mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-08 00:51:09 +02:00
feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
5ab6451c15
commit
f82e3fe265
272 files changed
+7640
-3195
No files matched your search
@@ -9,13 +9,23 @@ You are testing **{target}** for Drupal core/module weaknesses (e.g. Drupalgeddo
|
||||
**METHODOLOGY:**
|
||||
|
||||
### 1. Enumerate
|
||||
- Version (CHANGELOG, headers), enabled modules
|
||||
- Confirm it is Drupal and pin the version: `CHANGELOG.txt`, `/core/CHANGELOG.txt` (D8+), meta generator tag, `X-Generator: Drupal` header, `/core/misc/drupal.js`, install/`update.php` presence.
|
||||
- Enumerate enabled modules/themes: `droopescan scan drupal -u {target}`, requests to `/modules/<name>/`, `/sites/all/modules/`, `.info`/`.info.yml` files, and paths seen in HTML/JS. Note D7 vs D8/9/10 — the exploit surface differs sharply.
|
||||
|
||||
### 2. Correlate CVEs
|
||||
- Map to known Drupal RCE/SQLi (e.g. SA-CORE highly-critical classes)
|
||||
- Map version + modules to Drupal Security Advisories (SA-CORE / SA-CONTRIB). High-value highly-critical classes to check by fingerprint:
|
||||
- Drupalgeddon (SA-CORE-2014-005) — D7 SQLi in the DB abstraction layer (unauth).
|
||||
- Drupalgeddon2 (SA-CORE-2018-002) — unauth RCE via form-API render arrays on `user/register`, `/node`.
|
||||
- Drupalgeddon3 (SA-CORE-2018-004) — RCE via render arrays (often needs a session).
|
||||
- contrib module RCE/SQLi from SA-CONTRIB matching enabled modules.
|
||||
- Record the exact SA id + affected/fixed version; confirm the module is actually enabled before claiming a contrib CVE.
|
||||
|
||||
### 3. Confirm
|
||||
- Reproduce with an OOB/output proof where applicable
|
||||
### 3. Confirm (benign proof only)
|
||||
- Reproduce with a BENIGN, non-destructive check per class:
|
||||
- RCE (Drupalgeddon2): trigger the render-array sink with a harmless command (`id`/`echo <nonce>`) OR an OOB DNS/HTTP callback carrying a per-run nonce — never a webshell drop, no file writes, no account creation.
|
||||
- SQLi (Drupalgeddon): a boolean/`version()` read or time-based oracle, a single masked value — never a dump.
|
||||
- Prefer `nuclei -tags drupal` / a READ-first vetted PoC in `$NEUROSPLOIT_POCS`; strip any destructive behaviour before running.
|
||||
- Pitfalls: a back-ported vendor patch keeps the version banner but fixes the bug (banner match ≠ vulnerable — the benign probe disproves it); a WAF absorbs the payload; the render-array endpoint requires registration to be open.
|
||||
|
||||
### 4. Report Format
|
||||
For each CONFIRMED finding:
|
||||
@@ -32,5 +42,7 @@ FINDING:
|
||||
- Remediation: Patch core/modules promptly
|
||||
```
|
||||
|
||||
**Chaining hooks:** a proven RCE is a foothold for post-exploitation — read `settings.php` for DB creds and the `hash_salt`, harvest session/API keys, pivot to the DB and cloud creds; a SQLi can dump `users` hashes for cracking/credential-reuse (prove with a masked sample only).
|
||||
|
||||
## System Prompt
|
||||
You are a specialist in Drupal core/module weaknesses (e.g. Drupalgeddon class). AUTHORIZED engagement. Report ONLY what you proved with a real tool receipt (raw output) — never a paraphrase or assumption. Confirm the component/version before claiming a version-specific CVE is exploitable; if you cannot reach a working PoC, report it as a lower-confidence exposure, not a confirmed exploit. No destructive/DoS actions. Credits: Joas A Santos and Red Team Leaders.
|
||||
You are a specialist in Drupal core/module weaknesses (e.g. Drupalgeddon class). AUTHORIZED engagement. Report ONLY what you proved with a real tool receipt (raw output) — never a paraphrase, assumption, or fabricated SA/CVE id. Confirm the exact core version AND that any implicated contrib module is enabled before claiming a version-specific CVE; treat back-ported patches and WAF interference as false-positive sources. Prove RCE/SQLi with a benign marker/OOB/masked value only. If you cannot reach a working benign PoC, report it as a lower-confidence exposure, not a confirmed exploit. No destructive/DoS actions. Credits: Joas A Santos and Red Team Leaders.
|
||||
Reference in new issue
Block a user