# Unused Credentials & Keys — gitlab.vdss.com.vn / CGIS engagement
Date: 2026-08-17. Basis: L2/L4/L5/L6 artifacts. "Unused" = harvested but never validated/used for access (either unreachable target, out-of-scope, or superseded). No-masking per operator rule.

## USED (for contrast — these WERE validated/used)
- truonglt / 1qaz@123 → GitLab instance admin (OAuth, VALID 2026-08-17)
- postgres / Ctech2022!@# → CGIS PG SUPERUSER (.8, .57); .28 noti/nOTI@2025@#
- superuser_user / postgres → PG RCE on .57
- admin / Ctech@123! (and admin:geoserver) → GeoServer
- dace/dACe@2026@#, morning/MoRNinG@2026@#, eform/eForM@2026@#, postgres/TamDT@2026!@# → VDSS prod DB 103.149.99.107:2903 (verified exfil)

## UNUSED — VDSS internal DB creds (target unreachable: no route, RFC1918)
All point to 172.31.2.15 / 10.215.102.41 / 10.1.27.43 — internal vdss net, NO ROUTE (confirmed V21).
- PostgreSQL 172.31.2.15:5432 — mail/mAIl@2025@# (mail_noti, mail_system); poms/pOmS@2026!@#; vdoc/vDoc@2025@#; report_platform/rP@2025@#; cms_vdss/cMs@2025@#; dace/DaCe@2025@# (+dACe@2026@#); eform, morning/mOrNiNg@2025@#
- MariaDB 172.31.2.15:3306 — parking/pArKing@2025@# (car_parking, cate_parking, cms_parking, crm_parking, invoice_parking, motobike/motorbike_parking, parking_export, parking_mail, payment_parking, qr_parking)
- MySQL 10.215.102.41:3306 — MerchantX_ma (mb-ma): spring.datasource.password=Mb@123456! / MASSO@2025@#
- Redis 172.31.2.15 — TamDT@2025@# (poms); vDsS@2025@# (parking export/keycloak/payment)
- Keycloak 10.1.27.43:8831 realm ms-core — ob_user1 / c1ef48ee-39dd-4801-97a4-efd3ed733003

## UNUSED — VDSS allowlist-prod DB creds (target IP-allowlist filtered)
- cms_vdss_live / cms_vdss_draf @ 14.225.5.225:5432 — postgres/Vdss@2022# (UNREACHABLE)
- chondb @ 211.188.52.92:3306 — chon/cHon$2025!@# (UNREACHABLE)

## UNUSED — MB Bank / MerchantX (com.mbbank) supply-chain secrets
- rsa.private.key (shared RSA, dace/vdoc/morning/vdss-cms/chon) — full private key harvested; never used to sign/decrypt
- amazonProperties.accessKey = AKIAD2C822B77FCCD057 (AWS/OBS, **VALIDATED 2026-08-17: internal MB Bank only, no public route, not real AWS**)
- oauth2.clientSecret = c1ef48ee-39dd-4801-97a4-efd3ed733003 (mbbank oauth2)
- d-otp-ms.clientSecret = 2CPyCVy8NdFVOMDV8ymK5nyD5YVQWRJH
- messaging.kafka.proxy.password = XSCueTLxYNJqBDvd
- mms.core.password = Mb123abc..
- send.mail / spring.mail.password = dhynjshowqtuzxvl (Gmail app-password, merchantx)
- Jasypt ENC() values: ENC(wNs9TjYfwHVJG5QM9dCb3do5bXCQaOMZ), ENC(wa9nLi/D28Mq5kcoNt2I0BLS2tx3QR9f), ENC(PwnSgLOI7HlyGbHg9GKrhqVWKQUNrlaE) — undecrypted (jasypt password not recovered)
- JwtUtil SECRET_KEY = "your-secret-key" (placeholder, low value)

## UNUSED — bcy / FPT-akames MES secrets
- api-key.secret = XQI4lMdxGFEcCQFMWWOGSU1IMPXE03XY7hD3sodcH80xE56wYVrwH3tyQ0o5IFRe (reused across bcy services)
- azure.secret = 6hV8Q~LO46QPErIaO2AcX7gbtJl42YxG4o88kbjU and xB38Q~CaV9tHPgPo~-q14SFe1qb_zmL55APHjbui (Azure AD client secrets, **VALIDATED 2026-08-17: both expired/invalid**)
- keycloak.secret = XUNPTNv4bZv5ylS6Au1CYDEylQbu9Hqr; yoko.secret = 6hV8Q~LO46QPErIaO2AcX7gbtJl42YxG4o88kbjU
- keycloak client-secret (parking, reused x5) = LN1LjiodrgAeKi071TAPjHZLoCdjI0Ob
- OIDC_SECRET = 93N10HSO6Yes1xUfOj8BnM3sCIHulSzB; OIDC_SECRET_AAD = xB38Q~CaV9tHPgPo~-q14SFe1qb_zmL55APHjbui
- nas.config.password = Vietnam@123
- db.password = P@999w0rdAk@No1 (commented); akames; e372d76c-16d8-4e2c-aa4b-05edb477c0a8 (UUID-style db password)
- ldap-password / salt = 52056788-82d7-4cb3-b2ac-6958ec6ece69, 217b2403-1153-485d-81df-336460620388, 9bb3c6ae-40f9-4232-ba28-8cd9a64a60bb
- mail.smtp.password = fmqkbzlpljqyybmm (bcy email); mail.smtp.secret = 86ee15c0-c381-44f9-bfd2-89fe729a578e
- REDIS default 'akaMES'; cookieSecret (cf.cookieSecret)
- jwt.secret = 8L2jKxP5Qv9mW7nT3rY8sF4dG1hJ6kL9oP2qR5tU8vX= (report-platform / tamdt1 eform)
- C++ client secrets: 01EQJN4GJD88M5RB1WGQRNDYTW, 123456@a
- com.utils.mail.password = 123456

## UNUSED — Firebase service-account private keys (bcy notification)
- ptsc-marine-firebase.json — private_key (BEGIN PRIVATE KEY, full) — **VALIDATED 2026-08-17: ACTIVE project ptsc-marine (Petrovietnam), full Firebase Admin SDK access**
- stma-firebase-dev.json — private_key (BEGIN PRIVATE KEY, full) — **VALIDATED 2026-08-17: ACTIVE project stma-7b5f1, full Firebase Admin SDK access**

## UNUSED — GeoServer datastore PostGIS creds (crypt1-encrypted)
- 57 datastore.xml: user=postgres, passwd=crypt1:... (GeoServer reversible) — host 14.225.11.8/localhost. Superseded: we already hold cleartext Ctech2022!@# for those PG hosts, so decrypting crypt1 adds nothing.

## UNUSED — Misc CGIS app PG creds (from E:\Website appsettings)
- 123@123a, Bmbsoft@2020, acudgroup, vanhieu12 — harvested; only partially validated (123@123a used on localhost PG). Others unused for new access.

## SUMMARY
- Largest unused concentration: **VDSS internal DB creds** (~15 distinct) — blocked purely by network (no route), not by validity. Would unlock vdss core if a foothold inside 172.31.x appears.
- Highest-value unused: **shared RSA private key** + **2 Firebase SA keys** + **AWS accessKey AKIAD2C822B77FCCD057** + **Azure AD secrets** — cross-platform keys never validated (out of current network scope).
- Jasypt ENC() — recoverable IF jasypt password found in code/env (open low-priority item).
