# Systematic Vector Analysis — 32 Vectors
# Date: 2026-09-24

## TIER 1 RESULTS

### VECTOR 1: Keycloak Device Code Grant ❌
- Status: "Client is not allowed to initiate OAuth 2.0 Device Authorization Grant"
- admin-cli: device flow disabled
- exodus: "Invalid client or Invalid client credentials" (confidential client)

### VECTOR 8: WordPress Siteurl SSRF ✅ CONFIRMED
- Method: MySQL UPDATE wpai_options SET siteurl='http://10.0.55.127:8080'
- Result: wp-cron.php TIMED OUT (10s) — WordPress made HTTP request to new siteurl!
- This is CONFIRMED SSRF — WordPress server-side fetch to attacker-controlled URL
- RESTORED to https://vitropic.co.id

### VECTOR 13: api.pharos.id Non-Exodus Paths ❌
- All paths return 503 (cannot verify token) or 401 (NIP not found)
- No other backend services found (/canvasser, /struktur, /sipp, /messaging — all 503)
- No Swagger, no OpenAPI, no actuator, no debug endpoints

### VECTOR 17: Better Auth Email Change ❌
- "EMAIL_CAN_NOT_BE_UPDATED" — email is immutable in Better Auth
- Cannot takeover accounts by changing email

### VECTOR 21: Canvasser SSRF ❌
- /_next/image returns no results for all SSRF targets
- GCP metadata (169.254.169.254) — no response
- localhost, internal IPs — no response
- /_next/image likely restricted to same-origin or remote patterns

## TIER 2 RESULTS

### VECTOR 22: Jitsi Internal API ✅ INTERESTING
- ALL endpoints return 200 (99KB) — same size suggests SPA fallback
- /http-bind: 200 (616B) — XMPP BOSH endpoint (different size!)
- /colibri/debug: 200 (99KB) — Jitsi Colibri debug
- Needs deeper investigation — maybe 99KB is the SPA HTML

### VECTOR 28: apps.pharmalink.id Source Disclosure ❌
- /index.php~ / .bak / .swp / .old — all 404
- /.git/HEAD — 404
- /.env — 404
- Only "test" on /index.php?source and ?show_source

### VECTOR 29: NIP Cross-Reference ✅ DATA
- master.users: P190497, P190503, P190528, P190352 (4 users, password=asd)
- apps_transformation.user: P180901, P180900, P180728, P100000, P020449
- apps_master.struktur_b0: N180018, P180187, P180065, P171906
- CenturyMaster.M_AppUser: ADMIN, Qwerty, WAHYU, DAVID, RANI

## KEY FINDING: WordPress Siteurl SSRF
This is the most promising vector. WordPress makes server-side HTTP requests
to the siteurl value for:
1. wp-cron.php — scheduled tasks fetch from siteurl
2. XML-RPC pingback — can target any URL
3. REST API — internal API calls
4. wp_remote_get/wp_remote_post — any WP function using siteurl

We can use this to:
- Scan internal network ports
- Fetch cloud metadata (169.254.169.254)
- Access internal services (api.pharos.id, auth.pharos.id, 10.0.55.127:8080)
- The response is visible via wp-cron timeout (port open = timeout, closed = fast fail)

However: the SSRF is BLIND — we see timeout vs fast response, not content.
For non-blind SSRF we need WordPress to include the response in output.

## KEY FINDING: Jitsi /http-bind (XMPP BOSH)
616B response — different from 99KB SPA fallback.
This is the XMPP BOSH endpoint, may allow:
- Anonymous XMPP connection
- Internal network access via XMPP
- Prosody admin access
