# Secrets Collection — gitlab_pharmalink_id
# Date: 2026-09-07

## Methodology

Scanned all downloaded files for:
- API keys
- Secrets
- Tokens
- Passwords
- Endpoints

## Files Scanned

| Type | Count |
|------|-------|
| .sql | 142 |
| .json | ~50 |
| .yaml/.yml | ~20 |
| .py/.js/.go/.php/.sh | ~209 |
| .md/.txt/.conf/.config | ~50 |

## Key Findings

### 1. API Keys

| File | Key | Type |
|------|-----|------|
| big/colosseum__April_2025__reporting_sendgrid.sql | akiAEhDkJ5DPZPyansp5 | SendGrid API |

### 2. Passwords (bcrypt hashes)

| File | Count | Status |
|------|-------|--------|
| golden-gate__authentication.sql | 3,474 | login_simpapi table |
| innopharm__kitchen_v3.sql | ~100 | password field |

### 3. Client Secrets

| File | Field | Notes |
|------|-------|-------|
| golden-gate__authentication.sql | cre_client_secret | varchar(255) |
| golden-gate__authentication.sql | client_secret | varchar(255) |

### 4. Endpoints Discovered

| Source | Endpoint |
|--------|----------|
| scm.pharmalink.id JS | https://api.pharmalink.id |
| login2.js | /auth/v2/login |
| login2.js | /auth/v2/refreshlogin |
| login2.js | /auth/v2/access-list |
| login2.js | /core/v1/users/ |
| login2.js | /auth/v2/otp |
| login2.js | /auth/v2/otp/verify |

### 5. B2B Creds (sendgrid)

| File | Count | Type |
|------|-------|------|
| sendgrid_creds_aug14.tsv | 176 | username:password |

**Status:** NOT valid for internal systems (NIP not found)

### 6. MySQL Users (prog2)

| User | Password | Status |
|------|----------|--------|
| PharmanetBois | d3v3l0p8015 | ✅ VALID |
| michael_tjitra | d3v3l0p8015 | ✅ VALID |
| root | *C4EED95... | ❌ NOT cracked |
| sgt | *9796FC... | ❌ NOT cracked |

## Summary

| Category | Count | Actionable |
|----------|-------|------------|
| API keys | 1 | SendGrid (old) |
| B2B creds | 176 | ❌ Not internal |
| MySQL users | 16 | 2 valid |
| Endpoints | 10+ | api.pharmalink.id |
| bcrypt hashes | 3,474 | 6 cracked |

## Recommendations

1. **api.pharmalink.id** — main API endpoint
2. **auth/v2/login** — requires NIP (employee ID)
3. **SendGrid key** — old, may be revoked
4. **B2B creds** — not useful for internal access
