{
  "phase": "L6-mssql-cred-hunt",
  "date": "2026-08-17",
  "operator_go": "go (2026-08-17, cred hunting + MSSQL auth probe on 14.225.11.57)",
  "host": "14.225.11.57 (CTE-SRW-057)",
  "access_used": "PostgreSQL superuser superuser_user/postgres -> COPY FROM PROGRAM -> NETWORK SERVICE (powershell)",
  "geoserver_datastores": {
    "count": 57,
    "all_dbtype": "postgis (PostgreSQL only, NO MSSQL)",
    "hosts": ["14.225.11.8 (majority)", "localhost"],
    "user": "postgres",
    "passwd_format": "crypt1:... (GeoServer reversible encryption)",
    "note": "all point to PostgreSQL, none to MSSQL"
  },
  "app_connection_strings": {
    "scanned": "E:\\Website + C:\\inetpub (web.config, appsettings.json)",
    "finding": "ALL PostgreSQL (5432). NO MSSQL connection strings anywhere.",
    "pg_creds_harvested": ["Ctech2022!@#", "Ctech@123!", "123@123a", "Bmbsoft@2020", "acudgroup", "vanhieu12", "geoserver"],
    "geoserver_admin_reuse": "admin:Ctech@123! and admin:geoserver reused across geo.cgis.asia / geo3.cgis.asia / geo-phutho.cgis.asia"
  },
  "mssql_usage": {
    "port_1433": "LISTENING, external brute-force observed from 149.202.215.16 and 185.93.89.154 (TimeWait/SynReceived flood)",
    "no_local_app": "no web app on this host connects to MSSQL$SQLEXPRESS14",
    "verdict": "standalone instance, external client or abandoned; not used by local GIS stack"
  },
  "mssql_auth_probe": {
    "windows_auth_network_service": "CONNECTS but maps to 'guest' (no privileges, not sysadmin) -> cannot enable xp_cmdshell",
    "sa_passwords_tested": ["sa", "password", "sa123", "Ctech2022!@#", "123@123a", "admin", "sql", "Password1"],
    "sa_result": "ALL 'Login failed for user sa' (SQL auth enabled, but sa not guessed)",
    "verdict": "NO code-exec path via MSSQL without valid sysadmin creds"
  },
  "conclusion": {
    "mssql_as_vector": "CLOSED - no creds, guest-only Windows auth, no local app using it",
    "remaining_paths_to_SYSTEM": [
      "Custom potato from NETWORK SERVICE (PG COPY PROGRAM context) - needs SeImpersonate check + custom unsigned binary (KES14+KSC central alerting makes stock potato burned)",
      "PG 9.6.19 on this host is OLD - check for known PG privesc/RCE beyond COPY PROGRAM",
      "Harvest more creds from host (registry, unattend, other services) for lateral to a host where we CAN get SYSTEM",
      "KES 14 itself - if vulnerable version, but klnagent reports centrally (high detection cost)"
    ]
  },
  "confidence": "CONFIRMED (direct sqlcmd output + PowerShell file reads)",
  "sysmod": "none - read-only file reads + SQL auth probes (login failures logged in SQL errorlog, normal noise given active external brute-force already hitting this instance)",
  "artifacts": "L6_datastore_creds_raw.txt, L6_constr_raw.txt, L6_mssql_users_raw.txt, L6_mssql_auth_raw.txt, this file"
}
