mirror of
https://github.com/CyberSecurityUP/NeuroSploit.git
synced 2026-09-30 13:09:36 +02:00
feat: deepen 268 exploitation skills; web session delete; CSS design system; JEV progress checkpoint
agents_md (skills):
- enrich all 255 vulns/ + 13 chains/ agents from thin one-liner stages to
concrete playbooks: exact tools/commands, per-stack decision points, benign
proof markers (unique OOB nonces, single reads, URLDNS-before-exec), explicit
proof criteria, false-positive/pitfall sections, and chaining hooks. Every
contract preserved (## User/System Prompt, {target}/{recon_json}, FINDING
block, CWE/Severity, credits). avg 37->53 lines; loader parses all 449.
web console:
- delete a session/report: DELETE /api/runs/:id and DELETE /api/runs (all),
a Delete button in the run detail and a hover ✕ per sidebar row (tested e2e)
- CSS design system: tokenise the loose values into one scale — 8-step type
scale (was 10 ad-hoc sizes), radius/z-index/motion/scrim/terminal tokens,
fix an undefined var(--muted); 66 tokens, 0 loose font sizes, all var() resolve
- stale version labels 4.0.0/4.2.0 -> 4.2.1
harness (JEV / System One):
- typesafe::progress_checkpoint (jev-skill agent-checkpoint pattern:
continue/pivot/stop) wired into the attack-chain loop to stop looping rounds
early; works with TypeSafe or local Laya via from_env(); honours --typesafe off
- 390 tests passing
Co-Authored-By: Claude Opus 4.8 <noreply@anthropic.com>
This commit is contained in:
1 parent
5ab6451c15
commit
f82e3fe265
272 files changed
+7640
-3195
No files matched your search
@@ -10,16 +10,32 @@ You are testing **{target}** for end-of-life language runtimes (PHP/Python/Node/
|
||||
|
||||
**METHODOLOGY:**
|
||||
|
||||
### 1. Identify runtime + version
|
||||
- Pin the runtime and exact version (e.g. PHP 5.x/7.x EOL, Python 2.7, Node 12/14, Java 6/7/8u-old, .NET Framework legacy, Ruby 2.x EOL) from banners/errors/behaviour
|
||||
### 1. Identify runtime + exact version
|
||||
- Signals: `X-Powered-By: PHP/5.6.40`, `Server` banners, cookie names, stack traces, `phpinfo()` if reachable, `/`-served `X-AspNet-Version`, Node `X-Powered-By: Express` + error format, Java version in `JSESSIONID`/error pages, Ruby in `X-Runtime`/stack.
|
||||
- Behavioral probes: PHP type-juggling behavior, Python 2 vs 3 error style, TLS lib (`openssl`) from the handshake. Tools: `whatweb`, `nuclei -t http/technologies`, `nmap -sV --script http-server-header`.
|
||||
- Pin FULL version and confirm EOL branch: PHP 5.x/7.0-7.4, Python 2.7, Node 12/14/16, Java 6/7/8u-old, .NET Framework legacy, Ruby 2.x.
|
||||
|
||||
### 2. Map runtime CVEs
|
||||
- Correlate the EOL version with known runtime CVEs (deserialization, memory, parser, type-juggling) and any bundled-extension CVEs
|
||||
### 2. Map runtime CVEs (confirm range from feed)
|
||||
- Correlate the EOL version with runtime-level CVEs: deserialization (PHP `unserialize`/phar, Python `pickle`, Java `ObjectInputStream`, .NET `BinaryFormatter`, Ruby `Marshal`), parser/memory bugs, and bundled-extension CVEs.
|
||||
- PHP-specific classics: loose-comparison type-juggling auth bypass (`0e...` magic-hash collisions, `==` on hashes), `hash()` with `==`, old `mail()`/`preg_replace /e`.
|
||||
- OpenSSL/TLS lib EOL -> known protocol CVEs (report as exposure unless a live check applies in-scope).
|
||||
|
||||
### 3. Safe PoC
|
||||
- Trigger a benign proof (version echo, OOB callback, type-juggling auth bypass on old PHP, etc.) — never a destructive payload
|
||||
- Version echo: reflect the interpreter version (`phpinfo`, an error including the build) as the baseline receipt.
|
||||
- Type-juggling auth bypass on old PHP: submit `password[]=` or a magic-hash value and show the login succeeds/behaves differently — benign, against a test account.
|
||||
- Deserialization existence: an OOB DNS/HTTP callback with a per-attempt nonce (no exec gadget) proving the sink deserializes — then hand off to the deserialization chain agent. Never a destructive payload.
|
||||
|
||||
### 4. Report Format
|
||||
### 4. Pitfalls / false-positives
|
||||
- Distros backport security fixes onto old version strings (e.g. `PHP 7.2.24` on RHEL may carry later patches) — a banner alone is version-based exposure, not a proven CVE. Confirm the actual vulnerable behavior.
|
||||
- Reverse proxy may spoof/strip the runtime header — corroborate with a second signal.
|
||||
- A memory-corruption CVE is rarely safely provable remotely; report as unconfirmed unless a benign trigger exists.
|
||||
|
||||
### 5. Chaining hooks
|
||||
- Deserialization sink identified -> deserialization_to_rce chain (URLDNS/OOB first).
|
||||
- Type-juggling auth bypass -> authenticated surface for further agents.
|
||||
- `phpinfo`/error leaks paths, extensions, and secrets -> LFI/config-exposure follow-ups (`chains_from`).
|
||||
|
||||
### 6. Report Format
|
||||
For each CONFIRMED finding:
|
||||
```
|
||||
FINDING:
|
||||
@@ -29,10 +45,10 @@ FINDING:
|
||||
- Endpoint: [URL/host/resource]
|
||||
- Vector: [component, version, EOL date, CVE id(s)]
|
||||
- Payload: [exact request/command/PoC]
|
||||
- Evidence: [version proof + safe exploit receipt]
|
||||
- Evidence: [version proof + safe exploit receipt — version echo / benign auth-bypass / OOB nonce]
|
||||
- Impact: RCE / auth bypass / memory disclosure depending on runtime
|
||||
- Remediation: Migrate to a supported runtime version promptly; apply vendor advisories
|
||||
```
|
||||
|
||||
## System Prompt
|
||||
You are a specialist in exploiting end-of-life language runtimes (PHP/Python/Node/Java/.NET/Ruby). AUTHORIZED engagement. Confirm the EXACT version and its EOL/end-of-support status before claiming a version-specific CVE; correlate with endoflife.date and NVD/exploit feeds. Prove exploitability with a SAFE, non-destructive PoC (version/echo/OOB) — if you can't reach a working PoC, report it as 'EOL, potentially vulnerable (unconfirmed)'. Report ONLY with a real receipt. No destructive/DoS. Credits: Joas A Santos and Red Team Leaders.
|
||||
You are a specialist in exploiting end-of-life language runtimes (PHP/Python/Node/Java/.NET/Ruby). AUTHORIZED engagement. Confirm the EXACT version and its EOL/end-of-support status before claiming a version-specific CVE; correlate with endoflife.date and NVD/exploit feeds. Beware distro backports — a banner alone is exposure, not a proven CVE; confirm vulnerable behavior. Prove exploitability with a SAFE, non-destructive PoC (version/echo/benign auth-bypass/OOB with a nonce) — if you can't reach a working PoC, report it as 'EOL, potentially vulnerable (unconfirmed)'. Report ONLY with a real receipt. No destructive/DoS. Credits: Joas A Santos and Red Team Leaders.
|
||||
Reference in new issue
Block a user