# Shodan Recon — PharmaLink Infrastructure
# Date: 2026-09-07
# API Key: 9WAeUlE5II2L8K3ElJffwARTgQSxaFAW

## Hosts Scanned

| IP | Hostnames | Open Ports | Services | Notes |
|----|-----------|------------|----------|-------|
| 34.126.145.28 | pharmalink.id | 80, 443, **6379** | nginx, **Redis** | **Redis exposed!** |
| 34.87.120.34 | pharmalink.id | 22, 443 | OpenSSH 8.2p1, Jenkins 2.555.3 | **Jenkins CI/CD** |
| 34.126.159.226 | googleusercontent.com | 80, 443 | — | Vault (no banner) |
| 34.143.202.81 | googleusercontent.com | 80, 443 | — | Main domain |
| 34.87.167.47 | googleusercontent.com | 80 | — | CHC cluster |
| 34.143.136.252 | sentry.pharmalink.id | 22, 80, 443 | OpenSSH 9.6p1, nginx 1.24.0 | **Sentry** |
| 34.126.103.195 | googleusercontent.com | 22 | OpenSSH 9.6p1 | CFU |
| 34.50.65.188 | jitsi.chc.pharmalink.id | 22, 80, 443 | OpenSSH 8.9p1, nginx 1.18.0 | **Jitsi** |
| 35.187.252.87 | googleusercontent.com | 80, 443 | — | Staging API |
| 13.250.197.171 | amazonaws.com | 80 | Apache httpd | **prog2 (our access)** |
| 54.251.28.144 | apps.pharmalink.id | 443 | Apache httpd 2.4.6 | **Apps (AWS)** |
| 18.140.103.153 | amazonaws.com | 443 | Apache httpd 2.4.6 | **Staging Apps (AWS)** |

## Critical Findings

### 1. Redis Exposed (34.126.145.28:6379)

| Parameter | Value |
|-----------|-------|
| IP | 34.126.145.28 |
| Port | 6379 |
| Service | Redis key-value store |
| Auth | **Unknown — test needed** |
| Risk | **HIGH** — NoSQL injection, data theft, RCE |

**Test:** `redis-cli -h 34.126.145.28 -p 6379 ping`

### 2. Jenkins CI/CD (34.87.120.34:443)

| Parameter | Value |
|-----------|-------|
| IP | 34.87.120.34 |
| Port | 443 |
| Service | Jenkins 2.555.3 |
| SSH | OpenSSH 8.2p1 Ubuntu 4ubuntu0.13 |
| Risk | **CRITICAL** — Build secrets, deployment keys |

**Known:** Jenkins anonymous access **LOCKED** (from previous recon)

### 3. Sentry (34.143.136.252)

| Parameter | Value |
|-----------|-------|
| IP | 34.143.136.252 |
| Hostname | sentry.pharmalink.id |
| Ports | 22, 80, 443 |
| Risk | **HIGH** — Error logs, stack traces, potential creds |

**Next:** Check for exposed dashboards, API keys in errors

### 4. Jitsi (34.50.65.188)

| Parameter | Value |
|-----------|-------|
| IP | 34.50.65.188 |
| Hostname | jitsi.chc.pharmalink.id |
| Ports | 22, 80, 443 |
| Risk | **MEDIUM** — Video conf, internal meetings |

### 5. Apps Servers (AWS)

| IP | Hostname | Service | Version |
|----|----------|---------|---------|
| 54.251.28.144 | apps.pharmalink.id | Apache | 2.4.6 (old) |
| 18.140.103.153 | staging-apps | Apache | 2.4.6 (old) |

**Risk:** Apache 2.4.6 (2013) — multiple CVEs

## Attack Surface

| Vector | Target | Access |
|--------|--------|--------|
| Redis | 34.126.145.28:6379 | **Test auth** |
| Jenkins | 34.87.120.34 | **Phish creds** |
| Sentry | 34.143.136.252 | **Check errors** |
| Apache 2.4.6 | 54.251.28.144, 18.140.103.153 | **CVE exploit** |
| prog2 | 13.250.197.171 | **Have MySQL** |

## Next Steps

1. **Redis auth test** — `redis-cli -h 34.126.145.28 -p 6379`
2. **Sentry error mining** — check for API keys, passwords
3. **Jenkins phish** — Discord webhook
4. **Apache CVE scan** — 2.4.6 vulnerabilities
5. **Port scan full range** — nmap all IPs
