🔒 TEASER — preview · HIGH detail + PoC + impact in FULL
Agentic Testari Sentinel Hub · FriendlyAI agentictestari.com
Confidential
TEASER L3 preview · unlock FULL

Academia Lendária L3 — teaser preview

4 HIGH · 10 MEDIUM. Severe risks are on the public surface. This teaser shows counts and titles. The FULL report unlocks proof links, attacker/agent impact, owner, PoC, fix, and va

Target academialendaria.ai Date 2026-07-29 RoE public-max Mode TEASER
4
HIGH
10
MEDIUM
0
INFO
OK

Summary (teaser)

This is not “just a technical PDF”

A hacker uses these findings as a map. A hacker agent runs the same playbook in a 24/7 loop. Teaser = severity. FULL = proof + impact + fix.

recon → invasion → destructive · detail in FULL

Severe risks are on the public surface. This teaser shows counts and titles. The FULL report unlocks proof links, attacker/agent impact, owner, PoC, fix, and validation — so the team acts.

Stack in this run

ComponentIncluded?Note
Sentinel L3YESpublic-max
ParviClaw Core + AWPYES (lab)full pack in FULL
ParviSightpartialas run
PayBotFin Witnessas engagedhonest scope in FULL

HIGH findings — locked in teaser

AL-H1

Grafana with public metrics (no authentication)

HIGH
🔒 Impact · link · PoC · owner · fix in FULL
AL-H2

SSH port 22 open on portal server

HIGH
🔒 Impact · link · PoC · owner · fix in FULL
AL-H3

Impersonation provider advertised in Auth.js

HIGH
🔒 Impact · link · PoC · owner · fix in FULL
AL-H4

Grafana UI on brand DNS

HIGH
🔒 Impact · link · PoC · owner · fix in FULL

MEDIUM findings — short preview

AL-M1

CSP report-only with unsafe scripts

MEDIUM
Preview

www sends Content-Security-Policy only as report-only (does not block), still allowing inline scripts, eval, GTM and Facebook. Full impact, PoC, owner and fix → FULL report.

AL-M2

CORS open to any origin (*)

MEDIUM
Preview

All www responses advertise Access-Control-Allow-Origin: *. Lower risk on static pages, noisy and dangerous if authenticated APIs share the origin. Full impact, PoC, owner and fix → FULL report.

AL-M3

TLS cert shared with igorrover.com.br

MEDIUM
Preview

Certificate CN is portal.igorrover.com.br; SAN includes portal and cal of academialendaria.ai and igorrover.com.br. Full impact, PoC, owner and fix → FULL report.

AL-M4

Public portal health endpoint

MEDIUM
Preview

/api/health returns anonymous JSON with schema status — useful for recon. Full impact, PoC, owner and fix → FULL report.

AL-M5

Public Prometheus hostname (basic auth)

MEDIUM
Preview

prometheus.academialendaria.ai asks for user/password (better than Grafana) but remains brand-DNS attack surface. Full impact, PoC, owner and fix → FULL report.

AL-M6

Messy / malformed CAA records

MEDIUM
Preview

Multiple certificate issuers and malformed values (e.g. duplicated “issuewild” text). Full impact, PoC, owner and fix → FULL report.

AL-M7

Unknown paths return HTTP 502

MEDIUM
Preview

Vercel edge returns 502 with DNS_HOSTNAME_NOT_FOUND on many missing routes. Not a secret leak, but broken hygiene. Full impact, PoC, owner and fix → FULL report.

AL-M8

Apex HSTS weaker than www

MEDIUM
Preview

Apex redirect lacks includeSubDomains and preload present on www. Full impact, PoC, owner and fix → FULL report.

AL-M9

Brand DNS pointing to n8n

MEDIUM
Preview

n8n.academialendaria.ai resolves; HTTPS timed out this run (possible firewall). Still public inventory. Full impact, PoC, owner and fix → FULL report.

AL-M10

Supabase allowed in CSP connect-src

MEDIUM
Preview

Browser may talk to *.supabase.co. Ensure only intended anon key and RLS — no service key in client. Full impact, PoC, owner and fix → FULL report.

AWP + Core annexes (preview)

In FULL each file has captions (what it is / what it proves / what it is not) + how to run npx agent-witness-protocol verify.

In the FULL report
Open FULL report
🔒 Remediation order + PoCs + fix validation
In the FULL report
Unlock FULL