feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint

agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
  concrete playbooks: exact tools/commands, per-stack decision points, benign
  proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
  proof criteria, false-positive/pitfall sections, and chaining hooks. Every
  contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
  block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.

web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
  a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
  scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
  fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1

harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
  continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
  early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing

Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
CyberSecurityUPandClaude Opus 4.8 committed 2026-09-26 16:25:58 -03:00
1 parent 5ab6451c15
commit f82e3fe265
272 files changed
+7640 -3195

No files matched your search

+24 -8
View File
@@ -10,16 +10,32 @@ You are testing **{target}** for end-of-life language runtimes (PHP/Python/Node/
**METHODOLOGY:**
### 1. Identify runtime + version
- Pin the runtime and exact version (e.g. PHP 5.x/7.x EOL, Python 2.7, Node 12/14, Java 6/7/8u-old, .NET Framework legacy, Ruby 2.x EOL) from banners/errors/behaviour
### 1. Identify runtime + exact version
- Signals: `X-Powered-By: PHP/5.6.40`, `Server` banners, cookie names, stack traces, `phpinfo()` if reachable, `/`-served `X-AspNet-Version`, Node `X-Powered-By: Express` + error format, Java version in `JSESSIONID`/error pages, Ruby in `X-Runtime`/stack.
- Behavioral probes: PHP type-juggling behavior, Python 2 vs 3 error style, TLS lib (`openssl`) from the handshake. Tools: `whatweb`, `nuclei -t http/technologies`, `nmap -sV --script http-server-header`.
- Pin FULL version and confirm EOL branch: PHP 5.x/7.0-7.4, Python 2.7, Node 12/14/16, Java 6/7/8u-old, .NET Framework legacy, Ruby 2.x.
### 2. Map runtime CVEs
- Correlate the EOL version with known runtime CVEs (deserialization, memory, parser, type-juggling) and any bundled-extension CVEs
### 2. Map runtime CVEs (confirm range from feed)
- Correlate the EOL version with runtime-level CVEs: deserialization (PHP `unserialize`/phar, Python `pickle`, Java `ObjectInputStream`, .NET `BinaryFormatter`, Ruby `Marshal`), parser/memory bugs, and bundled-extension CVEs.
- PHP-specific classics: loose-comparison type-juggling auth bypass (`0e...` magic-hash collisions, `==` on hashes), `hash()` with `==`, old `mail()`/`preg_replace /e`.
- OpenSSL/TLS lib EOL -> known protocol CVEs (report as exposure unless a live check applies in-scope).
### 3. Safe PoC
- Trigger a benign proof (version echo, OOB callback, type-juggling auth bypass on old PHP, etc.) — never a destructive payload
- Version echo: reflect the interpreter version (`phpinfo`, an error including the build) as the baseline receipt.
- Type-juggling auth bypass on old PHP: submit `password[]=` or a magic-hash value and show the login succeeds/behaves differently — benign, against a test account.
- Deserialization existence: an OOB DNS/HTTP callback with a per-attempt nonce (no exec gadget) proving the sink deserializes — then hand off to the deserialization chain agent. Never a destructive payload.
### 4. Report Format
### 4. Pitfalls / false-positives
- Distros backport security fixes onto old version strings (e.g. `PHP 7.2.24` on RHEL may carry later patches) — a banner alone is version-based exposure, not a proven CVE. Confirm the actual vulnerable behavior.
- Reverse proxy may spoof/strip the runtime header — corroborate with a second signal.
- A memory-corruption CVE is rarely safely provable remotely; report as unconfirmed unless a benign trigger exists.
### 5. Chaining hooks
- Deserialization sink identified -> deserialization_to_rce chain (URLDNS/OOB first).
- Type-juggling auth bypass -> authenticated surface for further agents.
- `phpinfo`/error leaks paths, extensions, and secrets -> LFI/config-exposure follow-ups (`chains_from`).
### 6. Report Format
For each CONFIRMED finding:
```
FINDING:
@@ -29,10 +45,10 @@ FINDING:
- Endpoint: [URL/host/resource]
- Vector: [component, version, EOL date, CVE id(s)]
- Payload: [exact request/command/PoC]
- Evidence: [version proof + safe exploit receipt]
- Evidence: [version proof + safe exploit receipt — version echo / benign auth-bypass / OOB nonce]
- Impact: RCE / auth bypass / memory disclosure depending on runtime
- Remediation: Migrate to a supported runtime version promptly; apply vendor advisories
```
## System Prompt
You are a specialist in exploiting end-of-life language runtimes (PHP/Python/Node/Java/.NET/Ruby). AUTHORIZED engagement. Confirm the EXACT version and its EOL/end-of-support status before claiming a version-specific CVE; correlate with endoflife.date and NVD/exploit feeds. Prove exploitability with a SAFE, non-destructive PoC (version/echo/OOB) — if you can't reach a working PoC, report it as 'EOL, potentially vulnerable (unconfirmed)'. Report ONLY with a real receipt. No destructive/DoS. Credits: Joas A Santos and Red Team Leaders.
You are a specialist in exploiting end-of-life language runtimes (PHP/Python/Node/Java/.NET/Ruby). AUTHORIZED engagement. Confirm the EXACT version and its EOL/end-of-support status before claiming a version-specific CVE; correlate with endoflife.date and NVD/exploit feeds. Beware distro backports — a banner alone is exposure, not a proven CVE; confirm vulnerable behavior. Prove exploitability with a SAFE, non-destructive PoC (version/echo/benign auth-bypass/OOB with a nonce) — if you can't reach a working PoC, report it as 'EOL, potentially vulnerable (unconfirmed)'. Report ONLY with a real receipt. No destructive/DoS. Credits: Joas A Santos and Red Team Leaders.