feat: liveness preflight, auto-run registration agent, vault in .neurosploit

- Preflight: abort a run early with '✗ target unreachable … is DOWN' when the
  probe gets no HTTP response, instead of running agents against a dead host;
  print '✓ target is UP' otherwise.
- When no --auth/creds are set on a web run, force account_registration_and_forms
  to run first so the authenticated surface is always attempted and visible.
- Move the credential vault to <cwd>/.neurosploit/vault/<run-id>.json (persistent
  project store) via new RunConfig.vault_dir; header now prints the vault path at
  launch. engagement_ops + finish() resolve paths through vault_paths().
This commit is contained in:
CyberSecurityUP
2026-07-30 19:32:25 -03:00
parent a5cdd32a0a
commit a6643968e2
5 changed files with 65 additions and 12 deletions
+7 -1
View File
@@ -37,17 +37,23 @@
as a finder or in the validator voting panel, e.g.
`--model anthropic:claude-opus-5 --model moonshot:kimi-k3`.
- **Liveness preflight.** Before recon, the run confirms the target actually
answers HTTP; a dead host prints `✗ target unreachable — … is DOWN` and aborts
instead of running agents against nothing. A reachable host prints `✓ target is UP`.
- **Account registration & form analysis (+1 agent → total 430).** A new
`account_registration_and_forms` agent lets NeuroSploit reach the authenticated
surface on its own: it analyzes the app's forms (the deterministic probe now
extracts each `<form>`'s action/method/fields/kind/CSRF) and creates a benign
test account with **curl** or the **Playwright browser** when no creds are given.
When no `--auth`/creds are set on a web run, this agent is **run first
automatically** so the authenticated surface is always attempted (and visible).
- **Anti-flood guardrail (hard):** at most **2 accounts per engagement**, never
looping/scripting/batching the register endpoint or flooding the database —
reuse the account made; a test needing many sign-ups is reported as a lead and
stopped. Enforced in `SAFETY_DOCTRINE` (all flows) and the agent.
- **Credential vault:** every generated credential is saved to
**`<run-dir>/vault.json`** for the operator to consult; secrets are **masked in
**`.neurosploit/vault/<run-id>.json`** for the operator to consult; secrets are **masked in
the report**. The report adds a **"Test accounts created (DELETE after)"**
cleanup section listing each account and how it was created.
- **Finding labels:** findings are tagged **`auth_context`**