feat(net): fail-closed egress, self-hosted OOB channel, inbound SMS

transport.rs — internal engagements happen through a VPN, a bastion or a
tunnel, and the dangerous failure is silent: with the VPN down, 10.20.0.15
is a machine on the operator's own network and the scan succeeds against
the wrong host. So an internal target with no transport is refused before
any traffic leaves, and a transport that is up must prove it (the apparent
source address has to change) rather than be assumed. Supports SOCKS, HTTP
proxy, OpenVPN, SSH bastion (dynamic or single-host forward) and cloudflared.

oob.rs — our own Collaborator, self-hosted by default because callbacks are
engagement data (internal hostnames, resolver addresses, sometimes the
exfiltrated value). HTTP and DNS listeners written on tokio directly, no new
dependency. The two levels of proof are separated in code: an HTTP callback
proves egress, a DNS query proves only that a resolver saw the name — the
overclaim this channel otherwise invites.

inbox.rs — mail.tm and inbound SMS (Twilio or webhook). extract_code() scores
candidates by surrounding text and returns nothing rather than a guess, so a
copyright year never gets submitted as an OTP. A throttling claim requires
delivered messages carrying DISTINCT codes, not HTTP 200s.

Wired through RunConfig, the CLI (global flags, so a session cannot re-route
itself mid-engagement), the REPL and the web console's Authorization tab.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUP
2026-09-14 01:35:36 -03:00
co-authored by Claude Opus 5
parent 90b4614d94
commit 8aa776665a
12 changed files with 1901 additions and 2 deletions
+32
View File
@@ -460,6 +460,38 @@
<div class="field-help">OT blocks writes, disruptive actions, fuzzing and exploit payloads over industrial protocols, and caps the rate at ~1 req/s.</div>
</div>
</div>
<div class="section-title" style="margin-top:18px;">Egress &amp; out-of-band</div>
<div class="field-group">
<label class="field-label" for="transportSpec">Transport (how traffic reaches the target)</label>
<input id="transportSpec" type="text" placeholder="direct · socks5://127.0.0.1:1080 · openvpn:/path/client.ovpn · ssh://red@bastion.corp?forward=10.0.0.5:445 · cloudflared://db.internal:5432" spellcheck="false" />
<div class="field-help">
An <strong>internal</strong> target with no transport is <strong>refused</strong>, not tested — with the VPN down,
<code>10.20.0.15</code> belongs to whatever network this host is on, which is not the client's.
</div>
</div>
<div class="field-row">
<div class="field-group">
<label class="field-label" for="oobDomain">Out-of-band domain</label>
<input id="oobDomain" type="text" placeholder="oob.yourdomain.com" spellcheck="false" />
<div class="field-help">A wildcard pointed at this host. Without it blind SSRF/XXE/RCE can only be reported as leads — never confirmed.</div>
</div>
<div class="field-group">
<label class="field-label" for="oobHttp">OOB HTTP listener</label>
<input id="oobHttp" type="text" placeholder="0.0.0.0:8080" spellcheck="false" />
<div class="field-help">Where callbacks land. An HTTP callback proves egress; a DNS query alone does not.</div>
</div>
<div class="field-group">
<label class="field-label" for="oobDns">OOB DNS listener</label>
<input id="oobDns" type="text" placeholder="0.0.0.0:5353" spellcheck="false" />
<div class="field-help">Only if the zone is delegated here (NS record).</div>
</div>
</div>
<div class="field-group">
<label class="field-label" for="smsSpec">Inbound SMS (OTP &amp; rate-limit work)</label>
<input id="smsSpec" type="text" placeholder="twilio:&lt;sid&gt;:&lt;token&gt;:+15550101 · webhook:https://…/inbox:+15550101" spellcheck="false" />
<div class="field-help">A throttling claim counts <strong>delivered messages carrying distinct codes</strong>, not HTTP 200s.</div>
</div>
</div>
<div class="modal-panel" data-mpanel="creds" hidden>
<div class="field-group">