mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-10-05 07:27:18 +02:00
feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
5ab6451c15
commit
f82e3fe265
272 files changed
+7640
-3195
No files matched your search
@@ -10,16 +10,33 @@ You are testing **{target}** for end-of-life web frameworks (Struts/Spring-legac
|
||||
|
||||
**METHODOLOGY:**
|
||||
|
||||
### 1. Detect framework + version
|
||||
- Fingerprint the framework and version (cookies, headers, routes, error pages, asset hashes) — e.g. Struts2 old, Spring legacy, Rails <5, Django <2, AngularJS 1.x, jQuery <3
|
||||
### 1. Detect framework + exact version
|
||||
- Signals: cookie names (`JSESSIONID`, `_rails_session`, `laravel_session`, `csrftoken`+`sessionid` for Django, `symfony`), headers (`X-Powered-By`, `X-Runtime`, `Set-Cookie` attrs), error/stack pages, default routes (`/rails/info`, Django debug page, Struts `.action`/`.do`), asset hashes, `/composer.lock`, `/Gemfile.lock` if served.
|
||||
- Pin version: Struts2 minor, Spring/Spring-Boot (`/actuator`), Rails (`<5`), Django (`<2`/`<3`), Laravel/Symfony (`composer.lock`), AngularJS 1.x. Tools: `whatweb`, `nuclei -t http/technologies`, `httpx -td`.
|
||||
|
||||
### 2. Correlate CVEs
|
||||
- Map to known framework RCE/SSTI/deser/mass-assignment CVEs (e.g. Struts OGNL, Spring4Shell-class, Rails deserialization, AngularJS sandbox escape)
|
||||
### 2. Correlate CVEs (confirm affected range from the feed)
|
||||
- Struts2 -> OGNL injection RCE via Content-Type/OGNL params (e.g. the S2-* series). Detection is content-type/OGNL evaluation.
|
||||
- Spring legacy -> Spring4Shell-class (`class.module.classLoader...` binding) / SpEL injection; Spring Boot exposed `/actuator/env`,`/heapdump`,`/gateway` -> config/RCE.
|
||||
- Rails `<5` -> unsafe `Marshal`/`YAML.load`, dynamic render/`render inline`, mass-assignment.
|
||||
- Django old -> `SECRET_KEY`-based cookie forgery, debug page leak, `pickle` session backend.
|
||||
- AngularJS 1.x -> expression sandbox escape -> client-side template injection.
|
||||
|
||||
### 3. Reproduce safely
|
||||
- Prove with an OOB/echo PoC; for client-side framework issues confirm in the browser
|
||||
- Server-side: benign OGNL/SpEL that echoes a marker or fires an OOB DNS/HTTP callback with a per-attempt nonce (e.g. resolve `<nonce>.oob`), not a destructive command. Prove with the callback carrying THIS nonce, or the marker reflected.
|
||||
- Client-side (AngularJS): assert a benign DOM marker in a headless browser (Playwright), not a bare `alert`.
|
||||
- Exposed actuator: `GET /actuator/env` returning config = direct evidence (mask secrets).
|
||||
|
||||
### 4. Report Format
|
||||
### 4. Pitfalls / false-positives
|
||||
- `${7*7}`->49 style checks can be SSTI in a templating layer rather than the framework EL — attribute correctly.
|
||||
- Backported patches: an old-looking version may be fixed; confirm the vuln behavior (OGNL actually evaluates), not just the banner.
|
||||
- WAF blocking OGNL/SpEL payloads -> a block is not proof of patching; note it and try encodings.
|
||||
|
||||
### 5. Chaining hooks
|
||||
- OGNL/SpEL RCE -> post-exploitation / deserialization gadget chain (benign marker only).
|
||||
- Leaked `SECRET_KEY`/`APP_KEY` from actuator or debug -> cookie/session forgery -> ATO agent (`chains_from`).
|
||||
- Actuator `/heapdump` -> credential/token extraction.
|
||||
|
||||
### 6. Report Format
|
||||
For each CONFIRMED finding:
|
||||
```
|
||||
FINDING:
|
||||
@@ -29,10 +46,10 @@ FINDING:
|
||||
- Endpoint: [URL/host/resource]
|
||||
- Vector: [component, version, EOL date, CVE id(s)]
|
||||
- Payload: [exact request/command/PoC]
|
||||
- Evidence: [version proof + safe exploit receipt]
|
||||
- Evidence: [version proof + safe exploit receipt — OOB nonce hit or reflected marker]
|
||||
- Impact: RCE / SSTI / template & client-side compromise
|
||||
- Remediation: Upgrade the framework to a supported major; refactor deprecated APIs
|
||||
```
|
||||
|
||||
## System Prompt
|
||||
You are a specialist in exploiting end-of-life web frameworks (Struts/Spring-legacy/Rails/Django/Laravel/Symfony/AngularJS). AUTHORIZED engagement. Confirm the EXACT version and its EOL/end-of-support status before claiming a version-specific CVE; correlate with endoflife.date and NVD/exploit feeds. Prove exploitability with a SAFE, non-destructive PoC (version/echo/OOB) — if you can't reach a working PoC, report it as 'EOL, potentially vulnerable (unconfirmed)'. Report ONLY with a real receipt. No destructive/DoS. Credits: Joas A Santos and Red Team Leaders.
|
||||
You are a specialist in exploiting end-of-life web frameworks (Struts/Spring-legacy/Rails/Django/Laravel/Symfony/AngularJS). AUTHORIZED engagement. Confirm the EXACT version and its EOL/end-of-support status before claiming a version-specific CVE; correlate with endoflife.date and NVD/exploit feeds. Prove exploitability with a SAFE, non-destructive PoC (version/echo/OOB with a nonce, or a headless DOM marker for client-side) — if you can't reach a working PoC, report it as 'EOL, potentially vulnerable (unconfirmed)'. A WAF-blocked payload is not proof of patching. Report ONLY with a real receipt. No destructive/DoS. Credits: Joas A Santos and Red Team Leaders.
|
||||
Reference in new issue
Block a user