Agentic Testari Sentinel Hub · FriendlyAI agentictestari.com
Confidential
L3 MAX Public-max · non-destructive

Public surface assessment — Fennia

Fennia’s public marketing edge is modern Next.js on AWS CloudFront, CMS via Contentful, messaging via Salesforce Experience Cloud, and customer identity via Signicat (login.fennia.fi) plus Oma Fennia. No proven RCE/se…

Target fennia.fi Date 2026-07-29 RoE public-max · non-destructive Engagement eng_fennia_l3_1358
3
HIGH
5
MEDIUM
0
INFO
OK

Executive summary

Why act now

These findings are not theoretical: they are public surfaces a human or a hacker agent can consume today. Each card has proof links, impact, owner, fix, and validation — so the team takes risk seriously and acts.

Each finding includes: problem, where (clickable link), attacker/agent impact, owner, PoC (read-only), how to fix, and how to validate.

Fennia’s public marketing edge is modern Next.js on AWS CloudFront, CMS via Contentful, messaging via Salesforce Experience Cloud, and customer identity via Signicat (login.fennia.fi) plus Oma Fennia. No proven RCE/secret-key dump on pure public surface. Residual L3 risk is still material: DMARC p=none, production CSP with unsafe-inline/eval and non-prod hosts, and a public HTTP Basic dev edge (fefidev.aws.fennia.fi). True L3: HIGH 3 · MEDIUM 5.

Stack in this run

ComponentUsedNote
ParviClaw Core + AWPYES (lab)full pack on engagement
ParviSight browserpartialHTTP walk / agentic
PayBotFin Witness liveas engagedhonest scope in annex

Findings

Each finding includes: problem, where (clickable link), attacker/agent impact, owner, PoC (read-only), how to fix, and how to validate.

FE-H1

DMARC p=none

HIGH
The problem

DNS TXT _dmarc.fennia.fi live 2026-07-31: "v=DMARC1; p=none; rua=mailto:dmarcreports@fennia.fi". Policy p=none = monitor only; forged @fennia.fi not rejected on DMARC fail. Proof: dig TXT _dmarc.fennia.fi +short last_reprobe=2026-07-31.

Brand email spoofing / BEC remains easier while DMARC on fennia.fi is not reject.

Where

DNS record (not a website): _dmarc.fennia.fi TXT
Mail domain: @fennia.fi

What an attacker or hacker agent can do
  • Human: Forge invoices / IT resets as @fennia.fi while p=none.
  • Agent (LLM+tools): Re-check DMARC; automate brand-domain spoof campaigns.
  • If invasive/destructive: Financial fraud via trusted-looking mail — not CMS takeover from this alone. L3 only proves DNS policy (dig).
Who owns it

Fennia — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

dig TXT _dmarc.fennia.fi +short
How to fix

Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.

How to validate the fix

Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.

FE-H2

CSP allows unsafe-inline + unsafe-eval and embeds non-prod hosts

HIGH
The problem

Live CSP includes unsafe-*; Salesforce sb114/sb72/stagingnxt/prodcopy; fefidev/fefitest; http://localhost:3000; mixed http://cdn.evgnet.com last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

What an attacker or hacker agent can do
  • Human: Public headers surface on fennia.fi expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Fennia — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://cdn.evgnet.com' | egrep -i 'strict-transport|content-security|x-frame|x-content'
How to fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

How to validate the fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

FE-H3

Public dev host with HTTP Basic (fefidev)

HIGH
The problem

https://fefidev.aws.fennia.fi/ → 401 WWW-Authenticate: Basic + full production-like CSP last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

What an attacker or hacker agent can do
  • Human: Public headers surface on fennia.fi expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Fennia — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://fefidev.aws.fennia.fi/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
How to fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

How to validate the fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

FE-M1

Public /preview returns HTTP 500

MEDIUM
The problem

https://fefidev.aws.fennia.fi/ → 401 WWW-Authenticate: Basic + full production-like CSP last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

What an attacker or hacker agent can do
  • Human: Public headers surface on fennia.fi expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Fennia — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://fefidev.aws.fennia.fi/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
How to fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

How to validate the fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

FE-M2

HSTS only 7 days; apex 301 without HSTS

MEDIUM
The problem

https://fefidev.aws.fennia.fi/ → 401 WWW-Authenticate: Basic + full production-like CSP last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

What an attacker or hacker agent can do
  • Human: Public headers surface on fennia.fi expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Fennia — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://fefidev.aws.fennia.fi/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
How to fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

How to validate the fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

FE-M3

Brand-zone non-prod / analytics DNS public

MEDIUM
The problem

Live CSP includes unsafe-*; Salesforce sb114/sb72/stagingnxt/prodcopy; fefidev/fefitest; http://localhost:3000; mixed http://cdn.evgnet.com last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

What an attacker or hacker agent can do
  • Human: Public headers surface on fennia.fi expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Fennia — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://cdn.evgnet.com' | egrep -i 'strict-transport|content-security|x-frame|x-content'
How to fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

How to validate the fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

FE-M4

Fat SPF multi-vendor

MEDIUM
The problem

Live CSP includes unsafe-*; Salesforce sb114/sb72/stagingnxt/prodcopy; fefidev/fefitest; http://localhost:3000; mixed http://cdn.evgnet.com last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

What an attacker or hacker agent can do
  • Human: Public headers surface on fennia.fi expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Fennia — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://cdn.evgnet.com' | egrep -i 'strict-transport|content-security|x-frame|x-content'
How to fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

How to validate the fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

FE-M5

PUT/DELETE/PATCH return 200 HTML

MEDIUM
The problem

https://fefidev.aws.fennia.fi/ → 401 WWW-Authenticate: Basic + full production-like CSP last_reprobe=2026-07-31.

Weak browser security headers increase impact of XSS/clickjacking/MITM.

What an attacker or hacker agent can do
  • Human: Public headers surface on fennia.fi expands attacker recon.
  • Agent (LLM+tools): Keep surface in continuous recon.
  • If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Who owns it

Fennia — security / product / infrastructure (confirm internal owner)

PoC (proof — does not fix)

Read-only. Does not change the system.

curl -sSI 'https://fefidev.aws.fennia.fi/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
How to fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

How to validate the fix

Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.

Evidence annexes (AWP + Core)

Real pack from L3 max retest 2026-07-31 (public-max, non-destructive). Each file has a caption. Links open the artifact.

1) awp-receipt.json — AWP crypto

What it is: signed Agent Witness Protocol receipt (offline-verifiable).
What it proves: integrity of our test/engagement log.
What it is NOT: not alone proof of the bug on your host (that is each finding’s PoC).
→ download awp-receipt.json

2) leaves.jsonl — engagement diary

What it is: append-only leaves (scope, probes seal, catalog, quality, seal).
What it proves: timeline of this retest run.
→ download leaves.jsonl · leaf-chain.txt (PASS)

3) retest-raw.json — HTTP probes

What it is: status/headers/samples from public-max probes.
What it proves: what the internet saw during the run.
→ download retest-raw.json

4) agentic-walk.json — surface map

What it is: multi-page walk summary (URLs, sizes, forms).
→ download agentic-walk.json · core-export.json

5) folder

→ open full evidence folder · engagement eng_fennia_l3_retest_1361 · witness_mode local_awp_dev (DEV_LAB keys — not production ceremony).

How to use / verify AWP (open-source)

Client steps
  1. Download awp-receipt.json from the annex (or clone the evidence folder).
  2. On any machine with Node 18+:
# from the evidence folder
npx agent-witness-protocol verify awp-receipt.json

# or with local package
node /path/to/agent-witness-protocol/bin/awp.js verify awp-receipt.json

Honest PASS meaning: the receipt’s signature, Merkle inclusion, and checkpoint check out — the test log is intact.
PASS does NOT mean: your production bug is fixed, or that PayBotFin live network witness was used (this pack is local_awp_dev / DEV_LAB unless noted).

PayBotFin Witness: live network emit is optional and engagement-scoped. If not listed above as network_emit, do not claim live PayBot verification for this run.

Remediation order for the team

  1. Close HIGH public exposures first (auth / VPN / DNS / policy).
  2. Fix MEDIUM headers, mail policy, and non-prod exposure.
  3. Re-test every PoC from the public internet until closed.
  4. Archive AWP/evidence pack for audit and retest baseline.