mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 21:19:49 +02:00
feat: PoC validator, Kali sandbox, intercept proxy, compliance, +8 validators
Closes the three benchmark gaps and adds the two the user asked for. poc.rs — re-runs each finding's recorded proof and sorts it into reproduced / changed / gone / unverifiable. The last two are kept apart deliberately: a PoC that could not be tested (out of scope now, state-changing, nothing recorded) is never reported as one that failed. Never re-runs a mutating request to "confirm" it. Can only lower a finding's standing, never raise it. Wired as a run pass (--revalidate-poc) and a subcommand (neurosploit poc <run> --apply). proxy.rs — own recording forward proxy (HTTP in full; HTTPS tunnelled with honest metadata, no fake CA) that chains upstream to Burp / Caido / ZAP / mitmproxy. A bare tool routes straight through it; own+tool records here and forwards for full TLS interception. Flows -> flows.jsonl, distinct hosts become passive-discovery leads. Harness and agent child commands share one route. sandbox.rs — Kali docker/podman container: no host network, no mounted socket, no-new-privileges, workdir mounted, proxy/transport env inherited. A missing runtime is an explicit error, never a silent fallback to host execution — the whole point being to keep attack payloads off the operator's host. Subcommands sandbox up|exec|install|down. compliance.rs — maps confirmed findings onto PCI-DSS v4.0, HIPAA Security Rule and SOC 2 controls. Phrased as "bears on control X", never "compliant/non- compliant"; the disclaimer is rendered on top and absence of a finding is never presented as compliance. Report section + `neurosploit compliance <run>`. validation.rs — 8 new deterministic validators (19 -> 27 classes): verbose errors/stack traces (CWE-209), cleartext/HSTS (319), CRLF response splitting (113), dangerous HTTP methods (650), GraphQL introspection, exposed backup files (530), Host header injection (644), cacheable private responses (525). Each names exactly what it saw and rejects the classic false positives (a block page echoing a payload, the SPA served under a bogus path, a copyright year mistaken for a code). All wired through RunConfig, the CLI (global --intercept/--sandbox; run-level --revalidate-poc/--compliance) and the web console's Tooling & assurance block. 328 tests. Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
This commit is contained in:
1 parent
64d6efa8c3
commit
f1fb6b8bc7
16 files changed
+2528
-12
No files matched your search
@@ -473,6 +473,10 @@ function renderReview() {
|
||||
{ k: 'Budget', v: budgetSummary() },
|
||||
{ k: 'Egress', v: state.authz.transport || 'direct' },
|
||||
{ k: 'Out-of-band', v: state.authz.oobDomain ? `*.${state.authz.oobDomain}` : 'none — blind classes stay leads' },
|
||||
{ k: 'Intercept', v: $('#fieldIntercept').value === 'off' ? 'direct' : $('#fieldIntercept').value },
|
||||
{ k: 'Sandbox', v: $('#fieldSandbox').value ? 'Kali container' : 'host' },
|
||||
{ k: 'PoC re-validation', v: $('#fieldRevalidatePoc').checked ? 'on' : 'off' },
|
||||
{ k: 'Compliance', v: (['fieldCompPci', 'fieldCompHipaa', 'fieldCompSoc2'].map((id) => $(`#${id}`).checked && $(`#${id}`).value).filter(Boolean).join(', ')) || 'none' },
|
||||
{ k: 'Target auth', v: state.auth.header ? 'header set' : (state.auth.roles.length ? `${state.auth.roles.length} role(s)` : 'none') },
|
||||
];
|
||||
$('#reviewGrid').innerHTML = items.map((it) => `
|
||||
@@ -514,6 +518,10 @@ async function startExploitation() {
|
||||
// Budget is opt-in: 'unlimited' sends nothing, so a run nobody budgeted is
|
||||
// the same full run it was before this control existed.
|
||||
budget: $('#fieldBudget').value,
|
||||
intercept: $('#fieldIntercept').value,
|
||||
sandbox: $('#fieldSandbox').value || undefined,
|
||||
revalidatePoc: $('#fieldRevalidatePoc').checked,
|
||||
compliance: ['fieldCompPci', 'fieldCompHipaa', 'fieldCompSoc2'].map((id) => $(`#${id}`).checked && $(`#${id}`).value).filter(Boolean),
|
||||
tokenLimit: Number($('#fieldTokenLimit').value) || undefined,
|
||||
order: $('#fieldOrder').value,
|
||||
samplePerRoute: Number($('#fieldSampleRoute').value) || undefined,
|
||||
|
||||
@@ -240,6 +240,43 @@
|
||||
</div>
|
||||
<div class="field-group"><label class="field-label" for="fieldSampleRoute">Sample / route</label><input class="narrow" id="fieldSampleRoute" type="number" min="1" max="50" value="3" /><div class="field-help">Requests per endpoint family (<code>/api/users/{id}</code> is sampled, not enumerated).</div></div>
|
||||
</div>
|
||||
|
||||
<div>
|
||||
<div class="section-title">Tooling & assurance</div>
|
||||
<div class="section-desc">Optional. Route through a proxy, run in a container, re-check every PoC, and frame findings against a compliance framework.</div>
|
||||
</div>
|
||||
<div class="field-row">
|
||||
<div class="field-group"><label class="field-label" for="fieldIntercept">Intercepting proxy</label>
|
||||
<select class="narrow" id="fieldIntercept">
|
||||
<option value="off" selected>off · direct</option>
|
||||
<option value="own">own interceptor (record + passive discovery)</option>
|
||||
<option value="burp">Burp Suite</option>
|
||||
<option value="caido">Caido</option>
|
||||
<option value="zap">OWASP ZAP</option>
|
||||
<option value="mitmproxy">mitmproxy</option>
|
||||
<option value="own+burp">own + Burp</option>
|
||||
<option value="own+caido">own + Caido</option>
|
||||
</select>
|
||||
<div class="field-help">The harness and agent commands route through it. Full HTTPS interception needs one of the tools (own tunnels TLS).</div>
|
||||
</div>
|
||||
<div class="field-group"><label class="field-label" for="fieldSandbox">Sandbox</label>
|
||||
<select class="narrow" id="fieldSandbox">
|
||||
<option value="" selected>host (no container)</option>
|
||||
<option value="default">Kali container (kalilinux/kali-rolling)</option>
|
||||
</select>
|
||||
<div class="field-help">Runs attack commands off the host, with the Kali toolbox. Needs docker or podman.</div>
|
||||
</div>
|
||||
<div class="field-group"><label class="field-label">PoC re-validation</label>
|
||||
<div class="check-row"><input type="checkbox" id="fieldRevalidatePoc" /> <label for="fieldRevalidatePoc">Re-run every PoC; demote what no longer reproduces</label></div>
|
||||
</div>
|
||||
</div>
|
||||
<div class="field-group">
|
||||
<label class="field-label">Compliance mapping</label>
|
||||
<div class="check-row"><input type="checkbox" id="fieldCompPci" value="pci-dss" /> <label for="fieldCompPci">PCI-DSS v4.0</label></div>
|
||||
<div class="check-row"><input type="checkbox" id="fieldCompHipaa" value="hipaa" /> <label for="fieldCompHipaa">HIPAA Security Rule</label></div>
|
||||
<div class="check-row"><input type="checkbox" id="fieldCompSoc2" value="soc2" /> <label for="fieldCompSoc2">SOC 2 (Trust Services Criteria)</label></div>
|
||||
<div class="field-help">Maps confirmed findings onto control requirements in the report. Indicates gaps for an assessor — never a compliance verdict.</div>
|
||||
</div>
|
||||
</div>
|
||||
|
||||
<!-- Step 5 — Review -->
|
||||
|
||||
Reference in new issue
Block a user