Julkisen pinnan arviointi — Twoday
Marketing + dual VPN were only part of the surface. True L3 finds AOS runtime secrets, Metis Chat Open WebUI, GitLab, Jira and more on brand DNS. HIGH 8 · MEDIUM 4.
Johtoyhteenveto
Miksi toimia nyt
Nämä havainnot eivät ole teoreettisia: ne ovat julkisia pintoja. Jokaisessa kortissa on todiste, vaikutus, omistaja, korjaus ja validointi.
Marketing + dual VPN were only part of the surface. True L3 finds AOS runtime secrets, Metis Chat Open WebUI, GitLab, Jira and more on brand DNS. HIGH 8 · MEDIUM 4.
Pinossa tässä ajossa
| Komponentti | Käytössä | Huom |
|---|---|---|
| ParviClaw Core + AWP | KYLLÄ (lab) | pack engagementissa |
| ParviSight browser | osittain | HTTP walk |
| PayBotFin Witness live | sopimuksen mukaan | rehellinen laajuus |
Havainnot
Jokainen havainto: ongelma, missä, vaikutus, omistaja, PoC, korjaus, validointi.
AOS prod/dev/staging + runtime-env secrets
KORKEAhttps://aos.twoday.com, aos-dev, aos-staging serve “Agentic Orchestration Studio”. Public /runtime-env.js leaks VITE_AZURE_CLIENT_ID, VITE_AZURE_TENANT_ID, and production VITE_SENTRY_DSN. last_reprobe=2026-07-31.
Public engineering/tooling yields free recon (versions, configs, APIs).
- Human: Public eng surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
- If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://aos.twoday.com'
Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on twoday.com.
Persistent identity and observability abuse.
Metis Chat Open WebUI public
KORKEAhttps://metis-chat.twoday.com (uvicorn) identifies as Open WebUI 0.10.2; /api/config returns JSON including Microsoft OAuth providers. last_reprobe=2026-07-31.
Public engineering/tooling yields free recon (versions, configs, APIs).
- Human: Public eng surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
- If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://metis-chat.twoday.com'
Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on twoday.com.
Continuous targeting of AI chat edge.
GitLab public (gitlab.fi.twoday.com)
KORKEAhttps://twoday.com/ — Redirects to /users/sign_in — GitLab is internet-facing. last_reprobe=2026-07-31.
Public engineering/tooling yields free recon (versions, configs, APIs).
- Human: Public eng surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
- If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://twoday.com/'
Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on twoday.com.
Permanent high-value target.
Jira public (jira.twoday.com)
KORKEAhttps://twoday.com/ response headers — JIRA 10.3.23 fingerprint; issues cookies/session headers on contact. last_reprobe=2026-07-31.
Public engineering/tooling yields free recon (versions, configs, APIs).
- Human: Public eng surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
- If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://twoday.com/'
Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on twoday.com.
Ongoing recon and auth attacks.
Insight Flow prod+dev public
KORKEAhttps://insightflow.twoday.com and insightflow.dev.twoday.com (Kestrel) return product UI. last_reprobe=2026-07-31.
Public brand surface on twoday.com expands recon until closed.
- Human: Public edge surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://insightflow.twoday.com'
Remove unnecessary public hosts on twoday.com DNS or enforce strong auth/WAF; re-test from internet.
Dev data/config leakage risk.
lut.twoday.com IIS 500
KORKEAhttps://twoday.com/ — Microsoft-IIS/10.0 Internal Server Error on brand host. last_reprobe=2026-07-31.
Public brand surface on twoday.com expands recon until closed.
- Human: Public edge surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://twoday.com/'
Remove unnecessary public hosts on twoday.com DNS or enforce strong auth/WAF; re-test from internet.
Noise + possible misconfig window.
Contracts Zefort public
KORKEAhttps://twoday.com/ — Contract UI (noindex) on brand DNS. last_reprobe=2026-07-31.
Public engineering/tooling yields free recon (versions, configs, APIs).
- Human: Public eng surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
- If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://twoday.com/'
Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on twoday.com.
Targeted attacks on contract workflows.
Thin marketing CSP
KORKEAhttps://twoday.com/ response headers — www CSP does not constrain scripts. last_reprobe=2026-07-31.
Weak browser security headers increase impact of XSS/clickjacking/MITM.
- Human: Public headers surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://twoday.com/' | egrep -i 'strict-transport|content-security|x-frame|x-content'
Add/tighten HSTS, CSP, XFO, nosniff, Referrer-Policy, Permissions-Policy on https://twoday.com/.
Deferred XSS risk.
DMARC quarantine not reject
KESKIDNS TXT at _dmarc.twoday.com publishes a DMARC policy with p=none (monitor-only). Receiving servers do not quarantine/reject forged @twoday.com mail on DMARC fail. This is email brand spoofing / BEC risk, not a website bug. Proof: dig TXT _dmarc.twoday.com +short last_reprobe=2026-07-31.
Brand email spoofing / BEC remains easier while DMARC on twoday.com is not reject.
DNS record (not a website): _dmarc.twoday.com TXT
Mail domain: @twoday.com
- Human: Forge invoices / IT resets as
@twoday.comwhilep=none. - Agent (LLM+tools): Re-check DMARC; automate brand-domain spoof campaigns.
- If invasive/destructive: Financial fraud via trusted-looking mail — not CMS takeover from this alone. L3 only proves DNS policy (dig).
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
dig TXT _dmarc.twoday.com +short
Align SPF/DKIM for all legitimate senders; move DMARC to p=quarantine then p=reject; monitor rua; document third-party senders.
Re-run PoC from public internet until closed (twoday.com).
Large product host estate
KESKIholidaybalancefinland, insights/Sociuu, metis, metis-docs-mcp, get.help Atlassian, etc. last_reprobe=2026-07-31.
Public engineering/tooling yields free recon (versions, configs, APIs).
- Human: Public eng surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Probe APIs/health in loops; correlate versions with CVEs.
- If invasive/destructive: Source/secrets/CI risk if auth weak later. L3 only proves public exposure.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://twoday.com/'
Remove from public DNS or require VPN/SSO; disable anonymous APIs; re-test from the public internet on twoday.com.
Re-run PoC from public internet until closed (twoday.com).
HubSpot sourcemaps
KESKISeveral hsstatic *.js.map downloadable. (surface: https://twoday.com/). last_reprobe=2026-07-31.
Public brand surface on twoday.com expands recon until closed.
- Human: Public edge surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://twoday.com/'
Remove unnecessary public hosts on twoday.com DNS or enforce strong auth/WAF; re-test from internet.
Re-run PoC from public internet until closed (twoday.com).
Permissions-Policy gaps
KESKIOther headers largely present; permissions-policy not observed. (surface: https://twoday.com/). last_reprobe=2026-07-31.
Public brand surface on twoday.com expands recon until closed.
- Human: Public edge surface on twoday.com expands attacker recon.
- Agent (LLM+tools): Keep surface in continuous recon.
- If invasive/destructive: Escalate if second bug/credential. L3 public-max is read-only.
Twoday — turva / tuote / infra (vahvista omistaja)
Read-only. Does not change the system.
curl -sSI 'https://twoday.com/'
Remove unnecessary public hosts on twoday.com DNS or enforce strong auth/WAF; re-test from internet.
Re-run PoC from public internet until closed (twoday.com).
Liitteet (AWP + Core)
Oikea pack L3 max retestistä 2026-07-31 (public-max, ei-tuhoava). Jokaisella tiedostolla on kuvateksti.
Mikä se on: allekirjoitettu Agent Witness Protocol -kuitti (offline-tarkistettava).
Mitä se todistaa: meidän testi-/engagement-lokimme eheyden.
Mitä se EI ole: ei yksin todista bugia hostissanne (se on kunkin havainnon PoC).
→ lataa awp-receipt.json
Miten AWP:ta käytetään / varmennetaan (open-source)
npx agent-witness-protocol verify awp-receipt.json
PASS (rehellisesti): kuitin allekirjoitus ja Merkle-todiste ok — testiloki on ehjä.
PASS ei tarkoita: että tuotantobugi on korjattu, tai että PayBotFin live-witness oli käytössä (local_awp_dev / DEV_LAB).
Korjausjärjestys tiimille
- Sulje HIGH-julkiset altistukset ensin (auth / VPN / DNS).
- Korjaa MEDIUM-otsikot, postikäytäntö ja non-prod.
- Uudelleentestaa PoC:t julkisesta netistä kunnes kiinni.
- Arkistoi AWP/evidence auditointia ja retestiä varten.