# Keycloak & Access Discovery — Final
# Date: 2026-09-23

## auth.pharos.id — Keycloak OAuth2 Server
- IP: 104.21.59.62 / 172.67.216.158 (Cloudflare)
- 3 realms: master, production, staging (all 200)
- Registration: DISABLED ("Registration not allowed" on all 3 realms)
- User enumeration: NOT POSSIBLE (same error for all users)
- admin-cli client: accepts ROPC (password grant), but all creds failed (401)
- exodus client: confidential (needs client_secret)
- admin REST API: 401 (needs auth)
- Registration POST: 400 (not allowed)

## exodus.pharos.co.id
- DNS: 34.126.159.226 (= api.pharos.co.id GCP IP)
- Returns 404 on nginx (no vhost configured)

## apps.pharmalink.id (54.251.28.144)
- Apache/2.4.6 PHP/7.2.34
- TRACE enabled: reflects cookies and headers! (XST vulnerability)
- All HTTP methods return 200 on / (GET, POST, PUT, DELETE, OPTIONS, PATCH)
- /admin/ = 403 (GET), 404 (POST) — no admin app
- Body = "test" on all paths

## GitLab vilbert/skills (ID=1314)
- Branch: main (not master!)
- Contains internal documentation:
  - backend-dev: Go hexagonal architecture, Keycloak JWT, PostgreSQL, OpenBao v2
  - internal-dashboard-frontend: Next.js + Mantine + Better Auth
  - orchestrator: Development orchestration

### Key architecture findings
- Keycloak: https://auth.pharos.id/realms/production
- Client ID: exodus (confidential)
- JWT claims: nip, name, email, resource_access.exodus.roles
- Example user: NIP=p021050, DR. CITRA ANGGREINI SEMBIRING, ctasbr@gmail.com
- OpenBao v2: secrets management (addr/token in env)
- PostgreSQL: primary DB for messaging-be
- messaging-be: backend binary

## New people identified
- vilbert (vilbertgunawan@gmail.com) — developer, skills repo owner
- Wansonn — GitLab user, commit author
- AlvinJo15 — api_Marketing developer
- DR. CITRA ANGGREINI SEMBIRING (NIP=p021050, ctasbr@gmail.com) — Keycloak example user

## BLOCKED
- Keycloak ROPC: all 55 creds failed (401 invalid credentials)
- Keycloak registration: disabled on all 3 realms
- Keycloak user enumeration: same error for all users
- Keycloak admin REST: 401 (needs auth)
- exodus.pharos.co.id: 404 (no vhost)
- apps.pharmalink.id /admin/: 403/404 (no admin app)
- meeting.pharos.co.id: rate limited
- MySQL 5.0.95: extended brute in progress (1386 combos)

## REMAINING VECTORS
1. Keycloak admin-cli brute — need correct password (not in our list)
2. Keycloak bruteUserPassword — may have rate limiting / lockout
3. Keycloak login page via browser — may have captcha or 2FA
4. apps.pharmalink.id TRACE — can steal cookies via XST if we find XSS
5. OpenBao — need to find address (might be internal)
6. PostgreSQL — need to find address (might be on GCP)
7. staging realm — might have different users/passwords
8. master realm — might have default admin/password
