Academia Lendária L3 — teaser preview
4 HIGH · 10 MEDIUM. Severe risks are on the public surface. This teaser shows counts and titles. The FULL report unlocks proof links, attacker/agent impact, owner, PoC, fix, and va
Summary (teaser)
This is not “just a technical PDF”
A hacker uses these findings as a map. A hacker agent runs the same playbook in a 24/7 loop. Teaser = severity. FULL = proof + impact + fix.
recon → invasion → destructive · detail in FULLSevere risks are on the public surface. This teaser shows counts and titles. The FULL report unlocks proof links, attacker/agent impact, owner, PoC, fix, and validation — so the team acts.
Stack in this run
| Component | Included? | Note |
|---|---|---|
| Sentinel L3 | YES | public-max |
| ParviClaw Core + AWP | YES (lab) | full pack in FULL |
| ParviSight | partial | as run |
| PayBotFin Witness | as engaged | honest scope in FULL |
HIGH findings — locked in teaser
Grafana with public metrics (no authentication)
HIGHSSH port 22 open on portal server
HIGHImpersonation provider advertised in Auth.js
HIGHGrafana UI on brand DNS
HIGHMEDIUM findings — short preview
CSP report-only with unsafe scripts
MEDIUMwww sends Content-Security-Policy only as report-only (does not block), still allowing inline scripts, eval, GTM and Facebook. Full impact, PoC, owner and fix → FULL report.
CORS open to any origin (*)
MEDIUMAll www responses advertise Access-Control-Allow-Origin: *. Lower risk on static pages, noisy and dangerous if authenticated APIs share the origin. Full impact, PoC, owner and fix → FULL report.
TLS cert shared with igorrover.com.br
MEDIUMCertificate CN is portal.igorrover.com.br; SAN includes portal and cal of academialendaria.ai and igorrover.com.br. Full impact, PoC, owner and fix → FULL report.
Public portal health endpoint
MEDIUM/api/health returns anonymous JSON with schema status — useful for recon. Full impact, PoC, owner and fix → FULL report.
Public Prometheus hostname (basic auth)
MEDIUMprometheus.academialendaria.ai asks for user/password (better than Grafana) but remains brand-DNS attack surface. Full impact, PoC, owner and fix → FULL report.
Messy / malformed CAA records
MEDIUMMultiple certificate issuers and malformed values (e.g. duplicated “issuewild” text). Full impact, PoC, owner and fix → FULL report.
Unknown paths return HTTP 502
MEDIUMVercel edge returns 502 with DNS_HOSTNAME_NOT_FOUND on many missing routes. Not a secret leak, but broken hygiene. Full impact, PoC, owner and fix → FULL report.
Apex HSTS weaker than www
MEDIUMApex redirect lacks includeSubDomains and preload present on www. Full impact, PoC, owner and fix → FULL report.
Brand DNS pointing to n8n
MEDIUMn8n.academialendaria.ai resolves; HTTPS timed out this run (possible firewall). Still public inventory. Full impact, PoC, owner and fix → FULL report.
Supabase allowed in CSP connect-src
MEDIUMBrowser may talk to *.supabase.co. Ensure only intended anon key and RLS — no service key in client. Full impact, PoC, owner and fix → FULL report.
AWP + Core annexes (preview)
In FULL each file has captions (what it is / what it proves / what it is not) + how to run npx agent-witness-protocol verify.