Julkisen pinnan arviointi — CGI
Enterprise marketing edge. Strong email; CSP quality is the main HIGH class (unsafe-inline/eval, polyfill.io, huge third-party allowlist) plus large internal-style DNS inventory. True L3: HIGH 3 · MEDIUM 3.
Johtoyhteenveto
Miksi toimia nyt
Nämä havainnot eivät ole teoreettisia: ne ovat julkisia pintoja. Jokaisessa kortissa on todiste, vaikutus, omistaja, korjaus ja validointi.
Enterprise marketing edge. Strong email; CSP quality is the main HIGH class (unsafe-inline/eval, polyfill.io, huge third-party allowlist) plus large internal-style DNS inventory. True L3: HIGH 3 · MEDIUM 3.
Pinossa tässä ajossa
| Komponentti | Käytössä | Huom |
|---|---|---|
| ParviClaw Core + AWP | KYLLÄ (lab) | pack engagementissa |
| ParviSight browser | osittain | HTTP walk |
| PayBotFin Witness live | sopimuksen mukaan | rehellinen laajuus |
Havainnot
Jokainen havainto: ongelma, missä, vaikutus, omistaja, PoC, korjaus, validointi.
CSP unsafe-inline + unsafe-eval
KORKEAhttps://cgi.com/ response headers — Production script-src includes 'unsafe-inline' and 'unsafe-eval' plus a very large host allowlist. last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on cgi.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Cgi — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://cgi.com/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://cgi.com/.
Any future XSS or compromised tag becomes high impact.
CSP trusts polyfill.io + broad CDNs
KORKEAscript-src includes https://polyfill.io (and other broad CDNs like unpkg, rawgit, jsdelivr). last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on cgi.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Cgi — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://polyfill.io' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://cgi.com/.
Silent malicious JS via “allowed” CDN.
Massive third-party script allowlist
KORKEAhttps://cgi.com/ response headers — CSP permits analytics/ads/chat/marketing hosts at scale (HubSpot, ZoomInfo, Crazy Egg, Facebook, Bing, New Relic, Leadoo, Siteimprove, …). last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on cgi.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Cgi — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://cgi.com/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://cgi.com/.
Continuous supply-chain exposure.
Large Drupal/JS surface
KESKIPublic JS bundles under /sites/default/files/js/; multi-MB sitemap. (surface: https://cgi.com/). last_reprobe=2026-07-31.
Public brand surface on cgi.com expands recon until closed.
- Human: Public edge surface on cgi.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Cgi — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://cgi.com/'
Remove unnecessary public hosts on cgi.com DNS or enforce strong auth/WAF; re-test from internet.
Re-run PoC from public internet until closed (cgi.com).
aide-dev.cgi.com public IIS 200
KESKICSP permits analytics/ads/chat/marketing hosts at scale (HubSpot, ZoomInfo, Crazy Egg, Facebook, Bing, New Relic, Leadoo, Siteimprove, …). last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on cgi.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Cgi — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://aide-dev.cgi.com' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://cgi.com/.
Re-run PoC from public internet until closed (cgi.com).
accel360 / appstore / brand edges public
KESKIProduction script-src includes 'unsafe-inline' and 'unsafe-eval' plus a very large host allowlist. last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on cgi.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Cgi — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://cgi.com/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://cgi.com/.
Re-run PoC from public internet until closed (cgi.com).
Liitteet (AWP + Core)
Oikea pack L3 max retestistä 2026-07-31 (public-max, ei-tuhoava). Jokaisella tiedostolla on kuvateksti.
Mikä se on: allekirjoitettu Agent Witness Protocol -kuitti (offline-tarkistettava).
Mitä se todistaa: meidän testi-/engagement-lokimme eheyden.
Mitä se EI ole: ei yksin todista bugia hostissanne (se on kunkin havainnon PoC).
→ lataa awp-receipt.json
Miten AWP:ta käytetään / varmennetaan (open-source)
npx agent-witness-protocol verify awp-receipt.json
PASS (rehellisesti): kuitin allekirjoitus ja Merkle-todiste ok — testiloki on ehjä.
PASS ei tarkoita: että tuotantobugi on korjattu, tai että PayBotFin live-witness oli käytössä (local_awp_dev / DEV_LAB).
Korjausjärjestys tiimille
- Sulje HIGH-julkiset altistukset ensin (auth / VPN / DNS).
- Korjaa MEDIUM-otsikot, postikäytäntö ja non-prod.
- Uudelleentestaa PoC:t julkisesta netistä kunnes kiinni.
- Arkistoi AWP/evidence auditointia ja retestiä varten.