Agentic Testari Sentinel Hub · FriendlyAI agentictestari.com
Luottamuksellinen
L3 MAX Public-max · ei-tuhoava

Julkisen pinnan arviointi — Eficode

Marketing on Vercel/Next.js is modern (HSTS, nosniff). Material risk is public engineering/identity tooling on brand DNS: SonarQube with unauthenticated status/version, Bitwarden vault, Helix TeamHub, Jenkins 2.555.3,…

Kohde eficode.com Päivä 2026-07-29 RoE public-max · ei-tuhoava Engagement eng_eficode_l3_1358
7
HIGH
6
MED
0
INFO
OK

Johtoyhteenveto

Miksi toimia nyt

Nämä havainnot eivät ole teoreettisia: ne ovat julkisia pintoja. Jokaisessa kortissa on todiste, vaikutus, omistaja, korjaus ja validointi.

Jokainen havainto: ongelma, missä, vaikutus, omistaja, PoC, korjaus, validointi.

Marketing on Vercel/Next.js is modern (HSTS, nosniff). Material risk is public engineering/identity tooling on brand DNS: SonarQube with unauthenticated status/version, Bitwarden vault, Helix TeamHub, Jenkins 2.555.3, Jira OAuth edge, GlobaLeaks, and broken efitube hosts (502). True L3: HIGH 7 · MEDIUM 6.

Pinossa tässä ajossa

KomponenttiKäytössäHuom
ParviClaw Core + AWPKYLLÄ (lab)pack engagementissa
ParviSight browserosittainHTTP walk
PayBotFin Witness livesopimuksen mukaanrehellinen laajuus

Havainnot

Jokainen havainto: ongelma, missä, vaikutus, omistaja, PoC, korjaus, validointi.

EF-H1

Public SonarQube with unauthenticated system status/version

KORKEA
Ongelma

https://eficode.com/ — UI HTTP 200; /api/system/status returns JSON status:UP version 2025.5.0.113872. last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
Miten korjata

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

Miten validoida korjaus

Permanent recon + auth attack surface on engineering intel.

EF-H2

Public Bitwarden vault on brand DNS

KORKEA
Ongelma

https://eficode.com/ — Password-manager edge responds on brand DNS. last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
Miten korjata

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

Miten validoida korjaus

Continuous auth attacks against vault edge.

EF-H3

Public Helix TeamHub (source/collab)

KORKEA
Ongelma

https://eficode.com/ — Source/collaboration platform “Helix TeamHub” returns 200. last_reprobe=2026-07-31.

Public brand surface on eficode.com expands recon until closed.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public edge surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
Miten korjata

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

Miten validoida korjaus

Long-lived recon target.

EF-H4

Jenkins internet-facing

KORKEA
Ongelma

https://eficode.com/ response headers — Headers x-jenkins: 2.555.3; 403 root → login path 200 last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
Miten korjata

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

Miten validoida korjaus

Residual public exposure continues.

EF-H5

Jira auth edge public

KORKEA
Ongelma

https://eficode.com/ — HTTP 401 Unauthorized nginx — Jira/Atlassian-style edge online. last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
Miten korjata

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

Miten validoida korjaus

Persistent identity attacks.

EF-H6

GlobaLeaks whistleblow public

KORKEA
Ongelma

https://whistleblow.eficode.com serves GlobaLeaks. last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://whistleblow.eficode.com'
Miten korjata

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

Miten validoida korjaus

If misconfigured, sensitive reports at risk.

EF-H7

Broken public media hosts (502)

KORKEA
Ongelma

https://eficode.com/ — efitube / dev-efitube nginx 502 last_reprobe=2026-07-31.

Public brand surface on eficode.com expands recon until closed.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public edge surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
Miten korjata

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

Miten validoida korjaus

Residual public exposure continues.

EF-M1

CSP only frame-ancestors on www

KESKI
Ongelma

DNS TXT at _dmarc.eficode.com publishes a DMARC policy with p=none (monitor-only). Receiving servers do not quarantine/reject forged @eficode.com mail on DMARC fail. This is email brand spoofing / BEC risk, not a website bug. Proof: dig TXT _dmarc.eficode.com +short last_reprobe=2026-07-31.

Brand email spoofing / BEC remains easier while DMARC on eficode.com is not reject.

Missä

DNS record (not a website): _dmarc.eficode.com TXT
Mail domain: @eficode.com

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Forge invoices / IT resets as @eficode.com while p=none.
  • Agent (LLM+tools): Re-check DMARC; automate brand-domain spoof campaigns.
  • If invasive/destructive: Financial fraud via trusted-looking mail — not CMS takeover from this alone. L3 only proves DNS policy (dig).
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

dig TXT _dmarc.eficode.com +short
Miten korjata

Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.

Miten validoida korjaus

Re-run PoC from public internet until closed (eficode.com).

EF-M2

No security.txt

KESKI
Ongelma

Automated clients get 403 checkpoint — good bot friction, but hides marketing posture from scanners (including us). last_reprobe=2026-07-31.

Public brand surface on eficode.com expands recon until closed.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public edge surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
Miten korjata

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

Miten validoida korjaus

Re-run PoC from public internet until closed (eficode.com).

EF-M3

DMARC `p=quarantine` not reject

KESKI
Ongelma

DNS TXT at _dmarc.eficode.com publishes a DMARC policy with p=none (monitor-only). Receiving servers do not quarantine/reject forged @eficode.com mail on DMARC fail. This is email brand spoofing / BEC risk, not a website bug. Proof: dig TXT _dmarc.eficode.com +short last_reprobe=2026-07-31.

Brand email spoofing / BEC remains easier while DMARC on eficode.com is not reject.

Missä

DNS record (not a website): _dmarc.eficode.com TXT
Mail domain: @eficode.com

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Forge invoices / IT resets as @eficode.com while p=none.
  • Agent (LLM+tools): Re-check DMARC; automate brand-domain spoof campaigns.
  • If invasive/destructive: Financial fraud via trusted-looking mail — not CMS takeover from this alone. L3 only proves DNS policy (dig).
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

dig TXT _dmarc.eficode.com +short
Miten korjata

Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.

Miten validoida korjaus

Re-run PoC from public internet until closed (eficode.com).

EF-M4

Brand DNS maps corp stack

KESKI
Ongelma

intra, it, jira, netsuite, eficloud, invoicing, atlassian.consulting, etc. (surface: https://eficode.com/). last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
Miten korjata

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

Miten validoida korjaus

Re-run PoC from public internet until closed (eficode.com).

EF-M5

eficloud public Nextcloud login

KESKI
Ongelma

302 → `/login`; Apache + NC cookies (surface: https://eficode.com/). last_reprobe=2026-07-31.

Public brand surface on eficode.com expands recon until closed.

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public edge surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
Miten korjata

Remove unnecessary public hosts on eficode.com DNS or enforce strong auth/WAF; re-test from internet.

Miten validoida korjaus

Re-run PoC from public internet until closed (eficode.com).

EF-M6

Shared engineering IP for Sonar/TeamHub/Jenkins

KESKI
Ongelma

UI HTTP 200; /api/system/status returns JSON status:UP version 2025.5.0.113872. last_reprobe=2026-07-31.

Public engineering/tooling yields free recon (versions, configs, APIs).

Mitä hyökkääjä tai agentti-hakkeri voi tehdä
  • Human: Public eng surface on eficode.com expands attacker recon.
  • Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
  • If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Kenen vastuulla

Eficode — turva / tuote / infra (vahvista omistaja)

PoC (todiste — ei korjaa)

Read-only. Does not change the system.

curl -sSI 'https://eficode.com/'
Miten korjata

Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on eficode.com.

Miten validoida korjaus

Re-run PoC from public internet until closed (eficode.com).

Liitteet (AWP + Core)

Oikea pack L3 max retestistä 2026-07-31 (public-max, ei-tuhoava). Jokaisella tiedostolla on kuvateksti.

1) awp-receipt.json — AWP-krypto

Mikä se on: allekirjoitettu Agent Witness Protocol -kuitti (offline-tarkistettava).
Mitä se todistaa: meidän testi-/engagement-lokimme eheyden.
Mitä se EI ole: ei yksin todista bugia hostissanne (se on kunkin havainnon PoC).
→ lataa awp-receipt.json

2) leaves.jsonl — engagement-päiväkirja

→ lataa leaves.jsonl · leaf-chain.txt (PASS)

3) retest-raw.json — HTTP-probet

→ lataa retest-raw.json

4) agentic-walk.json + core-export

agentic-walk.json · core-export.json · kansio

Miten AWP:ta käytetään / varmennetaan (open-source)

npx agent-witness-protocol verify awp-receipt.json

PASS (rehellisesti): kuitin allekirjoitus ja Merkle-todiste ok — testiloki on ehjä.
PASS ei tarkoita: että tuotantobugi on korjattu, tai että PayBotFin live-witness oli käytössä (local_awp_dev / DEV_LAB).

Korjausjärjestys tiimille

  1. Sulje HIGH-julkiset altistukset ensin (auth / VPN / DNS).
  2. Korjaa MEDIUM-otsikot, postikäytäntö ja non-prod.
  3. Uudelleentestaa PoC:t julkisesta netistä kunnes kiinni.
  4. Arkistoi AWP/evidence auditointia ja retestiä varten.