mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-07 08:27:22 +02:00
feat: importable scope configs + /scope-file REPL command; Rockstar & NASA templates
- /scope-file <path> (aliases /scopefile, /import-scope): import a ready scope config (hard allowlist + exclusions + guardrails) in the REPL — one step to "scope set correctly", instead of typing /inscope repeatedly. Pins the scope. - scope_pinned: once scope is set explicitly (scope-file / /inscope / capability), /target no longer re-derives the scope from the target, so an imported allowlist is not clobbered by picking a target. - examples/scopes/rockstargames.yaml and examples/scopes/nasa.yaml — ready TEMPLATES scoped to *.rockstargames.com / *.nasa.gov with conservative, bounty/VDP-safe guardrails (no destructive verbs, no mass accounts, low rate, forbidden payloads) and a clear "verify the program's current in/out-of-scope before running" banner. Both parse and enforce; subdomain enumeration happens inside the wildcard boundary. 422 tests passing. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
4ed0226a79
commit
4ef1c9cada
3 files changed
+176
-4
No files matched your search
@@ -0,0 +1,63 @@
|
||||
# ===========================================================================
|
||||
# NeuroSploit scope config — NASA (TEMPLATE)
|
||||
# ---------------------------------------------------------------------------
|
||||
# ⚠ BEFORE YOU RUN: confirm this matches NASA's CURRENT VDP scope.
|
||||
# NASA Vulnerability Disclosure Policy: https://www.nasa.gov/nasa-vulnerability-disclosure-policy/
|
||||
# (coordinated via https://bugcrowd.com/nasa-vdp). Open the policy/program
|
||||
# page and align `hard` / `exclude` with the EXACT in- and out-of-scope assets
|
||||
# it lists today. A VDP is for good-faith disclosure — follow its rules.
|
||||
#
|
||||
# `*.nasa.gov` authorizes the apex AND every subdomain, so NeuroSploit's recon
|
||||
# will enumerate subdomains and test within this boundary. NASA runs MANY
|
||||
# subdomains/mission sites; several are explicitly out of scope and some are
|
||||
# third-party hosted — verify before testing.
|
||||
#
|
||||
# Import it:
|
||||
# neurosploit run "*.nasa.gov" --scope-file examples/scopes/nasa.yaml --subscription
|
||||
# or in the REPL:
|
||||
# /scope-file examples/scopes/nasa.yaml
|
||||
# /authorization https://www.nasa.gov/nasa-vulnerability-disclosure-policy/
|
||||
# /target *.nasa.gov
|
||||
# /run
|
||||
# ===========================================================================
|
||||
|
||||
# --- HARD: the allowlist. Only these are testable. ------------------------
|
||||
hard:
|
||||
- "*.nasa.gov" # apex + every subdomain (VERIFY against the VDP)
|
||||
- nasa.gov
|
||||
|
||||
# --- EXCLUDE: carve-outs that always beat the allowlist. ------------------
|
||||
# Fill from the VDP's OUT-OF-SCOPE list. Typical for a large gov org: auth/SSO
|
||||
# providers, third-party-hosted services, APIs with their own terms, and any
|
||||
# system the policy names as excluded. Examples are PLACEHOLDERS — verify.
|
||||
exclude:
|
||||
# - auth.launchpad.nasa.gov
|
||||
# - "*.ndc.nasa.gov"
|
||||
# - api.nasa.gov # has its own API terms / key system — check first
|
||||
|
||||
# --- SOFT: guardrails inside the boundary (VDP-safe, conservative) ---------
|
||||
soft:
|
||||
observe_only: []
|
||||
|
||||
# No state-mutating verbs, no account creation — a government VDP expects
|
||||
# minimal-impact, good-faith testing.
|
||||
allow_destructive_methods: false
|
||||
allow_account_creation: false
|
||||
max_accounts: 0
|
||||
|
||||
# Low rate: these are production government systems.
|
||||
max_requests_per_minute: 60
|
||||
|
||||
forbidden_payloads:
|
||||
- "drop table"
|
||||
- "truncate table"
|
||||
- "delete from"
|
||||
- "rm -rf /"
|
||||
- "shutdown"
|
||||
- "while(true)"
|
||||
|
||||
notes:
|
||||
- "Authorized under NASA's Vulnerability Disclosure Policy (good-faith research only)."
|
||||
- "No DoS, no social engineering, no physical testing, no disruption of operations or spacecraft/mission systems."
|
||||
- "Access only the minimum data needed to demonstrate a vulnerability; never exfiltrate or retain PII/ITAR/sensitive data; stop and report if you encounter it."
|
||||
- "Verify in/out-of-scope on the VDP page before each run — scope changes."
|
||||
@@ -0,0 +1,74 @@
|
||||
# ===========================================================================
|
||||
# NeuroSploit scope config — Rockstar Games (TEMPLATE)
|
||||
# ---------------------------------------------------------------------------
|
||||
# ⚠ BEFORE YOU RUN: confirm this matches the program's CURRENT scope.
|
||||
# Rockstar Games bug bounty: https://hackerone.com/rockstargames
|
||||
# Open the program page and align the `hard` allowlist and `exclude` list
|
||||
# below with the EXACT in-scope / out-of-scope assets it lists today. Scope
|
||||
# on a bounty program changes; this file is a starting point, not authority.
|
||||
#
|
||||
# HARD scope is enforced in code: a request whose host is not covered by `hard`
|
||||
# (or hit by `exclude`) is REFUSED before it leaves. `*.rockstargames.com`
|
||||
# authorizes the apex AND every subdomain, so NeuroSploit's recon will
|
||||
# enumerate subdomains and test them within this boundary.
|
||||
#
|
||||
# Import it:
|
||||
# neurosploit run "*.rockstargames.com" --scope-file examples/scopes/rockstargames.yaml --subscription
|
||||
# or in the REPL:
|
||||
# /scope-file examples/scopes/rockstargames.yaml
|
||||
# /authorization https://hackerone.com/rockstargames
|
||||
# /target *.rockstargames.com
|
||||
# /run
|
||||
# ===========================================================================
|
||||
|
||||
# --- HARD: the allowlist. Only these are testable. ------------------------
|
||||
# Start with the apex + all subdomains the user named. ADD the specific extra
|
||||
# roots the program lists (and REMOVE this wildcard if the program only allows
|
||||
# named subdomains — check first).
|
||||
hard:
|
||||
- "*.rockstargames.com" # apex + every subdomain
|
||||
- rockstargames.com # the apex itself
|
||||
|
||||
# --- EXCLUDE: carve-outs that always beat the allowlist. ------------------
|
||||
# Fill these in from the program's OUT-OF-SCOPE list. Common exclusions on a
|
||||
# gaming publisher: live game servers, payment/billing, support/helpdesk,
|
||||
# status pages, third-party-hosted marketing. Examples below are PLACEHOLDERS —
|
||||
# verify the real ones on the program page before relying on them.
|
||||
exclude:
|
||||
# - support.rockstargames.com
|
||||
# - "*.status.rockstargames.com"
|
||||
# - https://www.rockstargames.com/billing
|
||||
|
||||
# --- SOFT: guardrails inside the boundary (bounty-safe defaults) -----------
|
||||
soft:
|
||||
# Hosts you may LOOK at but never send payloads to.
|
||||
observe_only: []
|
||||
|
||||
# State-mutating verbs (DELETE/PUT/PATCH) stay OFF — a scan must not change
|
||||
# the target's state to "prove" a bug on someone's production.
|
||||
allow_destructive_methods: false
|
||||
|
||||
# No account creation by default. Most programs forbid mass registration;
|
||||
# flip to true only if the program allows it AND keep it to a couple accounts.
|
||||
allow_account_creation: false
|
||||
max_accounts: 0
|
||||
|
||||
# Conservative rate: a bounty target is production. Raise only within the
|
||||
# program's stated limit.
|
||||
max_requests_per_minute: 120
|
||||
|
||||
# Classes that damage production rather than demonstrate a bug — never run.
|
||||
forbidden_payloads:
|
||||
- "drop table"
|
||||
- "truncate table"
|
||||
- "delete from"
|
||||
- "rm -rf /"
|
||||
- "shutdown"
|
||||
- "while(true)"
|
||||
|
||||
# Free-text context for the agents (NOT enforced — prose, not a control).
|
||||
notes:
|
||||
- "Authorized under the Rockstar Games bug bounty program (https://hackerone.com/rockstargames)."
|
||||
- "Stay within the program's rules of engagement: no DoS, no social engineering, no spam/mass-account creation, no disruption of live game services."
|
||||
- "Prove data access with a benign canary, never pull real player PII."
|
||||
- "Verify in/out-of-scope on the program page before each run — scope changes."
|
||||
Reference in new issue
Block a user