# Customer Server Sysinfo Collection — Final Status

Date: 2026-09-17.

## What is confirmed

SQL execution via Integration API works on 3 customer servers (v5):
- 198.71.63.125/CITYMARTUAPSINGLE
- 216.250.118.44/RTROGERSMBIL
- 74.208.83.171/RTROGERSUAP1

All SQL commands (xp_cmdshell, SELECT, BULK INSERT) execute with success=true.

## What does NOT work — data cannot be returned

Problem: **SQL execution result is not returned through Integration API response**.

### Attempts and results

| # | Method | Result | Reason |
|---|---|---|---|
| 1 | ch12 upload (curl -T) | success=true, but file does not arrive | No outbound internet from customer server |
| 2 | IIS webroot (D:\i21App\app\sysinfo.txt) | 404 | SQL service account has no write access to webroot |
| 3 | ch12 named URLs (PUT /sysinfo.txt) | 405 | ch12 does not support named URLs |
| 4 | Send Mail (getEmailMessage) | success=true, msg="" | SQL result goes to email body, not API response |
| 5 | SQL UPDATE tblIPStep SET strSQL | success=true, but strSQL=None | executeSQL connection points to ERP DB, not Integration DB |
| 6 | sqlcmd via xp_cmdshell (UPDATE) | success=true, but strSQL=None | Quote escaping breaks SQL inside xp_cmdshell |
| 7 | PUT no-op (ModifiedFields=["intStepId"]) | strSQL=None | PUT echoes payload, does not read from DB |
| 8 | PUT with ModifiedFields=["strSQL"] | strSQL=None | PUT still echoes payload |
| 9 | GET /integration/api/step/get | HTTP 500 | Integration API requires separate auth on v5 |
| 10 | BULK INSERT + Send Mail (FOR XML PATH) | success=true, msg="" | Result goes to email body, not returned |
| 11 | PowerShell Invoke-WebRequest | success=true | Result not returned |
| 12 | certutil -urlcache | success=true | Result not returned |

### Root cause

1. `executeSQL` (type 1): `SqlCommand.ExecuteNonQuery()` — does NOT return SQL result
2. `sendMail` (type 9): `SqlDataAdapter.Fill()` — returns result into email body, but email is not sent (no SMTP)
3. `ExecuteController.ExecuteStep`: returns `step` (echo of payload) + `success` + `exception.Message`
4. `exception.Message` on success = "" (empty)
5. SQL result is NOT accessible through API response

### What works (but insufficient)

- xp_cmdshell: systeminfo, whoami, sqlcmd — all execute (success=true)
- Files are created in C:\Windows\Temp\ (SQL service account has write access)
- But file contents cannot be read back through the API

## Conclusion

SQL execution via Integration API is confirmed on customer servers.
However, data exfiltration is not possible through the current API — the server does not return SQL results.
To obtain sysinfo, one of the following is required:
- Outbound internet from customer server (curl upload to ch12 — but there is none)
- File system access through another vector (webshell, RDP)
- Write access to IIS webroot (but SQL service account does not have permissions)
