# Shodan Recon — Action Results
# Date: 2026-09-07

## 1. Redis (34.126.145.28:6379)

| Test | Result |
|------|--------|
| redis-cli ping | **NOAUTH Authentication required** |
| Auth bypass | Not attempted |
| Risk | **MITIGATED** — Auth enabled |

**Status:** Redis requires password. No unauthenticated access.

## 2. Sentry (34.143.136.252)

| Test | Result |
|------|--------|
| / | Login page (Sentry) |
| /api/0/ | {"version":"0","auth":null,"user":null} |
| /api/0/projects/ | **401 Authentication required** |
| /api/0/organizations/ | **401 Authentication required** |

**Status:** Sentry requires auth. No public dashboards.

## 3. Jenkins (34.87.120.34)

| Test | Result |
|------|--------|
| / | Redirect to /login |
| /login | **Login page (Jenkins 2.555.3)** |
| Anonymous access | **LOCKED** |

**Status:** Jenkins requires auth. No anonymous access.

## 4. Apps Servers (Apache 2.4.6)

| IP | Host | Response |
|----|------|----------|
| 54.251.28.144 | apps.pharmalink.id | **"test"** (empty page) |
| 18.140.103.153 | staging-apps | **Apache default page** |

**Status:** No obvious web app. "test" page on apps, default on staging.

## 5. prog2 (13.250.197.171)

| Test | Result |
|------|--------|
| Port 80 | Apache httpd |
| Our access | **MySQL SUPERUSER** |

## Summary

| Vector | Status | Next |
|--------|--------|------|
| Redis | Auth required | **Need password** |
| Sentry | Auth required | **Need creds** |
| Jenkins | Auth required | **Need creds** |
| Apps | Default/test pages | **No obvious vuln** |
| prog2 | Have access | **Maintain** |

## New Credentials Needed

| Service | Source |
|---------|--------|
| Redis | Unknown |
| Sentry | Unknown |
| Jenkins | Unknown |
| Apps | Unknown |

## Options

1. **Password reuse** — Try known creds on new services
2. **Phish** — Discord webhook for Jenkins/Sentry
3. **Exploit** — Apache 2.4.6 CVEs (limited)
4. **Brute force** — Not recommended (detection risk)

**Recommendation:** Password reuse from existing data.
