diff --git a/README.md b/README.md index 01e5fdc..31dcfcc 100755 --- a/README.md +++ b/README.md @@ -1,4 +1,4 @@ -
-
+
@@ -52,7 +52,7 @@ Control TUI**.
### Highlights
-> **New in v4.2.2** โ **free, LLM-directed exploration**: an exploit agent's named
+> **New in v4.2.3** โ **free, LLM-directed exploration**: an exploit agent's named
> class is a starting point, not a cage โ it maps what the app actually does and
> reports any class it can prove, with **authentication / identity** (login, signup,
> password reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target and
diff --git a/TUTORIAL.md b/TUTORIAL.md
index f326f6e..46d3468 100644
--- a/TUTORIAL.md
+++ b/TUTORIAL.md
@@ -1,4 +1,4 @@
-# NeuroSploit โ Tutorial & User Guide (v4.2.2)
+# NeuroSploit โ Tutorial & User Guide (v4.2.3)
A complete, hands-on guide to installing, configuring and running NeuroSploit โ
the autonomous, multi-model penetration-testing harness.
@@ -102,7 +102,7 @@ Agents **degrade gracefully**: if `rustscan` is absent they use `nmap`; if neith
### Verify
```bash
-neurosploit --version # neurosploit 4.2.2
+neurosploit --version # neurosploit 4.2.3
neurosploit agents # {"vulns":255,...,"ai":30,...,"total":480}
neurosploit models # all providers & models
```
diff --git a/neurosploit-rs/Cargo.lock b/neurosploit-rs/Cargo.lock
index 213de3a..01b2b7c 100644
--- a/neurosploit-rs/Cargo.lock
+++ b/neurosploit-rs/Cargo.lock
@@ -940,7 +940,7 @@ dependencies = [
[[package]]
name = "neurosploit"
-version = "4.2.2"
+version = "4.2.3"
dependencies = [
"anyhow",
"clap",
@@ -957,7 +957,7 @@ dependencies = [
[[package]]
name = "neurosploit-harness"
-version = "4.2.2"
+version = "4.2.3"
dependencies = [
"anyhow",
"base64",
diff --git a/neurosploit-rs/Cargo.toml b/neurosploit-rs/Cargo.toml
index 230bfd5..f364c42 100644
--- a/neurosploit-rs/Cargo.toml
+++ b/neurosploit-rs/Cargo.toml
@@ -3,7 +3,7 @@ members = ["crates/harness", "app"]
resolver = "2"
[workspace.package]
-version = "4.2.2"
+version = "4.2.3"
edition = "2021"
license = "MIT"
repository = "https://github.com/JoasASantos/NeuroSploit"
diff --git a/neurosploit-rs/app/src/main.rs b/neurosploit-rs/app/src/main.rs
index 6bb8b00..ee45b63 100644
--- a/neurosploit-rs/app/src/main.rs
+++ b/neurosploit-rs/app/src/main.rs
@@ -13,8 +13,8 @@ use std::path::{Path, PathBuf};
#[command(
name = "neurosploit",
version,
- about = "NeuroSploit v4.2.2 โ multi-model autonomous pentest harness",
- long_about = "NeuroSploit v4.2.2 โ a Rust multi-model harness that drives a pool of LLMs \
+ about = "NeuroSploit v4.2.3 โ multi-model autonomous pentest harness",
+ long_about = "NeuroSploit v4.2.3 โ a Rust multi-model harness that drives a pool of LLMs \
(API key or local subscription: Claude/Codex/Gemini/Grok/OpenCode/Hermes) to autonomously test a target. \
After recon it INTELLIGENTLY selects only the agents matching the discovered surface, runs \
them in parallel, then validates every finding by cross-model voting before reporting.\n\n\
diff --git a/neurosploit-rs/crates/harness/src/pipeline.rs b/neurosploit-rs/crates/harness/src/pipeline.rs
index b875fd4..387ef50 100644
--- a/neurosploit-rs/crates/harness/src/pipeline.rs
+++ b/neurosploit-rs/crates/harness/src/pipeline.rs
@@ -94,7 +94,20 @@ const RECON_SYS: &str = "You are an elite web recon specialist on an AUTHORIZED
- Fingerprint the tech stack and EXACT versions (server, framework, libraries, CMS, JS libs) from headers, HTML, asset paths and JS.\n\
- Analyze responses deeply: status codes, ALL headers, Set-Cookie flags, verbose errors/stack traces, content types, and length/timing differentials.\n\
- Map auth (cookie/JWT/OAuth), APIs (REST & GraphQL), and any dev/staging/internal hosts referenced anywhere.\n\
-- BUG-BOUNTY RECON TRICKS (use what's installed; degrade gracefully): expand scope โ subdomains via crt.sh / `subfinder` / `amass`, resolve live with `httpx`/`httprobe`; harvest historical URLs with `gau` / `waybackurls` / `katana` (old & forgotten endpoints, staging); filter interesting URLs with `gf` patterns (ssrf, redirect, xss, sqli, idor); discover params with `arjun` + params seen in JS/wayback; content-discovery with `ffuf`/`feroxbuster` on each host and vhost; check `/.git`,`/.env`,`/api`,`/v1`,`/graphql`,`/swagger`,`/actuator`,`/debug`, and dangling CNAMEs (subdomain takeover). Prioritise auth/reset/payment/upload/admin/export flows.\n\
+- BUG-BOUNTY RECON ARSENAL (use what's installed; degrade gracefully to curl; PASSIVE-first; stay in scope; never hammer โ respect rate limits, don't degrade the service). Chain the tools the way a top bug-hunter does:\n\
+ ยท SUBDOMAINS (passive): `subfinder -d