mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-08 00:51:09 +02:00
fix: wildcard-target probe, per-run provenance, qwen via Hermes, broad default web objective
- Wildcard target from a scope-file (target: "*.nasa.gov") was probed literally → "builder error" / target unreachable. It's now reduced to the apex (https://nasa.gov) for the seed, while the scope keeps *.nasa.gov so subdomain enumeration stays authorized. (The /target command already did this; the engagement-file meta path didn't.) - Provenance was a OnceLock ("first run wins"), so in the REPL every run after the first minted markers and the provenance line with the FIRST run's id (nasa run showing a rockstargames id). Now a RwLock that rebinds per run — each engagement gets its own id; the build fingerprint stays stable. - Nous/Hermes: qwen3.8-max / qwen3.8-omni-flash added to the provider list so `nous:qwen3.8-max` routes qwen through the Hermes portal (model name passes through `hermes chat -m <model> --provider nous`). - Black-box `run` now gets a broad DEFAULT objective when none is set: a comprehensive WEB assessment grounded in OWASP Top 10 / ASVS / WSTG / CWE that traverses every applicable web vuln class then goes deep — web-only (this path loads only web vuln agents; mobile/binary are separate modes), so it never drifts into mobile/exe. 423 tests passing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
c2c6de1c3f
commit
101eca2700
5 files changed
+63
-21
No files matched your search
@@ -1925,8 +1925,9 @@ fn handle_provenance(cmd: ProvCmd) -> anyhow::Result<()> {
|
||||
}
|
||||
// A marker carrying this build's fingerprint came from this binary;
|
||||
// one that does not still came from NeuroSploit, just elsewhere.
|
||||
let mine = marks.iter().filter(|m| m.contains(&Provenance::process().build[..6])).count();
|
||||
println!(" \x1b[2m{mine} of them minted by this build ({}), the rest by another\x1b[0m", Provenance::process().build);
|
||||
let bld = Provenance::process().build;
|
||||
let mine = marks.iter().filter(|m| m.contains(&bld[..6.min(bld.len())])).count();
|
||||
println!(" \x1b[2m{mine} of them minted by this build ({bld}), the rest by another\x1b[0m");
|
||||
}
|
||||
ProvCmd::Verify { dir } => {
|
||||
let dir = std::path::Path::new(&dir);
|
||||
|
||||
@@ -927,7 +927,18 @@ pub async fn repl(base: &Path, auth: SessionAuth) -> anyhow::Result<()> {
|
||||
// classes — so one YAML defines the whole engagement.
|
||||
if let Ok(text) = std::fs::read_to_string(path) {
|
||||
let meta = read_engagement_meta(&text);
|
||||
if let Some(t) = meta.target { if s.policy.in_hard_scope(&t) { s.target = Some(t.clone()); println!(" \x1b[2m· target: {t}\x1b[0m"); } else { println!(" \x1b[33m⚠ file's target {t} is outside its own scope — ignored\x1b[0m"); } }
|
||||
if let Some(t) = meta.target {
|
||||
if s.policy.in_hard_scope(&t) {
|
||||
// A wildcard target (`*.nasa.gov`) is not a
|
||||
// host to probe — seed with the apex, since
|
||||
// the scope already authorizes the subdomains.
|
||||
let host = harness::scope::host_of(&t);
|
||||
let seed = if let Some(apex) = host.strip_prefix("*.") { format!("https://{apex}") }
|
||||
else if t.contains("://") { t.clone() } else { format!("https://{host}") };
|
||||
s.target = Some(seed.clone());
|
||||
println!(" \x1b[2m· target: {seed}\x1b[0m");
|
||||
} else { println!(" \x1b[33m⚠ file's target {t} is outside its own scope — ignored\x1b[0m"); }
|
||||
}
|
||||
if !meta.models.is_empty() { s.models = meta.models.clone(); println!(" \x1b[2m· models: {}\x1b[0m", meta.models.join(", ")); }
|
||||
if let Some(f) = meta.focus { s.instructions = Some(f.clone()); println!(" \x1b[2m· focus: {f}\x1b[0m"); }
|
||||
if let Some(o) = meta.objective { s.objective = Some(o.clone()); println!(" \x1b[2m· objective: {o}\x1b[0m"); }
|
||||
|
||||
Reference in new issue
Block a user