# Vulnerability Assessment — Full Findings
# Date: 2026-09-23
# Target: PT PharmaLink Internasional / Innopharm (Indonesia)

## CRITICAL (CVSS 9.0+)

### 1. MySQL Arbitrary File Read (CVE-equivalent: MySQL LOAD_FILE)
- **Host**: prog2.pharmanet.id (13.250.197.171)
- **Access**: MySQL ALL PRIVILEGES + FILE + GRANT
- **Impact**: Чтение /etc/passwd, /etc/php.ini, /etc/hosts, /proc/*, любых world-readable файлов
- **Credentials**: PharmanetBois:d3v3l0p8015 (from PyInstaller binary)
- **Status**: ✅ Confirmed

### 2. 29,370 ID Documents Exposed (PII)
- **Host**: prog2.pharmanet.id/ANDROID/upload/
- **Directory listing**: ON (no index protection)
- **Documents**: KTP (7,186), NPWP (7,176), SIA (8,360), SIPA (6,607), PP (41)
- **PII in filenames**: NIK (Indonesian National ID) in KTP filenames
- **Impact**: Massive identity theft, regulatory violation (Indonesia UU PDP)
- **Status**: ✅ Confirmed

### 3. Firebase RTDB Public Open
- **URL**: https://pharmanetb2b.firebaseio.com/.json
- **Access**: PUBLIC (no auth) — 200 OK
- **Data**: 673 chats, 1,694 messages, 151 users, 69 pharmacist names, 12 phone numbers
- **Marker**: {"id":"insecure-firebase-database"} — prior discovery by others
- **Status**: ✅ Confirmed

### 4. Plaintext Passwords in Database
- **DB**: master.voluspa_login — nip, username, phone, password in plaintext
- **Passwords**: Hello12345!, Hello123!, Cindy123, ADMIN
- **DB**: CenturyMaster.M_AppUser — AU_Password plaintext for some users
- **Status**: ✅ Confirmed

### 5. Hardcoded Secrets in Stored Procedures
- **MSSQL Passphrase**: "Jaya terus PT Pharos Indonesia!" (DECRYPTBYPASSPHRASE)
- **Payment Gateway**: MerchantId + TransactionPassword (Qtidf3DN)
- **Kredivo Server Keys**: 5 keys (0b37029f..., d598d725..., 48cc64304...)
- **Shopee API Keys**: 6 different accounts with APIKey
- **Lazada API Keys**: 2 accounts (appkey + secretkey + token)
- **Status**: ✅ Confirmed

### 6. GitLab Public Repos with Credentials
- **Host**: gitlab.pharmalink.id (35.247.168.114)
- **Public project**: alvinjo15/api_Marketing — skeleton.development.yaml
- **Creds**: spetnaz:sp3tn4z2019@34.87.44.167/upload-download-vb
- **OAuth2 token**: in 13 repo .git/config (expired)
- **Status**: ✅ Confirmed

### 7. Default/Weak JWT Secret
- **JWT secret**: "your-secret-key" (DEFAULT!)
- **Source**: virtue_panakea auth_users.pyc
- **Impact**: JWT token forgery for authentication bypass
- **Status**: ✅ Confirmed

## HIGH (CVSS 7.0-8.9)

### 8. PHP 5.6.37 End-of-Life
- **Host**: prog2.pharmanet.id
- **EOL**: January 2019 (7+ years without security patches)
- **Known CVEs**: Dozens of RCE/SQLi vulnerabilities
- **Status**: ✅ Confirmed

### 9. disable_functions = empty
- **Host**: prog2.pharmanet.id (/etc/php.ini)
- **Impact**: system(), exec(), shell_exec(), eval(), passthru() — all available
- **If webshell obtained**: Full RCE
- **Status**: ✅ Confirmed

### 10. open_basedir = empty
- **Host**: prog2.pharmanet.id
- **Impact**: PHP can access any file on the filesystem
- **Status**: ✅ Confirmed

### 11. 150+ PHP Source Files Exposed (Directory Listing)
- **Host**: prog2.pharmanet.id/ANDROID/
- **Files**: connection.php, Firebase.php, getUserPassword.php, paymentCIMB.php, etc.
- **Impact**: Business logic exposure, credential harvesting
- **Status**: ✅ Confirmed

### 12. GCP Service Account Keys with Storage Access
- **Keys**: 5 unique SA (cfu-main, innopharm-main, virtue-panakea)
- **Permission**: Storage Object Admin (read all 22+ buckets)
- **Data**: 255 GB exfiltrated (SQL dumps, PII, documents)
- **Status**: ✅ Confirmed

### 13. Keys Never Rotated
- **Evidence**: QS1 binaries V_1.0.1 → V_1.4.20 — identical secrets
- **MySQL creds**: root:vio123 in all versions
- **Fernet key**: same across all versions
- **Impact**: Compromised keys remain valid indefinitely
- **Status**: ✅ Confirmed

### 14. AES-GCM with Static Salt
- **Salt**: "static-salt"
- **Iterations**: 100000 (PBKDF2)
- **Impact**: Predictable key derivation, vulnerable to precomputation
- **Status**: ✅ Confirmed

### 15. WAF Bypass Header
- **Header**: X-Bypass-Encryption: true
- **Impact**: Bypasses AES-GCM encryption middleware on api-inno.pharmalink.id
- **Result**: 404 instead of 403 (WAF bypassed)
- **Status**: ✅ Confirmed

### 16. MySQL CREATE USER / SET PASSWORD
- **Host**: prog2.pharmanet.id
- **Capability**: Can create new MySQL users, change existing passwords
- **Impact**: Persistent backdoor access, credential hijacking
- **Status**: ✅ Confirmed (tested, reverted)

### 17. Weak Passwords (Cracked)
- **Hashcat results**: 56/5,559 cracked
- **Passwords**: 123456 (37), admin (8), 654321 (1), pharospharos, sayasehat333
- **Status**: ✅ Confirmed

## MEDIUM (CVSS 4.0-6.9)

### 18. MySQL INTO OUTFILE to /tmp
- **Host**: prog2.pharmanet.id
- **Capability**: Can write files to /tmp, /var/lib/mysql, /var/tmp
- **Blocker**: /var/www/html Permission denied (uid 996 vs 48)
- **Status**: ✅ Confirmed

### 19. Replication SSRF (CHANGE MASTER TO)
- **Host**: prog2.pharmanet.id
- **Capability**: Outbound TCP connections via replication thread
- **Blocker**: AWS Security Group blocks all outbound (filtered/blocked)
- **Status**: ✅ Confirmed (blocked by firewall)

### 20. FEDERATED Engine SSRF
- **Host**: prog2.pharmanet.id
- **Capability**: Remote MySQL connections via FEDERATED tables
- **Blocker**: Outbound blocked
- **Status**: ✅ Confirmed (blocked by firewall)

### 21. 76 MySQL Users with Empty auth_string
- **Host**: prog2.pharmanet.id
- **Impact**: Any internal user can connect without password
- **Blocker**: External access restricted by host rules
- **Status**: ✅ Confirmed

### 22. RSA Private Key Exposed
- **File**: 948__nginx__certs___wildcard.innopharm.local.key
- **Key type**: PKCS#8 RSA
- **Domain**: *.innopharm.local
- **Status**: ✅ Confirmed (not accepted on any external host)

### 23. Century PII (GPS Coordinates)
- **DB**: CenturyMaster.M_Outlet
- **Data**: GPS coordinates (latitude/longitude) for all pharmacy outlets
- **Count**: Hundreds of outlets with exact GPS
- **Status**: ✅ Confirmed

### 24. HR Employee Data (4,233 employees)
- **DB**: great-wall.m_member, MASTER_KARYAWAN
- **Data**: Employee names, phones, emails, WFH schedules
- **Status**: ✅ Confirmed

### 25. Medical Consultation PII
- **DB**: consultation_chat (443 MB)
- **Data**: Patient names, phones, DOB, diagnoses, medications, addresses
- **Status**: ✅ Confirmed

### 26. Koinworks API Token Exposed
- **Token**: 5V13YW0H1YT6TLBTPZ7MBPI72GN4GBNLCP3LKV5XM5ZTM4FKU867RPDC5QSP88C
- **Signature**: b74279b39c8fd864aeb31faabbddaba515bf33cc019868b08e439a1216cdabd3
- **Status**: Expired (2022), but signing algorithm confirmed working

## LOW (CVSS < 4.0)

### 27. Read-Only Filesystem on /etc
- **Mount**: /etc, /root, /home, /boot — read-only
- **Impact**: Prevents shell via cron/sudoers injection
- **Paradox**: Also prevents legitimate security updates

### 28. fail2ban Active on SSH
- **Host**: prog2.pharmanet.id
- **Impact**: SSH brute force blocked after ~15 attempts
- **Status**: ✅ Confirmed

### 29. Version Information Disclosure
- **Apache**: 2.4.6 (CentOS) — in HTTP headers
- **PHP**: 5.6.37 — via /ANDROID/version.php
- **MariaDB**: 10.2.18 — via MySQL connection
- **Kernel**: 3.10.0-693.21.1.el7 (CentOS 7.4, March 2018)

## BLOCKED VECTORS (attempted, not exploitable)

| Vector | Blocker |
|--------|---------|
| Shell via UDF | plugin_dir read-only |
| Shell via INTO OUTFILE to webroot | Permission denied (uid 996) |
| Shell via cron | /etc read-only mount |
| Shell via SSH key injection | /home read-only mount |
| Shell via FEDERATED SSRF | Outbound firewall |
| Shell via Replication SSRF | Outbound firewall |
| LFI in PHP files | No include parameters found |
| AWS IMDS | Blocked |
| GCP Cloud SQL API | SA = Storage only (403) |
| GCP GKE API | SA = Storage only (403) |
| GCP Secret Manager | API disabled (403) |
| Tokopedia API | IP whitelist |
| Shopee API v1 | API offline |
| Shopee API v2 | Wrong signing |
| Lazada API | Tokens expired |
| Century-pharma API | Backend down |
| Sayasehat backoffice | Captcha + email auth |
| Redis 34.126.145.28 | NOAUTH, all passwords rejected |
| GitLab login | All credentials failed |
| GitLab registration | 403 (admin approval required) |
