# New Binary Scan Results — Manufacturing-FE + Standalone + Arduino Flasher
# Date: 2026-09-21

## NEW FINDINGS

### 1. NEW Internal IP: 192.168.0.200 (arduino.exe)

| Binary | File | Finding |
|--------|------|---------|
| arduino.exe | config.pyc | http://192.168.0.200:8080 |
| arduino.exe | global_variable.pyc | 192.168.0.200 |
| autosampler.exe | global_variable.pyc | 192.168.0.200 |
| autosamplerhplc.exe | global_variable.pyc | 192.168.0.195 (different!) |

Previously only knew about 10.0.55.127:8080 and 192.168.0.195.

### 2. NEW Internal Endpoints (arduino.exe routes.pyc)

| Endpoint | Port | Purpose |
|----------|------|---------|
| /manufacture/server/services/compartment/compartmenton | 8602 | Compartment control |
| /getformdev | 8610 | Form device |

New ports: 8602, 8610 (previously knew 8081, 8600, 62001)

### 3. auth_users.pyc — Full SQL Schema (standalone master_manufacturing_be.exe)

```
TABLE: users
COLUMNS: user_id, user_fullname, role_id, is_active, username, nip, email,
         user_password, phone_number, change_password_yn, terms_conditions_yn,
         company_id, created_at, created_by, updated_at, updated_by
```

SQL queries found:
- INSERT INTO users (user_id, user_fullname, role_id, is_active, username, nip, email, user_password, ...)
- SELECT user_id, role_id, is_active, username, user_password, nip, user_fullname, company_id FROM users WHERE userName = %s
- UPDATE users SET user_password = %s WHERE user_id = %s
- UPDATE users SET user_password = %s, change_password_yn="N" WHERE user_id = %s

### 4. OTP Password Reset Flow (standalone)

Complete password reset logic:
- FuncResetPasswordFromOtp START/END
- "Kode OTP Reset Password" — OTP code for password reset
- Generate random password with uppercase, lowercase, digits, and symbols
- "Encrypted Password:" — password is encrypted before storage
- "Password reset successfully"
- company_serial_key table — device serial key validation

### 5. company_serial_key Table

```sql
SELECT company_id, device_id, serial_key
FROM company_serial_key
WHERE serial_key = %s AND factory_id = %s
```

### 6. factory_server Table

```sql
INSERT INTO factory_server(factory_id, server_mac_addr, created_at, created_by, updated_at, updated_by)
VALUES (%s, %s, NOW(), %s, NOW(), %s)
ON DUPLICATE KEY UPDATE updated_at = NOW(), updated_by = VALUES(updated_by)
```

### 7. routes.pyc — New API Endpoint

- /manufacture/auth/changepassword — password change endpoint

### 8. Config Values (confirmed same across all binaries)

| Key | Value | Found In |
|-----|-------|----------|
| Flask SECRET_KEY | 4e2e005ca612345f8684b8daa10be810 | All binaries |
| Fernet key | wN0oOz0d7dFPysLiaUYWTHG5RstxE9AJ9CqqIu2SqVE= | All binaries |
| AES API key | GkWdMVpsGDEgfM9+ISF/nUy5NMgCbjUdV0Gv1dxIFUM= | All binaries |
| MySQL prod | grom:d3v3l0p8015@34.87.44.167:3306/simpapi | theone binaries |
| MySQL stg | pharmavid:pharmavid123@34.101.249.224 | appname binaries |
| MySQL prod2 | manufactureprog:6S@Ys{mgxVM-8Zc.@34.124.180.65 | config_local_release |
| Internal API 1 | 10.0.55.127:8080 | Most binaries |
| Internal API 2 | 192.168.0.195 | autosamplerhplc |
| Internal API 3 | 192.168.0.200:8080 | arduino (NEW) |

### 9. arduino_flasher_v2.exe — Only 137 files in PYZ

Small binary — likely just Arduino firmware flashing utility. Entry point: arduino_flasher_v2.pyc. No new secrets found (uses same Fernet key).

## SUMMARY

All binaries now fully decomipled and scanned. New findings:
1. 192.168.0.200 — third internal IP (arduino binary)
2. Ports 8602, 8610 — new internal endpoints
3. auth_users table — full SQL schema with user_password column
4. OTP password reset flow — complete logic
5. company_serial_key — device registration table
6. factory_server — MAC address registration

No NEW credentials found — all binaries use the same set of secrets. But the auth_users table schema and OTP reset flow are new intelligence for potential exploitation via internal pivot.
