Agentic Testari Sentinel Hub · FriendlyAI agentictestari.com
Luottamuksellinen
L3 MAX Public-max · ei-tuhoava

Julkisen pinnan arviointi — CGI

Enterprise marketing edge. Strong email; CSP quality is the main HIGH class (unsafe-inline/eval, polyfill.io, huge third-party allowlist) plus large internal-style DNS inventory. True L3: HIGH 3 · MEDIUM 3.

Kohde cgi.com Päivä 2026-07-29 RoE public-max · ei-tuhoava Engagement eng_cgi_l3_1358
3
HIGH
3
MED
0
INFO
OK

Johtoyhteenveto

Miksi toimia nyt

Nämä havainnot eivät ole teoreettisia: ne ovat julkisia pintoja. Jokaisessa kortissa on todiste, vaikutus, omistaja, korjaus ja validointi.

Jokainen havainto: ongelma, missä, vaikutus, omistaja, PoC, korjaus, validointi.

Enterprise marketing edge. Strong email; CSP quality is the main HIGH class (unsafe-inline/eval, polyfill.io, huge third-party allowlist) plus large internal-style DNS inventory. True L3: HIGH 3 · MEDIUM 3.

Pinossa tässä ajossa

KomponenttiKäytössäHuom
ParviClaw Core + AWPKYLLÄ (lab)pack engagementissa
ParviSight browserosittainHTTP walk
PayBotFin Witness livesopimuksen mukaanrehellinen laajuus

Havainnot

Jokainen havainto: ongelma, missä, vaikutus, omistaja, PoC, korjaus, validointi.

CG-H1

CSP unsafe-inline + unsafe-eval

KORKEA
Ongelma

https://cgi.com/ response headers — Production script-src includes 'unsafe-inline' and 'unsafe-eval' plus a very large host allowlist. last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public headers surface on cgi.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Cgi — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://cgi.com/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Miten korjata

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://cgi.com/.

Miten validoida korjaus

Any future XSS or compromised tag becomes high impact.

CG-H2

CSP trusts polyfill.io + broad CDNs

KORKEA
Ongelma

script-src includes https://polyfill.io (and other broad CDNs like unpkg, rawgit, jsdelivr). last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public headers surface on cgi.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Cgi — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://polyfill.io' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Miten korjata

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://cgi.com/.

Miten validoida korjaus

Silent malicious JS via “allowed” CDN.

CG-H3

Massive third-party script allowlist

KORKEA
Ongelma

https://cgi.com/ response headers — CSP permits analytics/ads/chat/marketing hosts at scale (HubSpot, ZoomInfo, Crazy Egg, Facebook, Bing, New Relic, Leadoo, Siteimprove, …). last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public headers surface on cgi.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Cgi — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://cgi.com/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Miten korjata

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://cgi.com/.

Miten validoida korjaus

Continuous supply-chain exposure.

CG-M1

Large Drupal/JS surface

KESKI
Ongelma

Public JS bundles under /sites/default/files/js/; multi-MB sitemap. (surface: https://cgi.com/). last_reprobe=2026-07-31.

Public brand surface on cgi.com expands recon until closed.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public edge surface on cgi.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Cgi — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://cgi.com/'
Miten korjata

Remove unnecessary public hosts on cgi.com DNS or enforce strong auth/WAF; re-test from internet.

Miten validoida korjaus

Re-run PoC from public internet until closed (cgi.com).

CG-M2

aide-dev.cgi.com public IIS 200

KESKI
Ongelma

CSP permits analytics/ads/chat/marketing hosts at scale (HubSpot, ZoomInfo, Crazy Egg, Facebook, Bing, New Relic, Leadoo, Siteimprove, …). last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public headers surface on cgi.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Cgi — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://aide-dev.cgi.com' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Miten korjata

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://cgi.com/.

Miten validoida korjaus

Re-run PoC from public internet until closed (cgi.com).

CG-M3

accel360 / appstore / brand edges public

KESKI
Ongelma

Production script-src includes 'unsafe-inline' and 'unsafe-eval' plus a very large host allowlist. last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public headers surface on cgi.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Cgi — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://cgi.com/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Miten korjata

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://cgi.com/.

Miten validoida korjaus

Re-run PoC from public internet until closed (cgi.com).

Liitteet (AWP + Core)

Oikea pack L3 max retestistä 2026-07-31 (public-max, ei-tuhoava). Jokaisella tiedostolla on kuvateksti.

1) awp-receipt.json — AWP-krypto

Mikä se on: allekirjoitettu Agent Witness Protocol -kuitti (offline-tarkistettava).
Mitä se todistaa: meidän testi-/engagement-lokimme eheyden.
Mitä se EI ole: ei yksin todista bugia hostissanne (se on kunkin havainnon PoC).
→ lataa awp-receipt.json

2) leaves.jsonl — engagement-päiväkirja

→ lataa leaves.jsonl · leaf-chain.txt (PASS)

3) retest-raw.json — HTTP-probet

→ lataa retest-raw.json

4) agentic-walk.json + core-export

agentic-walk.json · core-export.json · kansio

Miten AWP:ta käytetään / varmennetaan (open-source)

npx agent-witness-protocol verify awp-receipt.json

PASS (rehellisesti): kuitin allekirjoitus ja Merkle-todiste ok — testiloki on ehjä.
PASS ei tarkoita: että tuotantobugi on korjattu, tai että PayBotFin live-witness oli käytössä (local_awp_dev / DEV_LAB).

Korjausjärjestys tiimille

  1. Sulje HIGH-julkiset altistukset ensin (auth / VPN / DNS).
  2. Korjaa MEDIUM-otsikot, postikäytäntö ja non-prod.
  3. Uudelleentestaa PoC:t julkisesta netistä kunnes kiinni.
  4. Arkistoi AWP/evidence auditointia ja retestiä varten.