Agentic Testari Sentinel Hub · FriendlyAI agentictestari.com
Confidential
L3 MAX Public-max · non-destructive

Public surface assessment — Eficode

Marketing on Vercel/Next.js is modern (HSTS, nosniff). Material risk is public engineering/identity tooling on brand DNS: SonarQube with unauthenticated status/version, Bitwarden vault, Helix TeamHub, Jenkins 2.555.3,…

Target eficode.com Date 2026-07-29 RoE public-max · non-destructive Engagement eng_eficode_l3_1358
7
HIGH
6
MEDIUM
0
INFO
OK

Executive summary

Why act now

These findings are not theoretical: they are public surfaces a human or a hacker agent can consume today. Each card has proof links, impact, owner, fix, and validation — so the team takes risk seriously and acts.

Each finding includes: problem, where (clickable link), attacker/agent impact, owner, PoC (read-only), how to fix, and how to validate.

Marketing on Vercel/Next.js is modern (HSTS, nosniff). Material risk is public engineering/identity tooling on brand DNS: SonarQube with unauthenticated status/version, Bitwarden vault, Helix TeamHub, Jenkins 2.555.3, Jira OAuth edge, GlobaLeaks, and broken efitube hosts (502). True L3: HIGH 7 · MEDIUM 6.

Stack in this run

ComponentUsedNote
ParviClaw Core + AWPYES (lab)full pack on engagement
ParviSight browserpartialHTTP walk / agentic
PayBotFin Witness liveas engagedhonest scope in annex

Findings

Each finding includes: problem, where (clickable link), attacker/agent impact, owner, PoC (read-only), how to fix, and how to validate.

EF-H1

Public SonarQube with unauthenticated system status/version

HIGH
The problem

https://eficode.com/ — UI HTTP 200; /api/system/status returns JSON status:UP version 2025.5.0.113872. last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

What an attacker or hacker agent can do
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
How to fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

How to validate the fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

EF-H2

Public Bitwarden vault on brand DNS

HIGH
The problem

https://eficode.com/ — Password-manager edge responds on brand DNS. last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

What an attacker or hacker agent can do
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
How to fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

How to validate the fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

EF-H3

Public Helix TeamHub (source/collab)

HIGH
The problem

https://eficode.com/ — Source/collaboration platform “Helix TeamHub” returns 200. last_reprobe=2026-07-31.

Public brand surface on eficode.com expands recon until closed.

What an attacker or hacker agent can do
  • Human: Public edge surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
How to fix

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

How to validate the fix

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

EF-H4

Jenkins internet-facing

HIGH
The problem

https://eficode.com/ response headers — Headers x-jenkins: 2.555.3; 403 root → login path 200 last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

What an attacker or hacker agent can do
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
How to fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

How to validate the fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

EF-H5

Jira auth edge public

HIGH
The problem

https://eficode.com/ — HTTP 401 Unauthorized nginx — Jira/Atlassian-style edge online. last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

What an attacker or hacker agent can do
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
How to fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

How to validate the fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

EF-H6

GlobaLeaks whistleblow public

HIGH
The problem

https://whistleblow.eficode.com serves GlobaLeaks. last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

What an attacker or hacker agent can do
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://whistleblow.eficode.com'
How to fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

How to validate the fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

EF-H7

Broken public media hosts (502)

HIGH
The problem

https://eficode.com/ — efitube / dev-efitube nginx 502 last_reprobe=2026-07-31.

Public brand surface on eficode.com expands recon until closed.

What an attacker or hacker agent can do
  • Human: Public edge surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
How to fix

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

How to validate the fix

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

EF-M1

CSP only frame-ancestors on www

MEDIUM
The problem

DNS TXT at _dmarc.eficode.com publishes a DMARC policy with p=none (monitor-only). Receiving servers do not quarantine/reject forged @eficode.com mail on DMARC fail. This is email brand spoofing / BEC risk, not a website bug. Proof: dig TXT _dmarc.eficode.com +short last_reprobe=2026-07-31.

Brand email spoofing / BEC remains easier while DMARC on eficode.com is not reject.

Where

DNS record (not a website): _dmarc.eficode.com TXT
Mail domain: @eficode.com

What an attacker or hacker agent can do
  • Human: Forge invoices / IT resets as @eficode.com while p=none.
  • Agent (LLM+tools): Re-check DMARC; automate brand-domain spoof campaigns.
  • If invasive/destructive: Financial fraud via trusted-looking mail — not CMS takeover from this alone. L3 only proves DNS policy (dig).
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

dig TXT _dmarc.eficode.com +short
How to fix

Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.

How to validate the fix

Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.

EF-M2

No security.txt

MEDIUM
The problem

Automated clients get 403 checkpoint — good bot friction, but hides marketing posture from scanners (including us). last_reprobe=2026-07-31.

Public brand surface on eficode.com expands recon until closed.

What an attacker or hacker agent can do
  • Human: Public edge surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
How to fix

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

How to validate the fix

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

EF-M3

DMARC `p=quarantine` not reject

MEDIUM
The problem

DNS TXT at _dmarc.eficode.com publishes a DMARC policy with p=none (monitor-only). Receiving servers do not quarantine/reject forged @eficode.com mail on DMARC fail. This is email brand spoofing / BEC risk, not a website bug. Proof: dig TXT _dmarc.eficode.com +short last_reprobe=2026-07-31.

Brand email spoofing / BEC remains easier while DMARC on eficode.com is not reject.

Where

DNS record (not a website): _dmarc.eficode.com TXT
Mail domain: @eficode.com

What an attacker or hacker agent can do
  • Human: Forge invoices / IT resets as @eficode.com while p=none.
  • Agent (LLM+tools): Re-check DMARC; automate brand-domain spoof campaigns.
  • If invasive/destructive: Financial fraud via trusted-looking mail — not CMS takeover from this alone. L3 only proves DNS policy (dig).
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

dig TXT _dmarc.eficode.com +short
How to fix

Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.

How to validate the fix

Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.

EF-M4

Brand DNS maps corp stack

MEDIUM
The problem

intra, it, jira, netsuite, eficloud, invoicing, atlassian.consulting, etc. (surface: https://eficode.com/). last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

What an attacker or hacker agent can do
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
How to fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

How to validate the fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

EF-M5

eficloud public Nextcloud login

MEDIUM
The problem

302 → `/login`; Apache + NC cookies (surface: https://eficode.com/). last_reprobe=2026-07-31.

Public brand surface on eficode.com expands recon until closed.

What an attacker or hacker agent can do
  • Human: Public edge surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
How to fix

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

How to validate the fix

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

EF-M6

Shared engineering IP for Sonar/TeamHub/Jenkins

MEDIUM
The problem

UI HTTP 200; /api/system/status returns JSON status:UP version 2025.5.0.113872. last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

What an attacker or hacker agent can do
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Who owns it

Eficode — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
How to fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

How to validate the fix

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

Evidence annexes (AWP + Core)

Real pack from L3 max retest 2026-07-31 (public-max, non-destructive). Each file has a caption. Links open the artifact.

1) awp-receipt.json — AWP crypto

What it is: signed Agent Witness Protocol receipt (offline-verifiable).
What it proves: integrity of our test/engagement log.
What it is NOT: not alone proof of the bug on your host (that is each finding’s PoC).
→ download awp-receipt.json

2) leaves.jsonl — engagement diary

What it is: append-only leaves (scope, probes seal, catalog, quality, seal).
What it proves: timeline of this retest run.
→ download leaves.jsonl · leaf-chain.txt (PASS)

3) retest-raw.json — HTTP probes

What it is: status/headers/samples from public-max probes.
What it proves: what the internet saw during the run.
→ download retest-raw.json

4) agentic-walk.json — surface map

What it is: multi-page walk summary (URLs, sizes, forms).
→ download agentic-walk.json · core-export.json

5) folder

→ open full evidence folder · engagement eng_eficode_l3_retest_1361 · witness_mode local_awp_dev (DEV_LAB keys — not production ceremony).

How to use / verify AWP (open-source)

Client steps
  1. Download awp-receipt.json from the annex (or clone the evidence folder).
  2. On any machine with Node 18+:
# from the evidence folder
npx agent-witness-protocol verify awp-receipt.json

# or with local package
node /path/to/agent-witness-protocol/bin/awp.js verify awp-receipt.json

Honest PASS meaning: the receipt’s signature, Merkle inclusion, and checkpoint check out — the test log is intact.
PASS does NOT mean: your production bug is fixed, or that PayBotFin live network witness was used (this pack is local_awp_dev / DEV_LAB unless noted).

PayBotFin Witness: live network emit is optional and engagement-scoped. If not listed above as network_emit, do not claim live PayBot verification for this run.

Remediation order for the team

  1. Close HIGH public exposures first (auth / VPN / DNS / policy).
  2. Fix MEDIUM headers, mail policy, and non-prod exposure.
  3. Re-test every PoC from the public internet until closed.
  4. Archive AWP/evidence pack for audit and retest baseline.