From c258299eb6704a13686c4f4d375d243952af4e9c Mon Sep 17 00:00:00 2001 From: CyberSecurityUP Date: Sun, 4 Oct 2026 07:56:22 -0300 Subject: [PATCH] v4.2.3: full recon arsenal (KingOfBugBounty), version bump MIME-Version: 1.0 Content-Type: text/plain; charset=UTF-8 Content-Transfer-Encoding: 8bit RECON_SYS enriched with the concrete bug-bounty recon arsenal and tool pipelines (subfinder/amass/assetfinder/crt.sh → httpx liveness → gau/waybackurls/katana/ gospider URL harvest → JS analysis & secret regexes → arjun/x8 params → gf vuln patterns + qsreplace → ffuf/feroxbuster content discovery → naabu ports → dnsx/ nuclei takeovers → cloud bucket grep → targeted nuclei → chained pipeline), passive-first and scope-respecting. Shared by the black-box run path, so it applies identically to the CLI, the REPL and the web console. Version bumped to 4.2.3 across CLI/clap/web/README/TUTORIAL. 423 tests. Co-Authored-By: Claude Opus 4.8 --- README.md | 6 +++--- TUTORIAL.md | 4 ++-- neurosploit-rs/Cargo.lock | 4 ++-- neurosploit-rs/Cargo.toml | 2 +- neurosploit-rs/app/src/main.rs | 4 ++-- neurosploit-rs/crates/harness/src/pipeline.rs | 15 ++++++++++++++- web/public/index.html | 4 ++-- web/server.js | 6 +++--- 8 files changed, 29 insertions(+), 16 deletions(-) diff --git a/README.md b/README.md index 01e5fdc..31dcfcc 100755 --- a/README.md +++ b/README.md @@ -1,4 +1,4 @@ -

🧠 NeuroSploit v4.2.2

+

🧠 NeuroSploit v4.2.3

Stars @@ -8,7 +8,7 @@

- + @@ -52,7 +52,7 @@ Control TUI**. ### Highlights -> **New in v4.2.2** — **free, LLM-directed exploration**: an exploit agent's named +> **New in v4.2.3** — **free, LLM-directed exploration**: an exploit agent's named > class is a starting point, not a cage — it maps what the app actually does and > reports any class it can prove, with **authentication / identity** (login, signup, > password reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target and diff --git a/TUTORIAL.md b/TUTORIAL.md index f326f6e..46d3468 100644 --- a/TUTORIAL.md +++ b/TUTORIAL.md @@ -1,4 +1,4 @@ -# NeuroSploit — Tutorial & User Guide (v4.2.2) +# NeuroSploit — Tutorial & User Guide (v4.2.3) A complete, hands-on guide to installing, configuring and running NeuroSploit — the autonomous, multi-model penetration-testing harness. @@ -102,7 +102,7 @@ Agents **degrade gracefully**: if `rustscan` is absent they use `nmap`; if neith ### Verify ```bash -neurosploit --version # neurosploit 4.2.2 +neurosploit --version # neurosploit 4.2.3 neurosploit agents # {"vulns":255,...,"ai":30,...,"total":480} neurosploit models # all providers & models ``` diff --git a/neurosploit-rs/Cargo.lock b/neurosploit-rs/Cargo.lock index 213de3a..01b2b7c 100644 --- a/neurosploit-rs/Cargo.lock +++ b/neurosploit-rs/Cargo.lock @@ -940,7 +940,7 @@ dependencies = [ [[package]] name = "neurosploit" -version = "4.2.2" +version = "4.2.3" dependencies = [ "anyhow", "clap", @@ -957,7 +957,7 @@ dependencies = [ [[package]] name = "neurosploit-harness" -version = "4.2.2" +version = "4.2.3" dependencies = [ "anyhow", "base64", diff --git a/neurosploit-rs/Cargo.toml b/neurosploit-rs/Cargo.toml index 230bfd5..f364c42 100644 --- a/neurosploit-rs/Cargo.toml +++ b/neurosploit-rs/Cargo.toml @@ -3,7 +3,7 @@ members = ["crates/harness", "app"] resolver = "2" [workspace.package] -version = "4.2.2" +version = "4.2.3" edition = "2021" license = "MIT" repository = "https://github.com/JoasASantos/NeuroSploit" diff --git a/neurosploit-rs/app/src/main.rs b/neurosploit-rs/app/src/main.rs index 6bb8b00..ee45b63 100644 --- a/neurosploit-rs/app/src/main.rs +++ b/neurosploit-rs/app/src/main.rs @@ -13,8 +13,8 @@ use std::path::{Path, PathBuf}; #[command( name = "neurosploit", version, - about = "NeuroSploit v4.2.2 — multi-model autonomous pentest harness", - long_about = "NeuroSploit v4.2.2 — a Rust multi-model harness that drives a pool of LLMs \ + about = "NeuroSploit v4.2.3 — multi-model autonomous pentest harness", + long_about = "NeuroSploit v4.2.3 — a Rust multi-model harness that drives a pool of LLMs \ (API key or local subscription: Claude/Codex/Gemini/Grok/OpenCode/Hermes) to autonomously test a target. \ After recon it INTELLIGENTLY selects only the agents matching the discovered surface, runs \ them in parallel, then validates every finding by cross-model voting before reporting.\n\n\ diff --git a/neurosploit-rs/crates/harness/src/pipeline.rs b/neurosploit-rs/crates/harness/src/pipeline.rs index b875fd4..387ef50 100644 --- a/neurosploit-rs/crates/harness/src/pipeline.rs +++ b/neurosploit-rs/crates/harness/src/pipeline.rs @@ -94,7 +94,20 @@ const RECON_SYS: &str = "You are an elite web recon specialist on an AUTHORIZED - Fingerprint the tech stack and EXACT versions (server, framework, libraries, CMS, JS libs) from headers, HTML, asset paths and JS.\n\ - Analyze responses deeply: status codes, ALL headers, Set-Cookie flags, verbose errors/stack traces, content types, and length/timing differentials.\n\ - Map auth (cookie/JWT/OAuth), APIs (REST & GraphQL), and any dev/staging/internal hosts referenced anywhere.\n\ -- BUG-BOUNTY RECON TRICKS (use what's installed; degrade gracefully): expand scope — subdomains via crt.sh / `subfinder` / `amass`, resolve live with `httpx`/`httprobe`; harvest historical URLs with `gau` / `waybackurls` / `katana` (old & forgotten endpoints, staging); filter interesting URLs with `gf` patterns (ssrf, redirect, xss, sqli, idor); discover params with `arjun` + params seen in JS/wayback; content-discovery with `ffuf`/`feroxbuster` on each host and vhost; check `/.git`,`/.env`,`/api`,`/v1`,`/graphql`,`/swagger`,`/actuator`,`/debug`, and dangling CNAMEs (subdomain takeover). Prioritise auth/reset/payment/upload/admin/export flows.\n\ +- BUG-BOUNTY RECON ARSENAL (use what's installed; degrade gracefully to curl; PASSIVE-first; stay in scope; never hammer — respect rate limits, don't degrade the service). Chain the tools the way a top bug-hunter does:\n\ + · SUBDOMAINS (passive): `subfinder -d -all -silent`, `amass enum -passive -d `, `assetfinder --subs-only `, and `curl -s \"https://crt.sh/?q=%25.&output=json\" | jq -r '.[].name_value'`. Merge + unique (`anew`/`sort -u`). (The harness also pre-seeds live in-scope subdomains for a wildcard scope — test ALL of them.)\n\ + · LIVE HOSTS: `cat subs | httpx -silent -threads 150 -title -status-code -tech-detect -web-server` — note each host's status; 401/403 = auth surface worth a bypass; filter soft-404s.\n\ + · URL/ENDPOINT HARVEST: `echo | waybackurls`, `gau --threads 50`, `katana -u https:// -d 5 -jc -silent`, `gospider -s https:// -d 5`. These surface forgotten/staging/old endpoints. De-dup with `uro`.\n\ + · JS ANALYSIS: pull every `.js` (`katana ... | grep '\\.js$' | httpx -silent`), then grep for routes `/(api|v[0-9])/`, hidden params, secrets (`AKIA[0-9A-Z]{16}`, `AIza[0-9A-Za-z_-]{35}`, `api_key|token|secret`), and `sourceMappingURL`. Run `nuclei -t exposures/` on JS URLs.\n\ + · PARAMS: `arjun -i urls -oT params --stable`, `x8`, plus params seen in JS/wayback; `unfurl -u keys < urls | sort -u`.\n\ + · GF VULN PATTERNS (then act): `cat urls | gf xss|gf sqli|gf ssrf|gf redirect|gf lfi` → test with `qsreplace` (e.g. ssrf → `qsreplace 'http://169.254.169.254/latest/meta-data/'`, sqli → `qsreplace \"'\"`, lfi → `qsreplace '../../etc/passwd'`).\n\ + · CONTENT DISCOVERY: `ffuf -u https:///FUZZ -w -mc 200,301,302,403 -recursion` / `feroxbuster -u https:// --auto-tune -x php,asp,jsp,bak,old`; always check `/.git`,`/.env`,`/config.php`,`/wp-config.php`,`/api`,`/v1`,`/graphql`,`/swagger`,`/actuator`,`/debug`,`/.well-known`.\n\ + · PORTS (in scope only): `naabu -host -top-ports 1000 -silent | httpx -silent`.\n\ + · DNS/TAKEOVER: `dnsx -silent -a -cname -resp < subs`; dangling CNAME → takeover: `cat subs | httpx -silent | nuclei -t takeovers/`.\n\ + · CLOUD: grep URLs for `s3.amazonaws.com`, `storage.googleapis.com`, `blob.core.windows.net`; `cloud_enum -l targets`.\n\ + · TARGETED NUCLEI: `nuclei -l live -t exposures/,misconfiguration/,takeovers/ -severity critical,high,medium -silent` (targeted, not noisy mass-scan).\n\ + · PIPELINE example: `subfinder -d -all -silent | httpx -silent | katana -d 3 -jc | gf sqli | nuclei -t exploits/ -severity critical,high`.\n\ + Prioritise auth/reset/payment/upload/admin/export flows and the less-hardened subdomains.\n\ Base everything on real observed responses — never assume. Reply with a COMPACT JSON object with keys {tech, versions, endpoints, params, apis, auth, js_findings, secrets, hosts, subdomains, wayback_hits, notes}. No prose."; /// Operator directives (focus instructions + auth material) prepended to diff --git a/web/public/index.html b/web/public/index.html index c53adba..2e852a4 100644 --- a/web/public/index.html +++ b/web/public/index.html @@ -3,7 +3,7 @@ -NeuroSploit v4.2.2 — Console +NeuroSploit v4.2.3 — Console @@ -33,7 +33,7 @@

- v4.2.2 + v4.2.3
diff --git a/web/server.js b/web/server.js index d00bf89..cb3cb2b 100644 --- a/web/server.js +++ b/web/server.js @@ -1,7 +1,7 @@ #!/usr/bin/env node 'use strict'; /** - * NeuroSploit v4.2.2 — web console backend. + * NeuroSploit v4.2.3 — web console backend. * * Zero-dependency Node HTTP server that: * - serves the static SPA in ./public @@ -1487,7 +1487,7 @@ const server = http.createServer(async (req, res) => { } if (req.method === 'GET' && p === '/api/meta') { - return sendJson(res, 200, { version: "4.2.2", binary: BIN, root: ROOT }); + return sendJson(res, 200, { version: "4.2.3", binary: BIN, root: ROOT }); } // ---- providers / API keys (in-memory only, never persisted) ---- @@ -1521,7 +1521,7 @@ const server = http.createServer(async (req, res) => { loadPersistedJobs(); server.listen(PORT, () => { - console.log(`NeuroSploit v4.2.2 web console → http://localhost:${PORT}`); + console.log(`NeuroSploit v4.2.3 web console → http://localhost:${PORT}`); console.log(` binary : ${BIN || '(not found — build neurosploit-rs first)'}`); console.log(` agents : ${AGENTS_DIR}`); console.log(` runs : ${RUNS_DIR}`);