# Vectors 2 & 3 — HTTP & Port 35679 Investigation
# Date: 2026-09-21

## VECTOR 2: MSSQL (port 1433) — CLOSED

| Check | Result |
|-------|--------|
| Port 1433 initial scan | OPEN |
| Port 1433 re-check | **CLOSED** (Connection refused) |
| TDS handshake | Connection refused |
| sa password brute (13 users × 17 passwords) | All failed |

MSSQL was initially open but closed during our session. Possibly:
- Service was stopped/crashed
- Security group rule changed
- iptables rule added

## VECTOR 3: HTTP (port 80/443) — LIMITED

### Port 80 (HTTP)
- Server: Apache (CentOS)
- Returns: 403 Forbidden + Apache test page
- DocumentRoot: /var/www/html/ (but no apps there)
- No PHP files found

### Port 443 (HTTPS)
- Server: Apache
- Returns: 200 OK — "Under Construction" page
- Static HTML with underconstruction.png image
- No dynamic content
- No PHP apps visible

### vHosts
- Host: all.apodoc.id → Apache CentOS test page
- Host: prog2.pharmanet.id → "Under Construction"
- No virtual hosts with apps

### Path enumeration
- Only / returns 200 (HTTPS) or 403 (HTTP)
- /cgi-bin/ → 403 (exists but forbidden)
- No admin panels, no phpMyAdmin, no APIs

### Web app configs
- /etc/httpd/conf/httpd.conf — NULL
- /etc/nginx/nginx.conf — NULL
- /etc/httpd/conf.d/* — all NULL
- Apache DocumentRoot = /var/www/html/ (confirmed from test page text)
- MySQL user cannot read httpd binary or configs

### Conclusion
HTTP is a bare Apache with default configs serving static "Under Construction" pages.
No exploitable PHP applications found.

## Port 35679 — UNKNOWN SERVICE

### Characteristics
| Property | Value |
|----------|-------|
| Port | 35679 (0x8B5F) |
| Protocol | TCP |
| State | LISTEN |
| UID | 0 (root) |
| IPv4 + IPv6 | Both listening |
| Inode | 124088739 |

### Probes
| Probe | Result |
|-------|--------|
| HTTP GET / | No response |
| TLS handshake | write:errno=104 (connection reset) |
| Raw TCP (empty) | No response |
| Binary probe | No response |
| TDS protocol | No response |

### What it could be
- AWS SSM agent (port varies)
- Custom monitoring agent
- Docker daemon (default 2375/2376, but could be custom)
- Some internal service
- Agent accepting connections from specific IPs only

The service accepts TCP connections but doesn't respond to any protocol probes.
Likely requires specific source IP or specific protocol handshake.

## NETWORK STATE SUMMARY (current)

| Port | Status | Service |
|------|--------|---------|
| 22 | OPEN | SSH (OpenSSH 7.4) |
| 25 | OPEN | SMTP (postfix) |
| 80 | OPEN | HTTP (Apache, 403) |
| 111 | **CLOSED** | rpcbind (was open) |
| 443 | OPEN | HTTPS (Apache, 200) |
| 1433 | **CLOSED** | MSSQL (was open) |
| 3306 | OPEN | MySQL (our access) |
| 35679 | OPEN | Unknown (root, no response) |

## REMAINING OPTIONS

1. **SSH (22)** — OpenSSH 7.4 (CVE-2024-6387 regreSSHion? CentOS 7.4 is very old)
   - Need cred stuffing — 8 users × 25 passwords = 200 attempts
   - Could also check for SSH key vulnerabilities

2. **MySQL only** — we have full DB access but no shell
   - Can read all databases (already doing)
   - Can write to /tmp, /var/tmp, /var/lib/mysql
   - Cannot escalate to shell without write access to webroot or plugin_dir

3. **Port 35679** — unknown, non-responsive
   - Would need internal access to investigate
