Agentic Testari Sentinel Hub · FriendlyAI agentictestari.com
Luottamuksellinen
L3 MAX Public-max · ei-tuhoava

Julkisen pinnan arviointi — Digia

HubSpot/Cloudflare marketing. Identity is the story: public Citrix ADC/Gateway, Entra SAML channels, admin SPAs, plus weak DMARC. True L3: HIGH 6 · MEDIUM 5.

Kohde digia.com Päivä 2026-07-29 RoE public-max · ei-tuhoava Engagement eng_digia_l3_1358
6
HIGH
5
MED
0
INFO
OK

Johtoyhteenveto

Miksi toimia nyt

Nämä havainnot eivät ole teoreettisia: ne ovat julkisia pintoja. Jokaisessa kortissa on todiste, vaikutus, omistaja, korjaus ja validointi.

Jokainen havainto: ongelma, missä, vaikutus, omistaja, PoC, korjaus, validointi.

HubSpot/Cloudflare marketing. Identity is the story: public Citrix ADC/Gateway, Entra SAML channels, admin SPAs, plus weak DMARC. True L3: HIGH 6 · MEDIUM 5.

Pinossa tässä ajossa

KomponenttiKäytössäHuom
ParviClaw Core + AWPKYLLÄ (lab)pack engagementissa
ParviSight browserosittainHTTP walk
PayBotFin Witness livesopimuksen mukaanrehellinen laajuus

Havainnot

Jokainen havainto: ongelma, missä, vaikutus, omistaja, PoC, korjaus, validointi.

DG-H1

Citrix NetScaler/ADC Gateway (login.digia.com)

KORKEA
Ongelma

https://digia.com/ — What / evidence: Live 200 title “NetScaler AAA”; Citrix LogonPoint fingerprints confirmed 2026-07-29. Fix: Patch/MFA; shrink public gateway; prefer allowlists last_reprobe=2026-07-31.

Internet-facing remote-access edge is a permanent high-value target.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Internet-facing remote-access edge is a permanent high-value target.
  • Agent (LLM+tools): Fingerprint appliance; CVE watch; clone login UX.
  • If invasive/destructive: Closer to internal network than marketing CMS. L3 only proves public exposure.
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://digia.com/'
Miten korjata

Patch appliance, enforce MFA + conditional access; prefer private/VPN allowlist; monitor CVE feeds.

Miten validoida korjaus

Exposure remains until closed.

DG-H2

DMARC p=none

KORKEA
Ongelma

DNS TXT at _dmarc.digia.com publishes a DMARC policy with p=none (monitor-only). Receiving servers do not quarantine/reject forged @digia.com mail on DMARC fail. This is email brand spoofing / BEC risk, not a website bug. Proof: dig TXT _dmarc.digia.com +short last_reprobe=2026-07-31.

Brand email spoofing / BEC remains easier while DMARC on digia.com is not reject.

Missä

DNS record (not a website): _dmarc.digia.com TXT
Mail domain: @digia.com

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Forge invoices / IT resets as @digia.com while p=none.
  • Agent (LLM+tools): Re-check DMARC; automate brand-domain spoof campaigns.
  • If invasive/destructive: Financial fraud via trusted-looking mail — not CMS takeover from this alone. L3 only proves DNS policy (dig).
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

dig TXT _dmarc.digia.com +short
Miten korjata

Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.

Miten validoida korjaus

Brand spoofing of @digia.com stays easy forever.

DG-H3

Entra SAML channel hosts

KORKEA
Ongelma

What / evidence: https://channel.digia.com + channel-test.digia.com both 200 public. Fix: Remove test host; CA/VPN; review app regs last_reprobe=2026-07-31.

Public auth/federation edges expand phishing and IdP attack surface.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public auth surface on digia.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://channel.digia.com'
Miten korjata

Remove non-prod auth edges from public DNS; prefer auth code+PKCE; conditional access; minimize public metadata where possible.

Miten validoida korjaus

Exposure remains until closed.

DG-H4

Center hosts throw Shibboleth config errors

KORKEA
Ongelma

What / evidence: https://center.digia.com + centerstaging.digia.com → HTTP 500 shibsp::ConfigurationException (live). Fix: Fix or de-publicize last_reprobe=2026-07-31.

Public auth/federation edges expand phishing and IdP attack surface.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public auth surface on digia.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://center.digia.com'
Miten korjata

Remove non-prod auth edges from public DNS; prefer auth code+PKCE; conditional access; minimize public metadata where possible.

Miten validoida korjaus

Exposure remains until closed.

DG-H5

DFAU admin/backend public SPAs

KORKEA
Ongelma

What / evidence: https://admin.dfau.digia.com 200; backend.dfau.digia.com 200 “React App”. Fix: SSO + allowlist or private DNS last_reprobe=2026-07-31.

Public brand surface on digia.com expands recon until closed.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public edge surface on digia.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://admin.dfau.digia.com'
Miten korjata

Remove unnecessary public hosts on digia.com DNS or enforce strong auth/WAF; re-test from internet.

Miten validoida korjaus

Exposure remains until closed.

DG-H6

Public non-prod/staging estate

KORKEA
Ongelma

Examples: https://centerstaging.digia.com (Apache 302), center.digia.com, historical annualreport*, digialab/dev signals in DNS. last_reprobe=2026-07-31.

Public brand surface on digia.com expands recon until closed.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public edge surface on digia.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://centerstaging.digia.com'
Miten korjata

Remove unnecessary public hosts on digia.com DNS or enforce strong auth/WAF; re-test from internet.

Miten validoida korjaus

Continuous recon gift; staging credential reuse risk.

DG-M1

Thin marketing CSP

KESKI
Ongelma

upgrade-insecure-requests only on brochure (surface: https://digia.com/). last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public headers surface on digia.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://digia.com/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Miten korjata

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://digia.com/.

Miten validoida korjaus

Re-run PoC from public internet until closed (digia.com).

DG-M2

No security.txt / CAA gaps

KESKI
Ongelma

disclosure + issuance policy missing (surface: https://digia.com/). last_reprobe=2026-07-31.

Public brand surface on digia.com expands recon until closed.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public edge surface on digia.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://digia.com/'
Miten korjata

Remove unnecessary public hosts on digia.com DNS or enforce strong auth/WAF; re-test from internet.

Miten validoida korjaus

Re-run PoC from public internet until closed (digia.com).

DG-M3

Missing nosniff/XFO samples

KESKI
Ongelma

header baseline incomplete on marketing (surface: https://digia.com/). last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public headers surface on digia.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://digia.com/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Miten korjata

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://digia.com/.

Miten validoida korjaus

Re-run PoC from public internet until closed (digia.com).

DG-M4

Extra edge ports / scan noise

KESKI
Ongelma

historical 8080/8443-style listeners (surface: https://digia.com/). last_reprobe=2026-07-31.

Public brand surface on digia.com expands recon until closed.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public edge surface on digia.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://digia.com/'
Miten korjata

Remove unnecessary public hosts on digia.com DNS or enforce strong auth/WAF; re-test from internet.

Miten validoida korjaus

Re-run PoC from public internet until closed (digia.com).

DG-M5

Third-party chat/bot IDs

KESKI
Ongelma

Leadoo/HubSpot recon surface (surface: https://digia.com/). last_reprobe=2026-07-31.

Public brand surface on digia.com expands recon until closed.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public edge surface on digia.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Digia — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://digia.com/'
Miten korjata

Remove unnecessary public hosts on digia.com DNS or enforce strong auth/WAF; re-test from internet.

Miten validoida korjaus

Re-run PoC from public internet until closed (digia.com).

Liitteet (AWP + Core)

Oikea pack L3 max retestistä 2026-07-31 (public-max, ei-tuhoava). Jokaisella tiedostolla on kuvateksti.

1) awp-receipt.json — AWP-krypto

Mikä se on: allekirjoitettu Agent Witness Protocol -kuitti (offline-tarkistettava).
Mitä se todistaa: meidän testi-/engagement-lokimme eheyden.
Mitä se EI ole: ei yksin todista bugia hostissanne (se on kunkin havainnon PoC).
→ lataa awp-receipt.json

2) leaves.jsonl — engagement-päiväkirja

→ lataa leaves.jsonl · leaf-chain.txt (PASS)

3) retest-raw.json — HTTP-probet

→ lataa retest-raw.json

4) agentic-walk.json + core-export

agentic-walk.json · core-export.json · kansio

Miten AWP:ta käytetään / varmennetaan (open-source)

npx agent-witness-protocol verify awp-receipt.json

PASS (rehellisesti): kuitin allekirjoitus ja Merkle-todiste ok — testiloki on ehjä.
PASS ei tarkoita: että tuotantobugi on korjattu, tai että PayBotFin live-witness oli käytössä (local_awp_dev / DEV_LAB).

Korjausjärjestys tiimille

  1. Sulje HIGH-julkiset altistukset ensin (auth / VPN / DNS).
  2. Korjaa MEDIUM-otsikot, postikäytäntö ja non-prod.
  3. Uudelleentestaa PoC:t julkisesta netistä kunnes kiinni.
  4. Arkistoi AWP/evidence auditointia ja retestiä varten.