mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-05 07:27:18 +02:00
v4.2.3: full recon arsenal (KingOfBugBounty), version bump
RECON_SYS enriched with the concrete bug-bounty recon arsenal and tool pipelines (subfinder/amass/assetfinder/crt.sh → httpx liveness → gau/waybackurls/katana/ gospider URL harvest → JS analysis & secret regexes → arjun/x8 params → gf vuln patterns + qsreplace → ffuf/feroxbuster content discovery → naabu ports → dnsx/ nuclei takeovers → cloud bucket grep → targeted nuclei → chained pipeline), passive-first and scope-respecting. Shared by the black-box run path, so it applies identically to the CLI, the REPL and the web console. Version bumped to 4.2.3 across CLI/clap/web/README/TUTORIAL. 423 tests. Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
07f97076de
commit
c258299eb6
8 files changed
+29
-16
No files matched your search
@@ -1,4 +1,4 @@
|
|||||||
<h1 align="center">🧠 NeuroSploit v4.2.2</h1>
|
<h1 align="center">🧠 NeuroSploit v4.2.3</h1>
|
||||||
|
|
||||||
<p align="center">
|
<p align="center">
|
||||||
<a href="https://github.com/JoasASantos/NeuroSploit/stargazers"><img src="https://img.shields.io/github/stars/JoasASantos/NeuroSploit?style=for-the-badge&logo=github&color=8b5cf6" alt="Stars"></a>
|
<a href="https://github.com/JoasASantos/NeuroSploit/stargazers"><img src="https://img.shields.io/github/stars/JoasASantos/NeuroSploit?style=for-the-badge&logo=github&color=8b5cf6" alt="Stars"></a>
|
||||||
@@ -8,7 +8,7 @@
|
|||||||
</p>
|
</p>
|
||||||
|
|
||||||
<p align="center">
|
<p align="center">
|
||||||
<img src="https://img.shields.io/badge/Version-4.2.2-blue?style=flat-square">
|
<img src="https://img.shields.io/badge/Version-4.2.3-blue?style=flat-square">
|
||||||
<img src="https://img.shields.io/badge/Harness-Rust%20%7C%20tokio-e6b673?style=flat-square">
|
<img src="https://img.shields.io/badge/Harness-Rust%20%7C%20tokio-e6b673?style=flat-square">
|
||||||
<img src="https://img.shields.io/badge/License-MIT-green?style=flat-square">
|
<img src="https://img.shields.io/badge/License-MIT-green?style=flat-square">
|
||||||
<img src="https://img.shields.io/badge/MD%20Agents-479-red?style=flat-square">
|
<img src="https://img.shields.io/badge/MD%20Agents-479-red?style=flat-square">
|
||||||
@@ -52,7 +52,7 @@ Control TUI**.
|
|||||||
|
|
||||||
### Highlights
|
### Highlights
|
||||||
|
|
||||||
> **New in v4.2.2** — **free, LLM-directed exploration**: an exploit agent's named
|
> **New in v4.2.3** — **free, LLM-directed exploration**: an exploit agent's named
|
||||||
> class is a starting point, not a cage — it maps what the app actually does and
|
> class is a starting point, not a cage — it maps what the app actually does and
|
||||||
> reports any class it can prove, with **authentication / identity** (login, signup,
|
> reports any class it can prove, with **authentication / identity** (login, signup,
|
||||||
> password reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target and
|
> password reset, MFA, OAuth/OIDC/SAML, JWT, session) as a first-class target and
|
||||||
|
|||||||
+2
-2
@@ -1,4 +1,4 @@
|
|||||||
# NeuroSploit — Tutorial & User Guide (v4.2.2)
|
# NeuroSploit — Tutorial & User Guide (v4.2.3)
|
||||||
|
|
||||||
A complete, hands-on guide to installing, configuring and running NeuroSploit —
|
A complete, hands-on guide to installing, configuring and running NeuroSploit —
|
||||||
the autonomous, multi-model penetration-testing harness.
|
the autonomous, multi-model penetration-testing harness.
|
||||||
@@ -102,7 +102,7 @@ Agents **degrade gracefully**: if `rustscan` is absent they use `nmap`; if neith
|
|||||||
### Verify
|
### Verify
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
neurosploit --version # neurosploit 4.2.2
|
neurosploit --version # neurosploit 4.2.3
|
||||||
neurosploit agents # {"vulns":255,...,"ai":30,...,"total":480}
|
neurosploit agents # {"vulns":255,...,"ai":30,...,"total":480}
|
||||||
neurosploit models # all providers & models
|
neurosploit models # all providers & models
|
||||||
```
|
```
|
||||||
|
|||||||
Generated
+2
-2
@@ -940,7 +940,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "neurosploit"
|
name = "neurosploit"
|
||||||
version = "4.2.2"
|
version = "4.2.3"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"clap",
|
"clap",
|
||||||
@@ -957,7 +957,7 @@ dependencies = [
|
|||||||
|
|
||||||
[[package]]
|
[[package]]
|
||||||
name = "neurosploit-harness"
|
name = "neurosploit-harness"
|
||||||
version = "4.2.2"
|
version = "4.2.3"
|
||||||
dependencies = [
|
dependencies = [
|
||||||
"anyhow",
|
"anyhow",
|
||||||
"base64",
|
"base64",
|
||||||
|
|||||||
@@ -3,7 +3,7 @@ members = ["crates/harness", "app"]
|
|||||||
resolver = "2"
|
resolver = "2"
|
||||||
|
|
||||||
[workspace.package]
|
[workspace.package]
|
||||||
version = "4.2.2"
|
version = "4.2.3"
|
||||||
edition = "2021"
|
edition = "2021"
|
||||||
license = "MIT"
|
license = "MIT"
|
||||||
repository = "https://github.com/JoasASantos/NeuroSploit"
|
repository = "https://github.com/JoasASantos/NeuroSploit"
|
||||||
|
|||||||
@@ -13,8 +13,8 @@ use std::path::{Path, PathBuf};
|
|||||||
#[command(
|
#[command(
|
||||||
name = "neurosploit",
|
name = "neurosploit",
|
||||||
version,
|
version,
|
||||||
about = "NeuroSploit v4.2.2 — multi-model autonomous pentest harness",
|
about = "NeuroSploit v4.2.3 — multi-model autonomous pentest harness",
|
||||||
long_about = "NeuroSploit v4.2.2 — a Rust multi-model harness that drives a pool of LLMs \
|
long_about = "NeuroSploit v4.2.3 — a Rust multi-model harness that drives a pool of LLMs \
|
||||||
(API key or local subscription: Claude/Codex/Gemini/Grok/OpenCode/Hermes) to autonomously test a target. \
|
(API key or local subscription: Claude/Codex/Gemini/Grok/OpenCode/Hermes) to autonomously test a target. \
|
||||||
After recon it INTELLIGENTLY selects only the agents matching the discovered surface, runs \
|
After recon it INTELLIGENTLY selects only the agents matching the discovered surface, runs \
|
||||||
them in parallel, then validates every finding by cross-model voting before reporting.\n\n\
|
them in parallel, then validates every finding by cross-model voting before reporting.\n\n\
|
||||||
|
|||||||
@@ -94,7 +94,20 @@ const RECON_SYS: &str = "You are an elite web recon specialist on an AUTHORIZED
|
|||||||
- Fingerprint the tech stack and EXACT versions (server, framework, libraries, CMS, JS libs) from headers, HTML, asset paths and JS.\n\
|
- Fingerprint the tech stack and EXACT versions (server, framework, libraries, CMS, JS libs) from headers, HTML, asset paths and JS.\n\
|
||||||
- Analyze responses deeply: status codes, ALL headers, Set-Cookie flags, verbose errors/stack traces, content types, and length/timing differentials.\n\
|
- Analyze responses deeply: status codes, ALL headers, Set-Cookie flags, verbose errors/stack traces, content types, and length/timing differentials.\n\
|
||||||
- Map auth (cookie/JWT/OAuth), APIs (REST & GraphQL), and any dev/staging/internal hosts referenced anywhere.\n\
|
- Map auth (cookie/JWT/OAuth), APIs (REST & GraphQL), and any dev/staging/internal hosts referenced anywhere.\n\
|
||||||
- BUG-BOUNTY RECON TRICKS (use what's installed; degrade gracefully): expand scope — subdomains via crt.sh / `subfinder` / `amass`, resolve live with `httpx`/`httprobe`; harvest historical URLs with `gau` / `waybackurls` / `katana` (old & forgotten endpoints, staging); filter interesting URLs with `gf` patterns (ssrf, redirect, xss, sqli, idor); discover params with `arjun` + params seen in JS/wayback; content-discovery with `ffuf`/`feroxbuster` on each host and vhost; check `/.git`,`/.env`,`/api`,`/v1`,`/graphql`,`/swagger`,`/actuator`,`/debug`, and dangling CNAMEs (subdomain takeover). Prioritise auth/reset/payment/upload/admin/export flows.\n\
|
- BUG-BOUNTY RECON ARSENAL (use what's installed; degrade gracefully to curl; PASSIVE-first; stay in scope; never hammer — respect rate limits, don't degrade the service). Chain the tools the way a top bug-hunter does:\n\
|
||||||
|
· SUBDOMAINS (passive): `subfinder -d <apex> -all -silent`, `amass enum -passive -d <apex>`, `assetfinder --subs-only <apex>`, and `curl -s \"https://crt.sh/?q=%25.<apex>&output=json\" | jq -r '.[].name_value'`. Merge + unique (`anew`/`sort -u`). (The harness also pre-seeds live in-scope subdomains for a wildcard scope — test ALL of them.)\n\
|
||||||
|
· LIVE HOSTS: `cat subs | httpx -silent -threads 150 -title -status-code -tech-detect -web-server` — note each host's status; 401/403 = auth surface worth a bypass; filter soft-404s.\n\
|
||||||
|
· URL/ENDPOINT HARVEST: `echo <host> | waybackurls`, `gau <host> --threads 50`, `katana -u https://<host> -d 5 -jc -silent`, `gospider -s https://<host> -d 5`. These surface forgotten/staging/old endpoints. De-dup with `uro`.\n\
|
||||||
|
· JS ANALYSIS: pull every `.js` (`katana ... | grep '\\.js$' | httpx -silent`), then grep for routes `/(api|v[0-9])/`, hidden params, secrets (`AKIA[0-9A-Z]{16}`, `AIza[0-9A-Za-z_-]{35}`, `api_key|token|secret`), and `sourceMappingURL`. Run `nuclei -t exposures/` on JS URLs.\n\
|
||||||
|
· PARAMS: `arjun -i urls -oT params --stable`, `x8`, plus params seen in JS/wayback; `unfurl -u keys < urls | sort -u`.\n\
|
||||||
|
· GF VULN PATTERNS (then act): `cat urls | gf xss|gf sqli|gf ssrf|gf redirect|gf lfi` → test with `qsreplace` (e.g. ssrf → `qsreplace 'http://169.254.169.254/latest/meta-data/'`, sqli → `qsreplace \"'\"`, lfi → `qsreplace '../../etc/passwd'`).\n\
|
||||||
|
· CONTENT DISCOVERY: `ffuf -u https://<host>/FUZZ -w <wordlist> -mc 200,301,302,403 -recursion` / `feroxbuster -u https://<host> --auto-tune -x php,asp,jsp,bak,old`; always check `/.git`,`/.env`,`/config.php`,`/wp-config.php`,`/api`,`/v1`,`/graphql`,`/swagger`,`/actuator`,`/debug`,`/.well-known`.\n\
|
||||||
|
· PORTS (in scope only): `naabu -host <host> -top-ports 1000 -silent | httpx -silent`.\n\
|
||||||
|
· DNS/TAKEOVER: `dnsx -silent -a -cname -resp < subs`; dangling CNAME → takeover: `cat subs | httpx -silent | nuclei -t takeovers/`.\n\
|
||||||
|
· CLOUD: grep URLs for `s3.amazonaws.com`, `storage.googleapis.com`, `blob.core.windows.net`; `cloud_enum -l targets`.\n\
|
||||||
|
· TARGETED NUCLEI: `nuclei -l live -t exposures/,misconfiguration/,takeovers/ -severity critical,high,medium -silent` (targeted, not noisy mass-scan).\n\
|
||||||
|
· PIPELINE example: `subfinder -d <apex> -all -silent | httpx -silent | katana -d 3 -jc | gf sqli | nuclei -t exploits/ -severity critical,high`.\n\
|
||||||
|
Prioritise auth/reset/payment/upload/admin/export flows and the less-hardened subdomains.\n\
|
||||||
Base everything on real observed responses — never assume. Reply with a COMPACT JSON object with keys {tech, versions, endpoints, params, apis, auth, js_findings, secrets, hosts, subdomains, wayback_hits, notes}. No prose.";
|
Base everything on real observed responses — never assume. Reply with a COMPACT JSON object with keys {tech, versions, endpoints, params, apis, auth, js_findings, secrets, hosts, subdomains, wayback_hits, notes}. No prose.";
|
||||||
|
|
||||||
/// Operator directives (focus instructions + auth material) prepended to
|
/// Operator directives (focus instructions + auth material) prepended to
|
||||||
|
|||||||
@@ -3,7 +3,7 @@
|
|||||||
<head>
|
<head>
|
||||||
<meta charset="utf-8" />
|
<meta charset="utf-8" />
|
||||||
<meta name="viewport" content="width=device-width, initial-scale=1" />
|
<meta name="viewport" content="width=device-width, initial-scale=1" />
|
||||||
<title>NeuroSploit v4.2.2 — Console</title>
|
<title>NeuroSploit v4.2.3 — Console</title>
|
||||||
<link rel="icon" href="data:image/svg+xml,<svg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 100 100%22><text y=%22.9em%22 font-size=%2290%22>🧠</text></svg>">
|
<link rel="icon" href="data:image/svg+xml,<svg xmlns=%22http://www.w3.org/2000/svg%22 viewBox=%220 0 100 100%22><text y=%22.9em%22 font-size=%2290%22>🧠</text></svg>">
|
||||||
<link rel="stylesheet" href="/vendor/xterm.css" />
|
<link rel="stylesheet" href="/vendor/xterm.css" />
|
||||||
<link rel="stylesheet" href="/style.css" />
|
<link rel="stylesheet" href="/style.css" />
|
||||||
@@ -33,7 +33,7 @@
|
|||||||
<div class="sb-groups" id="sbGroups"><!-- populated by app.js --></div>
|
<div class="sb-groups" id="sbGroups"><!-- populated by app.js --></div>
|
||||||
|
|
||||||
<div class="sb-bottom">
|
<div class="sb-bottom">
|
||||||
<span class="sb-version" id="sbVersion">v4.2.2</span>
|
<span class="sb-version" id="sbVersion">v4.2.3</span>
|
||||||
<div class="sb-bottom-actions">
|
<div class="sb-bottom-actions">
|
||||||
<button class="icon-btn" id="btnOpenAuth" title="Auth & API keys">🔑</button>
|
<button class="icon-btn" id="btnOpenAuth" title="Auth & API keys">🔑</button>
|
||||||
<button class="icon-btn" id="btnOpenRepl" title="Open terminal (Ctrl+`)">❭_</button>
|
<button class="icon-btn" id="btnOpenRepl" title="Open terminal (Ctrl+`)">❭_</button>
|
||||||
|
|||||||
+3
-3
@@ -1,7 +1,7 @@
|
|||||||
#!/usr/bin/env node
|
#!/usr/bin/env node
|
||||||
'use strict';
|
'use strict';
|
||||||
/**
|
/**
|
||||||
* NeuroSploit v4.2.2 — web console backend.
|
* NeuroSploit v4.2.3 — web console backend.
|
||||||
*
|
*
|
||||||
* Zero-dependency Node HTTP server that:
|
* Zero-dependency Node HTTP server that:
|
||||||
* - serves the static SPA in ./public
|
* - serves the static SPA in ./public
|
||||||
@@ -1487,7 +1487,7 @@ const server = http.createServer(async (req, res) => {
|
|||||||
}
|
}
|
||||||
|
|
||||||
if (req.method === 'GET' && p === '/api/meta') {
|
if (req.method === 'GET' && p === '/api/meta') {
|
||||||
return sendJson(res, 200, { version: "4.2.2", binary: BIN, root: ROOT });
|
return sendJson(res, 200, { version: "4.2.3", binary: BIN, root: ROOT });
|
||||||
}
|
}
|
||||||
|
|
||||||
// ---- providers / API keys (in-memory only, never persisted) ----
|
// ---- providers / API keys (in-memory only, never persisted) ----
|
||||||
@@ -1521,7 +1521,7 @@ const server = http.createServer(async (req, res) => {
|
|||||||
loadPersistedJobs();
|
loadPersistedJobs();
|
||||||
|
|
||||||
server.listen(PORT, () => {
|
server.listen(PORT, () => {
|
||||||
console.log(`NeuroSploit v4.2.2 web console → http://localhost:${PORT}`);
|
console.log(`NeuroSploit v4.2.3 web console → http://localhost:${PORT}`);
|
||||||
console.log(` binary : ${BIN || '(not found — build neurosploit-rs first)'}`);
|
console.log(` binary : ${BIN || '(not found — build neurosploit-rs first)'}`);
|
||||||
console.log(` agents : ${AGENTS_DIR}`);
|
console.log(` agents : ${AGENTS_DIR}`);
|
||||||
console.log(` runs : ${RUNS_DIR}`);
|
console.log(` runs : ${RUNS_DIR}`);
|
||||||
|
|||||||
Reference in new issue
Block a user