Julkisen pinnan arviointi — Fennia
Fennian julkinen markkinointireuna on moderni Next.js AWS CloudFrontissa, CMS Contentful, viestintä Salesforce Experience Cloud, identiteetti Signicat (login.fennia.fi) ja Oma Fennia. Ei todistettua RCE/salaisuusvuoto…
Johtoyhteenveto
Miksi toimia nyt
Nämä havainnot eivät ole teoreettisia: ne ovat julkisia pintoja. Jokaisessa kortissa on todiste, vaikutus, omistaja, korjaus ja validointi.
Fennian julkinen markkinointireuna on moderni Next.js AWS CloudFrontissa, CMS Contentful, viestintä Salesforce Experience Cloud, identiteetti Signicat (login.fennia.fi) ja Oma Fennia. Ei todistettua RCE/salaisuusvuotoa puhtaalla julkisella pinnalla. L3-jäännösriski on silti olennainen: DMARC p=none, tuotannon CSP unsafe-inline/eval + non-prod hostit, ja julkinen HTTP Basic -dev-reuna (fefidev.aws.fennia.fi). True L3: HIGH 3 · MEDIUM 5.
Pinossa tässä ajossa
| Komponentti | Käytössä | Huom |
|---|---|---|
| ParviClaw Core + AWP | KYLLÄ (lab) | pack engagementissa |
| ParviSight browser | osittain | HTTP walk |
| PayBotFin Witness live | sopimuksen mukaan | rehellinen laajuus |
Havainnot
Jokainen havainto: ongelma, missä, vaikutus, omistaja, PoC, korjaus, validointi.
DMARC p=none
KORKEADNS TXT _dmarc.fennia.fi live 2026-07-31: "v=DMARC1; p=none; rua=mailto:dmarcreports@fennia.fi". Policy p=none = monitor only; forged @fennia.fi not rejected on DMARC fail. Proof: dig TXT _dmarc.fennia.fi +short last_reprobe=2026-07-31.
Brand email spoofing / BEC remains easier while DMARC on fennia.fi is not reject.
DNS record (not a website): _dmarc.fennia.fi TXT
Mail domain: @fennia.fi
- Human: Forge invoices / IT resets as
@fennia.fiwhilep=none. - Agent (LLM+tools): Re-check DMARC; automate brand-domain spoof campaigns.
- If invasive/destructive: Financial fraud via trusted-looking mail — not CMS takeover from this alone. L3 only proves DNS policy (dig).
Fennia — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
dig TXT _dmarc.fennia.fi +short
Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.
Forged @fennia.fi mail continues to pass receivers that only honor reject/quarantine.
CSP sallii unsafe-inline + unsafe-eval ja upottaa non-prod hosteja
KORKEALive CSP includes unsafe-*; Salesforce sb114/sb72/stagingnxt/prodcopy; fefidev/fefitest; http://localhost:3000; mixed http://cdn.evgnet.com last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on fennia.fi expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Fennia — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://cdn.evgnet.com' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.
Residual risk continues until remediated.
Julkinen dev-isäntä HTTP Basicilla (fefidev)
KORKEAhttps://fefidev.aws.fennia.fi/ → 401 WWW-Authenticate: Basic + full production-like CSP last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on fennia.fi expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Fennia — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://fefidev.aws.fennia.fi/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.
Residual risk continues until remediated.
Julkinen /preview palauttaa HTTP 500
KESKIhttps://fefidev.aws.fennia.fi/ → 401 WWW-Authenticate: Basic + full production-like CSP last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on fennia.fi expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Fennia — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://fefidev.aws.fennia.fi/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.
Re-run PoC from public internet until closed (fennia.fi).
HSTS vain 7 päivää; apex 301 ilman HSTS:ää
KESKIhttps://fefidev.aws.fennia.fi/ → 401 WWW-Authenticate: Basic + full production-like CSP last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on fennia.fi expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Fennia — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://fefidev.aws.fennia.fi/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.
Re-run PoC from public internet until closed (fennia.fi).
Brändivyöhykkeen non-prod / analytics DNS julkinen
KESKILive CSP includes unsafe-*; Salesforce sb114/sb72/stagingnxt/prodcopy; fefidev/fefitest; http://localhost:3000; mixed http://cdn.evgnet.com last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on fennia.fi expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Fennia — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://cdn.evgnet.com' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.
Re-run PoC from public internet until closed (fennia.fi).
Lihava SPF multi-vendor
KESKILive CSP includes unsafe-*; Salesforce sb114/sb72/stagingnxt/prodcopy; fefidev/fefitest; http://localhost:3000; mixed http://cdn.evgnet.com last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on fennia.fi expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Fennia — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://cdn.evgnet.com' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.
Re-run PoC from public internet until closed (fennia.fi).
PUT/DELETE/PATCH palauttavat 200 HTML
KESKIhttps://fefidev.aws.fennia.fi/ → 401 WWW-Authenticate: Basic + full production-like CSP last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on fennia.fi expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Fennia — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://fefidev.aws.fennia.fi/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://fennia.fi/.
Re-run PoC from public internet until closed (fennia.fi).
Liitteet (AWP + Core)
Oikea pack L3 max retestistä 2026-07-31 (public-max, ei-tuhoava). Jokaisella tiedostolla on kuvateksti.
Mikä se on: allekirjoitettu Agent Witness Protocol -kuitti (offline-tarkistettava).
Mitä se todistaa: meidän testi-/engagement-lokimme eheyden.
Mitä se EI ole: ei yksin todista bugia hostissanne (se on kunkin havainnon PoC).
→ lataa awp-receipt.json
Miten AWP:ta käytetään / varmennetaan (open-source)
npx agent-witness-protocol verify awp-receipt.json
PASS (rehellisesti): kuitin allekirjoitus ja Merkle-todiste ok — testiloki on ehjä.
PASS ei tarkoita: että tuotantobugi on korjattu, tai että PayBotFin live-witness oli käytössä (local_awp_dev / DEV_LAB).
Korjausjärjestys tiimille
- Sulje HIGH-julkiset altistukset ensin (auth / VPN / DNS).
- Korjaa MEDIUM-otsikot, postikäytäntö ja non-prod.
- Uudelleentestaa PoC:t julkisesta netistä kunnes kiinni.
- Arkistoi AWP/evidence auditointia ja retestiä varten.