feat: free LLM-directed exploration (not boxed in one class), auth/OAuth focus, WAF-aware UA

Field feedback from a live run (only SQLi being hit, auth flows skipped, scanner
UA behind a CDN):

- EXPLORE_DOCTRINE injected into every exploit prompt: the agent's named class is
  a starting point, not a cage. It maps what the app actually does and reports
  ANY class it can prove — with authentication/identity (login, signup, password
  reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target, plus
  business-logic/multi-step flows and both client- and back-end surfaces. When
  its own class yields nothing, it pivots instead of idling.
- Selection (SELECT_SYS) now covers the surface instead of collapsing into one
  family: diverse set, MUST include auth/identity agents when any auth/OAuth/JWT
  surface is present, include business-logic/access-control on authed/multi-step
  flows, cover client + back-end when both exist.
- UA quality: /ua browser sets a realistic Chrome UA (attribution stays in the
  X-NeuroSploit-Scan header) for accuracy behind a WAF/CDN, where a self-declaring
  scanner UA gets blocked/challenged and causes false negatives; /ua identify
  keeps the transparent NeuroSploit UA. The UA doctrine now tells agents to
  compare both early and switch to the browser UA if responses differ.

422 tests passing.

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-10-04 00:30:01 -03:00
1 parent 3a820f09e6
commit 45ad7bf359
2 files changed
+48 -10

No files matched your search

+13 -3
View File
@@ -769,9 +769,19 @@ pub async fn repl(base: &Path, auth: SessionAuth) -> anyhow::Result<()> {
}
"/ua" | "/useragent" => {
match arg {
"" => println!(" user-agent: {} \x1b[2m(identifies NeuroSploit traffic)\x1b[0m",
s.user_agent.clone().unwrap_or_else(harness::pipeline::default_user_agent)),
"default" | "reset" => { s.user_agent = None; println!(" user-agent reset to default (NeuroSploit)"); }
"" => {
println!(" user-agent: {} \x1b[2m(attribution is also carried by the X-NeuroSploit-Scan header)\x1b[0m",
s.user_agent.clone().unwrap_or_else(harness::pipeline::default_user_agent));
println!(" \x1b[2m/ua browser → a real Chrome UA (recommended behind a WAF/CDN — a scanner UA can be blocked/challenged and cause false negatives)\x1b[0m");
println!(" \x1b[2m/ua identify → the NeuroSploit UA (max transparency; some programs require it) · /ua <custom> · /ua reset\x1b[0m");
}
"default" | "reset" | "identify" => { s.user_agent = None; println!(" user-agent: NeuroSploit identifying UA (most transparent — defenders see the scan in the UA)"); }
"browser" | "chrome" | "realistic" | "stealth" => {
let ua = harness::pipeline::realistic_user_agent().to_string();
s.user_agent = Some(ua.clone());
println!(" \x1b[32muser-agent: realistic browser\x1b[0m — {ua}");
println!(" \x1b[2mbetter test quality behind a WAF/CDN; the scan stays attributable via the X-NeuroSploit-Scan header\x1b[0m");
}
u => { s.user_agent = Some(u.to_string()); println!(" user-agent: {u}"); }
}
}