This machine presents a deliberately misconfigured Spring Boot application sitting behind HTTPS on port 443. The attack surface opened immediately with an exposed .git directory — reconstructing the source code with git-dumper revealed not only valid credentials but a non-standard IP trust header that was the only key to unlocking the actuator...