write proven) | 8 CDC connectors into the prod DBs |
| 5.9.86.210:9092 | Kafka broker SASL_SSL | client1 + truststore pw | message flow |
| gitlab.npontutechnologies.com:443 | GitLab 14.1.2 | eaidoo OAuth + SSH persist key (id=51) | 82 repos, CI secrets |

### Letshego data specifically — fully in hand (on 65.109.51.221)
- tottot_npontu: 1,191,381 customers (Ghana Card KYC), loan_history,
  7.78M penalty apps, transactions, audit_logs, consent_records.
- tottot_letshego + tottot_npontu.tenant_security_settings: FULL kowri
  disbursement_crediting_api_key (kgw_kiw-... / kgw_BFl2-...).
- kowri_credit_gateway: disbursement rail (momo payouts), api_clients caps.

## NEW: RCE on the 40-DB host (65.109.51.221) — CONFIRMED 2026-08-14
- `COPY ... FROM PROGRAM` executes OS commands as `postgres` (uid=107).
- Read /etc/hostname, /etc/passwd, ran `ip addr`, `hostname -I`.
- Host = Ubuntu-2004 (Hetzner), public IP 65.109.51.221, plus **13 internal
  docker bridge subnets** (172.17–172.29 .0.1 gateways) => the app tier
  (tottot / letshego / whatsapp / etc. containers) runs ON THIS SAME HOST.

### Internal app containers discovered (via RCE scan, read-only HTTP banner)
| Internal addr | Service | Identity |
|---|---|---|
| 172.29.2:3000 | Next.js | **"Npontu License Server"** (/dashboard) |
| 172.20.2:3000 | Express | (api) |
| 172.20.3:3000 | Express | (api) |
| 172.20.4/5/6:3000 | (no banner) | app containers |
| 172.29.3:5000 | (404 root) | app api |
| 172.26.3:8080 | (404 root) | app api |

## WHAT IS NOT ACCESSIBLE (gaps)
- Letshego's OWN corporate network / HQ LAN: we have none. Letshego data is
  reachable only because Npontu hosts it — there is no direct Letshego-infra
  foothold from this engagement.
- ABSA portal DB (138.201.221.144): local sqlite/mysql, SSH closed, no creds.
- SSH on 148.251.89.119 / 138.201.221.144 (keys valid but ports filtered).
- ~~Root on 65.109.51.221~~ — **ROOT ACHIEVED 2026-08-17** (see L8 below).

## L8 — LOCAL PRIVESC postgres -> root on 65.109.51.221 — CONFIRMED 2026-08-17
- PwnKit (CVE-2021-4034): **CLOSED**. policykit-1 = 0.105-26ubuntu1.**3**
  (patched; vulnerable < ...1.2). pkexec dated Feb 2022. Verified layout
  against berdav/arthepsy PoC, ran twice — usage+exit 127 = patched behaviour.
- Credential-reuse privesc (the working path):
  1. As `postgres` (RCE), read world-readable `/home/mylar/.env` -> DB_PASS
     `Myl@r1999`. `mylar` is uid=1003, member of group **sudo**.
  2. `su mylar` with `Myl@r1999` -> SUCCESS (password reuse DB->OS).
  3. `sudo -S` with same password -> **uid=0(root)**.
- ROOT PROOF captured: hostname=Ubuntu-2004-focal-64-minimal-hwe, root shadow
  hash, docker.sock (root:docker) reachable. Host also runs ollama (group 998).
- Confirmed access grants as root: full FS, docker daemon (all containers =
  Letshego/tottot app tier), all local creds, ability to add persistence
  (root SSH key / cron / setuid) — GATED, not yet done.
- Other sudo users (for alternate paths): jones, pontian (also docker), abraham,
  kenneth, aodoi, nosa, evans. mylar path already gives root; no need.

## LATERAL MOVEMENT PATHS (from current foothold) — updated
1. **DONE: postgres→root on 65.109.51.221** via mylar cred reuse (see L8).
   We now own the host running the entire Npontu/Letshego app tier.
2. **root → internal containers** (NOW TRIVIAL): docker exec into any container
   (Letshego/tottot app, License Server 172.29.2:3000, Express APIs), read live
   env secrets, source, JWT secrets from /var/lib/docker + container fs.
3. **Kafka Connect (5.9.86.210)**: arbitrary file write → SSH key/cron → shell
   on the Kafka host (different machine), pivot into its network.
4. **GitLab SSH persist key**: read all repos; maintainer escalation → CI runner
   RCE on build infra.
5. **hellio MySQL host (144.76.195.8)**: full app creds; FILE priv / INTO OUTFILE.
6. **NEW: east-west SSH from this host** (we are inside Hetzner now): retry the
   F1 SSH keys (SSH_RSA.pem/LIVE_RSA.pem) to 148.251.89.119 / 138.201.221.144 —
   internal routing is usually less filtered than our external IP.

## Bottom line for Letshego
Root on 65.109.51.221 = full control of the host that runs Letshego's entire
loan operation (app tier in docker containers + all secrets + all 40 DBs). The
highest-value next move is container introspection (Letshego app env/source) —
now unblocked without any further privesc.
