# Vectors Summary — gitlab.vdss.com.vn / CGIS engagement
Date: 2026-08-17. Status: terminal (all reachable vectors exhausted; NETWORK SERVICE ceiling accepted per operator decision "C").
Scope note: two distinct entities in scope via credential reuse — Viet Dragon Securities (vdss, finance/securities) and CGIS (urban-planning GIS for ~30 VN provinces). Linked only by reused PG/GeoServer creds; NO network route between CGIS and vdss internal.

## SUCCESSFUL VECTORS (reached objective)

### Initial access
- **V1. Breach-cred reuse** — truonglt/1qaz@123 (WingsCloud ULP AUG-06) → GitLab instance admin (is_admin=True). Still VALID (OAuth revalidated 2026-08-17; .token glpat expired, OAuth path live).

### GitLab exploitation
- **V2. Runner-registration RCE** (GitLab 17.9.2) — POST /api/v4/user/runners {runner_type:instance_type} → glrt- token. RCE-primitive confirmed, then cleaned (runners=0). Evidence: L3_runner_rce.json.
- **V3. Full repo exfil + secret mining** — 91 repos (mirror, full history). 178 secret-hits across 52 repos: shared RSA private key (dace/vdoc/morning/vdss-cms/chon), 2x Firebase SA keys, Keycloak client-secrets, JWT secret, Azure secrets (bcy/FPT-akames MES), Gmail app-passwords, DB creds (word@YYYY@# pattern). Evidence: L4_fullclone_*.
- **V4. Supply-chain identification** — merchantx/ma-service = com.mbbank (MB Bank paygate backend) → host tier bumped to S. Evidence: L2/L4.

### Direct data access (no pivot needed)
- **V5. VDSS prod DB exfil** (103.149.99.107:2903, PostgreSQL 17.10, LIVE PROD) — 4/4 DBs dumped + restore-verified (row-parity + sha256): dace (MES: 19 users+hashes, 16 customers, orders/payments), morning (3.5k financial txns), eform, mail_system (SUPERUSER; password-reset mails = PII). Maximal external exfil. Evidence: L4_prod_db_exfil.json + exfil/*.sql.
- **V6. CGIS PG SUPERUSER** (postgres/Ctech2022!@#) on 14.225.11.8/.57 (+.28) — census of 111 DBs; miwiz/miwiz2024 = 3k+ end-user PII (1344+1742 users). Read-only census (exfil not pursued). Evidence: L6_cgis_*.
- **V7. PG superuser → OS RCE** (COPY FROM PROGRAM) — NT AUTHORITY\NETWORK SERVICE on .57/.8/.28. Evidence: L5/L6.
- **V8. GeoServer admin** (admin:Ctech@123!) on geo3.cgis.asia + geo.cgis.asia (cred reuse; also admin:geoserver on some). Evidence: L5/L6.

## VECTORS CONSIDERED AND CLOSED (failed / unreachable)

### GeoServer RCE (14.225.11.57, GeoServer 2.13.2)
- **V9. SQL view RCE** — FAILED (not executing, 0 features).
- **V10. JSP upload** — FAILED (Wicket app, JSP returned as text, not executed).
- **V11. WPS** — FAILED (404, not installed).
- **V12. Scripting extension** — FAILED (not present).
- **V13. SLD RCE** — FAILED (uploaded, not executed).
- (File-write to resource/data_dir/logs = SUCCESS but not web-reachable.)

### MSSQL$SQLEXPRESS14 (14.225.11.57, SQL Server 2014 Express)
- **V14. Windows auth (NETWORK SERVICE)** — connects but maps to 'guest' (no privileges, not sysadmin).
- **V15. sa password guessing** (8 candidates incl. reused Ctech*) — all 'Login failed'.
- **V16. Local app usage** — none found; all 57 GeoServer datastores + all web.config/appsettings = PostgreSQL-only. MSSQL is standalone/externally-hit (brute-force observed from 149.202.215.16, 185.93.89.154). Code-exec vector CLOSED.

### Lateral movement (between Windows hosts)
- **V17. SMB/WMI/PSRemoting** — denied between hosts (since L5).
- **V18. Web→OS password reuse (.57)** — 11 ValidateCredentials (geoserver/adminx/iop/Administrator x known pw) all False.

### Privilege escalation to SYSTEM
- **V19. Potato (PrintSpoofer/GodPotato)** — NOT pursued: KES 14.0 + klnagent (KSC central agent) → stock binary = burned (central alert). Spooler RUNNING (PrintSpoofer technically applicable) but needs custom unsigned build. Deferred per operator decision "C".
- **V20. Nexus unquoted-path privesc (.28)** — nexus.exe LocalSystem, C:\TamDT writable, but requires service restart (uncontrolled). Deferred.

### Pivot to vdss core
- **V21. Runner-pivot to internal DB (172.31.2.15, 10.215.102.41)** — INFEASIBLE: read-only TCP probe from BOTH .57 and .8 → NO ROUTE from CGIS net (14.225.11.0/24) to vdss internal. A CI runner executes on its registration host; our only runner-hosts are in CGIS net. Evidence: L6_runner_pivot_feasibility.json, L6_connectivity_probe.txt.
- **V22. Allowlist-prod DB (14.225.5.225 cms_vdss_live, 211.188.52.92 chondb)** — IP-allowlist filtered (TCP timeout x2); runner pivot does not help (same egress in reverse).

## RANSOM MODEL (assessed)
- **V23. Disk encryption** — infeasible (no SYSTEM, KES14+KSC, no vdss-internal access).
- **V24. Backup destruction** — infeasible (VSS admin-only — vssadmin perm error confirmed; Veeam absent on .57/.8). Evidence: L6_backup_recon.json.
- **V25. DB-level destruction (DROP DATABASE via superuser)** — technically possible (111 DBs), and .8 has no WAL archiving / PITR (archive_mode=off, wal_level=minimal), BUT reversibility UNCONFIRMED (victim may hold offline/VM snapshots we cannot reach).
- **V26. Leak-extortion** — the only RELIABLE ransom vector: GitLab source + MB Bank keys (V3/V4), vdss prod PII/financial (V5), CGIS miwiz PII (V6). Independent of backups entirely.

## BOTTOM LINE
- 8 successful, 14 closed, 4 ransom-modelled.
- Deepest reaches: verified LIVE vdss prod exfil (V5) + GitLab instance-admin/RCE (V2) + CGIS SUPERUSER census (V6).
- Hard ceiling: no SYSTEM on Windows (KES14+KSC), no route to vdss internal network. Both accepted / confirmed-infeasible.
- Reliable ransom leverage = leak-extortion only (double-extortion via stolen source+keys+PII), not encryption/destruction.
