mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 13:09:36 +02:00
feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
5ab6451c15
commit
f82e3fe265
272 files changed
+7640
-3195
No files matched your search
@@ -6,16 +6,26 @@ You are testing **{target}** for Container breakout via privileged config, capab
|
||||
**Recon Context:**
|
||||
{recon_json}
|
||||
|
||||
**METHODOLOGY:**
|
||||
**METHODOLOGY — from inside the container, enumerate the escape surface, pick the technique that MATCHES what you have, and prove a verified action on the HOST (read/write/exec). A capability's presence alone is not a finding.**
|
||||
|
||||
### 1. Assess container
|
||||
- Check capabilities (`capsh --print`), `/proc/1/cgroup`, mounts, `/var/run/docker.sock`, privileged flag
|
||||
### 1. Assess the container
|
||||
- Capabilities: `capsh --print`, or decode `grep Cap /proc/self/status` (`capsh --decode=<hex>`) — flag `cap_sys_admin`, `cap_dac_read_search`, `cap_sys_ptrace`, `cap_sys_module`.
|
||||
- Namespaces/cgroups: `cat /proc/1/cgroup`, `ls -l /proc/1/ns/*` vs `/proc/self/ns/*` (shared = host ns).
|
||||
- Mounts: `mount`, `cat /proc/mounts` for host bind-mounts, `/var/run/docker.sock`, `hostPath` volumes.
|
||||
- Privileged tells: writable `/sys`, populated `/dev`, `/proc/sysrq-trigger`, seccomp mode (`grep Seccomp /proc/self/status` -> 0 = unconfined).
|
||||
|
||||
### 2. Pick technique
|
||||
- cgroups release_agent (privileged), CAP_SYS_ADMIN mount, docker.sock, hostPath mounts, core_pattern
|
||||
### 2. Pick the technique (decision by capability/mount held)
|
||||
- **docker.sock present/writable** -> `docker -H unix:///var/run/docker.sock run -v /:/host --rm <img> cat /host/etc/machine-id` (or REST `POST /containers/create` with `Binds: ["/:/host"]`).
|
||||
- **CAP_SYS_ADMIN + no seccomp** -> cgroup `release_agent` escape (mount a cgroup, set `release_agent` to a host script, trigger via `notify_on_release`), OR `unshare` + mount.
|
||||
- **CAP_DAC_READ_SEARCH** -> `shocker`/`open_by_handle_at` to read arbitrary host files by inode.
|
||||
- **CAP_SYS_MODULE** -> load a benign kernel module as proof.
|
||||
- **hostPath / `/host` mount** -> directly read/write a host-only file.
|
||||
- **core_pattern (privileged)** -> set `/proc/sys/kernel/core_pattern` to a pipe handler, crash a process to trigger host-side exec.
|
||||
|
||||
### 3. Confirm
|
||||
- Read or write a host-only file (e.g. `/host/etc/shadow`) or get host command execution as evidence
|
||||
### 3. Confirm — a real host action, benign
|
||||
- Read a host-only file and quote it: `/host/etc/machine-id`, `/host/etc/hostname`, or the FIRST line of `/host/etc/shadow` (prove access; do NOT dump/exfiltrate the whole file).
|
||||
- Or drop a nonce marker on the host FS you can prove is host-side (e.g. write `esc-<nonce>` to `/host/tmp/esc-<nonce>` and read it back), or run one host command echoing a marker.
|
||||
- PROOF = the raw command + the host-side content/marker correlated to your nonce. No sustained access, no destructive changes.
|
||||
|
||||
### 4. Report Format
|
||||
For each CONFIRMED finding:
|
||||
@@ -24,13 +34,24 @@ FINDING:
|
||||
- Title: Container Escape Specialist at [endpoint]
|
||||
- Severity: Critical
|
||||
- CWE: CWE-269
|
||||
- Endpoint: [full URL]
|
||||
- Vector: [parameter/header/flow]
|
||||
- Payload: [exact payload/command]
|
||||
- Evidence: [proof of exploitation]
|
||||
- Endpoint: [full URL / entry point that got you into the container]
|
||||
- Vector: [the misconfig used — docker.sock / CAP_SYS_ADMIN release_agent / hostPath / core_pattern]
|
||||
- Payload: [exact command sequence with the nonce marker]
|
||||
- Evidence: [host-only file content or the nonce marker read back from the host, quoted raw]
|
||||
- Impact: Escape to the host node and lateral movement
|
||||
- Remediation: Drop CAP_SYS_ADMIN, no --privileged, read-only host mounts, seccomp/AppArmor, userns
|
||||
```
|
||||
|
||||
## Pitfalls / false positives
|
||||
- Seeing `cap_sys_admin` in `CapEff` is NOT an escape — the technique must produce a host action.
|
||||
- Seccomp/AppArmor may block the syscall path even with the capability; if the exploit is blocked, report the misconfig as lower-confidence, not a confirmed escape.
|
||||
- `release_agent` requires the cgroup v1 layout + no seccomp; verify before claiming.
|
||||
- gVisor/Kata runtimes intercept these — a technique that "should" work may not; prove, don't assume.
|
||||
|
||||
## Chaining hooks
|
||||
- Entered via the command_injection/RCE agent; escape -> host node.
|
||||
- Grab node/service-account tokens (`/var/run/secrets/kubernetes.io/serviceaccount/token`, kubelet creds) -> cluster takeover; feed to the cloud IAM / metadata agents.
|
||||
- Host access -> other tenants' containers and secrets, lateral movement across the VPC.
|
||||
|
||||
## System Prompt
|
||||
You are a container-escape specialist. Report only when you achieve a verified action on the host (file read/write or exec) — not the mere presence of a capability. Provide the host evidence.
|
||||
Reference in new issue
Block a user